SRE Weekly Issue #278 • 📖 [The CloudSecList] Issue 95 • [tl;dr sec] #91 - DOM Invader, Ransomware self-assessment tool • AWS Firewall Manager now supports central monitoring of VPC routes for AWS Network Firewall • Amplify Admin UI now supports importing existing Amazon Cognito User Pools and Identity Pools • Amazon DevOps Guru - 2 updated methods • Firewall Management Service - 2 updated methods • AWS MediaTailor - 1 new methods • AWS Outposts - 1 updated methods • Configure SAML single sign-on for Kibana with AD FS on Amazon Elasticsearch Service • Automate resolution for IAM Access Analyzer cross-account access findings on IAM roles • Automatically update AWS WAF IP sets with AWS IP ranges • Build an end-to-end attribute-based access control strategy with AWS SSO and Okta • Phishing for AWS credentials via AWS SSO device code authentication • sebastian-mora/awsssome_phish • Overview of Data Transfer Costs for Common Architectures | Amazon Web Services • 🔥New blog post🔥 "How to defend against DNS exfiltration in <a href="https://twitter.com/hashtag/AWS" target="_blank">#AWS</a>?" This time I'll try to answer when and how Route 53 Resolver DNS Firewall and GuardDuty services can help you block and detect suspicious traffic. <a href="https://t.co/yq8xGeYthr" target="_blank">rzepsky.medium.com/how-to-defend-…</a> • 🌎 New <a href="https://twitter.com/code" target="_blank">@code</a> extension: Remote Repositories <a href="https://twitter.com/BrigitMurtaugh" target="_blank">@BrigitMurtaugh</a> and <a href="https://twitter.com/eamodio" target="_blank">@eamodio</a> describe how it lets you quickly browse, search, edit, and commit to any remote GitHub repository directly from within VS Code No clone necessary! <a href="https://t.co/mwAlsO1nDN" target="_blank">code.visualstudio.com/blogs/2021/06/…</a> • 🔥 DOM Invader <a href="https://twitter.com/garethheyes" target="_blank">@garethheyes</a> describes a new <a href="https://twitter.com/Burp_Suite" target="_blank">@Burp_Suite</a> tool: an extension to the embedded browser * Easily track a site's sources/sinks -&gt; DOM XSS * Easily manipulate web messages &amp; spoof their origin <a href="https://twitter.com/hashtag/bugbountytips" target="_blank">#bugbountytips</a> <a href="https://twitter.com/hashtag/websecurity" target="_blank">#websecurity</a> <a href="https://t.co/9yGZSYpHU7" target="_blank">portswigger.net/blog/introduci…</a> • Summit Route is back open for business! If you're interested in AWS security training or other services, we should talk. <a href="https://t.co/3Hu9IAMNqs" target="_blank">summitroute.com/#contact</a> • A fresh look at Macie by <a href="https://twitter.com/jcfarris" target="_blank">@jcfarris</a>. I like the idea of limiting scans to public buckets and making account owners bear the cost as a way for security teams to incentivize account owners to not have public buckets. <a href="https://t.co/NJXuIYobCa" target="_blank">chrisfarris.com/post/revisitin…</a> • On June 30, AWS added section 39.3 to their terms and conditions, adding IoT SiteWise Edge to the list of services that should not be used for critical systems. Others are Pinpoint, Lumberyard, Alexa for Business, Location Service, and all AI and machine learning services. • David Okeyode (<a href="https://twitter.com/asegunlolu" target="_blank">@asegunlolu</a>) and Karl Fosaaen (<a href="https://twitter.com/kfosaaen" target="_blank">@kfosaaen</a>) will be presenting "An Introduction to Azure Offensive Security" <a href="https://t.co/Mfhlw9rql8" target="_blank">fwdcloudsec.org/speakers.html#…</a> • Today marks the #26 issue of my Newsletter dedicated to AWS Security. I would like to thanks, my 240+ readers and all of them who are sending me suggestions to keep this NL sharp! :raised If you are not yet subscribed: <a href="https://t.co/wIf4agSwVu" target="_blank">app.mailbrew.com/zoph/aws-secur…</a> • It’s 2021. We have dancing robots and self driving cars, but hospitals are STILL transferring X-ray scans over CDs. Blows my mind. • The CFP for fwd:cloudsec closes next Friday (July 16), so this is the last weekend to work on your talk proposal! <a href="https://t.co/PPhMKQSBzK" target="_blank">fwdcloudsec.org/cfp.html</a> We've got another batch of early acceptances to announce. 🧵 • Pentagon discards $10 billion JEDI cloud deal awarded to Microsoft • Behind the scenes of AWS Lambda • Interactive Examples of Real-World AWS Cloud Hacks and How They Happen • Ec2instances.info now has Spot pricing information, is there anything else you'd like to see? • Amazon EC2 adds Resource Identifiers and Tags for VPC Security Group Rules • A PrintNightmare (CVE-2021-34527) Python Scanner. Scan entire subnets for hosts vulnerable to the PrintNightmare RCE • A series of free interactive AWS security training modules that teach developers how to identify and mitigate security vulnerabilities in their AWS hosted cloud applications. • 1Strategy achieves AWS Security Competency status and validates expertise in delivering secure solutions - Help Net Security • Moving to AWS Lambda? Here’s what you need to know - Security Boulevard • 1Strategy Achieves AWS Security Competency Status - Business Wire
12
Monday July, 2021

AWS Firewall Manager now supports central monitoring of VPC routes for AWS Network Firewall

Jul 8
Starting today, AWS Firewall Manager allows customers to centrally monitor route configurations for AWS Network Firewall, and get alerts on routes non-compliant with their configuration. With this launch, customers can now monitor VPC routes to ensure traffic egressing through Internet Gateway (IGW) is inspected by the Network Firewall deployed by …

Amplify Admin UI now supports importing existing Amazon Cognito User Pools and Identity Pools

Jul 6
Amplify Admin UI now supports importing existing Amazon Cognito User Pools and Identity Pools. This means you can link your Cognito User Pool and Identity Pool resources to your Amplify app to take advantage of authorization scenarios for your data model, and manage users and groups directly from the Admin …

Amazon DevOps Guru - 2 updated methods

Jul 8
Add AnomalyReportedTimeRange field to include open and close time of anomalies.

Firewall Management Service - 2 updated methods

Jul 8
AWS Firewall Manager now supports route table monitoring, and provides remediation action recommendations to security administrators for AWS Network Firewall policies with misconfigured routes.

AWS MediaTailor - 1 new methods

Jul 8
Add ListAlerts for Channel, Program, Source Location, and VOD Source to return alerts for resources.

AWS Outposts - 1 updated methods

Jul 8
Added property filters for listOutposts

Configure SAML single sign-on for Kibana with AD FS on Amazon Elasticsearch Service

Sajeev Attiyil BhaskaranJul 9
It’s a common use case for customers to integrate identity providers (IdPs) with Amazon Elasticsearch Service (Amazon ES) to achieve single sign-on (SSO) with Kibana. This integration makes it possible for users to leverage their existing identity credentials and offers administrators a single source of truth for user and permissions …

Automate resolution for IAM Access Analyzer cross-account access findings on IAM roles

Ramesh BalajepalliJul 8
In this blog post, we show you how to automatically resolve AWS Identity and Access Management (IAM) Access Analyzer findings generated in response to unintended cross-account access for IAM roles. The solution automates the resolution by responding to the Amazon EventBridge event generated by IAM Access Analyzer for each active …

Automatically update AWS WAF IP sets with AWS IP ranges

Fola BolodeokuJul 8
Note: This blog post describes how to automatically update AWS WAF IP sets with the most recent AWS IP ranges for AWS services. This related blog post describes how to perform a similar update for Amazon CloudFront IP ranges that are used in VPC Security Groups. You can use AWS …

Build an end-to-end attribute-based access control strategy with AWS SSO and Okta

Louay ShaatJul 6
This blog post discusses the benefits of using an attribute-based access control (ABAC) strategy and also describes how to use ABAC with AWS Single Sign-On (AWS SSO) when you’re using Okta as an identity provider (IdP). Over the past two years, Amazon Web Services (AWS) has invested heavily in making …
Rzepsky
Pawel Rzepa @Rzepsky

🔥New blog post🔥 "How to defend against DNS exfiltration in #AWS?"

This time I'll try to answer when and how Route 53 Resolver DNS Firewall and GuardDuty services can help you block and detect suspicious traffic.
rzepsky.medium.com/how-to-defend-…

56Jul 07 · 9:26 AM
clintgibler
Clint Gibler @clintgibler

🌎 New @code extension: Remote Repositories

@BrigitMurtaugh and @eamodio describe how it lets you quickly browse, search, edit, and commit to any remote GitHub repository directly from within VS Code

No clone necessary!

code.visualstudio.com/blogs/2021/06/…

25Jul 06 · 7:00 PM
clintgibler
Clint Gibler @clintgibler

🔥 DOM Invader

@garethheyes describes a new @Burp_Suite tool: an extension to the embedded browser
* Easily track a site's sources/sinks -> DOM XSS
* Easily manipulate web messages & spoof their origin

#bugbountytips #websecurity

portswigger.net/blog/introduci…

22Jul 06 · 5:00 PM
SummitRoute
Summit Route @SummitRoute

Summit Route is back open for business! If you're interested in AWS security training or other services, we should talk. summitroute.com/#contact

10Jul 08 · 3:30 PM
0xdabbad00
Scott Piper @0xdabbad00

A fresh look at Macie by @jcfarris. I like the idea of limiting scans to public buckets and making account owners bear the cost as a way for security teams to incentivize account owners to not have public buckets.
chrisfarris.com/post/revisitin…

10Jul 06 · 3:32 AM
0xdabbad00
Scott Piper @0xdabbad00

On June 30, AWS added section 39.3 to their terms and conditions, adding IoT SiteWise Edge to the list of services that should not be used for critical systems. Others are Pinpoint, Lumberyard, Alexa for Business, Location Service, and all AI and machine learning services.

6Jul 11 · 9:54 PM
fwdcloudsec
fwd:cloudsec @fwdcloudsec

David Okeyode (@asegunlolu) and Karl Fosaaen (@kfosaaen) will be presenting "An Introduction to Azure Offensive Security" fwdcloudsec.org/speakers.html#…

13Jul 09 · 6:20 PM
zoph
Victor GRENU @zoph

Today marks the #26 issue of my Newsletter dedicated to AWS Security. I would like to thanks, my 240+ readers and all of them who are sending me suggestions to keep this NL sharp! :raised

If you are not yet subscribed:
app.mailbrew.com/zoph/aws-secur…

3Jul 05 · 5:16 PM
kmcquade3
Kinnaird McQuade💥☁️ @kmcquade3

It’s 2021. We have dancing robots and self driving cars, but hospitals are STILL transferring X-ray scans over CDs. Blows my mind.

0Jul 05 · 5:16 PM
fwdcloudsec
fwd:cloudsec @fwdcloudsec

The CFP for fwd:cloudsec closes next Friday (July 16), so this is the last weekend to work on your talk proposal!
fwdcloudsec.org/cfp.html

We've got another batch of early acceptances to announce. 🧵

5Jul 09 · 6:20 PM

buymeacoffee