Security Newsletter - EA breached through Slack cookie. Colonial was breached through old VPN password. • SRE Weekly Issue #274 • 📖 [The CloudSecList] Issue 91 • [tl;dr sec] #87 - Easy Temporary Cloud Access, Monopol-easy Money • AWS Managed Microsoft Active Directory (AD) and AD Connector now support AD authentication with AWS Transfer Family • Amazon Cognito now supports targeted sign out through refresh token revocation • Amazon Cognito is now available in the Middle East (BAH) Region • Amazon Cognito is now available in the Middle East (Bahrain) Region • Amazon Elastic Compute Cloud - 2 new 1 updated methods • AWS MediaConnect - 3 updated methods • AWS Elemental MediaLive - 15 updated methods • Amazon Appflow - 3 updated methods • Xen Security Advisories (XSA-372, 373, 374, 375, and 377) • runC Security Issue (CVE-2021-30465) • Announcing the AWS Security and Privacy Knowledge Hub for Australia and New Zealand • Creating a notification workflow from sensitive data discover with Amazon Macie, Amazon EventBridge, AWS Lambda, and Slack • How to implement SaaS tenant isolation with ABAC and AWS IAM • Phishing for AWS credentials via AWS SSO device code authentication • fwd:cloudsec • Open Source Insights • <a href="https://twitter.com/hashtag/Pacu" target="_blank">#Pacu</a> is officially part of <a href="https://twitter.com/kalilinux" target="_blank">@kalilinux</a>! <a href="https://t.co/kv7F5O2EBK" target="_blank">pkg.kali.org/pkg/pacu</a> <a href="https://t.co/i05UaLAYwu" target="_blank">github.com/RhinoSecurityL…</a> • [Blog post] Identity providers implementing 'device code' authentication flows are by design vulnerable to phishing attacks rendering MFA ineffective. 🎣 AWS SSO is one of them. <a href="https://t.co/H9EXW7zjfS" target="_blank">blog.christophetd.fr/phishing-for-a…</a> Includes proof-of-concept, IoCs and detection strategies with CloudTrail. • ⚛️ Mobile <a href="https://twitter.com/pdnuclei" target="_blank">@pdnuclei</a> templates 40+ nuclei templates that scan for: * Secrets and tokens * Interesting settings, configurations, &amp; method calls by <a href="https://twitter.com/0xgaurang" target="_blank">@0xgaurang</a> &amp; <a href="https://twitter.com/Tyl0us" target="_blank">@Tyl0us</a> <a href="https://twitter.com/hashtag/bugbounty" target="_blank">#bugbounty</a> <a href="https://twitter.com/hashtag/security" target="_blank">#security</a> <a href="https://t.co/5FRhHBY86N" target="_blank">github.com/optiv/mobile-n…</a> • 🚂 Steampipe: select * from cloud; Stop writing one-off scripts and using a bunch of tools/APIs Use SQL 🚀 to query across: * Your cloud env (AWS, Azure, ...) * Slack * GitHub * Kubernetes * Twitter * and many other resources <a href="https://t.co/vJFOy9F8ZU" target="_blank">steampipe.io</a> • This morning I sat down at my desk and my computer was super hot. Turns out there's an issue with VS Code / Electron where it will use 100% of a core waiting for the user to approve an update - even if it's 4 AM and that user won't be up for hours. <a href="https://t.co/utAsEbx8T7" target="_blank">github.com/microsoft/vsco…</a> • There have been times I've felt overwhelmed, stressed, and other concerns over fwd:cloudsec, but in looking at the CFP submissions so far, I'm so excited! This is going to be awesome. And the CFP is still open! 🤯(CFP closes July 16. Conference on Sep 13-14). • Heard this today from someone using a security tool that I wrote: “I don’t want to say that it only took 10 minutes to apply 300+ security guardrails with your tool… but it only took 10 minutes.” 😂 I love this. Makes me so happy. • Probably my favourite blog on ABAC in AWS IAM so far <a href="https://t.co/mCOcFMjY0e" target="_blank">aws.amazon.com/blogs/security…</a> It goes in to when ABAC is appropriate (when you have a large number of tenants in a single account), which is not always the case. The different service examples (DDB, ES, S3) are good too. • Learning Terraform was a turning point for me in my career and in my confidence as a technologist. I don’t use it as much these days, but I feel a twinge of nostalgia after seeing this. Terraform has come a long way. Congrats to the HashiCorp team and to the community. • I really think GitHub actions is about to be the silent vector for AWS account compromises. • Why is Amazon using Fastly.com for their CDN and not Cloudfront? • AWS Removes NAT Gateway’s Dependence on Internet Gateway for Private Communications • iOS 15 uses Cloudflare Warp to mask users IPs which is causing issues with Cloudfront GEO restrictions • Turn off BitLocker on Windows Devices before Importing a VM into AWS! • Top ten AWS identity health checks to improve security in the cloud • Crypto Exchange Security: "As of today, there are a total of 51 hacking events, with lost funds amounting to a total of approximately $2.1 billion at the time of these hacks, with the Mt.Gox hack of 2014 being the biggest casualty yet with $661,348,000 of stolen funds." • Ive created a easy to use Honeypot called "Pottr" for real time threat detection, please check out my demo, feedback is very much appreciated :) • AWS, Google Cloud, and Azure: How their security features compare - CSO Online • CyberArk Expands Availability of Identity Security Offerings on AWS Marketplace - Yahoo Finance • AWS Security Compliance Cheat Sheet - Security Boulevard
14
Monday June, 2021

AWS Managed Microsoft Active Directory (AD) and AD Connector now support AD authentication with AWS Transfer Family

Jun 11
AWS Directory Service for Microsoft Active Directory, also known as AWS Managed Microsoft AD, and AD Connector now enable you to use AD authentication with AWS Transfer Family, a fully managed service for transferring files over Secure File Transfer Protocol (SFTP), File Transfer Protocol over SSL (FTPS), and File Transfer …

Amazon Cognito now supports targeted sign out through refresh token revocation

Jun 11
By default, Amazon Cognito refresh tokens expire 30 days after a user signs in to a user pool. When you create an app, you can set the app's refresh token expiration to any value between 60 minutes and 10 years. Amazon Cognito now enables you to revoke refresh tokens in …

Amazon Cognito is now available in the Middle East (BAH) Region

Jun 9
Amazon Cognito is now available in the Middle East (BAH) Region. Amazon Cognito makes it easy to add authentication, authorization, and user management to your web and mobile apps. Amazon Cognito scales to millions of users and supports sign-in with social identity providers such as Apple, Facebook, Google, and Amazon, …

Amazon Cognito is now available in the Middle East (Bahrain) Region

Jun 9
Amazon Cognito is now available in the Middle East (Bahrain) Region. Amazon Cognito makes it easy to add authentication, authorization, and user management to your web and mobile apps. Amazon Cognito scales to millions of users and supports sign-in with social identity providers such as Apple, Facebook, Google, and Amazon, …

Amazon Elastic Compute Cloud - 2 new 1 updated methods

Jun 11
Amazon EC2 adds new AMI property to flag outdated AMIs

AWS MediaConnect - 3 updated methods

Jun 11
When you enable source failover, you can now designate one of two sources as the primary source. You can choose between two failover modes to prevent any disruption to the video stream. Merge combines the sources into a single stream. Failover allows switching between a primary and a backup stream.

AWS Elemental MediaLive - 15 updated methods

Jun 11
AWS MediaLive now supports OCR-based conversion of DVB-Sub and SCTE-27 image-based source captions to WebVTT, and supports ingest of ad avail decorations in HLS input manifests.

Amazon Appflow - 3 updated methods

Jun 10
Adding MAP_ALL task type support.

Xen Security Advisories (XSA-372, 373, 374, 375, and 377)

aws@amazon.comJun 8

Initial Publication Date: 2021/06/08 3:30 PM PDT

The Xen Security Team has released Xen Security Advisories 372, 373, 374, 375, and 377 regarding the Xen hypervisor. AWS customers’ data and instances are not affected by this issue, and no customer action is required.

runC Security Issue (CVE-2021-30465)

aws@amazon.comJun 8

Initial Publication Date: 2021/06/08 2:20 PM PDT

AWS is aware of the recently disclosed security issue in runC which is a component of many container management systems (CVE-2021-30465). With the exception of the AWS services listed below, no customer action is required to address this issue.

Amazon Elastic Container Service …

Announcing the AWS Security and Privacy Knowledge Hub for Australia and New Zealand

Phil RodriguesJun 14
Cloud technology provides organizations across Australia and New Zealand with the flexibility to adapt quickly and scale their digital presences up or down in response to consumer demand. In 2021 and beyond, we expect to see cloud adoption continue to accelerate as organizations of all sizes realize the agility, operational, …

Creating a notification workflow from sensitive data discover with Amazon Macie, Amazon EventBridge, AWS Lambda, and Slack

Bruno SilvieraJun 10
Following the example of the EU in implementing the General Data Protection Regulation (GDPR), many countries are implementing similar data protection laws. In response, many companies are forming teams that are responsible for data protection. Considering the volume of information that companies maintain, it’s essential that these teams are alerted …

How to implement SaaS tenant isolation with ABAC and AWS IAM

Michael PeltsJun 9
Multi-tenant applications must be architected so that the resources of each tenant are isolated and cannot be accessed by other tenants in the system. AWS Identity and Access Management (IAM) is often a key element in achieving this goal. One of the challenges with using IAM, however, is that the …
christophetd
Christophe @christophetd

[Blog post]
Identity providers implementing 'device code' authentication flows are by design vulnerable to phishing attacks rendering MFA ineffective.

🎣 AWS SSO is one of them.

blog.christophetd.fr/phishing-for-a…

Includes proof-of-concept, IoCs and detection strategies with CloudTrail.

39Jun 09 · 9:09 PM
clintgibler
Clint Gibler @clintgibler

⚛️ Mobile @pdnuclei templates

40+ nuclei templates that scan for:
* Secrets and tokens
* Interesting settings, configurations, & method calls

by @0xgaurang & @Tyl0us

#bugbounty #security

github.com/optiv/mobile-n…

35Jun 10 · 1:00 AM
clintgibler
Clint Gibler @clintgibler

🚂 Steampipe: select * from cloud;

Stop writing one-off scripts and using a bunch of tools/APIs

Use SQL 🚀 to query across:
* Your cloud env (AWS, Azure, ...)
* Slack
* GitHub
* Kubernetes
* Twitter
* and many other resources

steampipe.io

14Jun 07 · 5:00 PM
__steele
Aidan W Steele @__steele

This morning I sat down at my desk and my computer was super hot.

Turns out there's an issue with VS Code / Electron where it will use 100% of a core waiting for the user to approve an update - even if it's 4 AM and that user won't be up for hours.

github.com/microsoft/vsco…

8Jun 11 · 2:05 AM
0xdabbad00
Scott Piper @0xdabbad00

There have been times I've felt overwhelmed, stressed, and other concerns over fwd:cloudsec, but in looking at the CFP submissions so far, I'm so excited! This is going to be awesome. And the CFP is still open! 🤯(CFP closes July 16. Conference on Sep 13-14).

7Jun 14 · 3:51 AM
kmcquade3
Kinnaird McQuade💥☁️ @kmcquade3

Heard this today from someone using a security tool that I wrote:

“I don’t want to say that it only took 10 minutes to apply 300+ security guardrails with your tool… but it only took 10 minutes.” 😂

I love this. Makes me so happy.

0Jun 11 · 12:09 AM
elrowan
rowan @elrowan

Probably my favourite blog on ABAC in AWS IAM so far aws.amazon.com/blogs/security…

It goes in to when ABAC is appropriate (when you have a large number of tenants in a single account), which is not always the case. The different service examples (DDB, ES, S3) are good too.

4Jun 10 · 12:06 AM
kmcquade3
Kinnaird McQuade💥☁️ @kmcquade3

Learning Terraform was a turning point for me in my career and in my confidence as a technologist. I don’t use it as much these days, but I feel a twinge of nostalgia after seeing this. Terraform has come a long way. Congrats to the HashiCorp team and to the community.

HashiCorp
HashiCorp @HashiCorp

Today we are announcing the GA release of #Terraform 1.0. This marks a major milestone for interoperability, ease of upgrades, and maintenance for your automation workflows for what has become a standard for cloud provisioning. #HashiConf hashi.co/3glQiFt

1Jun 09 · 6:21 AM
jcfarris
Chris Farris @jcfarris

I really think GitHub actions is about to be the silent vector for AWS account compromises.

ben11kehoe
Ben Kehoe @ben11kehoe

@elrowan @github needs to bite the bullet and open some AWS accounts so Actions don’t need IAM User creds.

2Jun 08 · 2:13 AM

iOS 15 uses Cloudflare Warp to mask users IPs which is causing issues with Cloudfront GEO restrictions

With iOS/iPadOS 15 Apple uses Cloudflare’s warp technology to mask the users IP thus creating issues with the Cloudfront GEO restrictions.

Does this mean that people have to switch to AWS WAF to be able to properly detect the iOS 15 users?

Someone has reported that the relay is using …

Turn off BitLocker on Windows Devices before Importing a VM into AWS!

This may seem obvious at first, but if you forgot to disable and decrypt the drive you might get an error message like so:

 Windowsdeleted  ClientError: Boot Configuration Data store not found

If you get this error message, it could be because you have Bitlocker enabled. I googled that error …

buymeacoffee