November 24, 2025
🥖 Palette Cleanser
Salutations, friends,
It looks like someone unleashed the pre:Invent security announcement cannon this week. There's flat rate pricing for CloudFront. STS can issue IAM roles and users JWTs to authenticate to stuff outside AWS. Developers can get temporary local creds with 'aws login'. Of course, AI agents are helping with incident response. And you can pay to enforce encryption in transit within VPCs, which feels kind of icky but in practice probably makes sense.
I'm not sure yet who is being put out of business this re:Invent, but it has to be someone. In case you are attending, AWS has written a guide for security enjoyers. I'll make sure to get you the YouTube playlist once it's all done and dusted.
Finally, thank you for all the feedback recently. A few of you have called me out for letting a few lower-quality articles slip into a recent issue. I'm sorry. Others have also asked for more chef's selections. I'll do my best to eliminate the former, but I rely on the internet content machine to produce enough of the good stuff for y'all to consume. Sometimes there just isn't enough. Please keep making cool content, and if you do create or find something worthy, send it my way at ilovecontent@awssecuritydigest.com.
Have feedback about AWS Security Digest? Tell us here. This issue is also available to share online.
📋 Chef's selections
-
Phishing for AWS Credentials via the New ‘aws login’ Flow by Adan Álvarez Vilchez
Adan didn't even let this feature fall out of his LinkedIn feed before finding a way to abuse it, and I like the simplicity of it. The feature is meant to make it easy for developers to get CLI creds in their local environment, which it does. But in an effort to support an edge case, AWS made it susceptible to phishing. The "--remote" flag was added for login when a browser isn't available on the local system, and so the browser session has to be on a different system by definition, meaning the authentication flow can be intermediated.
-
All Paths Lead to Your Cloud: A Mapping of Initial Access Vectors to Your AWS Environment by Golan Myers, Ofir Balassiano
I think putting "all paths" and "a mapping" in the title maybe overstates what's in this article. Yes, the resource types mentioned can be exposed, and yes, the descriptions are mostly good background reading and worth understanding for newer folks. However, there are many more resources that can be exposed and more ways to expose the ones mentioned. NLB, anyone? Cool tidbit though: "97% of [Palo] customers have AWS users in their cloud accounts." Yet Datadog claims, "two in five (39%) organizations still use IAM users." What does that say about each customer base? I'll let you pontificate.
-
Enable Whichever Version of Security Hub AWS is Supporting These Days by Rich Mogull
When there's a free spot in chef's selections, we can always rely on Rich to make a solid tutorial. Be careful you don't accidentally spend all your money on this one though. This piece walks you through the chaos of “new Security Hub vs Security Hub CSPM,” including how AWS split the product in half and stapled the non-CSPM bits back together under a new name. Rich even shows you how to enable delegated admin and org-wide Config (the part that quietly lights your wallet on fire) so you can see exactly how findings flow into the new aggregation layer.
🥗 AWS security blogs
- 📣 AWS Payments Cryptography announces support for post-quantum cryptography to secure data in transit
- 📣 AWS WAF announces Web Bot Auth support
- 📣 AWS Security Incident Response now provides agentic AI-powered investigation
- 📣 AWS introduces new VPC Encryption Controls and further raises the bar on data encryption
- 📣 Amazon EKS add-ons now supports the AWS Secrets Store CSI Driver provider
- 📣 AWS Control Tower now supports seven new compliance frameworks and 279 additional AWS Config rules
- 📣 AWS Security Token Service Now Supports Internet Protocol version 6 (IPv6)
- Enforce consistent tagging across IaC deployments with AWS Organizations Tag Policies by Nereida Woo
- AI-assisted game production: From static concept to interactive prototype by Armando Vargas
- Introducing attribute-based access control for Amazon S3 general purpose buckets by Matheus Guimaraes
- Simplify access to external services using AWS IAM Outbound Identity Federation by Donnie Prakoso
- Protect your Amazon S3 files with Menlo File Security by Erick Dame
- Enhancing API security with Amazon API Gateway TLS security policies by Anton Aleksandrov
- Streamline container image signatures with Amazon ECR managed signing by Josh Polkinghorn
- How to manage AI Bots with AWS WAF and enhance security by Kartik Bheemisetty
- AWS and Telos announce Xacta’s achievement of FedRAMP High authorization by Michael McGehee
- Practical steps to minimize key exposure using AWS Security Services by Jennifer Paz
- Accelerate investigations with AWS Security Incident Response AI-powered capabilities by Daniel Begimher
- The Agentic AI Security Scoping Matrix: A framework for securing autonomous AI systems by Aaron Brown
- Introducing the Landing Zone Accelerator on AWS Universal Configuration and LZA Compliance Workbook by Kevin Donohue
- Transfer data across AWS partitions with IAM Roles Anywhere by Jenn Reed
- How to update CRLs without public access using AWS Private CA by Rochak Karki
- Simplified developer access to AWS with ‘aws login’ by Shreya Jain
- AWS designated as a critical third-party provider under EU’s DORA regulation by Andrew Vennekotter
- Simplify cloud security with managed rules from AWS Marketplace for AWS Network Firewall by Dhanil Parwani
- New Amazon Threat Intelligence findings: Nation-state actors bridging cyber and kinetic warfare by CJ Moses
- Analyze AWS Network Firewall logs using Amazon OpenSearch dashboard by Hoorang Broujerdi
- How to automate Session Manager preferences across your organization by Nima Fotouhi
- Post-quantum (ML-DSA) code signing with AWS Private CA and AWS KMS by Panos Kampanakis
- Advanced notice: Amazon S3 to disable the use of SSE-C encryption by default for all new buckets and select existing buckets in April 2026 by Will Cavin
🍛 Reddit threads on r/aws
- Introducing VPC encryption controls: Enforce encryption in transit within and across VPCs in a Region
- AWS Secrets Manager announces managed external secrets
- Simplified developer access to AWS with ‘aws login’
- AWS Security Incident Response now offers metered pricing with free tier
- Is Cloud identity risk least privilege really enough?
- AWS Payments Cryptography announces support for post-quantum cryptography to secure data in transit
- Encrypt user data in database
- Route 53 domain registration verification email {mistakenly} flagged as spam
💸 Sponsor shoutout
Meet Pleri: your AI-powered cloud security teammate. She’s not a chatbot. Pleri proactively finds meaningful security work and fixes issues before they become problems.
Learn more about Pleri and see her in action.
🤖 Dessert
Dessert is made by robots, for those that enjoy the industrial content.
🧁 IAM permission changes
- secretsmanager
- cost-optimization-hub
- cloudformation
- invoicing
- partnercentral
- bedrock-agentcore
- signin
- organizations
- kinesisvideo
- braket
- tag
- lakeformation
- iam
- cloudtrail
- quicksight
- dms
- mgn
- identitystore
- securityhub
- s3
- license-manager
- autoscaling
- bedrock
- guardduty
- ecs
- application-signals
- notifications-contacts
- glue
- kafka
- odb
- pricingplanmanager
- imagebuilder
- backup
- logs
- dynamodb
- healthlake
- appstream
- eks-mcp
- athena
- airflow-serverless
- lambda
- es
- cloudformation
- glue
- billing
- route53
🍪 API changes
- Amazon API Gateway
- Amazon Athena
- Amazon Bedrock AgentCore Control
- Runtime for Amazon Bedrock Data Automation
- Amazon Bedrock Runtime
- Amazon Bedrock
- AWS CloudFormation
- Compute Optimizer Automation
- Amazon Connect Service
- Amazon Elastic Compute Cloud
- Amazon Elastic Container Registry
- Amazon Elastic Kubernetes Service
- AWS Invoicing
- Amazon Kinesis Video Streams
- AWS Key Management Service
- AWS Lambda
- Amazon Lex Model Building V2
- AWS Elemental MediaPackage v2
- odb
- AWS Organizations
- Amazon Q Connect
- Amazon QuickSight
- Amazon Relational Database Service
- Redshift Serverless
- Amazon Redshift
- Amazon SageMaker Service
- Security Incident Response
- Amazon Simple Email Service
- AWS Transfer Family
- Amazon CloudWatch Application Signals
- Auto Scaling
- Amazon Bedrock AgentCore
- Runtime for Amazon Bedrock Data Automation
- Data Automation for Amazon Bedrock
- Braket
- Amazon CloudFront
- AWS CloudTrail
- Amazon Connect Service
- AWS Device Farm
- AWS Database Migration Service
- Amazon Aurora DSQL
- Amazon Elastic Compute Cloud
- Amazon EC2 Container Service
- Elastic Load Balancing
- Amazon EMR
- AWS Glue
- EC2 Image Builder
- AWS Lake Formation
- AWS License Manager
- AWS Network Manager
- AWS Organizations
- Amazon QuickSight
- Amazon Recycle Bin
- Amazon Simple Storage Service
- Amazon SageMaker Service
- AWS SecurityHub
- Amazon API Gateway
- AmazonApiGatewayV2
- AWS Backup
- AWS Billing and Cost Management Pricing Calculator
- Amazon Bedrock Runtime
- AWS Billing
- AWSBillingConductor
- AWS Cost Explorer Service
- AWS CloudTrail
- AmazonConnectCampaignServiceV2
- Cost Optimization Hub
- Amazon DataZone
- Amazon Elastic Compute Cloud
- Amazon Elastic Container Registry
- Amazon EC2 Container Service
- Amazon EMR
- Amazon FSx
- Amazon GuardDuty
- AWS Health APIs and Notifications
- AWS Identity and Access Management
- Inspector2
- AWS Invoicing
- AWS Lambda
- Amazon CloudWatch Logs
- AWS MediaConnect
- AWS Elemental MediaLive
- AWS Network Firewall
- Network Flow Monitor
- Partner Central Channel API
- CloudWatch RUM
- Amazon Simple Storage Service
- Amazon SageMaker Service
- AWS Secrets Manager
- AWS Sign
- AWS Step Functions
- AWS Security Token Service
- Auto Scaling
- AWS Backup
- Amazon Bedrock Runtime
- AWS CloudFormation
- Amazon Connect Service
- Amazon Elastic Compute Cloud
- AWS Identity and Access Management
- Managed Streaming for Kafka
- Amazon CloudWatch Logs
- AWS Resource Groups Tagging API
- Amazon AppStream
- AWS Backup
- Amazon Bedrock
- AWS Device Farm
- AWS Database Migration Service
- Amazon Elastic Compute Cloud
- AWS Glue
- Amazon GuardDuty
- Amazon Lex Model Building V2
- AWS Elemental MediaLive
- AWS Elemental MediaPackage v2
- AmazonMWAAServerless
- Amazon OpenSearch Service
- AWS Parallel Computing Service
- Amazon Route 53 Resolver
🍹 IAM managed policy changes
- AmazonRedshiftFederatedAuthorization
- AWSMcpServiceActionsFullAccess
- AWSIdentityCenterExternalManagementPolicy
- DynamoDBGlobalTableSettingsManagementServiceRolePolicy
- AmazonS3TablesFullAccess
- AmazonConnectSynchronizationServiceRolePolicy
- AWSTransformApplicationECSDeploymentPolicy
- AWSTransformApplicationDeploymentPolicy
- AWSSecurityHubOrganizationsAccess
- AWSSecurityHubFullAccess
- SageMakerStudioProjectRoleMachineLearningPolicy
- AmazonConnectSynchronizationServiceRolePolicy
- AWS_ConfigRole
- AWSConfigServiceRolePolicy
- AWSSecurityIncidentResponseServiceRolePolicy
- SageMakerStudioProjectProvisioningRolePolicy
- AWSSecurityIncidentResponseServiceRolePolicy
- SageMakerStudioProjectProvisioningRolePolicy
- AmazonRDSPerformanceInsightsReadOnly
- AmazonRDSPerformanceInsightsFullAccess
- AmazonECSServiceRolePolicy
- AmazonEKSMCPReadOnlyAccess
- CloudWatchReadOnlyAccess
- CloudWatchFullAccessV2
- CloudWatchApplicationSignalsReadOnlyAccess
- CloudWatchApplicationSignalsFullAccess
- AmazonTimestreamInfluxDBFullAccessWithoutMarketplaceAccess
- AWSIncidentManagerResolverAccess
- AWSGroundStationAgentInstancePolicy
- SageMakerStudioProjectUserRolePolicy
- AWSGroundStationAgentInstancePolicy
- AWSBackupServiceRolePolicyForScans
- AWSBackupGuardDutyRolePolicyForScans
- AmazonGuardDutyFullAccess_v2
- AmazonGuardDutyFullAccess
- AWSBackupOperatorAccess
- AWSBackupFullAccess
- SignInLocalDevelopmentAccess
- AWSPartnerCentralChannelManagement
- AWSPartnerCentralChannelHandshakeApprovalManagement
- SecurityLakeResourceManagementServiceRolePolicy
- CostOptimizationHubReadOnlyAccess
- CostOptimizationHubAdminAccess
- AWSPrivateMarketplaceRequests
- AWSPartnerCentralFullAccess
- AWSLicenseManagerServiceRolePolicy
- CostOptimizationHubReadOnlyAccess
- AWSPartnerCentralFullAccess
- AmazonSageMakerSpacesRouterPolicy
- AmazonSageMakerSpacesControllerPolicy
- ComputeOptimizerServiceRolePolicy
- AWSWAFConsoleReadOnlyAccess
- AWSWAFConsoleFullAccess
- SageMakerStudioUserIAMPermissiveExecutionPolicy
- SageMakerStudioUserIAMDefaultExecutionPolicy
- SageMakerStudioDomainExecutionRolePolicy
- SageMakerStudioAdminIAMPermissiveExecutionPolicy
- SageMakerStudioAdminIAMDefaultExecutionPolicy
- CloudFrontReadOnlyAccess
- CloudFrontFullAccess
- Billing
- AmazonConnectServiceLinkedRolePolicy
- AWSWAFConsoleReadOnlyAccess
- AWSWAFConsoleFullAccess
- AWSBillingReadOnlyAccess
- AmazonTimestreamInfluxDBFullAccess
- AWSResourceExplorerServiceRolePolicy
- AWSElasticLoadBalancingServiceRolePolicy
- AIOpsConsoleAdminPolicy
- AmazonEBSCSIDriverPolicy
- AmazonDataZoneSageMakerEnvironmentRolePermissionsBoundary
- AmazonAppStreamServiceAccess
- AWSSecurityHubV2ServiceRolePolicy
☕ CloudFormation resource changes
🎮 Amazon Linux vulnerabilities
📺 AWS security bulletins
🚬 Security documentation changes
- IAM Documentation Update
- IAM Documentation Update
- amazon-mq Documentation Update
- amazon-mq Documentation Update
- apigateway Documentation Update
- apigateway Documentation Update
- apigateway Documentation Update
- apigateway Documentation Update
- apprunner Documentation Update
- audit-manager Documentation Update
- aurora-dsql Documentation Update
- autoscaling Documentation Update
- autoscaling Documentation Update
- aws-backup Documentation Update
- aws-backup Documentation Update
- aws-backup Documentation Update
- aws-backup Documentation Update
- aws-backup Documentation Update
- aws-backup Documentation Update
- aws-backup Documentation Update
- aws-backup Documentation Update
- bedrock Documentation Update
- bedrock Documentation Update
- cli Documentation Update
- cli Documentation Update
- cli Documentation Update
- cli Documentation Update
- cli Documentation Update
- cli Documentation Update
- cli Documentation Update
- cli Documentation Update
- cli Documentation Update
- config Documentation Update
- controltower Documentation Update
- controltower Documentation Update
- controltower Documentation Update
- controltower Documentation Update
- controltower Documentation Update
- controltower Documentation Update
- data-exchange Documentation Update
- dcv Documentation Update
- dcv Documentation Update
- drs Documentation Update
- drs Documentation Update
- drs Documentation Update
- ec2 Documentation Update
- fis Documentation Update
- govcloud-us Documentation Update
- govcloud-us Documentation Update
- guardduty Documentation Update