📢 MAMIP (Monitor AWS Managed IAM Policies)
Policies changed since last week:
- AWSApplicationMigrationFullAccess
- AWSApplicationMigrationReadOnlyAccess
- AWSAuditManagerAdministratorAccess
- AWSSSOMasterAccountAdministrator
- AWSSSOMemberAccountAdministrator
- AWSSSOReadOnly
- AWSSupportServiceRolePolicy
- AmazonLexReadOnly
- AmazonSageMakerGroundTruthExecution
- ComprehendReadOnly







We have some new best friends in town!! These are powerful condition keys to help you establish an organizational boundary. 👏 🎉

We've launched 3 new condition keys to help you to control access along your AWS organizational boundaries:
🔑 aws:ResourceOrgID
🔑 aws:ResourceOrgPaths
🔑 aws:ResourceAccount
Learn how to get started. go.aws/3LpD74q




aws:ResourceOrgID has arrived

The AWS Security, Identity & Compliance Blog #AWSSecurity
aws.amazon.com/blogs/security…
By: Rishi Mehrotra* and Michael Switzer



AWS IAM came out with 3 new condition keys that can help you establish a Data Perimeter and prevent exfiltration etc.
If you remember the Endgame tool that showed how to blast open resource policies & share things with the world - this will prevent that. 🔥
Great work, AWS team

We've launched 3 new condition keys to help you to control access along your AWS organizational boundaries:
🔑 aws:ResourceOrgID
🔑 aws:ResourceOrgPaths
🔑 aws:ResourceAccount
Learn how to get started. go.aws/3LpD74q




How to control access to AWS resources based on AWS account, OU, or organization | AWS Security Blog. Going to be a super helpful relay for orgs looking to keep shadow cloud resources out of sensitive places aws.amazon.com/blogs/security…



If you haven't submitted a talk proposal to fwd:cloudsec, you should! It's a great (if not the best) cloud security conference happening in Boston on July 25th.
fwdcloudsec.org/cfp.html
Below are a few things I'd *love* to see. 🧵⬇️

You now can (and should!) submit talks fwd:cloudsec! fwdcloudsec.org/cfp.html
We just sent out updates to the mailing list:
- The conference will be one day at District Hall in Boston, MA on July 25th (the day before re:Inforce).
- Tickets will go on sale April 18th at noon ET



🧪 @datadoghq Security Labs Repo
Information, exploits, and scripts
Currently contains PoCs for:
* Dirty Pipe container breakout
* Spring4Shell
* JWT Null Signature Vulnerability
By @christophetd & @andrewkrug
github.com/DataDog/securi…



AWS breaking changes coming up:
April 30: Lambda ARNs are changing in IAM policies when versions or aliases are referenced: forum.serverless.com/t/lambda-secur…
May 18: GovCloud RDS TLS certs are changing. github.com/SummitRoute/aw…



This was long overdue! 🔑🔑

New AWS::EC2::KeyPair
Use the KeyPair resource to create or import a key pair.
docs.aws.amazon.com/AWSCloudFormat… #ec2 #cloudformation


Yes, of course you could make the service cheaper, I'm really wondering what people see as big gaps in the AWS services that they use.
If I had just one option here, I'd probably go for a deeper integration between Aurora Postgres and IAM. You can use IAM roles to …
- 🖊️ This newsletter was forwarded to you? Subscribe here
- 📢 Promote your content with ASD Sponsorship
- 💌 Want to suggest new content: contact me or reply to this email