In a nutshell
- You asked for a less dazzling logo. We did an update for your eyes.
- We are introducing metering on highlight and sponsoring links to see what interests you the most. I will share later the app behind this magic (fully serverless on AWS)
- Community is warming up for this summer AWS Sec con in Boston MA: re:Inforce and fwd:CloudSec
📢 MAMIP (Monitor AWS Managed IAM Policies)
Policies changed since last week:
- AWSControlTowerServiceRolePolicy
- AWSProtonFullAccess
- AWSSupportServiceRolePolicy
- AWSThinkboxDeadlineResourceTrackerAdminPolicy
- AWSWellArchitectedOrganizationsServiceRolePolicy
- FMSServiceRolePolicy
Sponsor
The cheapest, most secure, and greener cloud asset is the one that doesn't exist.
While working on dev, training, or just studying the AWS ecosystem you will create, update, and manage many assets that could lead to unexpected costs at the end of the month.
To avoid any surprise, we build a SaaS app called unusd.cloud that could save you money. (Free forever for one AWS Account).

Doing a cloud pen test and you only have low privilege AWS creds?
@bishopfox describes how you can escalate privileges by examining CloudTrail assumeRole events to learn other AWS accounts you can pivot to.
#pentesting #cloudsecurity
bishopfox.com/blog/cloudtrai…



🛡️ggshield
CLI tool that can detect more than 300 types of secrets
By @GitGuardian
#bugbounty #bugbountytips
github.com/GitGuardian/gg…



Lost a few followers after voicing frustration over Roe v Wade being overturned.
Don’t let the door hit you on the way out! 🖕🏼



I've been writing code for over 20 years now and nothing makes me feel quite as incompetent as trying to write Typescript. 😥



Who is going to ReInforce in July? And @QuinnyPig can we take a then and now picture? I think I still have this shirt.




I’ve been trying and failing all day to find the words to express how I feel about SCOTUS’ latest decision. I can’t. I’m broken. Maybe soon I’ll have the energy to express my incandescent rage, but for now all I can muster is tears.



🔖 Unwanted Permissions that may impact security when using the ReadOnlyAccess policy in AWS
With this analysis, Tempest researchers identified at least 41 actions that can lead to improper data access.
sidechannel.blog/en/unwanted-pe…



And now we have a cover page! 🤩
(I have to admit that, my graphic skills aside, I had fun using @canva)


It's official: I'm writing a book! 📖
"The CloudSec Engineer" will be a book on how to enter, establish yourself, and thrive in the cloud security industry as an individual contributor.
1/




If you're looking to pass your AWS Security Speciality, search no more twitter.com/adriancantrill…

I've just opened early access for my AWS Security Specialty course (details on this thread reddit.com/r/AWSCertifica…) direct link to the course learn.cantrill.io/p/aws-certifie… and a new bundle learn.cantrill.io/p/aws-security… - new demos/lessons coming - Please Retweet
#100daysofcloud #labEveryday




Is this... Is this... another landing zone approach from AWS? 🧐
aws.amazon.com/solutions/impl…


I don't see any docs that diverge from
In this blog, we will discuss how cloud and DevOps act as mutually strengthening strategies for increasing organisational agility through IT.
https://www.umbrellainfocare.com/blogs/cloud-and-devops-are-made-for-each-other
- 🖊️ This newsletter was forwarded to you? Subscribe here
- 📢 Promote your content with ASD Sponsorship
- 💌 Want to suggest new content: contact me or reply to this email