📢 MAMIP (Monitor AWS Managed IAM Policies)
Policies changed since last week:
- AWSApplicationMigrationAgentInstallationPolicy
- AWSCloudTrail_ReadOnlyAccess
- AWSServiceCatalogAppRegistryFullAccess
- AWSServiceCatalogAppRegistryReadOnlyAccess
- AWSServiceRoleForImageBuilder
- AmazonRedshiftQueryEditorV2NoSharing
- AmazonRedshiftQueryEditorV2ReadSharing
- AmazonRedshiftQueryEditorV2ReadWriteSharing
- ComputeOptimizerServiceRolePolicy










The @HashiCorp Terraform AWS provider has just hit 1,000 resource types, beating @AWSCloudFormer after a surge in 2021. CloudFormation currently trails by 80 types.
Congrats to all the contributors of the AWS provider! 🎉




Three steps to troubleshooting in Cloud:
1. It's not IAM
2. There's no way it's IAM
3. It was IAM



🔖 Use CloudTrail to Pivot to AWS Accounts
How to utilize the AWS CloudTrail service to discover other AWS accounts that you could pivot to. From @bishopfox
bishopfox.com/blog/cloudtrai…



5 years ago today I started a 2 week solo road trip around Ukraine 🇺🇦. Write your politicians to continue supporting Ukraine.




Listen to Koz. If you need to report or escalate an event, state the facts and be right, a lot. Hyperbole never pays off in the long term.
Holds true for coordinated disclosure as well.

If you send an aggressive escalation email, make sure you're 100% correct otherwise you just look like a jackass. Much better to send a clinical email.



🤖 How we use Dependabot to secure GitHub
How @github’s ProdSec rolled out Dependabot and how they track and prioritize tech debt
💯 post on effectively rolling out any security tooling at a company (not just SCA)
github.blog/2022-05-25-how…




AWS KMS everywhere is a money grab not a security strategy



Looking for people that use Prowler custom checks to give me feedback for the next version of Prowler. I’ll put a Prowler Pro hat in your mailbox. If you are interested, please, fill out this form verica-io.typeform.com/to/FTZv1kmy




TIL that people in the USA get fixed-rate mortgages.. for the lifetime of the loan? And this is the typical arrangement?
Here in Australia the vast majority of home loans are variable rate (I think that’s ARM in USA-speak?). When people do fix, it’s for <5 years.




Finally.

Paige Thompson has been found guilty on seven counts related to computer and wire fraud. The Seattle software engineer was responsible for one of the largest data breaches in U.S. history. st.news/3tKbyMr


An unprivileged user can use OCI to query any information about the cloud without any policy allowing it.
Oracle let it happen by default and after almost 2 weeks talking with their support, they are not considering this as a security problem.
Whats your opinion?
Check it:
$ oci …
- 🖊️ This newsletter was forwarded to you? Subscribe here
- 📢 Promote your content with ASD Sponsorship
- 💌 Want to suggest new content: contact me or reply to this email