Issue #47

Monday · November 29, 2021

๐Ÿฅ— AWS security blogs

  • AWS Security Profiles: Megan Oโ€™Neil, Sr. Security Solutions Architect โ€” In the week leading up to AWS re:Invent 2021, weโ€™ll share conversations weโ€™ve had with people at AWS who will be presenting, and get a sneak peek at their work. How long have you been at Amazon Web Services (AWS), and what do you do in your current role? Iโ€™ve โ€ฆ
  • How to enable secure seamless single sign-on to Amazon EC2 Windows instances with AWS SSO โ€” Today, weโ€™re launching new functionality that simplifies the experience to securely access your AWS compute instances running Microsoft Windows. We took on this update to respond to customer feedback around creating a more streamlined experience for administrators and users to more securely access their EC2 Windows instances. The new experience โ€ฆ
  • 2021 PCI 3DS report now available โ€” We are excited to announce that Amazon Web Services (AWS) has released the latest 2021 PCI 3-D Secure (3DS) attestation to support our customers implementing EMVยฎ 3-D Secure services on AWS. Although AWS doesnโ€™t directly perform the functions of 3DS Server (3DSS), 3DS Directory Server (DS), or 3DS Access Control โ€ฆ
  • AWS Security Profiles: Merritt Baer, Principal in OCISO โ€” In the week leading up AWS re:Invent 2021, weโ€™ll share conversations weโ€™ve had with people at AWS who will be presenting, and get a sneak peek at their work. How long have you been at Amazon Web Services (AWS), and what do you do in your current role? Iโ€™m a โ€ฆ

๐Ÿ› Reddit threads on r/aws

๐Ÿ“Œ Newsletters

๐Ÿ“Œ AWS Security by CloudNews

  • AWS Single Sign-On is now in scope for AWS SOC reporting โ€” AWS Single Sign-On (AWS SSO) is now in scope for AWS SOC 1 , SOC 2, and SOC 3 reports. You can now use AWS SSO in applications requiring audited evidence of the controls in our System and Organization Controls (SOC) reporting. For example, if you use AWS to manage โ€ฆ
  • AWS WAF adds support for Captcha โ€” AWS today announced AWS WAF Captcha to help block unwanted bot traffic by requiring users to successfully complete challenges before their web request are allowed to reach AWS WAF protected resources. Captcha is an acronym for Completely Automated Public Turing test to tell Computers and Humans Apart and is commonly โ€ฆ
  • AWS Single Sign-On now provides one-click login to Amazon EC2 instances running Microsoft Windows โ€” You can now enable one-click single sign-on to your Amazon Elastic Compute Cloud instances running Microsoft Windows (Amazon EC2 Windows Instances) with AWS Single Sign-Onand, nbsp;(AWS SSO). You can connect your instances with users from AWS SSO or any AWS SSO supported identity provider, such as Okta, Ping, and OneLogin. โ€ฆ

๐Ÿ“Œ Top Links from Security Folks

  • pre:Invent 2021 - Chris Farris โ€” There were 234 AWS announcements in pre:Invent season. I breakdown and snark about 27 of them relating to security and governance.

๐Ÿ“Œ r/netsec

๐Ÿ“Œ r/cloudsecurity

  • Advise for learning cloud security โ€” Hello, I'm trying to explore the cloud security field and i was wondering what advice you can give to a beginner or best learning path for cloud security. I know basics of AWS, Azure, GCP.

๐Ÿ“Œ "AWS Security" on Google News

๐Ÿง IAM permission changes

  • quicksight: 4 new actions, 1 new resource โ€” 4 new actions: CreateEmailCustomizationTemplate (create a quicksight email customization template), DeleteEmailCustomizationTemplate (delete a quicksight email customization template), DescribeEmailCustomizationTemplate (describe a quicksight email customization template), UpdateEmailCustomizationTemplate (update a quicksight email customization template); 1 new resource: emailCustomizationTemplate
  • iotsitewise: 6 new actions, 1 new resource, 2 new conditions | 4 updated actions โ€” 6 new actions: AssociateTimeSeriesToAssetProperty (associate a time series with an asset property), DeleteTimeSeries (delete a time series), DescribeTimeSeries (describe a time series), DisassociateTimeSeriesFromAssetProperty (disassociate a time series from an asset property), GetInterpolatedAssetPropertyValues (retrieve interpolated values for an asset property), ListTimeSeries (list time series); 1 new resource: time-series; 2 new conditions: โ€ฆ
  • workspaces: 3 updated actions โ€” 3 updated actions: DescribeTags (access), CreateTags (conditions), DeleteTags (conditions)

๐Ÿช API changes

Get every AWS security change,
on a plate every Monday.

6,700+ engineers, builders and CISOs let us diff the AWS changelog every week.