SRE Weekly Issue #300 • 📖 [The CloudSecList] Issue 117 • [tl;dr sec] #112 - re:Invent, Python Security • Amazon Lex Model Building V2 - 6 updated methods • AWS Network Firewall - 1 new 4 updated methods • AWS Route53 Recovery Control Config - 3 new 3 updated methods • Amazon Route 53 Domains - 2 new 5 updated methods • Update for Apache Log4j2 Issue (CVE-2021-44228) • Apache Log4j2 Issue (CVE-2021-44228) • How to customize behavior of AWS Managed Rules for AWS WAF • Privacy video: Innovating securely • Hardening the security of your AWS Elastic Beanstalk Application the Well-Architected way • Using CloudTrail to identify unexpected behaviors in individual workloads • kafka: 3 new resources • rekognition: 5 updated actions, 1 updated resource • textract: 1 new action • We've hit the 30 minute mark into us-east-1 being down (based on the first post to hacker news) and no updates to the AWS status page yet. 🔥 • Second log4j2 bulletin from AWS (published 7:30 PM PDT on Saturday): <a href="https://t.co/xfT3c3yzVv" target="_blank">aws.amazon.com/security/secur…</a> More AWS services are impacted. Subtle acknowledgements that S3 and other services are now patched or are being patched. 😬 The recommended WAF rules do not look comprehensive. • This is how we re-bootstrapped detection &amp; response at scale in AWS cloud. Just a year in and we are already seeing some nice wins from all these investments. Nice work - Alex Bainbridge, Nick Siow and Michael Grima! And we are…<a href="https://t.co/BralY5meLU" target="_blank">lnkd.in/g8CJqbu8</a> <a href="https://t.co/1UQ1izgSia" target="_blank">lnkd.in/gzrztPY5</a> • 🐳 Awesome <a href="https://twitter.com/hashtag/Kubernetes" target="_blank">#Kubernetes</a> Security A curated list of awesome Kubernetes security resources, by <a href="https://twitter.com/ksoclabs" target="_blank">@ksoclabs</a> * Open source projects * General resources * Twitter accounts <a href="https://t.co/bauJX9V4Sg" target="_blank">github.com/ksoclabs/aweso…</a> • I released a small Spring Boot web application vulnerable to Log4Shell so everyone can easily play with it. <a href="https://t.co/PR7GbSlFhG" target="_blank">github.com/christophetd/l…</a> cc <a href="https://twitter.com/LunaSecIO" target="_blank">@LunaSecIO</a> <a href="https://twitter.com/hashtag/log4j" target="_blank">#log4j</a> • 🙈 Cloud service provider security mistakes by <a href="https://twitter.com/0xdabbad00" target="_blank">@0xdabbad00</a> AWS, GCP, and Azure Mistakes on the cloud providers' side of the shared responsibility model CVEs, SOC 2 Type 2 failures, security researchers compromising managed services, and more <a href="https://t.co/xiKoly69E4" target="_blank">github.com/SummitRoute/cs…</a> • The repository now contains both a vulnerable web application and the precise exploitation steps to RCE. Hopefully this will be useful for defenders crafting detection rules! <a href="https://t.co/PR7GbSlFhG" target="_blank">github.com/christophetd/l…</a> • Ask not what you can log4j, ask what j can log 4 you. • I made today "try something new day" for my org. No meetings, emails, or pings. Just go try something new and take a picture. I went to a private yoga experience. For any folks in Seattle, I highly recommend it and it is like a mini retreat. Also makes a great gift! • IAM access analysis directly embedded in the S3 console to help you understand that the access control you granted is what you intended. • 500/502 Errors on AWS Console • A software engineer at Amazon had their total comp increased to $180,000 after earning a promotion to SDE-II. But instead of celebrating, the coder was dismayed to find someone hired in the same role, which might require as few as 2 or 3 YOE, can earn as much as $300,000. • AWS us-east-1 outage brings down services around the world • Anyone Else Lowkey Think the AWS Console Login Captchas Are Hard AF Sometimes..? • Post AWS outage, what changes do you plan to make? • RCE 0-day exploit found in log4j, a popular Java logging package • Log4shell - using the vulnerability to patch the vulnerability - very clever • SOC 2 Compliance questions • Horangi and AWS launch holistic cloud security offering - SecurityBrief Asia • AWS exec: ‘Embrace more automation’ to boost cloud security - VentureBeat
13
Monday December, 2021
Amazon Lex Model Building V2 - 6 updated methods
Dec 9
Added support for grammar slot type in Amazon Lex. You can author your own grammar in the XML format per the SRGS specification to collect information in a conversation.
AWS Network Firewall - 1 new 4 updated methods
Dec 9
This release adds support for managed rule groups.
AWS Route53 Recovery Control Config - 3 new 3 updated methods
Dec 9
This release adds tagging supports to Route53 Recovery Control Configuration. New APIs: TagResource, UntagResource and ListTagsForResource. Updates: add optional field `tags` to support tagging while calling CreateCluster, CreateControlPanel and CreateSafetyRule.
Amazon Route 53 Domains - 2 new 5 updated methods
Dec 9
Amazon Route 53 domain registration APIs now support filtering and sorting in the ListDomains API, deleting a domain by using the DeleteDomain API and getting domain pricing information by using the ListPrices API.
Update for Apache Log4j2 Issue (CVE-2021-44228)
aws@amazon.comDec 13

Last Updated Date: 2021/12/12 9:40 PM PDT

AWS is aware of the recently disclosed security issue relating to the open-source Apache “Log4j2" utility (CVE-2021-44228). We are actively monitoring this issue, and are working on addressing it for any AWS services which either use Log4j2 or provide it to customers as …

Apache Log4j2 Issue (CVE-2021-44228)
aws@amazon.comDec 11

Initial Publication Date: 2021/12/10 7:20 PM PDT

AWS is aware of the recently disclosed security issue relating to the open-source Apache “Log4j2" utility (CVE-2021-44228). We are actively monitoring this issue, and are working on addressing it for any AWS services which either use Log4j2 or provide it to customers as …

How to customize behavior of AWS Managed Rules for AWS WAF
Madhu KondurDec 10
AWS Managed Rules for AWS WAF provides a group of rules created by AWS that can be used help protect you against common application vulnerabilities and other unwanted access to your systems without having to write your own rules. AWS Threat Research Team updates AWS Managed Rules to respond to an …
Privacy video: Innovating securely
Chad WoolfDec 9
I’m pleased to share a video of a conversation about privacy I had with my colleague Laura Dawson, the North American Lead at the AWS Institute. Privacy is becoming more of a strategic issue for our customers, similar to how security is today. We discussed how, while the two topics …
Hardening the security of your AWS Elastic Beanstalk Application the Well-Architected way
Laurens BrinkerDec 9
Launching an application in AWS Elastic Beanstalk is straightforward. You define a name for your application, select the platform you want to run it on (for example, Ruby), and upload the source code. The default Elastic Beanstalk configuration is intended to be a starting point which prioritizes simplicity and ease of setup. …
Using CloudTrail to identify unexpected behaviors in individual workloads
Volker RathDec 8
In this post, we describe a practical approach that you can use to detect anomalous behaviors within Amazon Web Services (AWS) cloud workloads by using behavioral analysis techniques that can be used to augment existing threat detection solutions. Anomaly detection is an advanced threat detection technique that should be considered …
kafka: 3 new resources
Dec 9
3 new resources: topic, group, transactional-id
rekognition: 5 updated actions, 1 updated resource
Dec 9
5 updated actions: TagResource (resources), UntagResource (resources), CreateCollection (resources), CreateProjectVersion (resources), CreateStreamProcessor (resources); 1 updated resource: dataset (arn)
textract: 1 new action
Dec 9
1 new action: AnalyzeID (detect relevant information from identity documents provided as input)
0xdabbad00
Scott Piper @0xdabbad00

We've hit the 30 minute mark into us-east-1 being down (based on the first post to hacker news) and no updates to the AWS status page yet. 🔥

0xdabbad00
Scott Piper @0xdabbad00

Second log4j2 bulletin from AWS (published 7:30 PM PDT on Saturday): aws.amazon.com/security/secur…
More AWS services are impacted.
Subtle acknowledgements that S3 and other services are now patched or are being patched. 😬
The recommended WAF rules do not look comprehensive.

0xdabbad00
Scott Piper @0xdabbad00

AWS security bulletin on the log4j issue: aws.amazon.com/security/secur…
Doesn't say much other than you should use their WAF product... which can be bypassed.

secdrama
Srinath Kuruvadi @secdrama

This is how we re-bootstrapped detection & response at scale in AWS cloud. Just a year in and we are already seeing some nice wins from all these investments. Nice work - Alex Bainbridge, Nick Siow and Michael Grima!

And we are…lnkd.in/g8CJqbu8 lnkd.in/gzrztPY5

clintgibler
Clint Gibler @clintgibler

🐳 Awesome #Kubernetes Security

A curated list of awesome Kubernetes security resources, by @ksoclabs

* Open source projects
* General resources
* Twitter accounts

github.com/ksoclabs/aweso…

christophetd
Christophe @christophetd

I released a small Spring Boot web application vulnerable to Log4Shell so everyone can easily play with it.

github.com/christophetd/l…

cc @LunaSecIO #log4j

clintgibler
Clint Gibler @clintgibler

🙈 Cloud service provider security mistakes by @0xdabbad00

AWS, GCP, and Azure

Mistakes on the cloud providers' side of the shared responsibility model

CVEs, SOC 2 Type 2 failures, security researchers compromising managed services, and more

github.com/SummitRoute/cs…

christophetd
Christophe @christophetd

The repository now contains both a vulnerable web application and the precise exploitation steps to RCE. Hopefully this will be useful for defenders crafting detection rules!

github.com/christophetd/l…

christophetd
Christophe @christophetd

I released a small Spring Boot web application vulnerable to Log4Shell so everyone can easily play with it.

github.com/christophetd/l…

cc @LunaSecIO #log4j

__steele
Aidan W Steele @__steele

Ask not what you can log4j, ask what j can log 4 you.

bjohnso5y
Brigid Johnson @bjohnso5y

I made today "try something new day" for my org. No meetings, emails, or pings. Just go try something new and take a picture. I went to a private yoga experience. For any folks in Seattle, I highly recommend it and it is like a mini retreat. Also makes a great gift!

jim_scharf
Jim Scharf @jim_scharf

IAM access analysis directly embedded in the S3 console to help you understand that the access control you granted is what you intended.

AWSIdentity
AWS Identity @AWSIdentity

The #AmazonS3 console automatically runs more than 1️⃣0️⃣0️⃣ actionable policy checks from IAM Access Analyzer as you author policies, saving you developer 🕐 & helping you apply security best practices. go.aws/3rqJtcO

500/502 Errors on AWS Console

As always their Service Health Dashboard says nothing is wrong.

I'm getting 500/502 errors from two different computers(in different geographical locations), completely different AWS accounts.

Anyone else experiencing issues?

ETA 11:37 AM ET: SHD has been updated:

8:22 AM PST We are investigating increased error rates for the AWS …

Anyone Else Lowkey Think the AWS Console Login Captchas Are Hard AF Sometimes..?

I swear sometimes I sit there and have to do it like 10 times until I'm able to get it right.

(┛◉Д◉)┛彡┻━┻

Post AWS outage, what changes do you plan to make?

I’ll start: Our company has pilot light regional failover, which is effective when aws is working but our app is not.

Our application processes are stateless, but we store data in an aurora multi az cluster and use elasticache redis for queuing and pubsub, and single region s3 for audio …

SOC 2 Compliance questions

Hey, I know that there's a big focus on SaaS companies vulnerability regarding data security. If you have any questions regarding SOC 2 compliance. I would love to answer any questions below. I've been speaking to quite a few people within this domain and there seems to be a lot …

buymeacoffee