📢 MAMIP (Monitor AWS Managed IAM Policies)
Policies changed since last week:
- AWSIdentitySyncFullAccess
- AWSIdentitySyncReadOnlyAccess
- AWSMigrationHubRefactorSpacesFullAccess
- AWSSSODirectoryAdministrator
- AWSSSODirectoryReadOnly
- AWSSSOMasterAccountAdministrator
- AWSSSOMemberAccountAdministrator
- AmazonEKSWorkerNodePolicy
- AmazonRDSServiceRolePolicy
- AmazonSageMakerAdmin-ServiceCatalogProductsServiceRolePolicy

Did you know that Dirty Pipe could also be used to escape unprivileged containers and gain root access on a Kubernetes host?
📖 Write-up: datadoghq.com/blog/engineeri…
👀 Proof of concept: github.com/datadog/dirtyp…
A thread on how it's done. 🧵⬇️




Advanced Persistent Teenager

Experts say the LAPSUS$ data extortion group that hit Okta and Microsoft this week is run by a 17-year-old from the UK who recently bought the Doxbin doxing website, and then leaked its database. Naturally, Doxbin responded by doxing the LAPSUS$ leader. krebsonsecurity.com/2022/03/a-clos…



"Fantastic AWS Hacks and Where to Find Them" - Getting started in AWS security, and how companies are getting hacked on AWS
📖Slides: dtdg.co/fantastic-aws-…
🧠Mindmap: mindmeister.com/map/2211520103…
🎨 by @MindsEyeCCF




Just blogged: "What to look for when reviewing a company's infrastructure" - A comprehensive guide that provides a structured approach to reviewing the security architecture of a multi-cloud SaaS company and finding its most critical components. marcolancini.it/2022/blog-clou…



#hugops to everyone in the Okta security team this week, it’s going to be a long one. For orgs using Okta, the details aren’t clear, so I’d be threat hunting for successful auths to services where there’s no matching okra session (a la golden SAML). I’d also be looking for…

LAPSUS$ extortion group claims to have breached @okta. They have released 8 photos as proof.
The photos we are sharing has been edited so no sensitive information or user identities are displayed.
Image 1 - 4 attached below.




Let's talk flexible work hours. I usually don't work on Fridays afternoons. My brain is fried 🧠 🍳. I love working on Sundays. I get to explore my thinky thoughts with a clear mind. This is today.




This appears to be legit. Sent to my flaws.cloud root email. Apparently AWS may now close your account if you don't respond within 5 days to what they think is a security incident, but there is no support case in the account to respond to (and no closed cases). 🤔




Huh. Someone emailed me that flAWS was broken, for the final level related to Lambda. I got an AccessDenied trying look at the Lambda service, while logged in as root, no SCPs on the account. EC2, IAM, S3, all work. Created root access key, still AccessDenied for only Lambda. 🤔

This appears to be legit. Sent to my flaws.cloud root email. Apparently AWS may now close your account if you don't respond within 5 days to what they think is a security incident, but there is no support case in the account to respond to (and no closed cases). 🤔




What performance are people getting from the new Lambda ephemeral storage? My results when running `npm ci` (575 MB written) inside Lambda:
/tmp
38 secs
108K writes
= ~15MB/s, ~2800 IOPS
EFS
180 secs
252K writes
= ~3MB/s, ~1400 IOPS
4-5x faster is nice, but less than expected



🗡️ How we found vulnerabilities in GitHub Actions CI/CD pipelines
@_alex_il_ describes vulnerable patterns in GitHub Actions that can lead to an attacker being able to steal secrets, inject code, etc.
+ mitigations on how to keep this from happening
cycode.com/blog/github-ac…


It has been great to see this community grow. Please let us know what is working well and what can be improved.
Some recent updates: * Twitter links are now allowed * We are working on some more AMAs (suggestions welcome) * For now we've pinned the MFA message to …
I am new to cloud security. I am looking for some suggestions around which cloud security certifications should I start with and what are the resources that I would/ should refer to prepare for these certifications?
- 🖊️ This newsletter was forwarded to you? Subscribe here
- 📢 Promote your content with Sponsorship
- 💌 Want to suggest new content: contact me or reply to this email