SRE Weekly Issue #328 • 📖 [The CloudSecList] Issue 143 • [tl;dr sec] #138 - Career Resources, Finding Secrets at Scale • Amazon Lookout for Equipment - 1 new methods • Application Migration Service - 4 new 6 updated methods • AWS Migration Hub Refactor Spaces - 1 new 1 updated methods • Amazon SageMaker Service - 6 updated methods • AWS re:Inforce 2022: Threat detection and incident response track preview • New AWS whitepaper: AWS User Guide to Financial Services Regulations and Guidelines in New Zealand • Wickr for Government achieves FedRAMP Ready designation

ASD Logo

27
Monday June, 2022

In a nutshell

  1. You asked for a less dazzling logo. We did an update for your eyes.
  2. We are introducing metering on highlight and sponsoring links to see what interests you the most. I will share later the app behind this magic (fully serverless on AWS)
  3. Community is warming up for this summer AWS Sec con in Boston MA: re:Inforce and fwd:CloudSec

📢 MAMIP (Monitor AWS Managed IAM Policies)

Policies changed since last week:

Weekly diff


👉🏻 From AWS Bots: 📃 MAMIP / 🤖 MASE / 👮🏻‍♂️ MGDA

Amazon Lookout for Equipment - 1 new methods
Jun 23
This release adds visualizations to the scheduled inference results. Users will be able to see interference results, including diagnostic results from their running inference schedulers.
Application Migration Service - 4 new 6 updated methods
Jun 23
New and modified APIs for the Post-Migration Framework
AWS Migration Hub Refactor Spaces - 1 new 1 updated methods
Jun 23
This release adds the new API UpdateRoute that allows route to be updated to ACTIVE/INACTIVE state. In addition, CreateRoute API will now allow users to create route in ACTIVE/INACTIVE state.
Amazon SageMaker Service - 6 updated methods
Jun 23
SageMaker Ground Truth now supports Virtual Private Cloud. Customers can launch labeling jobs and access to their private workforce in VPC mode.
AWS re:Inforce 2022: Threat detection and incident response track preview
Celeste BishopJun 23
Register now with discount code SALXTDVaB7y to get $150 off your full conference pass to AWS re:Inforce. For a limited time only and while supplies last. Today we’re going to highlight just some of the sessions focused on threat detection and incident response that are planned for AWS re:Inforce 2022. …
New AWS whitepaper: AWS User Guide to Financial Services Regulations and Guidelines in New Zealand
Julian BusicJun 21
Amazon Web Services (AWS) has released a new whitepaper to help financial services customers in New Zealand accelerate their use of the AWS Cloud. The new AWS User Guide to Financial Services Regulations and Guidelines in New Zealand—along with the existing AWS Workbook for the RBNZ’s Guidance on Cyber Resilience—continues …
Wickr for Government achieves FedRAMP Ready designation
Anne GrahnJun 20
AWS is pleased to announce that Wickr for Government (WickrGov) has achieved Federal Risk and Authorization Management Program (FedRAMP) Ready status at the Moderate Impact Level, and is actively working toward FedRAMP Authorized status. FedRAMP is a US government-wide program that promotes the adoption of secure cloud services across the …

Sponsor

The cheapest, most secure, and greener cloud asset is the one that doesn't exist.

While working on dev, training, or just studying the AWS ecosystem you will create, update, and manage many assets that could lead to unexpected costs at the end of the month.

To avoid any surprise, we build a SaaS app called unusd.cloud that could save you money. (Free forever for one AWS Account).

refactor-spaces: 1 new action
Jun 24
1 new action: UpdateRoute (Grants permission to update a route from an application)
macie:
Jun 24
AWS Service Removed
outposts: 2 new actions
Jun 23
2 new actions: GetConnection (Grants permission to get information about the connection for your Outpost server), StartConnection (Grants permission to start a connection for your Outpost server)
clintgibler
Clint Gibler @clintgibler

Doing a cloud pen test and you only have low privilege AWS creds?

@bishopfox describes how you can escalate privileges by examining CloudTrail assumeRole events to learn other AWS accounts you can pivot to.

#pentesting #cloudsecurity

bishopfox.com/blog/cloudtrai…

51Jun 24 · 5:00 PM
kmcquade3
Kinnaird McQuade ⛅️🧨 @kmcquade3

Lost a few followers after voicing frustration over Roe v Wade being overturned.

Don’t let the door hit you on the way out! 🖕🏼

2Jun 25 · 4:52 AM
__steele
Aidan W Steele @__steele

I've been writing code for over 20 years now and nothing makes me feel quite as incompetent as trying to write Typescript. 😥

0Jun 22 · 5:33 AM
bjohnso5y
Brigid Johnson @bjohnso5y

Who is going to ReInforce in July? And @QuinnyPig can we take a then and now picture? I think I still have this shirt.

1Jun 24 · 3:39 PM
__steele
Aidan W Steele @__steele

I’ve been trying and failing all day to find the words to express how I feel about SCOTUS’ latest decision. I can’t. I’m broken. Maybe soon I’ll have the energy to express my incandescent rage, but for now all I can muster is tears.

1Jun 25 · 11:56 AM
lancinimarco
Marco Lancini @lancinimarco

🔖 Unwanted Permissions that may impact security when using the ReadOnlyAccess policy in AWS

With this analysis, Tempest researchers identified at least 41 actions that can lead to improper data access.

sidechannel.blog/en/unwanted-pe…

7Jun 22 · 10:00 PM
lancinimarco
Marco Lancini @lancinimarco

And now we have a cover page! 🤩
(I have to admit that, my graphic skills aside, I had fun using @canva)

lancinimarco
Marco Lancini @lancinimarco

It's official: I'm writing a book! 📖

"The CloudSec Engineer" will be a book on how to enter, establish yourself, and thrive in the cloud security industry as an individual contributor.

1/

2Jun 21 · 8:40 PM
christophetd
Christophe @christophetd

If you're looking to pass your AWS Security Speciality, search no more twitter.com/adriancantrill…

adriancantrill
Adrian Cantrill @adriancantrill

I've just opened early access for my AWS Security Specialty course (details on this thread reddit.com/r/AWSCertifica…) direct link to the course learn.cantrill.io/p/aws-certifie… and a new bundle learn.cantrill.io/p/aws-security… - new demos/lessons coming - Please Retweet

#100daysofcloud #labEveryday

5Jun 21 · 6:21 AM
elrowan
rowan @elrowan

Is this... Is this... another landing zone approach from AWS? 🧐

aws.amazon.com/solutions/impl…

2Jun 27 · 1:38 AM
Together, DevOps and Cloud are a powerhouse.

In this blog, we will discuss how cloud and DevOps act as mutually strengthening strategies for increasing organisational agility through IT.

https://www.umbrellainfocare.com/blogs/cloud-and-devops-are-made-for-each-other