Monday,
October 20, 2025

๐Ÿฅ– Palette Cleanser

Hello lovelies,

Since it was quiet on AWS security island this week, we're doing something a little different. fwd:cloudsec Europe 2025 videos were published this week, and Chef's selection includes all the AWS-relevant videos instead of the usual blog posts. If this upsets you, please publish a blog post this week so I have something to feed my subscribers. Remember to submit your content via email.

This caught my eye this week. For years, if you wanted to rewrite URLs or host headers on AWS, you had to bolt on something like Cloudflare, NGINX, or custom Lambda@Edge hacks. Now ALB just does it natively with regex matching and transforms. I'm excited because this is useful but also because I can't wait for the open redirect chains, host header injection, and sneaky path rewrites that bypass naive WAF rules or origin-based allowlists.

Have feedback about AWS Security Digest? Tell us here. This issue is also available to share online.

๐Ÿ“‹ Chef's selections

๐Ÿฅ— AWS security blogs

๐Ÿ› Reddit threads on r/aws


๐Ÿ’ธ Sponsor shoutout

Pleri logo

Meet Pleri: your AI-powered cloud security teammate. Sheโ€™s not a chatbot. Pleri proactively finds meaningful security work and fixes issues before they become problems.

Learn more about Pleri and see her in action.


๐Ÿค– Dessert

Dessert is made by robots, for those that enjoy the industrial content.

๐Ÿง IAM permission changes

๐Ÿช API changes

๐Ÿน IAM managed policy changes

โ˜• CloudFormation resource changes

๐ŸŽฎ Amazon Linux vulnerabilities

๐Ÿ“บ AWS security bulletins

    No bulletins this week.

๐Ÿšฌ Security documentation changes

YouTube Twitter LinkedIn