Security Newsletter - VMWare vCenter vulnerable to critical exploit. Microsoft releases CodeQL queries for Solarwinds. Hiding c2 servers in Bitcoin transactions. • How to protect sensitive data for its entire lifecycle in AWS • Fall 2020 PCI DSS report now available with eight additional services in scope • I made a thing. Assume AWS IAM roles from GitHub Actions. Now I can use the best CI solution with the best cloud and not have to create IAM users. The role sessions are even tagged with repo, SHA, run numbers, etc for much saner CloudTrail trawling. <a href="https://t.co/p2BRDTQsX6" target="_blank">github.com/glassechidna/a…</a> • So last night I passed the AWS Machine Learning - Specialty exam 😃 That was a tough one! 😅 For anyone interested in AI/ML I would encourage you to study for it 📚 I learnt a ton and liked how a large % of the exam was focused on general ML knowledge vs the AWS services. • ☁️ Security Logging in Cloud Environments <a href="https://twitter.com/lancinimarco" target="_blank">@lancinimarco</a>: Designing a state of the art multi-account security-related logging platform Covers: * CloudTrail, CloudWatch, GuardDuty, Config * Collecting logs * Storage &amp; audit trail * Monitoring &amp; alerting <a href="https://t.co/YqXezv3hmX" target="_blank">marcolancini.it/2021/blog-secu…</a> • Happy 10th birthday <a href="https://twitter.com/AWSCloudFormer" target="_blank">@AWSCloudFormer</a>! 🥳 • Thursday night: Wine 🍷 and PR-FAQing 📄Me thinks this will make for a pretty awesome doc. • Damn QuickSight docs, that's dark. • In a new blog post we review downloading and exploring EBS snapshots using the EBS Direct API's. Snapshot download isn't logged in CloudTrail, making this a difficult attack to detect. <a href="https://t.co/bUfQWn7TNM" target="_blank">bit.ly/3qXWgAz</a> • 🤬 Damn Vulnerable <a href="https://twitter.com/GraphQL" target="_blank">@GraphQL</a> App by Dolev Farhi Get hands-on experience exploiting a GraphQL app, including: * Denial-of-service * Info disclosure * Code execution * Injection * Authorization bypass * and more <a href="https://twitter.com/hashtag/bugbountytips" target="_blank">#bugbountytips</a> <a href="https://t.co/Sydm3kIf6N" target="_blank">github.com/dolevf/Damn-Vu…</a> • Spending my Saturday night reviewing CFP submissions for the <a href="https://twitter.com/CloudNativeFdn" target="_blank">@CloudNativeFdn</a> Cloud Native Security Day 2021. There's still time to register! <a href="https://t.co/9ucPNfTjkK" target="_blank">events.linuxfoundation.org/cloud-native-s…</a> • My mom gets vaccinated tomorrow 💙☺️ • 😏 <a href="https://t.co/vFPwTnzOD0" target="_blank">aws.amazon.com/security-hub/?…</a> • Just spent 30mins troubleshooting why aws-cdk was not installing properly. Turns out I was installing aws-sdk 🤦‍♂️😂 <a href="https://twitter.com/hashtag/Fridays" target="_blank">#Fridays</a> • "When seconds matter, CloudTrail takes minutes" • This is a great diagram showing how the various AWS security services interact <a href="https://t.co/ttSQwi4Ldy" target="_blank">marcolancini.it/2021/blog-secu…</a> thanks <a href="https://twitter.com/lancinimarco" target="_blank">@lancinimarco</a>, this belongs in the official docs! • If you're using Amazon Cognito, you should watch this short (but great) summary of how to do it securely: <a href="https://t.co/mNWVnlhSOb" target="_blank">youtube.com/watch?v=QDR-pX…</a> Slowly working my way through the <a href="https://twitter.com/hashtag/AWS" target="_blank">#AWS</a> re:Invent 2020 catalogue, let me know if you've got recommendations! • Building a Serverless multi-player game that scaled • 10 Best Free AWS Learning Resources for Beginners • Describe instances, sns topics, sqs, cloudwatch etc. across all AWS regions from the command line. • In 2021, AWS Athena and QuickSight are actually good for analyzing your mountain of ELB logs • Has anyone here worked for an AWS (or other "cloud") consultancy? What's it like? • I recently discovered that all versions of Windows Server 2012 (but not Server 2012 R2) are affected by a DLL hijacking vulnerability that can be exploited for privilege escalation. This bug can be triggered by a regular user and does not require a system reboot. Here is my writeup: • PortSwigger Research: Top 10 web hacking techniques of 2020 • What AWS training would be most relevant to someone in the C-suite?
1
Monday March, 2021

Security Newsletter - VMWare vCenter vulnerable to critical exploit. Microsoft releases CodeQL queries for Solarwinds. Hiding c2 servers in Bitcoin transactions.

Dieter Van der StockMar 01
Hi everyone, As always, I hope this e-mail finds you well :-) Thanks to those who gave feedback and/or showed interest in my project! Plenty of work left to do, I'll keep you posted :-) I would also like to welcome a new sponsor, the appsec testing platfor

How to protect sensitive data for its entire lifecycle in AWS

Raj JainFeb 26
Many Amazon Web Services (AWS) customer workflows require ingesting sensitive and regulated data such as Payments Card Industry (PCI) data, personally identifiable information (PII), and protected health information (PHI). In this post, I’ll show you a method designed to protect sensitive data for its entire lifecycle in AWS. This method …

Fall 2020 PCI DSS report now available with eight additional services in scope

Michael OyeniyaFeb 25
We continue to expand the scope of our assurance programs and are pleased to announce that eight additional services have been added to the scope of our Payment Card Industry Data Security Standard (PCI DSS) certification. This gives our customers more options to process and store their payment card data …
__steele
Aidan W Steele @__steele

I made a thing. Assume AWS IAM roles from GitHub Actions. Now I can use the best CI solution with the best cloud and not have to create IAM users.

The role sessions are even tagged with repo, SHA, run numbers, etc for much saner CloudTrail trawling.

github.com/glassechidna/a…

40Feb 28 · 5:50 AM
steven_bryen
Steven Bryen @steven_bryen

So last night I passed the AWS Machine Learning - Specialty exam 😃

That was a tough one! 😅

For anyone interested in AI/ML I would encourage you to study for it 📚 I learnt a ton and liked how a large % of the exam was focused on general ML knowledge vs the AWS services.

4Feb 26 · 10:50 AM
clintgibler
Clint Gibler @clintgibler

☁️ Security Logging in Cloud Environments

@lancinimarco: Designing a state of the art multi-account security-related logging platform

Covers:
* CloudTrail, CloudWatch, GuardDuty, Config
* Collecting logs
* Storage & audit trail
* Monitoring & alerting

marcolancini.it/2021/blog-secu…

30Feb 23 · 5:00 PM
bjohnso5y
Brigid Johnson @bjohnso5y

Thursday night: Wine 🍷 and PR-FAQing 📄Me thinks this will make for a pretty awesome doc.

0Feb 26 · 4:23 AM
__steele
Aidan W Steele @__steele

Damn QuickSight docs, that's dark.

1Feb 24 · 3:41 AM
RhinoSecurity
Rhino Security Labs @RhinoSecurity

In a new blog post we review downloading and exploring EBS snapshots using the EBS Direct API's. Snapshot download isn't logged in CloudTrail, making this a difficult attack to detect. bit.ly/3qXWgAz

15Feb 26 · 6:23 PM
clintgibler
Clint Gibler @clintgibler

🤬 Damn Vulnerable @GraphQL App by Dolev Farhi

Get hands-on experience exploiting a GraphQL app, including:
* Denial-of-service
* Info disclosure
* Code execution
* Injection
* Authorization bypass
* and more

#bugbountytips

github.com/dolevf/Damn-Vu…

8Feb 23 · 7:00 PM
lancinimarco
Marco Lancini @lancinimarco

Spending my Saturday night reviewing CFP submissions for the @CloudNativeFdn Cloud Native Security Day 2021. There's still time to register! events.linuxfoundation.org/cloud-native-s…

3Feb 27 · 9:45 PM
kmcquade3
Kinnaird McQuade💥☁️ @kmcquade3

My mom gets vaccinated tomorrow 💙☺️

0Feb 25 · 3:45 AM
steven_bryen
Steven Bryen @steven_bryen

Just spent 30mins troubleshooting why aws-cdk was not installing properly. Turns out I was installing aws-sdk 🤦‍♂️😂 #Fridays

2Feb 26 · 5:13 PM
matthewdfuller
Matt Fuller @matthewdfuller

"When seconds matter, CloudTrail takes minutes"

QuinnyPig
Corey Quinn @QuinnyPig

CloudTrail could be a database too. I would think that the ~20 minute delay between "thing happens" and "it shows up in the logs" would be a blocker, but people still use Bitcoin so...

4Feb 26 · 6:18 PM
elrowan
rowan @elrowan

This is a great diagram showing how the various AWS security services interact marcolancini.it/2021/blog-secu… thanks @lancinimarco, this belongs in the official docs!

3Feb 25 · 10:16 PM
elrowan
rowan @elrowan

If you're using Amazon Cognito, you should watch this short (but great) summary of how to do it securely: youtube.com/watch?v=QDR-pX…

Slowly working my way through the #AWS re:Invent 2020 catalogue, let me know if you've got recommendations!

3Mar 01 · 1:46 AM

Describe instances, sns topics, sqs, cloudwatch etc. across all AWS regions from the command line.

There are definitely some times that you want to query across all regions in the CLI. I always have done this in the past by piping together a bash loop and some jq like this:

for region in `aws ec2 describe-regions --output text | cut -f4`
do
     echo -e "\nListing …

Has anyone here worked for an AWS (or other "cloud") consultancy? What's it like?

Hello,

Early on in my career I had a job as an IT consultant (not AWS related).

I enjoyed it because:

  • Flow of projects ensured things never got too dull
  • Lots of different experience puts your career trajectory "on steroids"
  • Work with some smart, hardworking people
  • Experience with both hard …

What AWS training would be most relevant to someone in the C-suite?

Hi everyone,

I have the opportunity to take training in Cyber and I'm wondering - what cloud-related training would be most ideal for someone in a senior leadership / c-suite role?

Thanks in advance!