Issue #139

Monday ยท January 15, 2024

๐Ÿฅ– Palate Cleanser

Hey folks,

AWS is still shipping some new significant features, and there is no (yet) freeze before re:Invent 2023 (in 14 days).

Interestingly, following the announcement of Block Public Sharing for AMI a few weeks ago, AWS introduced the same capacity but for Snapshots.

I've updated my AWS Security Survival Kit (Open Source) with this new capacity to let you apply bare minimal AWS security to your accounts. (Alerting and Configuration)

Victor

๐Ÿ“‹ Chef's selections

  1. Amazon EC2 Instance Metadata Service IMDSv2 by default
  2. Block Public Sharing of Amazon EBS Snapshots
  3. Amazon GuardDuty introduces new machine learning capability

๐Ÿ› Reddit threads on r/aws

๐Ÿช API changes

๐Ÿน IAM managed policy changes

Managed Policy changed since last week: 16
  1. ๐Ÿšฉ AWSAuditManagerServiceRolePolicy
  2. ๐Ÿšฉ AWSIAMIdentityCenterAllowListForIdentityContext
  3. AWSIPAMServiceRolePolicy
  4. AWSIncidentManagerIncidentAccessServiceRolePolicy
  5. AWSKeyManagementServiceCustomKeyStoresServiceRolePolicy
  6. AWSResourceExplorerServiceRolePolicy
  7. AWSSecurityHubServiceRolePolicy
  8. AWSServiceCatalogAppRegistryFullAccess
  9. AWSServiceRolePolicyForBackupRestoreTesting
  10. AWSTrustedAdvisorServiceRolePolicy
  11. AccessAnalyzerServiceRolePolicy
  12. AmazonConnectCampaignsServiceLinkedRolePolicy
  13. AmazonRekognitionReadOnlyAccess
  14. ๐Ÿšฉ AmplifyBackendDeployFullAccess
  15. ๐Ÿšฉ CloudWatchApplicationSignalsServiceRolePolicy
  16. ๐Ÿšฉ PartnerCentralAccountManagementUserRoleAssociation
Weekly diff

๐Ÿค– Powered by MAMIP - ๐Ÿšฉ Sensitive IAM Actions included

โ˜• CloudFormation resource changes

๐ŸŽฎ Amazon Linux vulnerabilities

This section will show you the latest (Important and Critical) CVEs on Amazon Linux.
  • Nothing to see here this week.

Get every AWS security change,
on a plate every Monday.

6,700+ engineers, builders and CISOs let us diff the AWS changelog every week.