Issue #83

Monday · September 12, 2022

πŸ₯— AWS security blogs

  • Using AWS Shield Advanced protection groups to improve DDoS detection and mitigation β€” Amazon Web Services (AWS) customers can use AWS Shield Advanced to detect and mitigate distributed denial of service (DDoS) attacks that target their applications running on Amazon Elastic Compute Cloud (Amazon EC2), Elastic Local Balancing (ELB), Amazon CloudFront, AWS Global Accelerator, and Amazon Route 53. By using protection groups for …
  • Implement step-up authentication with Amazon Cognito, Part 2: Deploy and test the solution β€” This solution consists of two parts. In the previous blog post Implement step-up authentication with Amazon Cognito, Part 1: Solution overview, you learned about the architecture and design of a step-up authentication solution that uses AWS services such as Amazon API Gateway, Amazon Cognito, Amazon DynamoDB, and AWS Lambda to …
  • Implement step-up authentication with Amazon Cognito, Part 1: Solution overview β€” In this blog post, you’ll learn how to protect privileged business transactions that are exposed as APIs by using multi-factor authentication (MFA) or security challenges. These challenges have two components: what you know (such as passwords), and what you have (such as a one-time password token). By using these multi-factor …

πŸ› Reddit threads on r/aws

πŸ“Œ Newsletters

πŸ“Œ Top Links from Security Folks

πŸ“Œ "AWS Security" on Google News

🧁 IAM permission changes

  • connect: 1 updated action β€” 1 updated action: UntagResource (conditions)
  • transfer: 6 new actions, 1 new resource | 3 updated actions β€” 6 new actions: DeleteHostKey (Grants permission to delete a host key associated with a server), DescribeHostKey (Grants permission to describe a host key associated with a server), ImportHostKey (Grants permission to add a host key to a server), ListHostKeys (Grants permission to list host keys associated with a server), StartFileTransfer …
  • sns: 2 new actions β€” 2 new actions: GetDataProtectionPolicy (Grants permission to return the data protection policy of the topic), PutDataProtectionPolicy (Grants permission to allow a topic owner to set the data protection policy)

πŸͺ API changes

Get every AWS security change,
on a plate every Monday.

6,700+ engineers, builders and CISOs let us diff the AWS changelog every week.