🔦 Highlight of the week
📢 MAMIP (Monitor AWS Managed IAM Policies)
Policies changed since last week:
- AWSApplicationMigrationFullAccess
- AWSApplicationMigrationReadOnlyAccess
- AWSAuditManagerAdministratorAccess
- AWSBackupServiceLinkedRolePolicyForBackup
- AWSSSOServiceRolePolicy
- AmazonCodeGuruProfilerAgentAccess
- AmazonSageMakerFullAccess
- AmazonSageMakerGroundTruthExecution
- MonitronServiceRolePolicy
- ReadOnlyAccess

🔒 Tool: SSH No Ports
SSH to a remote Linux host/device without that device having any open ports (not even 22) on external interfaces
All network connectivity is outbound
No need to know the target's IP
By @atsigncompany
github.com/atsign-foundat…



🥶 Frostbyte
A POC project that combines different defense evasion techniques to build better #redteam payloads
➡️ Embed an encrypted shellcode stub into a known signed executable & still keep it signed like how the Zloader malware did
By @0xpwnisher
github.com/pwn1sher/frost…



8.5 years…completed it!
Worked Hard, Had Fun, Made History ✅
Friday was my last day @awscloud - made so many amazing friends and lifelong memories🧡 ✌️




There is a threat actor that is scanning and exploiting AWS environments that are not enforcing IMDSv2, and are running vulnerable software.
Reminder: there are vendors that do not allow enforcing IMDSv2 that need to release fixes (including AWS): github.com/SummitRoute/im…

Since July 2021, @Mandiant identified exploitation of public-facing web applications by threat actors (UNC2903) to harvest credentials using Amazon’s Instance Metadata Service (IMDS).
mandiant.com/resources/clou…
#aws #imds #cloud #cloudsecurity #incidentresponse #breaches #dfir



I think we have an answer (a few, actually) already. The twitterverse is magic

@__steele @QuinnyPig Alice, Bob, Carol, Eve,… en.wikipedia.org/wiki/Alice_and…
Trent is the trusted third party.



I’m happy to share that I’m starting a new position as Director of Engineering & Distinguished Engineer @showpad
Very excited to be joining a customer focused, high-growth SaaS organisation 🚀
P.S - We are hiring (DMs open) 😜



Important parts of Heroku were hacked. 😬
"a threat actor ... downloaded stored customer GitHub integration OAuth tokens ... exfiltrate the hashed and salted passwords for customers’ user accounts"

Update: Heroku Security Notification status.heroku.com/incidents/2413



Just asked "How do I add line numbers to a word doc?" Line number vs no line number has been a hot topic for debate throughout my AWS career. I am finally making the leap! Let's hope this works out.



Yet another dependency takeover - this one in Ruby gems. #SupplyChainSecurity
github.com/rubygems/rubyg…


(Apologies for the ranty-ness, but this is seriously driving me up the wall because I keep having to fix it multiple times a day)
On Ubuntu, every time I connect to the VPN with the AWS VPN Client, it sets net.ipv4.ip_forward=0
This fucks up networking on my machine, particularly Docker …
Hi,
We have an integration with a printer manufacturer and their printers are set up in a way that requests our APIs every second to check if we have a print job available for the given printer.
Unfortunately, the printer manufacturer has not heard of webhooks or sockets and is …
EDIT: going to say this is solved. It was most likely the transfer fee that got us (we have 425M objects from all kinds of different logging systems like aws config, flow logs, etc etc).
Solution: Looking at using intelligent tiering or maybe just zipping logs up once …
I was making copies of my main instance and created 7 copies of it.
I immediately stopped them (so that they don't eat up my free hours) but didn't fully delete/terminate them until half an hour later.
I know EC2 gives 750 hours of free usage each month, but I'm …
Hello Guys! anyone studying for the GPCS? Currently studying CCSK and I cant go with CCSP next due that I dont have enough experience.
Do i need to go train with SANS first for me to take the GPCS?
Thanks!
- 🖊️ This newsletter was forwarded to you? Subscribe here
- 📢 Promote your content with ASD Sponsorship
- 💌 Want to suggest new content: contact me or reply to this email