Sponsor
Are you prepared for 0-day exploits?
Automatically detect IAM privilege escalations in your AWS accounts and get to know your real exposure of your infrastructure and data. CodeShield Cloud detects and shows fix recommendations for your IAM permission setup.
Get your scan results in just 15 minutes – scan for free now.
In a nutshell
I'm back from the Holidays, got some fresh mountain air, and feeling recharged for the following forthcoming challenges.
I hope you also take time to rest with your friends and family.
The good news is that we are now 1000+ readers on this AWS Security Digest. I'm so grateful for your trust, support, and interest in this initiative.
Let's reach the next 2000 readers milestone!
🔦 Highlight of the week
- Missed summer cloudsec confs? Here's the replay: fwdcloudsec and re:Inforce
- [DEFCON30] My preferred presentation from Christophe about Stratus Red Team
- Serverless Security 101: How to think about serverless cloud security?
📢 MAMIP (Monitor AWS Managed IAM Policies)
Policies changed since last week:
- AWSBackupServiceRolePolicyForS3Backup
- AdministratorAccess-Amplify
- AmazonEKSLocalOutpostClusterPolicy
- AmazonRedshiftQueryEditorV2NoSharing
- AmazonRedshiftQueryEditorV2ReadSharing
- AmazonRedshiftQueryEditorV2ReadWriteSharing
- AmazonSSMManagedEC2InstanceDefaultPolicy
- AmazonWorkSpacesAdmin
Sponsor - Improve security and compliance for your AWS infrastructure with Teleport
Easily control who can provision and access your critical AWS resources while improving security and compliance.
Join Teleport for a webinar on September 15 to learn how to:
- Secure your growing AWS infrastructure.
- Meet security and compliance regulations through complete visibility.
- Increase developer productivity while saving time and money.




🗒️ A Guide On Implementing An Effective SAST Workflow
@anshuman_bh on setting up a dev-friendly SAST workflow for free using open source tools: Semgrep and @owasp's @defectdojo
anshumanbhartiya.com/posts/sast-wor…




Control Tower just got APIs too like SSO. Great to see this happen, but every announcement about Control Tower and SSO are things I expected they would have had by now and scares me about what basic things they still don't have. twitter.com/publiccloudbot…

AWS SDK for Go has a new release "Release v1.44.90", published at 2022-09-01 18:25:44 (UTC)
#pcb_aws
github.com/aws/aws-sdk-go…



5-and-a-half years after launch, and we now have #AWS CloudFormation support for Amazon Connect so I can deprecate this yucky thing.
Better late than never I guess 🤷♂️
aws.amazon.com/about-aws/what…

#Amazon Connect doesn't have CloudFormation support or even APIs to manage its resources. Here's a solution to that, but it's dirty 😏 github.com/iann0036/amazo…




This didn't have APIs before? AWS expected businesses to click around in the web console to manage identities?
Meaning no way to have approval flows? Looks like previously using ansible for browser automation was the solution? github.com/aws/aws-sdk/is…
🤮

Announcing new AWS IAM Identity Center (successor to AWS SSO) APIs to manage users and groups at scale
AWS is launching additional APIs to create, read, update and delete users and groups in AWS IAM Identity Center (successor to AWS Single Sign-On)... aws.amazon.com/about-aws/what…



☁️ @wiz_io worked with Azure to get middleware agents new auto-patching capabilities
So now you don't have to manually patch critical vulns in software Azure installed for you that you may not know you have
wiz.io/blog/auto-patc…



"I just knew in my heart that I really, really didn't want to use Terraform."
- @__steele, writing a love letter to CloudFormation today



#awswishlist fulfilled 🥹
Thank you soo much to the Step Functions crew - you have made my day!
aws.amazon.com/about-aws/what…



People are going to love bringing up this tweet when we inevitably will have no choice but to use Kubernetes

Now that I run a company, I can make ridiculous rules like making Kubernetes illegal




Come join my excellent team in Seattle, WA! We love making new friends.

I’m #hiring in Seattle, WA .@AWSSecurityInfo for #SecurityEngineers interested in working within Coordinated Vulnerability Disclosure #cvd. Want to collaborate with Security Researchers and the Security Research community? Hit me up and let's talk!
amazon.jobs/en/jobs/199862…
#aws


Just a heads up, AWS just added 4,718,592 new IPs in their second largest expansion to date.
This is something like a 7% increase, and impacts pretty much all of the regions, though they haven't doled out the IP addresses to specific services yet.
Edit: They've actually added 7,602,312 IPs …
What would stop them from doing so, against, say, a static website hosted using S3? Is there a good way to deny some requests such that one avoids getting billed for them?
(Context: I want to host a static website on S3, but I wouldn't want to end up with …
- 🖊️ This digest was forwarded to you? Subscribe here
- 📢 Promote your content with sponsorship
- 💌 Want to suggest new content: contact me or reply to this email