📖 [The CloudSecList] Issue 95
[tl;dr sec] #91 - DOM Invader, Ransomware self-assessment tool
AWS Firewall Manager now supports central monitoring of VPC routes for AWS Network Firewall
Amplify Admin UI now supports importing existing Amazon Cognito User Pools and Identity Pools
Amazon DevOps Guru - 2 updated methods
Firewall Management Service - 2 updated methods
AWS MediaTailor - 1 new methods
Configure SAML single sign-on for Kibana with AD FS on Amazon Elasticsearch Service
Automate resolution for IAM Access Analyzer cross-account access findings on IAM roles
Automatically update AWS WAF IP sets with AWS IP ranges
Build an end-to-end attribute-based access control strategy with AWS SSO and Okta
Phishing for AWS credentials via AWS SSO device code authentication



sebastian-mora/awsssome_phish


Overview of Data Transfer Costs for Common Architectures | Amazon Web Services


🔥New blog post🔥 "How to defend against DNS exfiltration in #AWS?"
This time I'll try to answer when and how Route 53 Resolver DNS Firewall and GuardDuty services can help you block and detect suspicious traffic.
rzepsky.medium.com/how-to-defend-…



🌎 New @code extension: Remote Repositories
@BrigitMurtaugh and @eamodio describe how it lets you quickly browse, search, edit, and commit to any remote GitHub repository directly from within VS Code
No clone necessary!
code.visualstudio.com/blogs/2021/06/…



🔥 DOM Invader
@garethheyes describes a new @Burp_Suite tool: an extension to the embedded browser
* Easily track a site's sources/sinks -> DOM XSS
* Easily manipulate web messages & spoof their origin
#bugbountytips #websecurity
portswigger.net/blog/introduci…



Summit Route is back open for business! If you're interested in AWS security training or other services, we should talk. summitroute.com/#contact



A fresh look at Macie by @jcfarris. I like the idea of limiting scans to public buckets and making account owners bear the cost as a way for security teams to incentivize account owners to not have public buckets.
chrisfarris.com/post/revisitin…



On June 30, AWS added section 39.3 to their terms and conditions, adding IoT SiteWise Edge to the list of services that should not be used for critical systems. Others are Pinpoint, Lumberyard, Alexa for Business, Location Service, and all AI and machine learning services.




David Okeyode (@asegunlolu) and Karl Fosaaen (@kfosaaen) will be presenting "An Introduction to Azure Offensive Security" fwdcloudsec.org/speakers.html#…



Today marks the #26 issue of my Newsletter dedicated to AWS Security. I would like to thanks, my 240+ readers and all of them who are sending me suggestions to keep this NL sharp! :raised
If you are not yet subscribed:
app.mailbrew.com/zoph/aws-secur…




It’s 2021. We have dancing robots and self driving cars, but hospitals are STILL transferring X-ray scans over CDs. Blows my mind.



The CFP for fwd:cloudsec closes next Friday (July 16), so this is the last weekend to work on your talk proposal!
fwdcloudsec.org/cfp.html
We've got another batch of early acceptances to announce. 🧵


- 🖊️ This newsletter was fwd to you? Subscribe here
- 💌 Want to suggest new content: contact me or reply to this email
- ⚡️ Powered by Mailbrew
- 🐦 Follow me on Twitter or hire me.