📖 [The CloudSecList] Issue 94
[tl;dr sec] #90 - Eradicating Subdomain Takeovers, GitHub’s AI Pair Programmer
AWS Firewall Manager is now available in the Asia Pacific (Osaka) Region
IAM Access Analyzer adds new policy checks to help validate conditions during IAM policy authoring
AWS WAF adds 15 new text transformations
Amazon Elastic Compute Cloud - 12 updated methods
Amazon SageMaker Service - 5 updated methods
Auto Scaling - 3 updated methods
AWS Glue DataBrew - 6 updated methods
How to monitor and track failed logins for your AWS Managed Microsoft AD
AWS achieves Spain’s ENS High certification across 149 services
How to integrate third-party IdP using developer authenticated identities
AWS Security Reference Architecture: A guide to designing with AWS security services
Additional IAM Access Analyzer policy checks
You can now use @AWSCloudFormer to buy and sell US stock. Now you can reward yourself on a successful CloudFront deployment by buying some $GME within the same stack. 1/
166
29Jun 28 · 11:48 PM
This is a nice visualisation of data transfer costs in AWS aws.amazon.com/blogs/architec… ...
118
25Jul 01 · 11:54 PM
🐘Remember when Access Analyzer launched policy validation to help you author secure and functional policies? Today, we are rolling out seven more checks. 🐘(1/10)
87
27Jun 30 · 12:59 AM
Excited to announce that as of Monday, I will be taking on a new role at AWS. I am pumped to start as Specialist SA for AWS Infinidash.
DM's are open if you're using or looking into Infinidash. I would love to help.
107
6Jul 02 · 3:45 PM
Life with ADHD: “I didn’t write it down, therefore I forgot”
95
9Jul 05 · 1:04 AM
Coming soon - AWS re:Dash 🚀
The first technical conference dedicated to everything AWS Infinidash
#infinidash #comingsoon
81
10Jul 02 · 4:23 PM
In 4 years, AWS has now released 4 ways to deal with managing the security of an organization from Landing Zones -> Control Tower -> Secure Environment Accelerator -> this which has the accompanying repo github.com/aws-samples/aw…
#AWS Prescriptive Guidance: The AWS Security Reference Architecture - docs.aws.amazon.com/prescriptive-g…
54
8Jun 29 · 9:21 PM
@paulschwarzen @github @barracud4_ @carlospolopm @HolyBugx @owasp @gose1 @lancinimarco @jupiterone_io @halbecaf @TheRSC @Skyscanner @Nebuk89 @AyoubFandiGRC 🎓 File Upload Master Class
@barracud4_ Media payloads
github.com/barrracud4/ima…
@carlospolopm, @HolyBugx
Checklist, bypass filters
book.hacktricks.xyz/pentesting-web…
@owasp Unrestricted File Upload
owasp.org/www-community/…
Cheatsheet
cheatsheetseries.owasp.org/cheatsheets/Fi…
#bugbountytips #bugbounty
37
20Jul 01 · 5:00 PM
Have you registered for #reInforce yet? This event will offer interactive educational content to help you modernize your security strategy as well as tools to stay ahead of the evolving security landscape. Register: aws.amazon.com/blogs/security…
36
14Jun 28 · 10:16 PM
I ❤️ this lookup table for aws:username, aws:userid, and aws:PrincipalType values in AWS IAM conditions
HINT: Use aws:userid over aws:username, since username is only for IAM Users and you shouldn't be using them to access your AWS environment in 2021
36
11Jun 30 · 7:19 AMI'm starting a new medium series about developing a "complex" serverless application
For the past year, I've been working on a pet project: detecting locked bike stations in Paris' Velib network using the AWS serverless stack (and initially Kafka). Now that it is "finished" (i.e. spending more time on it would not help me learn much more), I've decided to write some …
- 🖊️ This newsletter was fwd to you? Subscribe here
- 💌 Want to suggest new content: contact me or reply to this email
- ⚡️ Powered by Mailbrew



