Sponsor
On-Demand: Identity-Based Data Security on AWS
Easily control who can provision and access your critical AWS resources while improving security and compliance with Teleport for AWS.
- Secure your growing AWS infrastructure
- Meet security and compliance regulations through complete visibility
- Increase developer productivity while saving time and money
In a nutshell
My thoughts on the Twitter takeover: You can be the richest man in the world, and have market-disrupting companies, if your management isn't based on goodwill, empathy, or morality it has no value or merit.
A little thought for our colleagues and friends at Twitter. Such a way of doing things would be unthinkable in France or the EU thanks to labor law.
I'm sharing this spreadsheet of tweeps if you have open positions for them.
📢 MAMIP (Monitor AWS Managed IAM Policies)
Policies changed since last week:
- AWSConfigServiceRolePolicy
- AWSControlTowerServiceRolePolicy
- AWSFMAdminReadOnlyAccess
- AWSResourceExplorerServiceRolePolicy
- AWS_ConfigRole
- AmazonQLDBConsoleFullAccess
- AmazonQLDBFullAccess
- AmazonWorkSpacesWebReadOnly
- CloudTrailServiceRolePolicy
- ReadOnlyAccess
Initial Publication Date: 2022/11/01 09:00 PDT
AWS is aware of the recently reported issues regarding OpenSSL 3.0 (CVE-2022-3602 and CVE-2022-3786). AWS services are not affected, and no customer action is required. Additionally, Amazon Linux 1 and Amazon Linux 2 do not ship with OpenSSL 3.0 and are not affected by …





I won’t be attending re:invent after all. 🙁
Nor have I done a good job of responding to DMs or following up on commitments for ages.
I’ve been having an extremely bad time this year and I am checking into a psych hospital and changing meds. So hopefully 2023 will be better.



the speed with which he went from "legalize comedy" to "i will literally ban everyone that i think is making fun of me" is just outstanding



My colleagues have released a post and in-depth exploitation walk-through of the OpenSSL vulnerability: securitylabs.datadoghq.com/articles/opens…
tldr
• It was downgraded from critical to high
• It's exploitable for DoS on Windows, probably not RCE
• It's likely not exploitable on Linux at all



I have no idea if publishing this is a good idea. But I think it’s important to normalise bipolar disorder, even the ugly bits.
I think my career will be okay and I hope that people won’t treat me differently from now on.



Dropped off my ballot today for my first vote in a US general election. Please do vote, it really matters! 🇺🇸



Maybe we should leave our thoughts and hot takes in a file called .plan in our home directory?



🗒️ awesome-cybersecurity-conferences
A list of a number of security conferences around the world and a link to their videos and slides
By @Eliyahu_Tal_
github.com/TalEliyahu/awe…



New on Hacking the Cloud - AWS Organizations Defaults: A short post on the default behavior of AWS Organizations and how compromising the management account can lead to the compromise of the entire organization. hackingthe.cloud/aws/general-kn…



🗒️ @owasp Software Component Verification Standard (SCVS)
Overview by Chris Hughes on the 3 levels of maturity across 6 control categories
* Inventory
* SBOM
* Build Environment
* Package Management
* Component Analysis
* Pedigree and Provenance
blog.aquia.us/blog/2022-09-2…


Could be obvious, could be not but I think this needs to be said.
Once in a while I see people recommend DynamoDb when someone is asking how to optimize costs in RDS (because Ddb has nice free tier, etc.) like it's a drop-in replacement -- it is not. It's …
- 🖊️ This digest was forwarded to you? Subscribe here
- 📢 Promote your content with sponsorship
- 💌 Want to suggest new content: contact me or reply to this email