In a nutshell
Happy New Year, fellow AWS security professionals! As we kick off a new year, let's resolve to stay vigilant and keep our cloud infrastructure secure. From implementing proper identity and access management to regularly reviewing and updating security policies, let's make this year the safest one yet for our organization. Here's to a happy and secure new year!
📢 MAMIP (Monitor AWS Managed IAM Policies)
Policies changed since last week:




Security vendor: "You should absolutely be defining your infrastructure in code; it's a security best practice."
Also security vendor: "So to configure our product, just log in to our UI and follow these 85 point-and-click steps."



New year, new #AWS project! ⌨️☁️
I loved the KMS external key stores announcement so I made a mock external key manager using APIGW, Lambda and DDB to learn how it works and mess with keying material.
You can deploy this yourself by installing from github.com/iann0036/toyxks




I used to think this too. It's uncouth to talk about money, but having a software engineering degree opens up life-changing opportunities for Australians willing to work in the USA. It can literally make you more than ONE MILLION DOLLARS better off in four years.

college doesn’t matter



Last week, I reported a public bucket at a French bank, filled with about 16GB of data, with nothing noteworthy except static assets. They gave me a credit of $10 for the report. Security for living, I guess :)



7 years in a row (after fixing it for just two years) ... Google continues to be an absolute mess of "organizing the world's information" with lyrics. This year they credit Rod Stewart for Auld Lang Syne. Previous years include Kenny G and Billy Joel.


6 years now and the Google lyrics team continue to get the basics woefully wrong. They're still falsely attributing long out of copyright Robert Byrne's "Auld Lang Syne" to Dougie MacClean, but now also Theodore Shapiro. I've now submitted 5 corrections, to no avail.




if you're in the seattle area, my friend colleen (wedding florist! flower farmer! event planner!) is doing a monthly bouquet club this year from april to october 💐
do every month, pick a few of the months. get pretty, locally-grown flowers.
diademflowers.com/flower-shop/p/…



It’s been an amazing year for Datadog Security Labs! We’ve released a number of open source tools, shared the results of our research projects. Be sure to subscribe to our RSS feed, we have more cloud vulnerabilities to be released soon :)
securitylabs.datadoghq.com/articles/secur…



I'm stoked to be speaking at @wiz_io's CloudSec 360!
Hope to see you there 👇

Check this out — tldrsec.com creator @clintgibler has been added to the CloudSec 360 lineup!
Join to learn how to identify issues before production, build automation into your processes and scale your security into the future 🚀




Today just isn't the same without a Chaos Communication Congress. So many great talks and such a perfect week for soaking in the mind-blowing breaks and exploits. Hoping for its return! twitter.com/i/web/status/1…


Anyone else know how to get around target groups not supporting IPv6 ec2 instance targets? They only support hardcoded IPv6 addresses, which doesn't really work with EC2 auto scaling and load balancing.
https://github.com/aws/containers-roadmap/issues/1653
" IPv6 target groups only support IP type targets."
Kind of posting this for visibility too. …
With my company we are developing several web applications.
We are using fargate clusters to run our applications backends (usually laravel apps).
We are using a load balancer to route the traffic to the different containers and the frontends are served by cloudfront.
My question is: are fargate clusters the …
Added 52.219.220.0/23
Added 52.95.191.0/24
- 🖊️ This digest was forwarded to you? Subscribe here
- 📢 Promote your content with sponsorship
- 💌 Want to suggest new content: contact me or reply to this email