October 27, 2025
🥖 Palette Cleanser
Earlier this week, I was worried y'all wouldn't get this issue on time because DynamoDB in us-east-1 took too many downers and couldn't balance it out with uppers fast enough. Whoever wrote the post-outage summary at AWS might want to consider using paragraphs next time. Luckily, Gergely Orosz wrote a fantastic, readable summary of the incident.
Whenever there's a big cloud outage, the hot takes come thick and fast. One in particular always comes up: no matter the root cause, it's evidence and impetus to go multi-cloud or move back on-prem. Each organization has to figure that out for themselves, but here's my warning: you already struggle trying to understand, hire for, and do security in AWS. On its own, AWS has ~430 services, 17,000+ API methods, and 19,000+ IAM permissions. Adding another cloud provider to the mix isn't going to make it twice as hard, it's going to make it virtually impossible.
But you don't have to listen to me. I'm just a super serious internet guy.
Have feedback about AWS Security Digest? Tell us here. This issue is also available to share online.
📋 Chef's selections
-
My AWS Account Got Hacked - Here Is What Happened by Zvi Wexlstein
Zvi's story is interesting because it shows how fast and methodical attackers are, and how a single hardcoded key can cascade into organizational control and financial damage. An exposed AWS key in a personal Next.js project led to a full account compromise that started with a spam email flood to hide AWS notifications. The attacker used the leaked key to create IAM users, launch EC2 instances for likely crypto mining, and set up SES DKIM records to prepare a phishing campaign from the victim’s own domains.
-
ECS on EC2: Covering Gaps in IMDS Hardening by Latacora
Sorry I missed this one in early October. When you run ECS tasks on EC2 instead of Fargate, all containers share the same host and can reach the EC2 instance metadata service, which exposes credentials for other tasks on that instance. Even with IMDSv2 and a hop limit of 1, tasks can sometimes still grab those credentials, so you have to explicitly block metadata access; otherwise, a compromised container can steal IAM roles and move laterally across tasks. More hardening deets inside.
-
Querying Terraform state with AWS Athena by Aidan Steele
There are some credibility challenges to claiming this is a security post, but it's certainly interesting, and if you squint you might be able to find a security use case. Turns out Athena can turn Terraform state in S3 into a queryable dataset by using the Amazon Ion serde to parse its pretty-printed JSON and unnesting resource arrays with cross joins. It’s a clever trick (Aidan has many) for auditing infrastructure at scale.
🥗 AWS security blogs
- 📣 AWS Secret-West Region is now available
- Reduce Vulnerabilities on AWS with Orca Security’s Reachability Analysis by Merin Eralil
- Enhance Identity Governance and Protection on AWS using Cisco Duo IAM by Sudha Thillai Govindarajan
- Enhancing container security in Amazon EKS Auto Mode with KubeArmor by Raj Seshadri
- Enhance email security using VPC endpoints with Amazon SES by Mamadou Ba
- How Fischer Identity rapidly built a natural-language tool for user permissions queries with AWS by Ceren Wickham
- Building Trusted Research Environments on AWS by James Grant
- How to choose the right AWS service for managing secrets and configurations by Zachary Miller
- Using AWS Secrets Manager Agent with Amazon EKS by Sumanth Culli
- The attendee guide to digital sovereignty sessions at AWS re:Invent 2025 by Brittany Bunch
🍛 Reddit threads on r/aws
💸 Sponsor shoutout
Meet Pleri: your AI-powered cloud security teammate. She’s not a chatbot. Pleri proactively finds meaningful security work and fixes issues before they become problems.
Learn more about Pleri and see her in action.
🤖 Dessert
Dessert is made by robots, for those that enjoy the industrial content.
🧁 IAM permission changes
🍪 API changes
- Amazon DataZone
- Amazon GameLift Streams
- Amazon Location Service Maps V2
- Amazon Location Service
- RTBFabric
- Amazon SageMaker Service
- AWS SecurityHub
- Amazon Aurora DSQL
- AWS Lambda
- Amazon Connect Service
- AmazonConnectCampaignServiceV2
- AWS Device Farm
- Amazon Elastic Compute Cloud
- AWS Elemental MediaLive
- Amazon Route 53
- RTBFabric
- Amazon EMR
- AWS Elemental MediaConvert
- AWSMarketplace Metering
🍹 IAM managed policy changes
- AWSSystemsManagerJustInTimeAccessServicePolicy
- AWSSystemsManagerChangeManagementServicePolicy
- AWSResourceExplorerServiceRolePolicy
- SageMakerStudioEMRContainersSystemNamespaceRolePolicy
- AmazonAuroraDSQLReadOnlyAccess
- AmazonAuroraDSQLFullAccess
- AmazonAuroraDSQLConsoleFullAccess
- AWSIPAMServiceRolePolicy
- ReadOnlyAccess
- AmazonEKSServiceRolePolicy
- AmazonAppStreamReadOnlyAccess
☕ CloudFormation resource changes
🎮 Amazon Linux vulnerabilities
- CVE-2025-40022
- CVE-2025-40020
- CVE-2025-40019
- CVE-2025-40023
- CVE-2025-40024
- CVE-2023-53733
- CVE-2025-40018
- CVE-2025-40021
- CVE-2025-50950
- CVE-2025-50949
- CVE-2025-50951
- CVE-2025-62813
- CVE-2025-12105
- CVE-2022-50568
- CVE-2023-53695
- CVE-2023-53724
- CVE-2022-50559
- CVE-2022-50582
- CVE-2023-53694
- CVE-2023-53720
- CVE-2022-50566
- CVE-2023-53706
- CVE-2022-50564
- CVE-2023-53726
- CVE-2023-53697
- CVE-2023-53722
- CVE-2022-50560
- CVE-2022-50575
- CVE-2025-40778
- CVE-2022-50561
- CVE-2023-53728
- CVE-2022-50577
- CVE-2023-53703
- CVE-2023-53731
- CVE-2023-53725
- CVE-2023-53711
- CVE-2022-50579
- CVE-2025-40780
- CVE-2023-53721
- CVE-2023-53723
- CVE-2023-53707
- CVE-2022-50562
- CVE-2023-53704
- CVE-2023-53708
- CVE-2022-50556
- CVE-2022-50569
- CVE-2023-53693
- CVE-2023-53710
- CVE-2023-53718
- CVE-2023-53702
- CVE-2023-53727
- CVE-2023-53700
- CVE-2023-53716
- CVE-2022-50567
- CVE-2022-50570
- CVE-2022-50571
- CVE-2022-50565
- CVE-2022-50563
- CVE-2023-53698
- CVE-2023-53709
- CVE-2022-50580
- CVE-2022-50572
- CVE-2022-50557
- CVE-2023-53714
- CVE-2025-11411
- CVE-2022-50573
- CVE-2022-50576
- CVE-2022-50574
- CVE-2023-53692
- CVE-2022-50578
- CVE-2023-53732
- CVE-2023-53730
- CVE-2023-53715
- CVE-2022-50581
- CVE-2022-50558
- CVE-2023-53696
- CVE-2023-53717
- CVE-2023-53705
- CVE-2025-8677
- CVE-2023-53713
- CVE-2023-53719
- CVE-2023-53712
- CVE-2023-53699
- CVE-2023-53729
- CVE-2025-53042
- CVE-2025-53067
- CVE-2025-53040
- CVE-2025-53053
- CVE-2025-53069
- CVE-2025-53062
- CVE-2025-53066
- CVE-2025-53054
- CVE-2025-53057
- CVE-2025-53045
- CVE-2025-53044
- CVE-2025-61748
- CVE-2025-40017
- CVE-2025-40010
- CVE-2025-40005
- CVE-2025-40008
- CVE-2025-40016
- CVE-2025-40009
- CVE-2025-40007
- CVE-2025-40015
- CVE-2025-40011
- CVE-2025-40013
- CVE-2025-40004
- CVE-2025-40012
📺 AWS security bulletins
-
No bulletins this week.
🚬 Security documentation changes
- acm Documentation Update
- acm Documentation Update
- acm Documentation Update
- amazonq Documentation Update
- appflow Documentation Update
- appflow Documentation Update
- appstream2 Documentation Update
- appstudio Documentation Update
- appstudio Documentation Update
- appsync Documentation Update
- aws-supply-chain Documentation Update
- aws-supply-chain Documentation Update
- cli Documentation Update
- cloudhsm Documentation Update
- codeartifact Documentation Update
- comprehend Documentation Update
- connect Documentation Update
- connect Documentation Update
- connect Documentation Update
- connect Documentation Update
- connect Documentation Update
- connect Documentation Update
- connect Documentation Update
- dcv Documentation Update
- dcv Documentation Update
- dcv Documentation Update
- dcv Documentation Update
- dcv Documentation Update
- deadline-cloud Documentation Update
- deepracer Documentation Update
- devops-guru Documentation Update
- devops-guru Documentation Update
- diagnostic-tools Documentation Update
- eks Documentation Update
- eks Documentation Update
- forecast Documentation Update
- forecast Documentation Update
- greengrass Documentation Update
- iot-sitewise Documentation Update
- iotanalytics Documentation Update
- lake-formation Documentation Update
- lex Documentation Update
- lex Documentation Update
- linux Documentation Update
- linux Documentation Update
- location Documentation Update
- machine-learning Documentation Update
- machine-learning Documentation Update
- machine-learning Documentation Update
- managedservices Documentation Update