Issue #57

Monday · February 14, 2022

πŸ₯— AWS security blogs

  • C5 Type 2 attestation report now available with 141 services in scope β€” Amazon Web Services (AWS) is pleased to announce the issuance of the new Cloud Computing Compliance Controls Catalogue (C5) Type 2 attestation report. We added 18 additional services and service features to the scope of the 2021 report. Germany’s national cybersecurity authority, Bundesamt fΓΌr Sicherheit in der Informationstechnik (BSI), established …

πŸ› Reddit threads on r/aws

πŸ“Œ Newsletters

πŸ“Œ Top Links from Security Folks

πŸ“Œ r/netsec

πŸ“Œ r/cloudsecurity

  • AWS Cloud Security challenge - 1 β€” Hey folks, Starting these random challenges for people to try out and learn cloud hacking. You can start the hunt from s3-challenge-1 bucket. :) ​ Have fun !

πŸ“Œ "AWS Security" on Google News

🧁 IAM permission changes

  • ds: 1 new action | 4 updated actions β€” 1 new action: DescribeClientAuthenticationSettings (retrieve information about the type of client authentication for the specified directory, if the type is specified. if no type is specified, information about all client authentication types that are supported for the specified directory is retrieved. currently, only smartcard is supported); 4 updated actions: ConnectDirectory …
  • quicksight: 2 new actions β€” 2 new actions: AccountConfigurations (to enable setting default access to aws resources), ScopeDownPolicy (scoping policies for permissions to aws resources)
  • cloudformation: 1 new action β€” 1 new action: DescribeChangeSetHook (return the hook invocation information for the specified change set)

πŸͺ API changes

Get every AWS security change,
on a plate every Monday.

6,700+ engineers, builders and CISOs let us diff the AWS changelog every week.