Issue #42

Monday · October 25, 2021

πŸ› Reddit threads on r/aws

πŸ“Œ Newsletters

πŸ“Œ Top Links from Security Folks

  • Attacking and Securing CI/CD Pipeline β€” ATT&CK-like Threat Matrix for CI/CD Pipeline on GitHub: https://github.com/rung/threat-matrix-cicd -------- Place: CODE BLUE 2021 OpenTalks at Tokyo Presenter: Hiroki SUEZAWA (https://www.suezawa.net…

πŸ“Œ r/netsec

πŸ“Œ r/cloudsecurity

  • Career Path / How did you land a job in cloud sec? β€” For those of you currently working a cloud security role, what path did you take to get there? Previous job titles/descriptions and what certifications? I'm very much interested in cloud security and trying to learn as much as I can. Currently Im a tier 2 engineer but get promoted to …

πŸ“Œ "AWS Security" on Google News

🧁 IAM permission changes

  • elasticache: 1 updated condition β€” 1 updated condition: aws:TagKeys (type)
  • elasticmapreduce: 3 new actions β€” 3 new actions: GetAutoTerminationPolicy (retrieve the auto-termination policy associated with a cluster), PutAutoTerminationPolicy (create or update the auto-termination policy associated with a cluster), RemoveAutoTerminationPolicy (remove the auto-termination policy associated with a cluster)
  • ec2: 6 new actions, 2 new resources | 2 updated actions | 1 removed condition β€” 6 new actions: CancelCapacityReservationFleets (cancel one or more capacity reservation fleets), CreateCapacityReservationFleet (create a capacity reservation fleet), GetVpnConnectionDeviceSampleConfiguration (download an aws-provided sample configuration file to be used with the customer gateway device), GetVpnConnectionDeviceTypes (obtain a list of customer gateway devices for which sample configuration files can be provided), ModifyCapacityReservationFleet (modify …

πŸͺ API changes

Get every AWS security change,
on a plate every Monday.

6,700+ engineers, builders and CISOs let us diff the AWS changelog every week.