Discover, review, and remediate unintended access to Secrets Manager secrets using IAM Access Analyzer
AWS Identity and Access Management (IAM) Access Analyzer now analyzes AWS Secrets Manager resource-based policies to help you discover secrets that can be accessed publicly or from other accounts or organizations. IAM Access Analyzer makes it easier to identify and remediate unintended public, cross-account, or cross-organization sharing of your Secrets …
AWS Shield Advanced now provides mitigation metrics and network traffic timelines
Sudo Security Issue (CVE-2021-3156)
[V2] Last Updated: 2021/01/27 1:00PM PDT
CVE Identifier: CVE-2021-3156
This is an update for this issue.
AWS is aware of the security issue recently disclosed by the open source community affecting the Linux "sudo" utility (CVE-2021-3156). This issue may permit unprivileged users to run privileged commands, or cause affected hosts …
Verified episode 3: In conversation with Noopur Davis from Comcast
AWS is the first global cloud service provider to comply with the new K-ISMS-P standard

This update exposes a lot of the internals of how Lambda works. Ex. Lambda runs on EC2 nitro bare metal instances and invokes are done using SQS behind the scenes.

Newer than New (Feb 2021) - Security Overview of #AWS Lambda - d1.awsstatic.com/whitepapers/Ov…




Whoa, tl;dr sec has >5,000 subscribers 🚀
To celebrate, I want to give back
So for every like/RT of this tweet I'll donate $1 to Feeding America (up to $1K) for the next week
Thanks for reading 🙏 Here's to another year of great security research!
tldrsec.com



I am dropping a new AWS Security tool in the next week. Stay tuned



🛠️ @TomNomNom tool overview by @DanielMiessler #bugbountytips
* gf - Security-focused grep
* httprobe - Find domains listening on web ports
* unfurl - Break down URLs into components
* meg - Check paths across domains
* waybackurls - Find archived URLs
danielmiessler.com/blog/a-tomnomn…



AWS security bulletin on the sudo issue. Just says AWS infrastructure (ie. their side of the responsibility model) is not affected, but you should update your systems. aws.amazon.com/security/secur…



I hope you have as much fun reviewing these scenarios as I had writing them. From the far-fetched to the mundane, being able to quickly conjure a response to risks is a hallmark of a well-developed security strategy. #Cloud #Security #AWS #DevOps
matthewdf10.medium.com/cloud-security…



I'm hiring! Looking for folks that are interested in automating incident response in the cloud. If you are interested or know someone, please reach out! hashicorp.com/job/2607537



Another Lockdown haircut in Steve’s Barbers 💈 Not bad if you ask me... if you excuse the fact I cut his forehead with the scissors ✂️ 🤦♂️




Someone was looking for this, soo...
Here's a quick project to rename #AWS CloudFormation stacks 🚀
github.com/iann0036/cfn-s…
Check the documentation as to how this works before using, as some stacks won't be eligible.



✋😲Let's review the resources that Access Analyzer can inspect for you - and this across all accounts if using AWS Organizations:
S3 buckets
IAM roles
KMS keys
Lambda functions & layers
SQS queues
Secrets Mgr secrets
More here: docs.aws.amazon.com/IAM/latest/Use… And there's more to come!

Now use #AWSIAM Access Analyzer to monitor & analyze resource policies for AWS Secrets Manager to identify publicly or cross-account accessible secrets. go.aws/2YhYCxr




Possibly one of the least flattering photos I’ve ever taken. I just wanted to highlight that Archie is a wonderful snuggly nurse boy while I’m lying in bed with debilitating back pain. And Missy is off somewhere soaking up the sunshine
#nofilter #nochin




Not a headline I thought I’d ever read in my lifetime tbh ⛄️




Very nice to see @wildlifestudios' job searches on the @ekoparty website!
ekoparty.org/en_US/jobs/det…


New open source project - Use AWS like it's Heroku!
Hi r/aws!
The flexibility and scalability of AWS is great, but AWS is definitely not the easiest hosting platform to use (let's just say that it doesn't have the most award-winning UI 😏). This is why Platform as a Service (PaaS) like Heroku that is more user friendly can even …
Other than compliance and "it's best practice", what is the reason to secure data in AWS at rest?
What is the reasoning for securing data at rest that's sitting on AWS's disks? Is it just that someone could physically/virtually break into their datacenters and steal a bunch of data?
I know it's easy to do and I pretty much always default to doing it, I just always wondered …