AWS WAF adds support for JSON parsing and inspection
Introducing Amazon VPC Endpoints for AWS CloudHSM
https://aws.amazon.com/about-aws/whats-new/2021/02/introducing-amazon-vpc-endpoints-aws-cloudhsm/
AWS Identity and Access Management now supports tags on additional resources
https://aws.amazon.com/about-aws/whats-new/2021/02/aws-identity-and-access-management-now-supports-tags-on-additional-resources/
AWS CloudHSM Adds New Availability Zones
https://aws.amazon.com/about-aws/whats-new/2021/02/aws-cloudhsm-adds-new-availability-zones/
Use tags to manage and secure access to additional types of IAM resources
Mitigate data leakage through the use of AppStream 2.0 and end-to-end auditing

I’ve spent the past weeks building a 2 day class in Cloud Security Engineering. Unfortunately, I won’t be able to upload the slides anywhere but the labs are made public. Hope someone finds them to be useful despite the lack of context provided by the slides.



🏷️IAM has more resources to tag🏷️ This is cool because now you can tag customer managed policies. Helps organize and control access to specific policies among other IAM resources. amzn.to/2Oref3L




🛡️ A Practical Guide to Writing Secure Dockerfiles
@madhuakula on useful Docker security resources + tools
* Securely passing in secrets
* Tools: BuiltKit, hadolint, dockle, dive, conftest
* DockerSlim: autogenerating Seccomp and AppArmor profiles
speakerdeck.com/madhuakula/a-p…



🤬 Creating IAM policies is hard
What if we could just observe AWS CLI calls and auto-generate an IAM policy?
Tool by @iann0036 that uses client-side monitoring (CSM) to do just that 🙌
github.com/iann0036/iamli…



If you perform penetration tests on AWS accounts regularly and are interested in trying out an extremely destructive 😈 AWS pentesting tool I am going to open source next week-ish, please ping me.



From @tdmalone in the og-aws Slack, you can't enforce HTTPS via an SCP because some AWS services use HTTP. ☹️




Dropping that new AWS security tool in 48 hours.
I honestly can’t contain my excitement.
Relevant content:




Lab 6: Memory dump of Windows instances with upload to S3.
Lab 7: Simple AWS response lab using boto3 and Python
github.com/karimelmel/clo…
The class will be held for a non-profit the coming week!



In my latest post, I talk about that weird situation of having the same root email for two #AWS accounts and what its implications are.
onecloudplease.com/blog/case-of-t…



Given the S3 durability guarantee that AWS loses 1 object per year for every 100B objects, and that in 2012 S3 was already storing 900B objects, I wish AWS would define what happens when they lose an S3 object. aws.amazon.com/s3/faqs/


This is neat. I saw in a job ad that AWS handles 750M TPS. I then found this article about it handling 1M TPS 9 years ago.
Talk about rapid growth! Will it continue at that rate? Which services contribute the most to that? S3 and CloudFront, maybe?




CloudFormation::Council::Bens, assemble! Custom resource providers can now be defined in templates
docs.aws.amazon.com/AWSCloudFormat…
@ben11kehoe @benbridts



This is neat. I saw in a job ad that AWS handles 750M TPS. I then found this article about it handling 1M TPS 9 years ago.
Talk about rapid growth! Will it continue at that rate? Which services contribute the most to that? S3 and CloudFront, maybe?




Opened a mid-level Pentester role as well. If you're passionate about cybersecurity but the specs dont quite match up, reach out to us anyway! Careers@rhinosecuritylabs.com
apply.workable.com/j/0C7173C530



🎥🍿An overview and demo of how to implement fine-grained access control with Amazon Cognito identity pools and a demo of using attributes from identity providers for access control (ABAC). More on identity pools here: docs.aws.amazon.com/cognito/latest…
@AWSIdentity
youtube.com/watch?v=tAUmz9…


AWS Support is better than any other vendor support I've used.
I've been working professionally in IT for a decade in a variety of roles. I've opened tickets with Microsoft, VMware, Novell, Oracle, SolarWinds, Dell, EMC, NetApp, Red Hat, and many more. I've been working full time with AWS for over four years now and their Support has ALWAYS been top …
When discussing the cost of AWS with your clients do you bring up electricity costs for on-prem servers?
I was trying to get a client to move to 365 and AWS. They did like the cost estimation I had setup. To put the final nail in the coffin and seal the deal I calculated the run time for their servers and wattage. I also got one of their …
Zscaler Newbie
Dear Group Members,
What are your thoughts about ZScaler and what do you think are the benefits using it as well as the predictions for the future?
How would you describe ZScaler using a few words?
And what are/is the main difference(s) to traditional network security or Cisco’s technology?
Happy …