SRE Weekly Issue #290 • 📖 [The CloudSecList] Issue 107 • [tl;dr sec] #103 - Cloud Security Guardrails, Lateral Movement in GitHub Orgs • AWS Account - 3 new methods • AWS Cloud Control API - 8 new methods • AWS Data Exchange - 5 new 3 updated methods • Amazon Macie 2 - 2 updated methods • Enable Security Hub PCI DSS standard across your organization and disable specific controls • Validate IAM policies in CloudFormation templates using IAM Access Analyzer • Securely extend and access on-premises Active Directory domain controllers in AWS • Introducing the Ransomware Risk Management on AWS Whitepaper • Updates to single-valued and multivalued condition keys • dataexchange: 5 new actions, 1 new resource | 4 updated actions • transfer: 12 new actions, 1 new resource | 3 updated actions • events: 1 updated condition • account: 3 new actions, 2 new resources, 3 new conditions • AWS Cloud Control API, a Uniform API to Access AWS & Third-Party Services | Amazon Web Services • This is a fairly urgent Sr Cloud Security Engineer role on my team at Netflix. Please apply directly if you like working on AWS IAM &amp; credentials mgmt, reducing blast radius, right-sizing of permissions and cloud guardrails at scal…<a href="https://t.co/ryPZz3RnaF" target="_blank">lnkd.in/g9fmfekS</a> <a href="https://t.co/BwCimMAq9d" target="_blank">lnkd.in/g7dCSw9</a> • 8years ago today - my first Day1 <a href="https://twitter.com/awscloud" target="_blank">@awscloud</a>. What a journey! There was no CloudTrail, Kinesis, Lambda, APIGW, Step Functions, Amplify or even Chime 😉 We had not long launched DataPipeline, Opsworks, Simple Workflow and CloudSearch 😜 Change is constant, keep learning folks! • 1/ Here's the IAM Policy Validator for AWS CloudFormation, an <a href="https://twitter.com/hashtag/Opensource" target="_blank">#Opensource</a> project that uses IAM Access Analyzer to validate that policies are secure &amp; functional within your CFN templates, as part of a CI/CD pipeline, before they're deployed! <a href="https://twitter.com/AWSIdentity" target="_blank">@AWSIdentity</a> <a href="https://t.co/QsnSFWCEVZ" target="_blank">aws.amazon.com/blogs/security…</a> • This post is AWS's response to Azure's recent container escape (Azurescape), to show how similar issues would not be able to impact AWS. • There's a bit of confusion about the new Lambda support for Graviton2 and Golang. It works great, you just need to: * GOARCH=arm64 go build * Use the `provided.al2` runtime instead of `go1.x` <a href="https://t.co/wS3AI9j62L" target="_blank">awsteele.com/blog/2021/09/2…</a> • This has been the biggest 24 hours of AWS announcements all year, and yet I have no idea what event is going on or why it all got released today. • This is very useful if you’re still living in VPCs <a href="https://t.co/SXAK4HJv0J" target="_blank">aws.amazon.com/about-aws/what…</a> • ☁️ Building Strong Security Guardrails in AWS <a href="https://twitter.com/marknca" target="_blank">@marknca</a> walks prioritizing and building simple guardrails to help devs avoid misconfigurations and other common security pitfalls in AWS CloudWatch event -&gt; Lambda -&gt; Slack message <a href="https://t.co/V0IpeGpRIU" target="_blank">markn.ca/2021/how-to-bu…</a> • 🔥 GitOops: Bloodhound for your CI/CD pipeline Helps identify lateral movement and privesc paths in GitHub orgs by abusing CI/CD pipelines and GitHub access controls Gather info -&gt; graph DB -&gt; query attack paths By <a href="https://twitter.com/AlxKatana" target="_blank">@AlxKatana</a> <a href="https://twitter.com/hashtag/redteam" target="_blank">#redteam</a> <a href="https://t.co/zFaPtxTeb8" target="_blank">github.com/ovotech/gitoops</a> • Current status: living vicariously through <a href="https://twitter.com/NerdPyle" target="_blank">@NerdPyle</a> dog walk threads. ❤️ • What Wonderful Times We Live In • Amazon EC2 now offers Global View on the console to view all resources across regions together • I Trust AWS IAM to Secure My Applications. I Don’t Trust the IAM Docs to Tell Me How. • You can now run AWS Lambda on the ARM64 architecture! • I built an open-source GraphQL powered search engine for your AWS infrastructure. • fail2ban - Remote Code Execution - CVE-2021-32749 • BruteShark Version V1.2.5 Released: Identify open ports, domains and users simply by entering PCAP files. Export it to JSON with few clicks :-) • Microsoft Preparing Big Cybersecurity Push With Ex-AWS Charlie Bell - Business Insider • 3 Security Initiatives AWS's New CEO Should Prioritize - Dark Reading
4
Monday October, 2021
AWS Account - 3 new methods
Sep 30
This release of the Account Management API enables customers to manage the alternate contacts for their AWS accounts. For more information, see https://docs.aws.amazon.com/accounts/latest/reference/accounts-welcome.html
AWS Cloud Control API - 8 new methods
Sep 30
Initial release of the SDK for AWS Cloud Control API
AWS Data Exchange - 5 new 3 updated methods
Sep 30
This release enables subscribers to set up automatic exports of newly published revisions using the new EventAction API.
Amazon Macie 2 - 2 updated methods
Sep 30
Amazon S3 bucket metadata now indicates whether an error or a bucket's permissions settings prevented Amazon Macie from retrieving data about the bucket or the bucket's objects.
Enable Security Hub PCI DSS standard across your organization and disable specific controls
Pablo PaganiSep 30
At this time, enabling the PCI DSS standard from within AWS Security Hub enables this compliance framework only within the Amazon Web Services (AWS) account you are presently administering. This blog post showcases a solution that can be used to customize the configuration and deployment of the PCI DSS standard …
Validate IAM policies in CloudFormation templates using IAM Access Analyzer
Matt LuttrellSep 29
In this blog post, I introduce IAM Policy Validator for AWS CloudFormation (cfn-policy-validator), an open source tool that extracts AWS Identity and Access Management (IAM) policies from an AWS CloudFormation template, and allows you to run existing IAM Access Analyzer policy validation APIs against the template. I also show you …
Securely extend and access on-premises Active Directory domain controllers in AWS
Mangesh BudkuleSep 29
If you have an on-premises Windows Server Active Directory infrastructure, it’s important to plan carefully how to extend it into Amazon Web Services (AWS) when you’re migrating or implementing cloud-based applications. In this scenario, existing applications require Active Directory for authentication and identity management. When you migrate these applications to …
Introducing the Ransomware Risk Management on AWS Whitepaper
Temi AdebamboSep 28
AWS recently released the Ransomware Risk Management on AWS Using the NIST Cyber Security Framework (CSF) whitepaper. This whitepaper aligns the National Institute of Standards and Technology (NIST) recommendations for security controls that are related to ransomware risk management, for workloads built on AWS. The whitepaper maps the technical capabilities …
Updates to single-valued and multivalued condition keys
Sep 30
The differences between single-valued and multivalued condition keys are now explained in more detail. The value type was added to each AWS global condition context key.
dataexchange: 5 new actions, 1 new resource | 4 updated actions
Oct 2
5 new actions: CreateEventAction (create an event action), DeleteEventAction (delete an event action), GetEventAction (get an event action), ListEventActions (list event actions for the account), UpdateEventAction (update information for an event action); 1 new resource: event-actions; 4 updated actions: ListDataSetRevisions (access), ListDataSets (access), ListJobs (access), ListRevisionAssets (access)
transfer: 12 new actions, 1 new resource | 3 updated actions
Oct 2
12 new actions: CreateAccess (add an access associated with a server), CreateWorkflow (create a workflow), DeleteAccess (delete access), DeleteWorkflow (delete a workflow), DescribeAccess (describe an access assigned to a server), DescribeExecution (describe an execution associated with a workflow), DescribeWorkflow (describe a workflow), ListAccesses (list accesses), ListExecutions (list executions associated with …
events: 1 updated condition
Oct 2
1 updated condition: events:source (type)
account: 3 new actions, 2 new resources, 3 new conditions
Oct 2
3 new actions: DeleteAlternateContact (delete the alternate contacts for an account), GetAlternateContact (retrieve the alternate contacts for an account), PutAlternateContact (modify the alternate contacts for an account); 2 new resources: account, accountInOrganization; 3 new conditions: account:AccountResourceOrgPaths (filters access by the resource path for an account in an organization), account:AccountResourceOrgTags/${TagKey} (filters …
secdrama
Srinath Kuruvadi @secdrama

This is a fairly urgent Sr Cloud Security Engineer role on my team at Netflix. Please apply directly if you like working on AWS IAM & credentials mgmt, reducing blast radius, right-sizing of permissions and cloud guardrails at scal…lnkd.in/g9fmfekS lnkd.in/g7dCSw9

steven_bryen
Steven Bryen @steven_bryen

8years ago today - my first Day1 @awscloud. What a journey!

There was no CloudTrail, Kinesis, Lambda, APIGW, Step Functions, Amplify or even Chime 😉

We had not long launched DataPipeline, Opsworks, Simple Workflow and CloudSearch 😜

Change is constant, keep learning folks!

mchancloud
Michael Chan @mchancloud

1/ Here's the IAM Policy Validator for AWS CloudFormation, an #Opensource project that uses IAM Access Analyzer to validate that policies are secure & functional within your CFN templates, as part of a CI/CD pipeline, before they're deployed! @AWSIdentity
aws.amazon.com/blogs/security…

0xdabbad00
Scott Piper @0xdabbad00

This post is AWS's response to Azure's recent container escape (Azurescape), to show how similar issues would not be able to impact AWS.

AWSBlogUnreal
AWS Blog Unofficial. @AWSBlogUnreal

The AWS Open Source Blog #AWSOpenSource
aws.amazon.com/blogs/opensour…
By: Jeremy Cowan, Sai Charan Teja Gopaluni* and Vijay K Sikha

__steele
Aidan W Steele @__steele

There's a bit of confusion about the new Lambda support for Graviton2 and Golang. It works great, you just need to:

* GOARCH=arm64 go build
* Use the `provided.al2` runtime instead of `go1.x`

awsteele.com/blog/2021/09/2…

0xdabbad00
Scott Piper @0xdabbad00

This has been the biggest 24 hours of AWS announcements all year, and yet I have no idea what event is going on or why it all got released today.

__steele
Aidan W Steele @__steele

This is very useful if you’re still living in VPCs aws.amazon.com/about-aws/what…

clintgibler
Clint Gibler @clintgibler

☁️ Building Strong Security Guardrails in AWS

@marknca walks prioritizing and building simple guardrails to help devs avoid misconfigurations and other common security pitfalls in AWS

CloudWatch event -> Lambda -> Slack message

markn.ca/2021/how-to-bu…

clintgibler
Clint Gibler @clintgibler

🔥 GitOops: Bloodhound for your CI/CD pipeline

Helps identify lateral movement and privesc paths in GitHub orgs by abusing CI/CD pipelines and GitHub access controls

Gather info -> graph DB -> query attack paths

By @AlxKatana #redteam

github.com/ovotech/gitoops

AlexandreSieira
Alexandre Sieira @AlexandreSieira

Current status: living vicariously through @NerdPyle dog walk threads. ❤️

What Wonderful Times We Live In

Caveat - not a technical post or question so much as a sort of love letter to the Cloud.

I'm 57 years old and I've been working in the data space for the last 25 years. My first database build was a tactical database in 1990 in dBase III when …

You can now run AWS Lambda on the ARM64 architecture!

Seriously. Check the AWS Console and the Lambda creation wizard. It asks whether you want x86_64 or arm64 as your code runtime!

Looks like they have already deployed it but it is yet to be officially announced.

I built an open-source GraphQL powered search engine for your AWS infrastructure.

Hey all!

CloudGraph is an open-source search engine for your public cloud infrastructure, powered by DGraph and GraphQL. Within seconds, query assets, configurations, and more across accounts and providers. CloudGraph also enables you to solve a host of security, compliance, governance, and FinOps challenges in the time it takes to …

buymeacoffee