SRE Weekly Issue #320 • 📖 [The CloudSecList] Issue 135 • [tl;dr sec] #130 - Project Zero on 0day Trends, ThinkstScapes • Amazon CodeGuru Reviewer - 3 updated methods • AWS Elemental MediaConvert - 11 updated methods • Amazon Relational Database Service - 16 updated methods • Amazon Simple Systems Manager (SSM) - 3 updated methods • New IDC whitepaper released – Trusted Cloud: Overcoming the Tension Between Data Sovereignty and Accelerated Digital Transformation • How to control access to AWS resources based on AWS account, OU, or organization • Extend your pre-commit hooks with AWS CloudFormation Guard • LGPD workbook for AWS customers managing personally identifiable information in Brazil • cloudformation: 1 updated condition • servicecatalog: 1 updated condition • iotwireless: 6 new actions, 1 new resource | 8 updated actions • The OPA AWS CloudFormation Hook • Wiz Research discovers "ExtraReplica"— a cross-account database vulnerability in Azure PostgreSQL • There's a Spotify Terraform provider 😂 • We have some new best friends in town!! These are powerful condition keys to help you establish an organizational boundary. 👏 🎉 • aws:ResourceOrgID has arrived • It’s happening! <a href="https://twitter.com/hashtag/awslondonsummit" target="_blank">#awslondonsummit</a> • AWS IAM came out with 3 new condition keys that can help you establish a Data Perimeter and prevent exfiltration etc. If you remember the Endgame tool that showed how to blast open resource policies &amp; share things with the world - this will prevent that. 🔥 Great work, AWS team • How to control access to AWS resources based on AWS account, OU, or organization | AWS Security Blog. Going to be a super helpful relay for orgs looking to keep shadow cloud resources out of sensitive places <a href="https://t.co/DYjX89USNE" target="_blank">aws.amazon.com/blogs/security…</a> • If you haven't submitted a talk proposal to fwd:cloudsec, you should! It's a great (if not the best) cloud security conference happening in Boston on July 25th. <a href="https://t.co/pTUaLZNI4n" target="_blank">fwdcloudsec.org/cfp.html</a> Below are a few things I'd *love* to see. 🧵⬇️ • 🧪 <a href="https://twitter.com/datadoghq" target="_blank">@datadoghq</a> Security Labs Repo Information, exploits, and scripts Currently contains PoCs for: * Dirty Pipe container breakout * Spring4Shell * JWT Null Signature Vulnerability By <a href="https://twitter.com/christophetd" target="_blank">@christophetd</a> &amp; <a href="https://twitter.com/andrewkrug" target="_blank">@andrewkrug</a> <a href="https://t.co/jpWxh5tQMx" target="_blank">github.com/DataDog/securi…</a> • AWS breaking changes coming up: April 30: Lambda ARNs are changing in IAM policies when versions or aliases are referenced: <a href="https://t.co/9C1n0L60hY" target="_blank">forum.serverless.com/t/lambda-secur…</a> May 18: GovCloud RDS TLS certs are changing. <a href="https://t.co/4qjuQqjOnH" target="_blank">github.com/SummitRoute/aw…</a> • This was long overdue! 🔑🔑 • AWS's Open Source Problem - by Corey Quinn • Amazon RDS now supports Internet Protocol Version 6 (IPv6) • AWS Step Functions expands support for over 20 new AWS SDK integrations • You have a magic wand, which when waved, let's you change anything about one AWS service. What do you change and why? • Amazon Rekognition introduces Streaming Video Events to provide real-time alerts on live video streams • Kubernetes Goat - Interactive Kubernetes Security Learning Playground 🚀 • KrbRelayUp - local privilege escalation in Windows domain environments where LDAP signing is not enforced • Can anyone recommend what’s the best route or certifications to start off getting in order to get a entry level job in this field w/ no experience but I also have full military benefits if anyone accepts that for certifications…? • AWS Wins Out Over Microsoft For $10B NSA Cloud Contract - CRN • Prowler Pro for AWS security launched by Verica - SC Media
2
Monday May, 2022
Amazon CodeGuru Reviewer - 3 updated methods
Apr 29
Amazon CodeGuru Reviewer now supports suppressing recommendations from being generated on specific files and directories.
AWS Elemental MediaConvert - 11 updated methods
Apr 29
AWS Elemental MediaConvert SDK nows supports creation of Dolby Vision profile 8.1, the ability to generate black frames of video, and introduces audio-only DASH and CMAF support.
Amazon Relational Database Service - 16 updated methods
Apr 29
Feature - Adds support for Internet Protocol Version 6 (IPv6) on RDS database instances.
Amazon Simple Systems Manager (SSM) - 3 updated methods
Apr 29
Update the StartChangeRequestExecution, adding TargetMaps to the Runbook parameter
New IDC whitepaper released – Trusted Cloud: Overcoming the Tension Between Data Sovereignty and Accelerated Digital Transformation
Marta TaggartApr 27
A new International Data Corporation (IDC) whitepaper sponsored by AWS, Trusted Cloud: Overcoming the Tension Between Data Sovereignty and Accelerated Digital Transformation, examines the importance of the cloud in building the future of digital EU organizations. IDC predicts that 70% of CEOs of large European organizations will be incentivized to …
How to control access to AWS resources based on AWS account, OU, or organization
Rishi MehrotraApr 27
AWS Identity and Access Management (IAM) recently launched new condition keys to make it simpler to control access to your resources along your Amazon Web Services (AWS) organizational boundaries. AWS recommends that you set up multiple accounts as your workloads grow, and you can use multiple AWS accounts to isolate …
Extend your pre-commit hooks with AWS CloudFormation Guard
Joaquin Manuel RinaudoApr 26
Git hooks are scripts that extend Git functionality when certain events and actions occur during code development. Developer teams often use Git hooks to perform quality checks before they commit their code changes. For example, see the blog post Use Git pre-commit hooks to avoid AWS CloudFormation errors for a …
LGPD workbook for AWS customers managing personally identifiable information in Brazil
Rodrigo FiuzaApr 25
Portuguese version AWS is pleased to announce the publication of the Brazil General Data Protection Law Workbook. The General Data Protection Law (LGPD) in Brazil was first published on 14 August 2018, and started its applicability on 18 August 2020. Companies that manage personally identifiable information (PII) in Brazil as …
cloudformation: 1 updated condition
May 2
1 updated condition: aws:TagKeys (type)
servicecatalog: 1 updated condition
May 2
1 updated condition: aws:TagKeys (type)
iotwireless: 6 new actions, 1 new resource | 8 updated actions
Apr 29
6 new actions: CreateNetworkAnalyzerConfiguration (Grants permission to create a NetworkAnalyzerConfiguration resource), DeleteNetworkAnalyzerConfiguration (Grants permission to delete the NetworkAnalyzerConfiguration), GetEventConfigurationsByResourceTypes (Grants permission to get event configurations by resource types), ListEventConfigurations (Grants permission to list information of available event configurations based on the AWS account), ListNetworkAnalyzerConfigurations (Grants permission to list information of …
kmcquade3
Kinnaird McQuade  @kmcquade3

There's a Spotify Terraform provider 😂

12Apr 29 · 8:14 PM
bjohnso5y
Brigid Johnson @bjohnso5y

We have some new best friends in town!! These are powerful condition keys to help you establish an organizational boundary. 👏 🎉

AWSIdentity
AWS Identity @AWSIdentity

We've launched 3 new condition keys to help you to control access along your AWS organizational boundaries:
🔑 aws:ResourceOrgID
🔑 aws:ResourceOrgPaths
🔑 aws:ResourceAccount
Learn how to get started. go.aws/3LpD74q

15Apr 27 · 11:23 PM
0xdabbad00
Scott Piper @0xdabbad00

aws:ResourceOrgID has arrived

AWSBlogUnreal
AWS Blog Unofficial. @AWSBlogUnreal

The AWS Security, Identity & Compliance Blog #AWSSecurity
aws.amazon.com/blogs/security…
By: Rishi Mehrotra* and Michael Switzer

9Apr 27 · 8:08 PM
kmcquade3
Kinnaird McQuade  @kmcquade3

AWS IAM came out with 3 new condition keys that can help you establish a Data Perimeter and prevent exfiltration etc.

If you remember the Endgame tool that showed how to blast open resource policies & share things with the world - this will prevent that. 🔥

Great work, AWS team

AWSIdentity
AWS Identity @AWSIdentity

We've launched 3 new condition keys to help you to control access along your AWS organizational boundaries:
🔑 aws:ResourceOrgID
🔑 aws:ResourceOrgPaths
🔑 aws:ResourceAccount
Learn how to get started. go.aws/3LpD74q

6Apr 28 · 3:28 AM
z1g1
Zack Glick @z1g1

How to control access to AWS resources based on AWS account, OU, or organization | AWS Security Blog. Going to be a super helpful relay for orgs looking to keep shadow cloud resources out of sensitive places aws.amazon.com/blogs/security…

11Apr 27 · 11:31 PM
christophetd
Christophe @christophetd

If you haven't submitted a talk proposal to fwd:cloudsec, you should! It's a great (if not the best) cloud security conference happening in Boston on July 25th.

fwdcloudsec.org/cfp.html

Below are a few things I'd *love* to see. 🧵⬇️

fwdcloudsec
fwd:cloudsec @fwdcloudsec

You now can (and should!) submit talks fwd:cloudsec! fwdcloudsec.org/cfp.html
We just sent out updates to the mailing list:
- The conference will be one day at District Hall in Boston, MA on July 25th (the day before re:Inforce).
- Tickets will go on sale April 18th at noon ET

13Apr 27 · 11:26 AM
clintgibler
Clint Gibler @clintgibler

🧪 @datadoghq Security Labs Repo

Information, exploits, and scripts

Currently contains PoCs for:

* Dirty Pipe container breakout
* Spring4Shell
* JWT Null Signature Vulnerability

By @christophetd & @andrewkrug

github.com/DataDog/securi…

8Apr 25 · 9:00 PM
0xdabbad00
Scott Piper @0xdabbad00

AWS breaking changes coming up:
April 30: Lambda ARNs are changing in IAM policies when versions or aliases are referenced: forum.serverless.com/t/lambda-secur…
May 18: GovCloud RDS TLS certs are changing. github.com/SummitRoute/aw…

9Apr 26 · 6:09 PM
iann0036
Ian Mckay @iann0036

This was long overdue! 🔑🔑

cfnupdates
CFN Updates @cfnupdates

New AWS::EC2::KeyPair

Use the KeyPair resource to create or import a key pair.
docs.aws.amazon.com/AWSCloudFormat… #ec2 #cloudformation

0Apr 30 · 8:09 AM