SRE Weekly Issue #274
📖 [The CloudSecList] Issue 91
[tl;dr sec] #87 - Easy Temporary Cloud Access, Monopol-easy Money
AWS Managed Microsoft Active Directory (AD) and AD Connector now support AD authentication with AWS Transfer Family
Amazon Cognito now supports targeted sign out through refresh token revocation
Amazon Cognito is now available in the Middle East (BAH) Region
Amazon Cognito is now available in the Middle East (Bahrain) Region
Amazon Elastic Compute Cloud - 2 new 1 updated methods
AWS MediaConnect - 3 updated methods
AWS Elemental MediaLive - 15 updated methods
Xen Security Advisories (XSA-372, 373, 374, 375, and 377)
runC Security Issue (CVE-2021-30465)
Initial Publication Date: 2021/06/08 2:20 PM PDT
AWS is aware of the recently disclosed security issue in runC which is a component of many container management systems (CVE-2021-30465). With the exception of the AWS services listed below, no customer action is required to address this issue.
Amazon Elastic Container Service …
Announcing the AWS Security and Privacy Knowledge Hub for Australia and New Zealand
Creating a notification workflow from sensitive data discover with Amazon Macie, Amazon EventBridge, AWS Lambda, and Slack
How to implement SaaS tenant isolation with ABAC and AWS IAM
Phishing for AWS credentials via AWS SSO device code authentication






[Blog post]
Identity providers implementing 'device code' authentication flows are by design vulnerable to phishing attacks rendering MFA ineffective.
🎣 AWS SSO is one of them.
blog.christophetd.fr/phishing-for-a…
Includes proof-of-concept, IoCs and detection strategies with CloudTrail.




⚛️ Mobile @pdnuclei templates
40+ nuclei templates that scan for:
* Secrets and tokens
* Interesting settings, configurations, & method calls
by @0xgaurang & @Tyl0us
#bugbounty #security
github.com/optiv/mobile-n…



🚂 Steampipe: select * from cloud;
Stop writing one-off scripts and using a bunch of tools/APIs
Use SQL 🚀 to query across:
* Your cloud env (AWS, Azure, ...)
* Slack
* GitHub
* Kubernetes
* Twitter
* and many other resources
steampipe.io




This morning I sat down at my desk and my computer was super hot.
Turns out there's an issue with VS Code / Electron where it will use 100% of a core waiting for the user to approve an update - even if it's 4 AM and that user won't be up for hours.
github.com/microsoft/vsco…




There have been times I've felt overwhelmed, stressed, and other concerns over fwd:cloudsec, but in looking at the CFP submissions so far, I'm so excited! This is going to be awesome. And the CFP is still open! 🤯(CFP closes July 16. Conference on Sep 13-14).



Heard this today from someone using a security tool that I wrote:
“I don’t want to say that it only took 10 minutes to apply 300+ security guardrails with your tool… but it only took 10 minutes.” 😂
I love this. Makes me so happy.



Probably my favourite blog on ABAC in AWS IAM so far aws.amazon.com/blogs/security…
It goes in to when ABAC is appropriate (when you have a large number of tenants in a single account), which is not always the case. The different service examples (DDB, ES, S3) are good too.



Learning Terraform was a turning point for me in my career and in my confidence as a technologist. I don’t use it as much these days, but I feel a twinge of nostalgia after seeing this. Terraform has come a long way. Congrats to the HashiCorp team and to the community.

Today we are announcing the GA release of #Terraform 1.0. This marks a major milestone for interoperability, ease of upgrades, and maintenance for your automation workflows for what has become a standard for cloud provisioning. #HashiConf hashi.co/3glQiFt




I really think GitHub actions is about to be the silent vector for AWS account compromises.


iOS 15 uses Cloudflare Warp to mask users IPs which is causing issues with Cloudfront GEO restrictions
With iOS/iPadOS 15 Apple uses Cloudflare’s warp technology to mask the users IP thus creating issues with the Cloudfront GEO restrictions.
Does this mean that people have to switch to AWS WAF to be able to properly detect the iOS 15 users?
Someone has reported that the relay is using …
Turn off BitLocker on Windows Devices before Importing a VM into AWS!
This may seem obvious at first, but if you forgot to disable and decrypt the drive you might get an error message like so:
Windowsdeleted ClientError: Boot Configuration Data store not found
If you get this error message, it could be because you have Bitlocker enabled. I googled that error …
- 🖊️ This newsletter was fwd to you? Subscribe here
- 💌 Want to suggest new content: contact me or reply to this email
- ⚡️ Powered by Mailbrew