SRE Weekly Issue #327 • 📖 [The CloudSecList] Issue 142 • [tl;dr sec] #137 - Malicious Terraform, How GitHub uses Dependabot • Amazon Connect Service - 3 updated methods • AmazonConnectCampaignService - 22 new methods • Redshift Data API Service - 7 updated methods • Redshift Serverless - 37 new methods • AWS HITRUST Inheritance: What customers should know • AWS and the UK rules on operational resilience and outsourcing • A sneak peek at the identity and access management sessions for AWS re:Inforce 2022 • How to secure an enterprise scale ACM Private CA hierarchy for automotive and manufacturing • lightsail: 1 new action | 63 updated actions, 3 updated resources • servicecatalog: 1 new action | 1 updated action • rbin: 2 new conditions | 8 updated actions • The Philosphy of Prevention - Chris Farris • A Deep Dive into Temporal's Access Control Strategy in AWS | Temporal Documentation • [tl;dr sec] #137 - Malicious Terraform, How GitHub uses Dependabot, Democratizing Security Detection • CloudSecList • The <a href="https://twitter.com/HashiCorp" target="_blank">@HashiCorp</a> Terraform AWS provider has just hit 1,000 resource types, beating <a href="https://twitter.com/AWSCloudFormer" target="_blank">@AWSCloudFormer</a> after a surge in 2021. CloudFormation currently trails by 80 types. Congrats to all the contributors of the AWS provider! 🎉 • Three steps to troubleshooting in Cloud: 1. It's not IAM 2. There's no way it's IAM 3. It was IAM • 🔖 Use CloudTrail to Pivot to AWS Accounts How to utilize the AWS CloudTrail service to discover other AWS accounts that you could pivot to. From <a href="https://twitter.com/bishopfox" target="_blank">@bishopfox</a> <a href="https://t.co/AR5HY09DoC" target="_blank">bishopfox.com/blog/cloudtrai…</a> • 5 years ago today I started a 2 week solo road trip around Ukraine 🇺🇦. Write your politicians to continue supporting Ukraine. • Listen to Koz. If you need to report or escalate an event, state the facts and be right, a lot. Hyperbole never pays off in the long term. Holds true for coordinated disclosure as well. • 🤖 How we use Dependabot to secure GitHub How <a href="https://twitter.com/github" target="_blank">@github</a>’s ProdSec rolled out Dependabot and how they track and prioritize tech debt 💯 post on effectively rolling out any security tooling at a company (not just SCA) <a href="https://t.co/e11cyZ22Df" target="_blank">github.blog/2022-05-25-how…</a> • AWS KMS everywhere is a money grab not a security strategy • Looking for people that use Prowler custom checks to give me feedback for the next version of Prowler. I’ll put a Prowler Pro hat in your mailbox. If you are interested, please, fill out this form <a href="https://t.co/Vwvltne6Nv" target="_blank">verica-io.typeform.com/to/FTZv1kmy</a> • TIL that people in the USA get fixed-rate mortgages.. for the lifetime of the loan? And this is the typical arrangement? Here in Australia the vast majority of home loans are variable rate (I think that’s ARM in USA-speak?). When people do fix, it’s for &lt;5 years. • Finally. • Switch to VPC Endpoints from NAT Gateways to Reduce Bandwidth Charges • Adventures in AWS Lambda Land - a Migration Gone Well • A 12-step guide to AWS cost optimisation • How AWS helped Safeguarding Ukraine’s data to preserve its present and build its future • Resoto – create an inventory of your cloud, and react to changes in your infrastructure • Breaking Secure Boot on Google Nest Hub (2nd Gen) to run Ubuntu • I have created a burp suite extension which allows pentester to keep track of each APIs, write test cases for individual APIs. Lastly the extension allows to map the vulnerable apis to the list of vulnerabilities using a custom checklist. • ORACLE CLOUD SECURITY FLAW? An unprivileged user can query information about all cloud service (with ids, admin emails, public ssh keys...) without any policy allowing it, and NO WAY TO BLOCK IT. • Raytheon Vet David Appel Named AWS National Security VP - GovCon Wire • AWS Security Insights Summit - Virtualization Review

ASD Logo

20
Monday June, 2022
Amazon Connect Service - 3 updated methods
Jun 17
This release updates these APIs: UpdateInstanceAttribute, DescribeInstanceAttribute and ListInstanceAttributes. You can use it to programmatically enable/disable High volume outbound communications using attribute type HIGH_VOLUME_OUTBOUND on the specified Amazon Connect instance.
AmazonConnectCampaignService - 22 new methods
Jun 17
Added Amazon Connect high volume outbound communications SDK.
Redshift Data API Service - 7 updated methods
Jun 16
This release adds a new --workgroup-name field to operations that connect to an endpoint. Customers can now execute queries against their serverless workgroups.
Redshift Serverless - 37 new methods
Jun 16
Add new API operations for Amazon Redshift Serverless, a new way of using Amazon Redshift without needing to manually manage provisioned clusters. The new operations let you interact with Redshift Serverless resources, such as create snapshots, list VPC endpoints, delete resource policies, and more.
AWS HITRUST Inheritance: What customers should know
Sonali VaidyaJun 16
As an Amazon Web Services (AWS) customer, you don’t have to assess the controls that you inherit from the AWS HITRUST Validated Assessment Questionnaire, because AWS already has completed HITRUST assessment using version 9.4 in 2021. You can deploy your environments onto AWS and inherit our HITRUST CSF certification, provided …
AWS and the UK rules on operational resilience and outsourcing
Arvind KannanJun 14
Financial institutions across the globe use Amazon Web Services (AWS) to transform the way they do business. Regulations continue to evolve in this space, and we’re working hard to help customers proactively respond to new rules and guidelines. In many cases, the AWS Cloud makes it simpler than ever before to …
A sneak peek at the identity and access management sessions for AWS re:Inforce 2022
Ilya EpshteynJun 13
Register now with discount code SALFNj7FaRe to get $150 off your full conference pass to AWS re:Inforce. For a limited time only and while supplies last. AWS re:Inforce 2022 will take place in-person in Boston, MA, on July 26 and 27 and will include some exciting identity and access management …
How to secure an enterprise scale ACM Private CA hierarchy for automotive and manufacturing
Anthony PasquarielloJun 13
In this post, we show how you can use the AWS Certificate Manager Private Certificate Authority (ACM Private CA) to help follow security best practices when you build a CA hierarchy. This blog post walks through certificate authority (CA) lifecycle management topics, including an architecture overview, centralized security, separation of …
lightsail: 1 new action | 63 updated actions, 3 updated resources
Jun 17
1 new action: GetLoadBalancerTlsPolicies (Grants permission to get a list of TLS security policies that you can apply to Lightsail load balancers); 63 updated actions: CreateDiskSnapshot (resources), DeleteDiskSnapshot (resources), CreateDiskFromSnapshot (resources), CreateRelationalDatabaseFromSnapshot (resources), CreateCertificate (conditions, resources), CreateContainerService (conditions, resources), CreateDistribution (conditions, resources), ExportSnapshot (resources, dependents), GetRelationalDatabaseMasterUserPassword (resources), TagResource (resources), UntagResource …
servicecatalog: 1 new action | 1 updated action
Jun 17
1 new action: ListAttributeGroupsForApplication (Grants permission to list the associated attribute groups for a given application); 1 updated action: AssociateResource (dependents)
rbin: 2 new conditions | 8 updated actions
Jun 16
2 new conditions: rbin:Attribute/ResourceType (Filters access by the resource type of the existing rule), rbin:Request/ResourceType (Filters access by the resource type in a request); 8 updated actions: TagResource (conditions), UntagResource (conditions), CreateRule (conditions), DeleteRule (conditions), GetRule (conditions), ListRules (conditions), ListTagsForResource (conditions), UpdateRule (conditions)
iann0036
Ian Mckay @iann0036

The @HashiCorp Terraform AWS provider has just hit 1,000 resource types, beating @AWSCloudFormer after a surge in 2021. CloudFormation currently trails by 80 types.

Congrats to all the contributors of the AWS provider! 🎉

9Jun 17 · 3:49 AM
kmcquade3
Kinnaird McQuade ⛅️🧨 @kmcquade3

Three steps to troubleshooting in Cloud:

1. It's not IAM
2. There's no way it's IAM
3. It was IAM

6Jun 20 · 12:06 AM
lancinimarco
Marco Lancini @lancinimarco

🔖 Use CloudTrail to Pivot to AWS Accounts

How to utilize the AWS CloudTrail service to discover other AWS accounts that you could pivot to. From @bishopfox

bishopfox.com/blog/cloudtrai…

8Jun 16 · 5:00 PM
0xdabbad00
Scott Piper @0xdabbad00

5 years ago today I started a 2 week solo road trip around Ukraine 🇺🇦. Write your politicians to continue supporting Ukraine.

1Jun 14 · 4:55 AM
notdurson
Dan Urson @notdurson

Listen to Koz. If you need to report or escalate an event, state the facts and be right, a lot. Hyperbole never pays off in the long term.

Holds true for coordinated disclosure as well.

seakoz
Jonathan Kozolchyk @seakoz

If you send an aggressive escalation email, make sure you're 100% correct otherwise you just look like a jackass. Much better to send a clinical email.

3Jun 17 · 4:35 AM
clintgibler
Clint Gibler @clintgibler

🤖 How we use Dependabot to secure GitHub

How @github’s ProdSec rolled out Dependabot and how they track and prioritize tech debt

💯 post on effectively rolling out any security tooling at a company (not just SCA)

github.blog/2022-05-25-how…

4Jun 14 · 10:30 PM
kmcquade3
Kinnaird McQuade ⛅️🧨 @kmcquade3

AWS KMS everywhere is a money grab not a security strategy

1Jun 13 · 7:27 PM
ToniBlyx
Toni de la Fuente @ToniBlyx

Looking for people that use Prowler custom checks to give me feedback for the next version of Prowler. I’ll put a Prowler Pro hat in your mailbox. If you are interested, please, fill out this form verica-io.typeform.com/to/FTZv1kmy

11Jun 16 · 6:37 PM
__steele
Aidan W Steele @__steele

TIL that people in the USA get fixed-rate mortgages.. for the lifetime of the loan? And this is the typical arrangement?

Here in Australia the vast majority of home loans are variable rate (I think that’s ARM in USA-speak?). When people do fix, it’s for <5 years.

1Jun 17 · 3:54 AM
0xdabbad00
Scott Piper @0xdabbad00

Finally.

seattletimes
The Seattle Times @seattletimes

Paige Thompson has been found guilty on seven counts related to computer and wire fraud. The Seattle software engineer was responsible for one of the largest data breaches in U.S. history. st.news/3tKbyMr

1Jun 18 · 3:27 AM
ORACLE CLOUD SECURITY FLAW? An unprivileged user can query information about all cloud service (with ids, admin emails, public ssh keys...) without any policy allowing it, and NO WAY TO BLOCK IT.

An unprivileged user can use OCI to query any information about the cloud without any policy allowing it.

Oracle let it happen by default and after almost 2 weeks talking with their support, they are not considering this as a security problem.

Whats your opinion?

Check it:
$ oci …