Issue #246

Monday · February 02, 2026

๐Ÿฅ– Palate Cleanser

OpenSSL and AI-driven vulnerability discovery tried to set the internet on fire this week but failed. Just. CVE-2025-15467 is a high-severity stack buffer overflow in OpenSSL's encrypted message parsing that requires no keys, no authentication, and no user interaction to trigger. Apparently, modern compiler protections save the day by reducing what could have been remote code execution to "just" a crash, but exploit developers are clever, so patch ASAP.

If you are a fan of Well-Architected and AI, it's worth noting AWS added over 15 generative AI security best practices to the Well-Architected Framework this week, covering everything from IAM least privilege for AI services and separation of duties for model governance to AI-specific incident response procedures, ransomware protection for models and prompts, and autonomous agent management frameworks.

Otherwise, some solid content this week. Enjoy.

Have feedback about AWS Security Digest? Tell us here. This issue is also available to share online.

๐Ÿ“‹ Chef's selections

  • Threat Actors Using AWS WorkMail in Phishing Campaigns by Jan Blazek

    Attackers with compromised AWS credentials quickly ran into the SES sandbox buzzkill (200 emails/day) and pivoted to WorkMail instead, which allows sending to far more external recipients with no sandbox restrictions. They registered phishing domains, verified them via SES, spun up WorkMail mailboxes, and sent campaigns that rode Amazonโ€™s sender reputation. Bonus points: emails sent via SMTP donโ€™t generate CloudTrail events, even with SES data events enabled, creating a nice little visibility blind spot for defenders.

  • Bringing OSS runtime security to AWS: Falco integration with AWS Security Hub CSPM by Dan Belmonte

    The folks at Sysdig published a one-click AWS Marketplace solution that deploys the Cloud Native Computing Foundation (CNCF)-graduated Falco runtime security tool to EKS clusters and pipes eBPF-based detections into Security Hub CSPM via CloudWatch and Lambda. It's a corporate blog, so thereโ€™s a bit of self-promotion (Falco was originally a Sysdig project), but the integration itself is open source and the MITRE ATT&CK-aligned ruleset for catching shell spawns, privilege escalation, suspicious file access, and unusual network activity in containers is genuinely useful.

  • Aren't AWS Cloud Investigations the same as On-Prem? - Part 2 (AWS S3) by Chester Le Bron

    I like Chester's posts because he always writes from his own experience. S3โ€™s flat namespace, globally unique bucket names, and multi-tier logging model (CloudTrail management events, optional CloudTrail data events at cost, and best-effort server access logs) make investigations a different beast from on-prem NAS forensics. The post walks through how compromised credentials can skip a traditional โ€œloginโ€ step, why exfiltration via S3 can slip past conventional data loss prevention (DLP), and how detecting anomalous GetObject calls at scale is both expensive and noisy unless logging and bucket policies are deliberately configured up front.

๐Ÿฅ— AWS security blogs

๐Ÿ› Reddit threads on r/aws


๐Ÿค– Dessert

Every machine-tracked change this week. Nobody else assembles this.

๐Ÿง IAM permission changes

๐Ÿช API changes

๐Ÿน IAM managed policy changes

โ˜• CloudFormation resource changes

    No resource updates this week.

๐ŸŽฎ Amazon Linux vulnerabilities

๐Ÿ“บ AWS security bulletins

    No bulletins this week.

๐Ÿšฌ Security documentation changes

Get every AWS security change,
on a plate every Monday.

6,700+ engineers, builders and CISOs let us diff the AWS changelog every week.