SRE Weekly Issue #337 • 📖 [The CloudSecList] Issue 153 • [tl;dr sec] #148 - OWASP Kubernetes Top 10, GraphQL Batching Attacks • AWS Control Tower - 4 new methods • AWS SSO Identity Store - 15 new 4 updated methods • Amazon Interactive Video Service - 3 updated methods • Amazon SageMaker Service - 2 updated methods • Scaling cross-account AWS KMS–encrypted Amazon S3 bucket access using ABAC • How to automate updates for your domain list in Route 53 Resolver DNS Firewall • Announcing new AWS IAM Identity Center APIs to manage users and groups at scale • How to let builders create IAM resources while improving security and agility for your organization • events: 1 new resource | 11 updated actions, 1 updated resource • controltower: 4 new actions • identitystore: 5 updated actions • Crawl, walk, run: Operationalizing your IaC security program - Bridgecrew Blog • GitHub - devops-kung-fu/bomber: Scans SBoMs for security vulnerabilities • 🗒️ A Guide On Implementing An Effective SAST Workflow <a href="https://twitter.com/anshuman_bh" target="_blank">@anshuman_bh</a> on setting up a dev-friendly SAST workflow for free using open source tools: Semgrep and <a href="https://twitter.com/owasp" target="_blank">@owasp</a>'s <a href="https://twitter.com/defectdojo" target="_blank">@defectdojo</a> <a href="https://t.co/jUrSIxGSol" target="_blank">anshumanbhartiya.com/posts/sast-wor…</a> • Control Tower just got APIs too like SSO. Great to see this happen, but every announcement about Control Tower and SSO are things I expected they would have had by now and scares me about what basic things they still don't have. <a href="https://t.co/cyb1s6B0dY" target="_blank">twitter.com/publiccloudbot…</a> • I've been making some very important transactions on my new business credit card. • 5-and-a-half years after launch, and we now have <a href="https://twitter.com/hashtag/AWS" target="_blank">#AWS</a> CloudFormation support for Amazon Connect so I can deprecate this yucky thing. Better late than never I guess 🤷‍♂️ <a href="https://t.co/OYvHylNFFm" target="_blank">aws.amazon.com/about-aws/what…</a> • This didn't have APIs before? AWS expected businesses to click around in the web console to manage identities? Meaning no way to have approval flows? Looks like previously using ansible for browser automation was the solution? <a href="https://t.co/LvWXudFD0K" target="_blank">github.com/aws/aws-sdk/is…</a> 🤮 • ☁️ <a href="https://twitter.com/wiz_io" target="_blank">@wiz_io</a> worked with Azure to get middleware agents new auto-patching capabilities So now you don't have to manually patch critical vulns in software Azure installed for you that you may not know you have <a href="https://t.co/CXLEnKNzY7" target="_blank">wiz.io/blog/auto-patc…</a> • "I just knew in my heart that I really, really didn't want to use Terraform." - <a href="https://twitter.com/__steele" target="_blank">@__steele</a>, writing a love letter to CloudFormation today • <a href="https://twitter.com/hashtag/awswishlist" target="_blank">#awswishlist</a> fulfilled 🥹 Thank you soo much to the Step Functions crew - you have made my day! <a href="https://t.co/4beNXXElqv" target="_blank">aws.amazon.com/about-aws/what…</a> • People are going to love bringing up this tweet when we inevitably will have no choice but to use Kubernetes • Come join my excellent team in Seattle, WA! We love making new friends. • AWS IP Ranges increase of 4,718,592 IPs • Announcing new AWS IAM Identity Center APIs to manage users and groups at scale • Since S3 charges by request, couldn't a malicious hacker cause a huge AWS bill just by spamming requests? • Just another reminder of the importance of not hard coding credentials • Find Risky Security Groups Fast in AWS! | by Ash Moran | Sep, 2022 - Medium • Aqua Security becomes AWS Security Competency partner - iTWire

ASD Logo

5
Monday September, 2022

Sponsor

Are you prepared for 0-day exploits?

Automatically detect IAM privilege escalations in your AWS accounts and get to know your real exposure of your infrastructure and data. CodeShield Cloud detects and shows fix recommendations for your IAM permission setup.

Get your scan results in just 15 minutes – scan for free now.

In a nutshell

I'm back from the Holidays, got some fresh mountain air, and feeling recharged for the following forthcoming challenges.

I hope you also take time to rest with your friends and family.

The good news is that we are now 1000+ readers on this AWS Security Digest. I'm so grateful for your trust, support, and interest in this initiative.

Let's reach the next 2000 readers milestone!

🔦 Highlight of the week

AWS Control Tower - 4 new methods
Sep 1
This release contains the first SDK for AWS Control Tower. It introduces a new set of APIs: EnableControl, DisableControl, GetControlOperation, and ListEnabledControls.
AWS SSO Identity Store - 15 new 4 updated methods
Aug 31
Expand IdentityStore API to support Create, Read, Update, Delete and Get operations for User, Group and GroupMembership resources.
Amazon Interactive Video Service - 3 updated methods
Aug 31
IVS Merge Fragmented Streams. This release adds support for recordingReconnectWindow field in IVS recordingConfigurations. For more information see https://docs.aws.amazon.com/ivs/latest/APIReference/Welcome.html
Amazon SageMaker Service - 2 updated methods
Aug 31
SageMaker Inference Recommender now accepts Inference Recommender fields: Domain, Task, Framework, SamplePayloadUrl, SupportedContentTypes, SupportedInstanceTypes, directly in our CreateInferenceRecommendationsJob API through ContainerConfig
Scaling cross-account AWS KMS–encrypted Amazon S3 bucket access using ABAC
Jorg HuserSep 2
This blog post shows you how to share encrypted Amazon Simple Storage Service (Amazon S3) buckets across accounts on a multi-tenant data lake. Our objective is to show scalability over a larger volume of accounts that can access the data lake, in a scenario where there is one central account …
How to automate updates for your domain list in Route 53 Resolver DNS Firewall
Guillaume NeauSep 1
Note: This post includes links to third-party websites. AWS is not responsible for the content on those websites. Following the release of Amazon Route 53 Resolver DNS Firewall, Amazon Web Services (AWS) published several blog posts to help you protect your Amazon Virtual Private Cloud (Amazon VPC) DNS resolution, including …
Announcing new AWS IAM Identity Center APIs to manage users and groups at scale
Sharanya RamakrishnanSep 1
If you use AWS IAM Identity Center (successor to AWS Single Sign-On) as your identity source, you create and manage your users and groups manually in the IAM Identity Center console. However, you may prefer to automate this process to save time, spend less administrative effort, and to scale effectively …
How to let builders create IAM resources while improving security and agility for your organization
Jeb BensonAug 31
Many organizations restrict permissions to create and manage AWS Identity and Access Management (IAM) resources to a group of privileged users or a central team. This post explains how you can safely grant these permissions to builders – the people who are developing, testing, launching, and managing cloud infrastructure – …

Sponsor - Improve security and compliance for your AWS infrastructure with Teleport

Easily control who can provision and access your critical AWS resources while improving security and compliance.

Join Teleport for a webinar on September 15 to learn how to:

  • Secure your growing AWS infrastructure.
  • Meet security and compliance regulations through complete visibility.
  • Increase developer productivity while saving time and money.

Register today

events: 1 new resource | 11 updated actions, 1 updated resource
Sep 3
1 new resource: rule-on-custom-event-bus; 11 updated actions: DeleteRule (resources), ListTagsForResource (resources), ListTargetsByRule (resources), EnableRule (resources), DisableRule (resources), DescribeRule (resources), PutTargets (resources), RemoveTargets (resources), TagResource (resources), PutRule (resources), UntagResource (resources); 1 updated resource: rule-on-default-event-bus (arn)
controltower: 4 new actions
Sep 3
4 new actions: DisableControl (Grants permission to remove a control from an organizational unit), EnableControl (Grants permission to activate a control for an organizational unit), GetControlOperation (Grants permission to get the current status of a particular EnabledControl or DisableControl operation), ListEnabledControls (Grants permission to list all enabled controls in a …
identitystore: 5 updated actions
Sep 3
5 updated actions: ListGroupMembershipsForMember (resources), ListGroups (resources), IsMemberInGroups (resources), ListGroupMemberships (resources), ListUsers (resources)
clintgibler
Clint Gibler @clintgibler

🗒️ A Guide On Implementing An Effective SAST Workflow

@anshuman_bh on setting up a dev-friendly SAST workflow for free using open source tools: Semgrep and @owasp's @defectdojo

anshumanbhartiya.com/posts/sast-wor…

13Aug 31 · 9:00 PM
0xdabbad00
Scott Piper @0xdabbad00

Control Tower just got APIs too like SSO. Great to see this happen, but every announcement about Control Tower and SSO are things I expected they would have had by now and scares me about what basic things they still don't have. twitter.com/publiccloudbot…

publiccloudbot
Public Cloud Bot @publiccloudbot

AWS SDK for Go has a new release "Release v1.44.90", published at 2022-09-01 18:25:44 (UTC)

#pcb_aws

github.com/aws/aws-sdk-go…

5Sep 01 · 10:44 PM
__steele
Aidan W Steele @__steele

I've been making some very important transactions on my new business credit card.

0Sep 02 · 4:10 AM
iann0036
Ian Mckay @iann0036

5-and-a-half years after launch, and we now have #AWS CloudFormation support for Amazon Connect so I can deprecate this yucky thing.

Better late than never I guess 🤷‍♂️

aws.amazon.com/about-aws/what…

iann0036
Ian Mckay @iann0036

#Amazon Connect doesn't have CloudFormation support or even APIs to manage its resources. Here's a solution to that, but it's dirty 😏 github.com/iann0036/amazo…

1Sep 03 · 2:51 AM
0xdabbad00
Scott Piper @0xdabbad00

This didn't have APIs before? AWS expected businesses to click around in the web console to manage identities?
Meaning no way to have approval flows? Looks like previously using ansible for browser automation was the solution? github.com/aws/aws-sdk/is…
🤮

awswhatsnew
What's New on AWS (Unoffical) @awswhatsnew

Announcing new AWS IAM Identity Center (successor to AWS SSO) APIs to manage users and groups at scale

AWS is launching additional APIs to create, read, update and delete users and groups in AWS IAM Identity Center (successor to AWS Single Sign-On)... aws.amazon.com/about-aws/what…

1Sep 01 · 10:12 PM
clintgibler
Clint Gibler @clintgibler

☁️ @wiz_io worked with Azure to get middleware agents new auto-patching capabilities

So now you don't have to manually patch critical vulns in software Azure installed for you that you may not know you have

wiz.io/blog/auto-patc…

5Aug 31 · 11:00 PM
kmcquade3
Kinnaird McQuade 💻☁️💥 @kmcquade3

"I just knew in my heart that I really, really didn't want to use Terraform."

- @__steele, writing a love letter to CloudFormation today

1Sep 05 · 5:31 AM
iann0036
Ian Mckay @iann0036

#awswishlist fulfilled 🥹

Thank you soo much to the Step Functions crew - you have made my day!

aws.amazon.com/about-aws/what…

samdengler
Sam Dengler @samdengler

@iann0036 @iann0036 this isn’t available today, but we are looking into adding additional functionality this this to Step Functions. I’ll take your request to the Step Functions team. In addition to an incrementer, what other functionality would be helpful to you?

2Sep 01 · 12:49 AM
kmcquade3
Kinnaird McQuade 💻☁️💥 @kmcquade3

People are going to love bringing up this tweet when we inevitably will have no choice but to use Kubernetes

kmcquade3
Kinnaird McQuade 💻☁️💥 @kmcquade3

Now that I run a company, I can make ridiculous rules like making Kubernetes illegal

1Aug 31 · 7:06 PM
notdurson
Dan Urson @notdurson

Come join my excellent team in Seattle, WA! We love making new friends.

XanaduRegio
Christian Severt @XanaduRegio

I’m #hiring in Seattle, WA .@AWSSecurityInfo for #SecurityEngineers interested in working within Coordinated Vulnerability Disclosure #cvd. Want to collaborate with Security Researchers and the Security Research community? Hit me up and let's talk!

amazon.jobs/en/jobs/199862…

#aws

4Sep 02 · 8:15 PM
AWS IP Ranges increase of 4,718,592 IPs

Just a heads up, AWS just added 4,718,592 new IPs in their second largest expansion to date.

This is something like a 7% increase, and impacts pretty much all of the regions, though they haven't doled out the IP addresses to specific services yet.

Edit: They've actually added 7,602,312 IPs …

Since S3 charges by request, couldn't a malicious hacker cause a huge AWS bill just by spamming requests?

What would stop them from doing so, against, say, a static website hosted using S3? Is there a good way to deny some requests such that one avoids getting billed for them?

(Context: I want to host a static website on S3, but I wouldn't want to end up with …