📢 MAMIP (Monitor AWS Managed IAM Policies)
Policies changed since last week:
- AWSBatchServiceRole
- AmazonConnectServiceLinkedRolePolicy
- AmazonLookoutVisionConsoleReadOnlyAccess
- AmazonLookoutVisionReadOnlyAccess
- AmazonRoute53RecoveryControlConfigReadOnlyAccess
- BatchServiceRolePolicy
Get notified of policy change using this Twitter bot. 🐦
Last Updated Date: 2021/12/12 9:40 PM PDT
AWS is aware of the recently disclosed security issue relating to the open-source Apache “Log4j2" utility (CVE-2021-44228). We are actively monitoring this issue, and are working on addressing it for any AWS services which either use Log4j2 or provide it to customers as …
Initial Publication Date: 2021/12/10 7:20 PM PDT
AWS is aware of the recently disclosed security issue relating to the open-source Apache “Log4j2" utility (CVE-2021-44228). We are actively monitoring this issue, and are working on addressing it for any AWS services which either use Log4j2 or provide it to customers as …

We've hit the 30 minute mark into us-east-1 being down (based on the first post to hacker news) and no updates to the AWS status page yet. 🔥

Second log4j2 bulletin from AWS (published 7:30 PM PDT on Saturday): aws.amazon.com/security/secur…
More AWS services are impacted.
Subtle acknowledgements that S3 and other services are now patched or are being patched. 😬
The recommended WAF rules do not look comprehensive.

AWS security bulletin on the log4j issue: aws.amazon.com/security/secur…
Doesn't say much other than you should use their WAF product... which can be bypassed.

This is how we re-bootstrapped detection & response at scale in AWS cloud. Just a year in and we are already seeing some nice wins from all these investments. Nice work - Alex Bainbridge, Nick Siow and Michael Grima!
And we are…lnkd.in/g8CJqbu8 lnkd.in/gzrztPY5

🐳 Awesome #Kubernetes Security
A curated list of awesome Kubernetes security resources, by @ksoclabs
* Open source projects
* General resources
* Twitter accounts
github.com/ksoclabs/aweso…

I released a small Spring Boot web application vulnerable to Log4Shell so everyone can easily play with it.
github.com/christophetd/l…
cc @LunaSecIO #log4j


🙈 Cloud service provider security mistakes by @0xdabbad00
AWS, GCP, and Azure
Mistakes on the cloud providers' side of the shared responsibility model
CVEs, SOC 2 Type 2 failures, security researchers compromising managed services, and more
github.com/SummitRoute/cs…

The repository now contains both a vulnerable web application and the precise exploitation steps to RCE. Hopefully this will be useful for defenders crafting detection rules!
github.com/christophetd/l…

I released a small Spring Boot web application vulnerable to Log4Shell so everyone can easily play with it.
github.com/christophetd/l…
cc @LunaSecIO #log4j


Ask not what you can log4j, ask what j can log 4 you.

IAM access analysis directly embedded in the S3 console to help you understand that the access control you granted is what you intended.

The #AmazonS3 console automatically runs more than 1️⃣0️⃣0️⃣ actionable policy checks from IAM Access Analyzer as you author policies, saving you developer 🕐 & helping you apply security best practices. go.aws/3rqJtcO

As always their Service Health Dashboard says nothing is wrong.
I'm getting 500/502 errors from two different computers(in different geographical locations), completely different AWS accounts.
Anyone else experiencing issues?
ETA 11:37 AM ET: SHD has been updated:
8:22 AM PST We are investigating increased error rates for the AWS …
I swear sometimes I sit there and have to do it like 10 times until I'm able to get it right.
(┛◉Д◉)┛彡┻━┻
I’ll start: Our company has pilot light regional failover, which is effective when aws is working but our app is not.
Our application processes are stateless, but we store data in an aurora multi az cluster and use elasticache redis for queuing and pubsub, and single region s3 for audio …
Hey, I know that there's a big focus on SaaS companies vulnerability regarding data security. If you have any questions regarding SOC 2 compliance. I would love to answer any questions below. I've been speaking to quite a few people within this domain and there seems to be a lot …
- 🖊️ This newsletter was fwd to you? Subscribe here
- 💌 Want to suggest new content: contact me or reply to this email
- ⚡️ Powered by Mailbrew
- 🐦 Follow me on Twitter or hire me.