November 03, 2025
๐ฅ Palette Cleanser
When AWS isn't down, Azure must be? It's been a bad couple of weeks for the big cloud service providers. But as Roman Siewko points out about typical AWS availability, "as of October 25, 2025, the rolling figures are 99.84% (1-year) and 99.95% (5-year)."
Unfortunately, there were some reports that Lambda costs in us-east-1 spiked on outage day, so it might be worth checking your bill and having a chat with your AWS rep.
In addition to ๐ฅ chef's selections this week, there's also a special bonus: all the presentations from the 2025 SANS CloudSecNext Summit are live on YouTube. Most of them are cloud-agnostic or multi-cloud.
Have feedback about AWS Security Digest? Tell us here. This issue is also available to share online.
๐ Chef's selections
-
The Silent Attackers: Exploiting VPC Endpoints to Expose AWS Accounts of S3 Buckets Without a Trace by Maya Parizer
In the latest round of "how to win AWS account IDs and influence Amazon into tacitly admitting account IDs are not not secret" (double not intended), Maya got network activity CloudTrail events to reveal account IDs of arbitrary S3 buckets. This was the simplest of all the techniques previously disclosed, which makes it even more impressive - so it's sad to see it "fixed." Previous research from Ben Bridts, Sam Cox, and myself.
-
Bedrock'n'role: Annoying trust relationships in Bedrock service roles by Daniel Grzelak
It me, playing with Bedrock. For certain resource types, the management console will generate execution roles with overly permissive trust policies. Oddly, some resources have fully scoped trusts and others use wildcards.
-
Datadog threat roundup: Top insights for Q3 2025 by Greg Foss, Christophe Tafani-Dereeper, Eslam Salem, and Tesnim Hamdouni
I look forward to each iteration of this cloud threaty-threats report. In case you weren't aware, long-term creds are still getting leaked and used in many breaches, disclosed and undisclosed. Also, attackers like AI as much or more than your manager. But my favorite part is that AI is being used to generate profiles for fake remote workers applying for remote jobs. The included screenshot is of a very attractive man, which finally gives me hope that being born horribly unattractive was actually a good thing and I'll start getting more job offers because I'm clearly not AI-generated.
๐ฅ AWS security blogs
- ๐ฃ Amazon Route 53 Resolver now supports AWS PrivateLink
- ๐ฃ AWS Payment Cryptography is now available in Canada(Montreal), Africa (Cape Town) and Europe (London)
- ๐ฃ Amazon Cognito now supports resource indicators to simplify enhancing protection of OAuth 2.0 resources
- Designing compliant and secure betting and gaming applications on AWS by Manthan Raval
- Malware protection for Amazon Elastic File System with Cloud Storage Security by Neil Salamack
- AWS IoT Services Alignment with the European Union Cyber Resilience Act (EU CRA) by Syed Rehan
- MOSIP on AWS: Technical deep dive exploring architecture, implementation, and deployment models by Andrew Johnston
- Building large language models for the public sector on AWS by Laura Verghote
๐ Reddit threads on r/aws
๐ธ Sponsor shoutout
Meet Pleri: your AI-powered cloud security teammate. Sheโs not a chatbot. Pleri proactively finds meaningful security work and fixes issues before they become problems.
Learn more about Pleri and see her in action.
๐ค Dessert
Dessert is made by robots, for those that enjoy the industrial content.
๐ง IAM permission changes
๐ช API changes
- Amazon Connect Cases
- Amazon Elastic Compute Cloud
- AWS Lambda
- AWS Elemental MediaConvert
- Amazon Omics
- Amazon SageMaker Service
- Amazon Prometheus Service
- Amazon Bedrock AgentCore Control
- AWS Clean Rooms Service
- Amazon DocumentDB with MongoDB compatibility
- Amazon EC2 Container Service
- EMR Serverless
- AWS Glue
- Managed integrations for AWS IoT Device Management
- AWS Key Management Service
- Amazon Bedrock Runtime
- Amazon CloudWatch Application Signals
- Amazon Elastic Compute Cloud
- Amazon EC2 Container Service
- Amazon GameLift Streams
- AWS Ground Station
- AWS Organizations
- Amazon Simple Storage Service
- Amazon SageMaker Service
- Amazon WorkSpaces
- Amazon Kinesis
๐น IAM managed policy changes
- SageMakerStudioProjectProvisioningRolePolicy
- SageMakerStudioEMRContainersSystemNamespaceRolePolicy
- AWSSupplyChainFederationAdminAccess
- SageMakerStudioUserIAMPermissiveExecutionPolicy
- SageMakerStudioUserIAMDefaultExecutionPolicy
- SageMakerStudioEMRContainersSystemNamespaceRolePolicy
- SageMakerStudioAdminIAMPermissiveExecutionPolicy
- SageMakerStudioAdminIAMDefaultExecutionPolicy
- AWSMediaConnectServicePolicy
- AWSIoTSiteWiseReadOnlyAccess
- AWSIoTSiteWiseReadOnlyAccess
- AWSServiceRoleForUserSubscriptions
- AWSIPAMServiceRolePolicy
- AmazonConnectServiceLinkedRolePolicy
- AWSIPAMServiceRolePolicy
- AWSQuickSetupSSMDeploymentRolePolicy
โ CloudFormation resource changes
๐ฎ Amazon Linux vulnerabilities
๐บ AWS security bulletins
-
No bulletins this week.
๐ฌ Security documentation changes
- cli Documentation Update
- deadline-cloud Documentation Update
- deadline-cloud Documentation Update
- kms Documentation Update
- kms Documentation Update
- kms Documentation Update
- kms Documentation Update
- kms Documentation Update
- launchwizard Documentation Update
- athena Documentation Update
- audit-manager Documentation Update
- b2bi Documentation Update
- bedrock Documentation Update
- cli Documentation Update
- cli Documentation Update
- cli Documentation Update
- cli Documentation Update
- cli Documentation Update
- cli Documentation Update
- cognito Documentation Update
- cognito Documentation Update
- cognito Documentation Update
- emr Documentation Update
- keyspaces Documentation Update
- keyspaces Documentation Update
- keyspaces Documentation Update
- keyspaces Documentation Update
- keyspaces Documentation Update
- keyspaces Documentation Update
- keyspaces Documentation Update
- keyspaces Documentation Update
- keyspaces Documentation Update
- keyspaces Documentation Update
- keyspaces Documentation Update
- managed-flink Documentation Update
- managedservices Documentation Update
- managedservices Documentation Update
- managedservices Documentation Update
- managedservices Documentation Update
- managedservices Documentation Update
- managedservices Documentation Update
- managedservices Documentation Update
- marketplace Documentation Update
- medialive Documentation Update
- medialive Documentation Update
- medialive Documentation Update
- medialive Documentation Update
- medialive Documentation Update
- medialive Documentation Update
- medialive Documentation Update