Monday,
December 01, 2025

๐Ÿฅ– Palette Cleanser

This week in AWS security has been dominated by two major events and not a lot of content otherwise, so I had to take things into my own hands.

First, re:Invent is about to begin. You can live stream the various keynotes if you are into that kind of thing. However, most of the big security announcements have already dropped, and there's a nice summary in chef's selections.

Second, phase 2 of Sha1-Hulud supply chain campaign kicked off, and every security vendor is covering it. There's even a pretty dashboard and search tool, but it seems to cover ~50% of affected repos. Something like 800 GitHub access tokens and 400 AWS credentials were compromised.

See you on the flip side.

Have feedback about AWS Security Digest? Tell us here. This issue is also available to share online.

๐Ÿ“‹ Chef's selections

  • Privilege escalation with SageMaker and there's more hiding in execution roles by Daniel Grzelak

    I don't understand SageMaker at all, but I did manage to make it spit out extra privileges by updating a notebook instance config, and it did help me understand a particular category of privilege escalation in AWS. Any time an AWS service executes a code-like thing with an execution role, and the code can be modified after initial creation, that results in an opportunity for privilege escalation. Can you spot that pattern in other services?

  • AWS pre:Invent security highlights: what changed and why it matters by Adan Alvarez

    Instead of reading three AWS announcement posts and guessing at the security impact, Adan breaks each update down into the risks, benefits, and detection signals that matter. Itโ€™s the version you need if you care about real-world attacker paths, not product announcements.

๐Ÿฅ— AWS security blogs

๐Ÿ› Reddit threads on r/aws


๐Ÿ’ธ Sponsor shoutout

Pleri logo

Meet Pleri: your AI-powered cloud security teammate. Sheโ€™s not a chatbot. Pleri proactively finds meaningful security work and fixes issues before they become problems.

Learn more about Pleri and see her in action.


๐Ÿค– Dessert

Dessert is made by robots, for those that enjoy the industrial content.

๐Ÿง IAM permission changes

๐Ÿช API changes

๐Ÿน IAM managed policy changes

โ˜• CloudFormation resource changes

๐ŸŽฎ Amazon Linux vulnerabilities

๐Ÿ“บ AWS security bulletins

    No bulletins this week.

๐Ÿšฌ Security documentation changes

YouTube Twitter LinkedIn