Issue #140

Monday ยท January 22, 2024

๐Ÿฅ– Palate Cleanser

Hey folks,

Big shoutout to our latest sponsor, Wiz, for their support with this newsletter โ€“ couldn't have done it without them!

This issue features an insightful report from Datadog's research team on Cloud Security's current landscape, offering a valuable perspective by comparing it to previous studies. It's a must-read for grasping corporate trends.

Plus, we've got updates on over 29 IAM Managed Policies.

Victor

๐Ÿ“‹ Chef's selections

  1. Reversing AWS IAM unique IDs
  2. Datadog's State of Cloud Security
  3. Use scalable controls for AWS services accessing your resources

๐Ÿฅ— AWS security blogs

๐Ÿ› Reddit threads on r/aws

๐Ÿง IAM permission changes

๐Ÿช API changes

  • TrustedAdvisor Public API - 10 new methods - AWS Trusted Advisor introduces new APIs to enable you to programmatically access Trusted Advisor best practice checks, recommendations, and prioritized recommendations. Trusted Advisor APIs enable you to integrate Trusted Advisor with your operational tools to automate your workloads.
  • AWS Lambda - 8 updated methods - Adds support for logging configuration in Lambda Functions. Customers will have more control how their function logs are captured and to which cloud watch log group they are delivered also.
  • Amazon Elastic Compute Cloud - 3 new 24 updated methods - AWS EBS now supports Snapshot Lock, giving users the ability to lock an EBS Snapshot to prohibit deletion of the snapshot. This release introduces the LockSnapshot, UnlockSnapshot & DescribeLockedSnapshots APIs to manage lock configuration for snapshots. The release also includes the dl2q_24xlarge.

๐Ÿน IAM managed policy changes

Managed Policy changed since last week: 29
  1. AWSApplicationAutoscalingSageMakerEndpointPolicy
  2. ๐Ÿšฉ AWSConfigServiceRolePolicy
  3. ๐Ÿšฉ AWSDataLifecycleManagerSSMFullAccess
  4. ๐Ÿšฉ AWSECRPullThroughCache_ServiceRolePolicy
  5. ๐Ÿšฉ AWSFaultInjectionSimulatorEC2Access
  6. AWSFaultInjectionSimulatorEKSAccess
  7. AWSFaultInjectionSimulatorRDSAccess
  8. AWSGitSyncServiceRolePolicy
  9. AWSIncidentManagerIncidentAccessServiceRolePolicy
  10. AWSIoTTwinMakerServiceRolePolicy
  11. AWSMarketplaceDeploymentServiceRolePolicy
  12. ๐Ÿšฉ AWSRefactoringToolkitFullAccess
  13. ๐Ÿšฉ AWSResourceExplorerFullAccess
  14. ๐Ÿšฉ AWSResourceExplorerOrganizationsAccess
  15. AWSResourceExplorerReadOnlyAccess
  16. AWSSSMForSAPServiceLinkedRolePolicy
  17. AWSSecurityHubFullAccess
  18. AWSSecurityHubOrganizationsAccess
  19. AWSServiceRoleForIoTSiteWise
  20. AWSVPCVerifiedAccessServiceRolePolicy
  21. ๐Ÿšฉ AWS_ConfigRole
  22. AWSrePostPrivateCloudWatchAccess
  23. ๐Ÿšฉ AmazonConnectServiceLinkedRolePolicy
  24. ๐Ÿšฉ AmazonDataZoneEnvironmentRolePermissionsBoundary
  25. AmazonDataZoneRedshiftManageAccessRolePolicy
  26. AmazonGuardDutyFullAccess
  27. AmazonGuardDutyReadOnlyAccess
  28. ๐Ÿšฉ AmplifyBackendDeployFullAccess
  29. EC2ImageBuilderLifecycleExecutionPolicy
Weekly diff

๐Ÿค– Powered by MAMIP - ๐Ÿšฉ Sensitive IAM Actions included

โ˜• CloudFormation resource changes

๐ŸŽฎ Amazon Linux vulnerabilities

This section will show you the latest (Important and Critical) CVEs on Amazon Linux.
  • No CVEs published this week on Amazon Linux OS.

Get every AWS security change,
on a plate every Monday.

6,700+ engineers, builders and CISOs let us diff the AWS changelog every week.