How to continuously audit and limit security groups with AWS Firewall Manager
AWS and EU data transfers: strengthened commitments to protect customer data

Big news! I'm shutting down my consulting business and just had my first day with @aurora_inno where I'll be leading AWS security. We're hiring!
I suspect I'll be busy for a while, so I wanted to write down some project ideas I wasn't able to get to: summitroute.com/blog/2021/02/1…



🚚 How to build a secure CI/CD pipeline for delivering infra as code
Great discussion of:
* Limitations of popular CI platforms (e.g. GitHub)
* Desired defense in depth features
* What they ended up building
tech.ovoenergy.com/building-a-sec…




Worried about the recently released tool "endgame" targeting your AWS environment? Two quick tips:
1. Look for any API calls with the User Agent "HotDogsAreSandwiches" (I disagree btw)
2. Look for any resource policies with a statement ID (SID) of "Endgame"



Just blogged: "Security Logging in Cloud Environments - AWS" - How to design a state of the art multi-account security logging platform in #AWS.
marcolancini.it/2021/blog-secu…



☁️ AWS security project ideas
Want to contribute to the #infosec community but not sure where to start?
Check out these project ideas by @0xdabbad00 for useful tools that don't yet exist.
summitroute.com/blog/2021/02/1…



This week I've had two male leaders more senior than I am share their moments of self doubt with me. As a female leader who has those feelings too, this act gave me the "hey, I really do belong here too" feeling. Share your doubt, it helps us all be more inclusive.




What info can you enumerate with AWS keys that have no permissions? I'm currently aware of:
- User ID
- ARN (+ account ID)
- Canonical ID
- Is GovCloud Account
- What regions are enabled/disabled



👍🔐🎉AWS IAM now supports 🏷tags for additional IAM resources including IAM managed policies and EC2 instance profiles. Now you can use ABAC for controlling which roles your users can attach to an Amazon EC2 instance profile and more. Check out the blog below! @AWSIdentity twitter.com/AWSSecurityInf…

Find out how to use tags to manage and secure access to additional types of IAM resources: go.aws/3b1cGBh



That almost nothing deleted is really gone. Customer asks for something to be deleted via GDPR or CCPA, it will be deleted from live database but it could take a year to roll off the backups.

Please quote this tweet with a thing that everyone in your field knows and nobody in your industry talks about because it would lead to general chaos.



So that’s one more tool that can use SQL to query AWS environments. Who knows of others?
* AWS Config + Athena
* steampipe.io
* cloudquery.io
* github.com/goldfiglabs/in…



For me - @IanColdwater inspires me to overcome fears, evangelize security knowledge, take the stage, and to just be a good human being.
@0xdabbad00 inspires me to push my boundaries with new tech, automate my knowledge, and to help the world learn about cloud security.



@clintgibler @aurora_inno It won't be like Apple where they cut out your tongue at orientation.
Also, I don't know who my TAM is yet (cc @z1g1), but someone over there at AWS better figure it out before our first meeting and send them reinforcements. 😂



Great post from @xssfox! A reminder to all to fully understand your security boundaries when mixing public repos and private assets.

How I hacked a .aws website and why your opensource projects build pipeline is likely broken.
sprocketfox.io/xssfox/2021/01…



Congrats to last year's sponsor Bridgecrew on their $200M acquisition by Palo Alto!
fwd:cloudsec is a great way for cloudsec companies to get noticed. Sponsor slots for the 2021 conference opening soon. Get on the mailing list for updates. fwdcloudsec.org

After two amazing years building the Bridgecrew team, platform, and open-source community, we’re thrilled to continue our journey with Palo Alto Networks! 💜
Read more about the proposed acquisition in our blog by Bridgecrew co-founder & CEO @IdanTendler.
bridge.dev/37lWlWL



🚨We have an upcoming #AWSGameDay at the end of February.
🎮This is a great opportunity to learn AWS with your peers in a safe and fun environment. If you haven't done a GameDay before, you're missing out!
🏆 Where will you end up on the leaderboard?
bit.ly/3u9hYTU



Dear AWS: Cost Explorer APIs Should be Free (or have a free allocation per month)
Lately I've been diving into my AWS bill a bit and am using Cost Explorer APIs and hilariously as soon as I began using them a new line item for Cost Explorer popped up in my bill.
I find it absolutely insane that Cost Explorer APIs cost money at all …
AWS just released an official AWS Quick Start
"Just launched superwerker - an open-source solution to automate the setup of an AWS Cloud environment with prescriptive best practices.
And it's also an official AWS Quick Start"
https://aws.amazon.com/quickstart/architecture/superwerker/
---
The whole AWS organization subaccount management is absolute garbage
The fact that you cannot close member accounts from the org.. I just had the displeasure of manually going through a good number of accounts, doing password recovery for every single one, and then manually deleting them one by one.. why? Whoever owns the CC of the Account should be …
- This newsletter was fwd to you? Subscribe here
- Want to suggest new content: contact me or reply to this email