December 08, 2025
๐ฅ Palette Cleanser
Every week the internet gods roll a d20, and sometimes it lands on 20, like it did this week. There was a bit of everything for everyone. re:Invent concluded, and all the security talks are live. There's a nice written recap in Chef's selections.
The internet also caught on fire in a big way as a remote code execution (RCE) vulnerability was identified in React Server Components (CVE-2025-55182) and given a fancy name, "React2Shell". The Next.js framework happens to use the vulnerable components and so it is also vulnerable, pre-auth (CVE-2025-66478). Almost immediately several proof-of-concept exploits popped up, quickly leading to mass exploitation and AWS issuing an advisory about "China-nexus cyber threat groups." There was even some social media drama as researchers bypassed Vercel's WAF, only to have Vercel's CEO cry BS and then walk it all back. More deets on the bugs from Datadog here.
Canary tokens are near and dear to my heart. In 2017 I published the first AWS canary token framework. I thought that was cool, but it is childโs play compared to what Tracebit launched this week: a 100% free version of their security canary platform. Once you sign up, you can deploy canaries for AWS sessions, SSH keys, browser cookies, password manager credentials, and emails in under 60 seconds. The beauty of canaries is their asymmetry, because for a tiny amount of effort they give you high-fidelity, real-time breach detection. Props to our sponsor Tracebit.
Have feedback about AWS Security Digest? Tell us here. This issue is also available to share online.
๐ Chef's selections
-
re:Invent 2025 recap by Chris Farris
I absolutely love this recap, even if the announcements are largely pre:Invent. Chris has elite snark and too much AWS experience for his own good. I feel like I learned more nuance from this one collection of stuff than from many deep technical posts. For example, "you can now explicitly disable SSE-C - a technique ransomware syndicates use to encrypt your data when you leak an access key."
-
AWS Lambda Managed Instances: A Security Overview by Eduard Agavriloae
This post provides an early security look at AWS Lambda Managed Instances, a new model where Lambda functions run on Bottlerocket-based EC2 instances controlled by AWS. Eduard found the environment far more locked down than ECS, EKS, or SageMaker nodes, with strict role-modification denials, no direct access paths, and a set of new โElevatorโ components orchestrating networking, isolation, and execution. The result is both a hardened design and a rare window into how Lambda likely works under the hood.
-
Amazon CloudFront mTLS with open-source serverless CA by Paul Schwarzenberger
This guide shows how to set up mutual TLS for Amazon CloudFront using an open source serverless private CA, including how to deploy the CA, create a CloudFront trust store, and validate access with a client certificate. CloudFront mTLS is brand new, and Paul highlights some important early lessons, such as the fact that the CA bundle must be stored in an S3 bucket in us-east-1 with a text/plain content type or CloudFront will not accept it. He is also salty that many services still have their own separate and inconsistent trust store systems, which creates real challenges for anyone trying to run mTLS at scale.
๐ฅ AWS security blogs
- ๐ฃ AWS Security Hub is now generally available with near real-time risk analytics
- ๐ฃ Amazon CloudWatch launches unified management and analytics for operational, security, and compliance data
- ๐ฃ AWS Security Agent (Preview): AI agent for proactive app security
- New AWS Security Agent secures applications proactively from design to deployment (preview) by Esra Kayabali
- China-nexus cyber threat groups rapidly exploit React2Shell vulnerability (CVE-2025-55182) by CJ Moses
๐ Reddit threads on r/aws
๐ธ Sponsor shoutout
Meet Pleri: your AI-powered cloud security teammate. Sheโs not a chatbot. Pleri proactively finds meaningful security work and fixes issues before they become problems.
Learn more about Pleri and see her in action.
๐ค Dessert
Dessert is made by robots, for those that enjoy the industrial content.
๐ง IAM permission changes
- eks
- aidevops
- s3tables
- mediaconnect
- aws-mcp
- s3vectors
- aws-marketplace
- partnercentral
- bedrock-agentcore
- partnercentral-account-management
- observabilityadmin
- transform-custom
- opensearch
- omics
- connect
- apigateway
- sagemaker
- security-ir
- transform
- securityagent
- lambda
- s3
- cloudwatch
- route53
- ecr
- route53globalresolver
- bedrock-mantle
- datazone
- logs
- cloudfront
๐ช API changes
- AWS Identity and Access Management
- Inspector2
- Partner Central Account API
- AWS Lambda
- Amazon Bedrock
- Amazon SageMaker Service
- Amazon Bedrock AgentCore Control
- Amazon Bedrock AgentCore
- Amazon Bedrock Runtime
- Amazon Bedrock
- AWS Cost Explorer Service
- Amazon DataZone
- Amazon FSx
- Amazon GuardDuty
- AWS Lambda
- Amazon CloudWatch Logs
- Nova Act Service
- CloudWatch Observability Admin Service
- Amazon OpenSearch Service
- OpenSearch Service Serverless
- Amazon Relational Database Service
- Amazon Simple Storage Service
- AWS S3 Control
- Amazon S3 Tables
- Amazon S3 Vectors
- Amazon SageMaker Service
- AWS Savings Plans
- AWS SecurityHub
- Amazon AppIntegrations Service
- Agents for Amazon Bedrock Runtime
- Agents for Amazon Bedrock
- AWS Clean Rooms Service
- AWS Clean Rooms ML
- Amazon Connect Service
- AmazonConnectCampaignServiceV2
- Amazon Connect Participant Service
- Amazon Connect Customer Profiles
- Amazon Elastic Kubernetes Service
- AWS Glue
- AWS Lambda
- Amazon Lex Model Building V2
- AWS Marketplace Agreement Service
- AWS Marketplace Catalog Service
- Partner Central Account API
- Partner Central Benefits API
- Partner Central Selling API
- Amazon Personalize
- Amazon Q Connect
- Amazon Route 53 Global Resolver
๐น IAM managed policy changes
- AWSIdentityCenterExternalManagementPolicy
- AWSTransformCustomManageTransformations
- AWSTransformCustomFullAccess
- AWSTransformCustomExecuteTransformations
- AmazonBedrockLimitedAccess
- AmazonBedrockFullAccess
- AmazonBedrockMantleReadOnly
- AmazonBedrockMantleInferenceAccess
- AmazonBedrockMantleFullAccess
- CloudWatchReadOnlyAccess
- CloudWatchLogsReadOnlyAccess
- CloudWatchLogsFullAccess
- CloudWatchFullAccessV2
- AmazonS3TablesFullAccess
- SecurityAgentWebAppAPIPolicy
- AWSLambdaBasicDurableExecutionRolePolicy
- BedrockAgentCoreFullAccess
- AWSObservabilityAdminTelemetryEnablementServiceRolePolicy
- AWSLambda_FullAccess
- AWSServiceRoleForAWSTransform
- AWSLambda_FullAccess
- AWSPartnerCentralMarketingManagement
- AWSPartnerCentralOpportunityManagement
- AWSPartnerCentralFullAccess
- AWSPartnerCentralChannelManagement
- AWSMarketplaceSellerProductsFullAccess
- AWSMarketplaceSellerFullAccess
- AWSMarketplaceRead-only
- AWSMarketplaceManageSubscriptions
- AWSLambdaServiceRolePolicy
- AWSLambdaManagedEC2ResourceOperator
- AWSPartnerCentralOpportunityManagement
- AWSPartnerCentralFullAccess
- AWSPartnerCentralChannelManagement
โ CloudFormation resource changes
-
No resource updates this week.
๐ฎ Amazon Linux vulnerabilities
- CVE-2025-65082
- CVE-2025-58098
- CVE-2025-55753
- CVE-2025-66200
- CVE-2025-59775
- CVE-2025-65637
- CVE-2025-40264
- CVE-2025-66287
- CVE-2025-40249
- CVE-2025-14010
- CVE-2025-40254
- CVE-2025-40260
- CVE-2025-12385
- CVE-2025-13751
- CVE-2025-13946
- CVE-2025-61727
- CVE-2025-13947
- CVE-2025-66220
- CVE-2025-64763
- CVE-2025-12084
- CVE-2025-64527
- CVE-2025-13945
- CVE-2025-66453
- CVE-2025-66293
- CVE-2025-66476
- CVE-2025-65955
- CVE-2025-61729
๐บ AWS security bulletins
๐ฌ Security documentation changes
- AmazonECS Documentation Update
- aurora-dsql Documentation Update
- bedrock Documentation Update
- bedrock Documentation Update
- bedrock Documentation Update
- bedrock Documentation Update
- cli Documentation Update
- cli Documentation Update
- cloudhsm Documentation Update
- cloudhsm Documentation Update
- cloudhsm Documentation Update
- controltower Documentation Update
- emr Documentation Update
- emr Documentation Update
- emr Documentation Update
- emr Documentation Update
- general Documentation Update
- guardduty Documentation Update
- iot-device-defender Documentation Update
- location Documentation Update
- nova Documentation Update
- nova Documentation Update
- nova Documentation Update
- nova Documentation Update
- nova Documentation Update
- nova Documentation Update
- nova Documentation Update
- nova Documentation Update
- nova Documentation Update
- privateca Documentation Update
- redshift Documentation Update
- redshift Documentation Update
- redshift Documentation Update
- singlesignon Documentation Update
- transfer Documentation Update
- transfer Documentation Update
- transfer Documentation Update
- transfer Documentation Update
- waf Documentation Update
- waf Documentation Update