<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0" xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd" xmlns:googleplay="http://www.google.com/schemas/play-podcasts/1.0"><channel><title><![CDATA[AWS Cloud Security Weekly]]></title><description><![CDATA[A hands-on style weekly newsletter for cloud security professional, including executives, focused on latest cloud security (especially AWS) news/releases/trends.]]></description><link>https://aws-cloudsec.com</link><image><url>https://substackcdn.com/image/fetch/$s_!po4I!,w_256,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F15838bce-c9b4-4b0c-b508-f95a721fd7ca_1200x1200.png</url><title>AWS Cloud Security Weekly</title><link>https://aws-cloudsec.com</link></image><generator>Substack</generator><lastBuildDate>Mon, 18 May 2026 05:14:17 GMT</lastBuildDate><atom:link href="https://aws-cloudsec.com/feed" rel="self" type="application/rss+xml"/><copyright><![CDATA[AJ]]></copyright><language><![CDATA[en]]></language><webMaster><![CDATA[awscloudsec@substack.com]]></webMaster><itunes:owner><itunes:email><![CDATA[awscloudsec@substack.com]]></itunes:email><itunes:name><![CDATA[Daniel Grzelak]]></itunes:name></itunes:owner><itunes:author><![CDATA[Daniel Grzelak]]></itunes:author><googleplay:owner><![CDATA[awscloudsec@substack.com]]></googleplay:owner><googleplay:email><![CDATA[awscloudsec@substack.com]]></googleplay:email><googleplay:author><![CDATA[Daniel Grzelak]]></googleplay:author><itunes:block><![CDATA[Yes]]></itunes:block><item><title><![CDATA[Issue 105]]></title><description><![CDATA[7 days of Cloud Security, recapped in 7 minutes or less!]]></description><link>https://aws-cloudsec.com/p/issue-105</link><guid isPermaLink="false">https://aws-cloudsec.com/p/issue-105</guid><pubDate>Tue, 22 Jul 2025 02:46:01 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!po4I!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F15838bce-c9b4-4b0c-b508-f95a721fd7ca_1200x1200.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p><em>This issue is sponsored by <a href="https://www.plerion.com/?utm_source=cloudsecweekly&amp;utm_medium=email&amp;utm_campaign=cswsponsorship">Plerion</a>. Get a free cloud security assessment &#187; <strong><a href="https://www.plerion.com/get-a-cloud-security-assessment?utm_source=cloudsecweekly&amp;utm_medium=email&amp;utm_campaign=cswsponsorship">HERE</a></strong>.</em></p><p><strong>ANNOUNCEMENT: This newsletter is moving to AWS Security Digest</strong></p><p>We are merging into <a href="https://awssecuritydigest.com/">AWS Security Digest</a> (ASD). It&#8217;s awesome and I think you&#8217;ll love it. </p><p>After today, all AWS Cloud Security Weekly subscribers will be automatically subscribed to ASD. Please allowlist the official email address:</p><p><code>Daniel Grzelak &lt;hello@awssecuritydigest.com&gt;</code></p><p>And look out for for &#8220;AWS Security Digest #220&#8221; in your inbox (or junk) next Monday at 8am ET.</p><p><strong>This week TLDR i.e. 1 minute version </strong>(For executives):</p><ol><li><p>AWS API MCP Server now available <a href="https://aws.amazon.com/about-aws/whats-new/2025/07/aws-api-mcp-server-available">Link</a></p></li><li><p>Improved security and isolation for AI agent operations <a href="https://aws.amazon.com/about-aws/whats-new/2025/07/amazon-bedrock-agentcore-preview/">Link</a></p></li><li><p>Centralized logging for EventBridge event bus enhances observability <a href="https://aws.amazon.com/about-aws/whats-new/2025/07/amazon-eventbridge-enhanced-logging-improved-observability">Link</a></p></li><li><p>AWS Private CA increases certificate limits for improved PKI management <a href="https://aws.amazon.com/about-aws/whats-new/2025/07/aws-private-ca-issuing-100-million-certificates-ca/">Link</a></p></li><li><p>AWS Firewall Manager supports AWS PrivateLink for secure management <a href="https://aws.amazon.com/about-aws/whats-new/2025/07/aws-firewall-manager-aws-private-link">Link</a></p><p></p></li></ol><p><strong>Trending in Cloud &amp; Cyber Security</strong>:</p><ol><li><p>AWS Security Blogs &amp; Bulletins:</p><ul><li><p>Secure authentication beyond IAM access keys <a href="https://aws.amazon.com/blogs/security/beyond-iam-access-keys-modern-authentication-approaches-for-aws/">Link</a></p></li><li><p>AWS completes audit with European financial institutions for compliance <a href="https://aws.amazon.com/blogs/security/aws-successfully-completes-ccag-2024-pooled-audit-with-eu-financial-institutions/">Link</a></p></li><li><p>Enhance FSx for Windows security with AI anomaly detection <a href="https://aws.amazon.com/blogs/storage/enhancing-fsx-for-windows-security-ai-powered-anomaly-detection/">Link</a></p></li><li><p>Secure multi-tenant agent cost management with Amazon Bedrock <a href="https://aws.amazon.com/blogs/machine-learning/manage-multi-tenant-amazon-bedrock-costs-using-application-inference-profiles/">Link</a></p></li><li><p>Secure Amazon Bedrock agent deployment and operations at scale <a href="https://aws.amazon.com/blogs/aws/introducing-amazon-bedrock-agentcore-securely-deploy-and-operate-ai-agents-at-any-scale/">Link</a></p></li></ul></li><li><p>General security blogs, articles, reports &amp; trending news/advisories:</p><ul><li><p>Exploring Delegated Admin Risks in AWS Organizations <a href="https://eot.awssecuritydigest.com/f/a/PyqDY6nK7XS2M6XOEXqYzQ~~/AAAHURA~/pxklML_X-luhddyJ1TIOCxauXmACF2A3-Ufh0L63O0C3V8h9mRWRb1N9ZrK9Lhm1XCCWHcnhdQdLrYLB1ygpqFv84Fy7llxBRH2X_YGfBB3k09sLJ5C5eW7rZQ5mobpC_5Ea9NLAmytebjQdsRJeDMay1lmkyDZsiteqL4J0JzdZ_r7HAbGAn7yYbXd2EwFbsjKGt9-ta4nShMCGj5koBA~~">Link</a></p></li><li><p>Code Execution Through Email: How I Used Claude to Hack Itself <a href="https://www.pynt.io/blog/llm-security-blogs/code-execution-through-email-how-i-used-claude-mcp-to-hack-itself">Link</a></p></li><li><p>Brewing Trouble &#8212; Dissecting a macOS Malware Campaign <a href="https://medium.com/deriv-tech/brewing-trouble-dissecting-a-macos-malware-campaign-90c2c24de5dc">Link</a></p></li><li><p>Deep Dive and Nuances of AWS's Programmatic IAM Action List and Service Authorization References (SAR) <a href="https://eot.awssecuritydigest.com/f/a/Y7tRccJ7SmOxd3MP5qtEuQ~~/AAAHURA~/dOhBd4lqGTuhvEy6Y_43ixj2DnBezi30ABa52Nigq1lqYAN1a9BT7kZ96qTXBbV0OCZf7ZLNdSd8j-DvlSo7P_2RwR1DMOi7upGnMAivC-nZbQiMiiPYdPjQxY-uNIv41OvFwWSF6D_EH6GT7lQG3rgy_FQ7-EEcrRxQc3XKzRLDnY4GVXGbyfnOPUqo0izlzWF8Yep6pnDVeTrstIpbaxurja2tUCwBXOL7TfIjZ3Y~">Link</a></p></li><li><p>API Keys for Bedrock: A Brief Security Overview <a href="https://eot.awssecuritydigest.com/f/a/EcZt0PMdt9bjbmOVjHl8xQ~~/AAAHURA~/KnzvTtcla0j6uAWIRwXu1OV5JYNc1qnKz1cooKKkrSDNFTCyToefI7SdbYNcG0oxq19m01I52oJjHytKZgzRWPmDY0UyFboWmfOhjRwvYeC7KkImFNwtRw7oqODOXcFq8NcvMzY3Bmpm1mL96DhMWgc_eIeS1A0OjfQUz_CRhUbCWBgKQVEeMyd7bAL0c1rWMICqcJNrqHXX9RR_fpb78oAXAvCkROGFOV0bPnjhoxMf7DwsJOyUhpNQ4zxE7-6X">Link</a></p></li><li><p>Attackers Targeting Governments in Southeast Asia Implement Novel Covert C2 Communication <a href="https://eot.awssecuritydigest.com/f/a/8vM75Yhud3Cg-xApJrfTSQ~~/AAAHURA~/H_FFOp6ifu3s7RNd4ILidYBUbTeAVwmXKqqBdJrUgbYQ1SsUkwWcTSfBGsAuZpgIrTlHIq3rjIS6lEIY9ekRLuStmZwntNDmigoza3bM5STVoHcjFFzrIZNtFfffTxcUgNRlvxzoQBtwoIKKJVeWe9RhjVfgFIfvfovqxEypuIafdh5qEVPM32whawSizoTNqSu3hlrVwFUWqSEgGq6ME8pt6Es9xcXDQyii62WOXFts8kgLtnJCy8AJ6XN4XqBJ">Link</a></p></li></ul></li></ol><p></p><p></p><p></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://aws-cloudsec.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://aws-cloudsec.com/subscribe?"><span>Subscribe now</span></a></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://aws-cloudsec.com/p/issue-105?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://aws-cloudsec.com/p/issue-105?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share</span></a></p><p></p><p></p><p></p>]]></content:encoded></item><item><title><![CDATA[Issue 104]]></title><description><![CDATA[7 days of Cloud Security, recapped in 7 minutes or less!]]></description><link>https://aws-cloudsec.com/p/issue-104</link><guid isPermaLink="false">https://aws-cloudsec.com/p/issue-104</guid><pubDate>Tue, 15 Jul 2025 03:01:45 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!po4I!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F15838bce-c9b4-4b0c-b508-f95a721fd7ca_1200x1200.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p><em>This issue is sponsored by <a href="https://www.plerion.com/?utm_source=cloudsecweekly&amp;utm_medium=email&amp;utm_campaign=cswsponsorship">Plerion</a>. Check out Plerion&#8217;s AWS security platform and cloud security teammate &#187; <strong><a href="https://www.plerion.com/pleri-ai?utm_source=cloudsecweekly&amp;utm_medium=email&amp;utm_campaign=cswsponsorship">HERE</a></strong>.</em></p><p><strong>ANNOUNCEMENT: AWS Cloud Security Weekly is moving!</strong></p><p>This is the second-last issue of AWS Cloud Security Weekly. Next week&#8217;s issue 105 will be the last, although the content archive will remain.</p><p>We are merging into <a href="https://awssecuritydigest.com/">AWS Security Digest</a> (ASD), maintained by <a href="https://www.linkedin.com/in/danielgrzelak/">Daniel Grzelak</a>. It&#8217;s awesome and I think you&#8217;ll love it. It covers much of the same content but includes a lot more detail, like API changes, IAM permission changes, managed policy updates, CloudFormation updates, Amazon Linux CVEs, and more.</p><p>If you haven&#8217;t seen it yet, check out <a href="https://awssecuritydigest.com/past-issues/aws-security-digest-218">this week&#8217;s issue</a> to compare the content and see if it&#8217;s your vibe. After next week&#8217;s issue, all AWS Cloud Security Weekly subscribers will be automatically subscribed to ASD. So if it&#8217;s not for you, please unsubscribe over the next week.</p><p>Thank you for all of your support over the last couple of years. &#9829;&#65039;</p><p><strong>This week TLDR i.e. 1 minute version </strong>(For executives):</p><p>There were no new security announcements this week from AWS but <a href="https://docs.aws.amazon.com/awsaccountbilling/latest/aboutv2/free-tier.html">free tier</a> did get a make over.</p><p><strong>Trending in Cloud &amp; Cyber Security</strong>:</p><ol><li><p>AWS Security Blogs &amp; Bulletins:</p><ul><li><p>Blocking DDoS attacks with AWS WAF <a href="https://aws.amazon.com/blogs/architecture/how-scale-to-win-uses-aws-waf-to-block-ddos-events/">Link</a></p></li><li><p>Assessing application resilience across multiple AWS accounts <a href="https://aws.amazon.com/blogs/mt/centralized-multi-account-application-resilience-assessment-using-aws/">Link</a></p></li><li><p>New SOC compliance reports covering 184 AWS services <a href="https://aws.amazon.com/blogs/security/spring-2025-soc-1-2-3-reports-are-now-available-with-184-services-in-scope/">Link</a></p></li><li><p>Establishing a European trust service provider for the AWS European Sovereign Cloud <a href="https://aws.amazon.com/blogs/security/establishing-a-european-trust-service-provider-for-the-aws-european-sovereign-cloud/">Link</a></p></li><li><p>PCI DSS compliance package for Spring 2025 <a href="https://aws.amazon.com/blogs/security/spring-2025-pci-dss-compliance-package-available-now/">Link</a></p></li></ul></li><li><p>General security blogs, articles, reports &amp; trending news/advisories:</p><ul><li><p>Exploiting Public APP_KEY Leaks to Achieve RCE in Hundreds of Laravel Applications <a href="https://blog.gitguardian.com/exploiting-public-app_key-leaks/">Link</a></p></li><li><p>Shift-Left Security with Amazon Inspector Code Security <a href="https://senayakut.com/shift-left-security-with-amazon-inspector-code-security-2f9ee342c753">Link</a></p></li><li><p>Career Longevity &amp; The Don't Fire Me Chart <a href="https://www.philvenables.com/post/career-longevity-the-don-t-fire-me-chart-1">Link</a></p></li><li><p>Unmasking Lambda's Hidden Threat - When Your Bootstrap Becomes a Backdoor <a href="https://sjimnar.github.io/blog/2025/07/11/unmasking-lambdas-hidden-threat---when-your-bootstrap-becomes-a-backdoor/">Link</a></p></li><li><p>Would you like an IDOR with that? Leaking 64 million McDonald&#8217;s job applications <a href="https://ian.sh/mcdonalds">Link</a></p></li><li><p>Investigate Your Own AWS Attack with Athena <a href="https://slaw.securosis.com/p/skills-challenge-investigate-your-own-aws-attack-with-athena-3d0d">Link</a></p></li><li><p>CVE-2025-48384: Git vulnerable to arbitrary file write on non-Windows systems Link <a href="https://securitylabs.datadoghq.com/articles/git-arbitrary-file-write/">Link</a></p></li><li><p>Bypassing Meta&#8217;s Llama Firewall: A Case Study in Prompt Injection Vulnerabilities <a href="https://medium.com/trendyol-tech/bypassing-metas-llama-firewall-a-case-study-in-prompt-injection-vulnerabilities-fb552b93412b">Link</a></p></li></ul></li></ol><p></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://aws-cloudsec.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://aws-cloudsec.com/subscribe?"><span>Subscribe now</span></a></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://aws-cloudsec.com/p/issue-104?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://aws-cloudsec.com/p/issue-104?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share</span></a></p><p></p><p></p><p></p>]]></content:encoded></item><item><title><![CDATA[Issue 103]]></title><description><![CDATA[7 days of Cloud Security, recapped in 7 minutes or less!]]></description><link>https://aws-cloudsec.com/p/issue-103</link><guid isPermaLink="false">https://aws-cloudsec.com/p/issue-103</guid><dc:creator><![CDATA[AWS-CloudSec Weekly Newsletter]]></dc:creator><pubDate>Tue, 08 Jul 2025 06:44:46 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!po4I!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F15838bce-c9b4-4b0c-b508-f95a721fd7ca_1200x1200.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p><em>This issue is sponsored by <a href="https://www.plerion.com/">Plerion</a>. Check out Plerion&#8217;s AWS security platform and cloud security teammate &#187; <strong><a href="https://www.plerion.com/pleri-ai">HERE</a></strong>.</em></p><p><strong>This week TLDR i.e. 1 minute version </strong>(For executives):</p><ol><li><p>Amazon Inspector expands security vulnerability scanning to more AWS Regions <a href="https://aws.amazon.com/about-aws/whats-new/2025/07/amazon-inspector-additional-aws-regions">Link</a></p></li><li><p>Amazon CloudFront supports HTTPS DNS records for enhanced security and performance <a href="https://aws.amazon.com/about-aws/whats-new/2025/07/amazon-cloudfront-https-dns-records">Link</a></p></li><li><p>AWS Site-to-Site VPN integrates with AWS Secrets Manager and improves security configurations <a href="https://aws.amazon.com/about-aws/whats-new/2025/07/aws-site-to-site-vpn-secrets-manager-integration">Link</a></p></li><li><p>AWS Fargate supports SOCI Index Manifest v2 for improved deployment consistency and integrity <a href="https://aws.amazon.com/about-aws/whats-new/2025/07/aws-fargate-soci-index-manifest-v2-deployment-consistency">Link</a></p></li><li><p>Amazon CloudWatch PutMetricData API supports CloudTrail logging for security and compliance <a href="https://aws.amazon.com/about-aws/whats-new/2025/07/amazon-cloudwatch-putmetricdata-api-aws-cloudtrail-data-event-logging">Link</a></p></li></ol><p><strong>Trending in Cloud &amp; Cyber Security</strong>:</p><ol><li><p>AWS Security Blogs &amp; Bulletins:</p><ul><li><p>Monitor AWS cloud resources for resilience across multiple accounts <a href="https://aws.amazon.com/blogs/mt/centralized-multi-account-application-resilience-assessment-using-aws/">Link</a></p></li><li><p>Strengthen security for AWS cloud storage with Superna Defender <a href="https://aws.amazon.com/blogs/apn/strengthen-your-aws-cloud-storage-security-with-superna-defender/">Link</a></p></li><li><p>Enhance remote secure access to AWS for hybrid workforces <a href="https://aws.amazon.com/blogs/security/remote-access-to-aws-a-guide-for-hybrid-workforces/">Link</a></p></li><li><p>CyberVadis report for third-party supplier risk assessment <a href="https://aws.amazon.com/blogs/security/2025-cybervadis-report-now-available-for-due-diligence-on-third-party-suppliers/">Link</a></p></li><li><p>Improve backup and recovery resilience with multi-party approval <a href="https://aws.amazon.com/blogs/storage/improve-recovery-resilience-with-aws-backup-support-for-multi-party-approval/">Link</a></p></li></ul></li><li><p>General security blogs, articles, reports &amp; trending news/advisories:</p><ul><li><p>Building a cloud security roadmap: Tools by layer and when you need them (pt.1) <a href="https://groundedcloudsecurity.substack.com/p/building-a-cloud-security-roadmap">Link</a></p></li><li><p>How Google Cloud is securing open-source credentials at scale <a href="https://cloud.google.com/blog/products/identity-security/securing-open-source-credentials-at-scale">Link</a></p></li><li><p>Instagram uses expiring certificates as single day TLS certificates <a href="https://hereket.com/posts/instagram-single-day-certificates/">Link</a></p></li><li><p>How I Scanned all of GitHub&#8217;s &#8220;Oops Commits&#8221; for Leaked Secrets <a href="https://trufflesecurity.com/blog/guest-post-how-i-scanned-all-of-github-s-oops-commits-for-leaked-secrets">Link</a></p></li><li><p>Hijacking Amazon EventBridge for launching Cross-Account attacks <a href="https://developer.squareup.com/blog/hijacking-amazon-eventbridge-for-launching-cross-account-attacks/">Link</a></p></li><li><p>Marketplace Takeover: How We Could&#8217;ve Taken Over Every Developer Using a VSCode Fork; Putting Millions at Risk <a href="https://blog.koi.security/marketplace-takeover-how-we-couldve-taken-over-every-developer-using-a-vscode-fork-f0f8cf104d44">Link</a></p></li><li><p>How to get rekt using AWS Neptune <a href="https://www.plerion.com/blog/how-to-get-rekt-using-aws-neptune">Link</a></p></li></ul></li></ol><p></p><p></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://aws-cloudsec.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://aws-cloudsec.com/subscribe?"><span>Subscribe now</span></a></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://aws-cloudsec.com/p/issue-103?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://aws-cloudsec.com/p/issue-103?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share</span></a></p><p></p><p></p><p></p>]]></content:encoded></item><item><title><![CDATA[Issue 102]]></title><description><![CDATA[7 days of Cloud Security, recapped in 7 minutes or less!]]></description><link>https://aws-cloudsec.com/p/issue-102</link><guid isPermaLink="false">https://aws-cloudsec.com/p/issue-102</guid><dc:creator><![CDATA[AWS-CloudSec Weekly Newsletter]]></dc:creator><pubDate>Tue, 17 Jun 2025 19:46:19 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe69a553d-ed82-4e57-a892-09bd3c3e3c56_1200x1200.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p><strong>This week TLDR i.e. 1 minute version </strong>(For executives):</p><ol><li><p>AWS WAF now supports automatic application layer distributed denial of service (DDoS) protection. </p></li><li><p>AWS Control Tower now supports seven new compliance frameworks. </p></li><li><p>AWS KMS adds support for post-quantum ML-DSA digital signatures. </p></li><li><p>Amazon Verified Permissions reduces authorization request price by up to 97%.</p></li><li><p>Amazon EKS Pod Identity simplifies the experience for cross-account access. </p></li><li><p>AWS CloudTrail enhances logging for Amazon S3 DeleteObjects API. </p></li><li><p>Amazon S3 extends additional context for HTTP 403 Access Denied error messages to AWS Organizations.</p><p></p></li></ol><p><strong>Trending in Cloud &amp; Cyber Security</strong>:</p><ol><li><p>AWS Security Blogs &amp; Bulletins:</p><ul><li><p>Bulletin: CVE-2025-6031 - Insecure device pairing in end-of-life Amazon Cloud Cam. <a href="https://aws.amazon.com/security/security-bulletins/AWS-2025-013/">Link</a>. </p></li><li><p>How to create post-quantum signatures using AWS KMS and ML-DSA. <a href="https://aws.amazon.com/blogs/security/how-to-create-post-quantum-signatures-using-aws-kms-and-ml-dsa/">Link</a>. </p></li><li><p>AWS CIRT announces the launch of the Threat Technique Catalog for AWS. <a href="https://aws.amazon.com/blogs/security/aws-cirt-announces-the-launch-of-the-threat-technique-catalog-for-aws/">Link</a>. </p></li></ul></li><li><p>General security blogs, articles, reports &amp; trending news/advisories:</p><ul><li><p>Amazon to launch second Secret Cloud Region in 2025. <a href="https://aws.amazon.com/blogs/publicsector/amazon-to-launch-second-secret-cloud-region-in-2025/">Link</a>. </p></li><li><p>AWS Temporary Sandbox environment. GitHub <a href="https://github.com/aws-solutions/innovation-sandbox-on-aws">Link</a>. </p></li><li><p>Revoking access to IAM Roles Anywhere using open-source private CA by Paul Schwarzenberger. <a href="https://medium.com/@paulschwarzenberger/revoking-access-to-iam-roles-anywhere-using-open-source-private-ca-47667cc92299">Link</a>. </p></li><li><p>OneLogin, Many Issues: How I Pivoted from a Trial Tenant to Compromising Customer Signing Keys by Julian Catrambone. <a href="https://specterops.io/blog/2025/06/10/onelogin-many-issues-how-i-pivoted-from-a-trial-tenant-to-compromising-customer-signing-keys/">Link</a>. </p></li><li><p>Hey ARNold: A Guide to All the Amazon Resource Identifiers Formats in AWS by Jason Kao. <a href="https://www.fogsecurity.io/blog/aws-arn-formats">Link</a>. </p></li><li><p>The Evolution of Linux Binaries in Targeted Cloud Operations by Nathaniel Quist, Bill Batchelor. <a href="https://unit42.paloaltonetworks.com/elf-based-malware-targets-cloud/">Link</a>. </p></li><li><p>Attackers Unleash TeamFiltration: Account Takeover Campaign (UNK_SneakyStrike) Leverages Popular Pentesting Tool. <a href="https://www.proofpoint.com/us/blog/threat-insight/attackers-unleash-teamfiltration-account-takeover-campaign">Link</a>. </p></li><li><p>First Forensic Confirmation of Paragon&#8217;s iOS Mercenary Spyware Finds Journalists Targeted by Bill Marczak and John Scott-Railton. <a href="https://citizenlab.ca/2025/06/first-forensic-confirmation-of-paragons-ios-mercenary-spyware-finds-journalists-targeted/">Link</a>. </p></li><li><p>AWS Data Perimeter policy examples. Github <a href="https://github.com/aws-samples/data-perimeter-policy-examples/tree/main/service_specific_guidance">Link</a>. </p></li></ul><p></p></li></ol><p><strong>This week Long i.e. 3-5 minutes version </strong>(For architects &amp; engineers):</p><ol><li><p>AWS has enhanced WAF application layer (L7) DDoS protection with faster automatic detection and mitigation, responding within seconds, leveraging AWS WAF Managed Rule group, which now detects and blocks DDoS attacks in real time across services like CloudFront and ALB, helping security and reliability teams reduce manual effort while keeping apps available. <a href="https://aws.amazon.com/about-aws/whats-new/2025/06/aws-waf-automatic-application-layer-ddos-protection/">Link</a>. Here&#8217;s my ruleset:</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!cV-V!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc67116ab-bf8d-4af7-b205-233cbde88e48_2562x1512.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!cV-V!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc67116ab-bf8d-4af7-b205-233cbde88e48_2562x1512.png 424w, https://substackcdn.com/image/fetch/$s_!cV-V!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc67116ab-bf8d-4af7-b205-233cbde88e48_2562x1512.png 848w, https://substackcdn.com/image/fetch/$s_!cV-V!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc67116ab-bf8d-4af7-b205-233cbde88e48_2562x1512.png 1272w, https://substackcdn.com/image/fetch/$s_!cV-V!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc67116ab-bf8d-4af7-b205-233cbde88e48_2562x1512.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!cV-V!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc67116ab-bf8d-4af7-b205-233cbde88e48_2562x1512.png" width="2562" height="1512" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/c67116ab-bf8d-4af7-b205-233cbde88e48_2562x1512.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1512,&quot;width&quot;:2562,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:264619,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://aws-cloudsec.com/i/166098251?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F104b852e-3c93-4d31-8818-20a36da9f120_2562x1512.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!cV-V!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc67116ab-bf8d-4af7-b205-233cbde88e48_2562x1512.png 424w, https://substackcdn.com/image/fetch/$s_!cV-V!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc67116ab-bf8d-4af7-b205-233cbde88e48_2562x1512.png 848w, https://substackcdn.com/image/fetch/$s_!cV-V!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc67116ab-bf8d-4af7-b205-233cbde88e48_2562x1512.png 1272w, https://substackcdn.com/image/fetch/$s_!cV-V!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc67116ab-bf8d-4af7-b205-233cbde88e48_2562x1512.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div></li><li><p>AWS Control Tower now supports seven additional compliance frameworks in Control Catalog, which include CIS v8.0, FedRAMP r4, ISO/IEC 27001:2013 Annex A, NIST CSF v1.1, NIST SP 800-171 r2, PCI DSS v4.0, and SSAE 18 SOC 2 (Oct 2023). <a href="https://aws.amazon.com/about-aws/whats-new/2025/06/aws-control-tower-new-compliance-frameworks/">Link</a>. </p></li><li><p>AWS Key Management Service (KMS) now supports the FIPS 203 ML-DSA, a quantum-resistant digital signature algorithm standardized by NIST. Designed to protect sensitive data against future quantum threats, ML-DSA is ideal for use cases like firmware and code signing, where signatures must remain secure and valid for years. <a href="https://aws.amazon.com/about-aws/whats-new/2025/06/aws-kms-post-quantum-ml-dsa-digital-signatures/">Link</a>. Here&#8217;s my key:</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!HmjL!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F76cf81f0-f6c8-486a-9280-cb6376dbbf50_2996x1170.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!HmjL!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F76cf81f0-f6c8-486a-9280-cb6376dbbf50_2996x1170.png 424w, https://substackcdn.com/image/fetch/$s_!HmjL!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F76cf81f0-f6c8-486a-9280-cb6376dbbf50_2996x1170.png 848w, https://substackcdn.com/image/fetch/$s_!HmjL!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F76cf81f0-f6c8-486a-9280-cb6376dbbf50_2996x1170.png 1272w, https://substackcdn.com/image/fetch/$s_!HmjL!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F76cf81f0-f6c8-486a-9280-cb6376dbbf50_2996x1170.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!HmjL!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F76cf81f0-f6c8-486a-9280-cb6376dbbf50_2996x1170.png" width="2996" height="1170" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/76cf81f0-f6c8-486a-9280-cb6376dbbf50_2996x1170.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1170,&quot;width&quot;:2996,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:299487,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://aws-cloudsec.com/i/166098251?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F919fcfb1-d54d-42ac-9f1d-ac60e6463bb3_2996x1170.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!HmjL!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F76cf81f0-f6c8-486a-9280-cb6376dbbf50_2996x1170.png 424w, https://substackcdn.com/image/fetch/$s_!HmjL!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F76cf81f0-f6c8-486a-9280-cb6376dbbf50_2996x1170.png 848w, https://substackcdn.com/image/fetch/$s_!HmjL!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F76cf81f0-f6c8-486a-9280-cb6376dbbf50_2996x1170.png 1272w, https://substackcdn.com/image/fetch/$s_!HmjL!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F76cf81f0-f6c8-486a-9280-cb6376dbbf50_2996x1170.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div></li><li><p>Amazon Verified Permissions has reduced pricing for single authorization requests by up to 97%, now costing $5 per million API calls. <a href="https://aws.amazon.com/about-aws/whats-new/2025/06/amazon-verified-permissions-reduces-price/">Link</a>. Updated pricing:</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!5MLw!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffe88693a-fc80-482b-8801-e86b5bf6987b_2334x1208.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!5MLw!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffe88693a-fc80-482b-8801-e86b5bf6987b_2334x1208.png 424w, https://substackcdn.com/image/fetch/$s_!5MLw!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffe88693a-fc80-482b-8801-e86b5bf6987b_2334x1208.png 848w, https://substackcdn.com/image/fetch/$s_!5MLw!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffe88693a-fc80-482b-8801-e86b5bf6987b_2334x1208.png 1272w, https://substackcdn.com/image/fetch/$s_!5MLw!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffe88693a-fc80-482b-8801-e86b5bf6987b_2334x1208.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!5MLw!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffe88693a-fc80-482b-8801-e86b5bf6987b_2334x1208.png" width="1456" height="754" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/fe88693a-fc80-482b-8801-e86b5bf6987b_2334x1208.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:754,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:237788,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://aws-cloudsec.com/i/166098251?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffe88693a-fc80-482b-8801-e86b5bf6987b_2334x1208.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!5MLw!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffe88693a-fc80-482b-8801-e86b5bf6987b_2334x1208.png 424w, https://substackcdn.com/image/fetch/$s_!5MLw!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffe88693a-fc80-482b-8801-e86b5bf6987b_2334x1208.png 848w, https://substackcdn.com/image/fetch/$s_!5MLw!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffe88693a-fc80-482b-8801-e86b5bf6987b_2334x1208.png 1272w, https://substackcdn.com/image/fetch/$s_!5MLw!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffe88693a-fc80-482b-8801-e86b5bf6987b_2334x1208.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div></li><li><p>Amazon EKS Pod Identity now simplifies cross-account access to AWS resources. With updated APIs, you can configure permissions by specifying IAM details from the target account when creating a Pod Identity association. Applications in your EKS cluster receive the required credentials at runtime&#8212;no code changes needed. Using IAM role chaining, EKS Pod Identity lets your pods access resources like S3 or DynamoDB in other accounts by assuming a local role and then a target role in the resource account, automatically handling credential delivery. <a href="https://aws.amazon.com/about-aws/whats-new/2025/06/amazon-eks-pod-identity-cross-account-access/">Link</a>. Here&#8217;s an example for external access:</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!seqy!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F600e1ff6-0769-4d1b-b552-6ac7cf06f2d1_1202x702.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!seqy!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F600e1ff6-0769-4d1b-b552-6ac7cf06f2d1_1202x702.png 424w, https://substackcdn.com/image/fetch/$s_!seqy!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F600e1ff6-0769-4d1b-b552-6ac7cf06f2d1_1202x702.png 848w, https://substackcdn.com/image/fetch/$s_!seqy!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F600e1ff6-0769-4d1b-b552-6ac7cf06f2d1_1202x702.png 1272w, https://substackcdn.com/image/fetch/$s_!seqy!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F600e1ff6-0769-4d1b-b552-6ac7cf06f2d1_1202x702.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!seqy!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F600e1ff6-0769-4d1b-b552-6ac7cf06f2d1_1202x702.png" width="1202" height="702" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/600e1ff6-0769-4d1b-b552-6ac7cf06f2d1_1202x702.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:702,&quot;width&quot;:1202,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:113150,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://aws-cloudsec.com/i/166098251?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3a52092f-3674-47d3-9fde-6fc12b5623aa_1202x702.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!seqy!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F600e1ff6-0769-4d1b-b552-6ac7cf06f2d1_1202x702.png 424w, https://substackcdn.com/image/fetch/$s_!seqy!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F600e1ff6-0769-4d1b-b552-6ac7cf06f2d1_1202x702.png 848w, https://substackcdn.com/image/fetch/$s_!seqy!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F600e1ff6-0769-4d1b-b552-6ac7cf06f2d1_1202x702.png 1272w, https://substackcdn.com/image/fetch/$s_!seqy!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F600e1ff6-0769-4d1b-b552-6ac7cf06f2d1_1202x702.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div></li><li><p>AWS has enhanced Amazon S3 DeleteObjects API logging in AWS CloudTrail to provide deeper visibility into bulk delete operations, helping you better protect and monitor your S3 buckets. Previously, CloudTrail recorded a single event for DeleteObjects API calls, showing who made the request and which bucket was affected, but not which specific objects were deleted. With this update, CloudTrail now also logs individual DeleteObject events for each object in the bulk request, offering detailed insights into exactly what was deleted. <a href="https://aws.amazon.com/about-aws/whats-new/2025/06/aws-cloudtrail-logging-amazon-s3-deleteobjects-api/">Link</a>.  For example, here&#8217;s my CloudTrail for DeleteObject event, with the details:</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!6jlB!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F374c9553-850c-4bb7-9beb-aeeffac8eb31_1000x1426.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!6jlB!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F374c9553-850c-4bb7-9beb-aeeffac8eb31_1000x1426.png 424w, https://substackcdn.com/image/fetch/$s_!6jlB!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F374c9553-850c-4bb7-9beb-aeeffac8eb31_1000x1426.png 848w, https://substackcdn.com/image/fetch/$s_!6jlB!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F374c9553-850c-4bb7-9beb-aeeffac8eb31_1000x1426.png 1272w, https://substackcdn.com/image/fetch/$s_!6jlB!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F374c9553-850c-4bb7-9beb-aeeffac8eb31_1000x1426.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!6jlB!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F374c9553-850c-4bb7-9beb-aeeffac8eb31_1000x1426.png" width="1000" height="1426" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/374c9553-850c-4bb7-9beb-aeeffac8eb31_1000x1426.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1426,&quot;width&quot;:1000,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:241306,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://aws-cloudsec.com/i/166098251?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F82477a09-7f0f-46d4-97f5-d2cdef5592b8_1000x1426.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!6jlB!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F374c9553-850c-4bb7-9beb-aeeffac8eb31_1000x1426.png 424w, https://substackcdn.com/image/fetch/$s_!6jlB!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F374c9553-850c-4bb7-9beb-aeeffac8eb31_1000x1426.png 848w, https://substackcdn.com/image/fetch/$s_!6jlB!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F374c9553-850c-4bb7-9beb-aeeffac8eb31_1000x1426.png 1272w, https://substackcdn.com/image/fetch/$s_!6jlB!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F374c9553-850c-4bb7-9beb-aeeffac8eb31_1000x1426.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div></li><li><p>Amazon S3 now provides enhanced context in HTTP 403 Access Denied responses for requests targeting resources in accounts within the same AWS Organization. These responses include details such as the type of policy that blocked the request, the reason for the denial, and information about the IAM user or role that attempted access. This added context helps you diagnose permission issues more effectively, pinpoint the cause of access denials, and correct misconfigured policies. The same detailed information is also captured in AWS CloudTrail logs. <a href="https://aws.amazon.com/about-aws/whats-new/2025/06/amazon-s3-context-http-403-access-denied-error-message-aws-organizations/">Link</a>. Here are my sample errors:</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!XvMr!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F546d4364-5bbb-4819-8a34-20bd3a13be0c_1504x156.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!XvMr!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F546d4364-5bbb-4819-8a34-20bd3a13be0c_1504x156.png 424w, https://substackcdn.com/image/fetch/$s_!XvMr!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F546d4364-5bbb-4819-8a34-20bd3a13be0c_1504x156.png 848w, https://substackcdn.com/image/fetch/$s_!XvMr!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F546d4364-5bbb-4819-8a34-20bd3a13be0c_1504x156.png 1272w, https://substackcdn.com/image/fetch/$s_!XvMr!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F546d4364-5bbb-4819-8a34-20bd3a13be0c_1504x156.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!XvMr!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F546d4364-5bbb-4819-8a34-20bd3a13be0c_1504x156.png" width="1504" height="156" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/546d4364-5bbb-4819-8a34-20bd3a13be0c_1504x156.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:156,&quot;width&quot;:1504,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:188123,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://aws-cloudsec.com/i/166098251?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F70fc28ea-e148-46f8-aa38-d91773b293a6_1504x204.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!XvMr!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F546d4364-5bbb-4819-8a34-20bd3a13be0c_1504x156.png 424w, https://substackcdn.com/image/fetch/$s_!XvMr!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F546d4364-5bbb-4819-8a34-20bd3a13be0c_1504x156.png 848w, https://substackcdn.com/image/fetch/$s_!XvMr!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F546d4364-5bbb-4819-8a34-20bd3a13be0c_1504x156.png 1272w, https://substackcdn.com/image/fetch/$s_!XvMr!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F546d4364-5bbb-4819-8a34-20bd3a13be0c_1504x156.png 1456w" sizes="100vw" fetchpriority="high"></picture><div></div></div></a></figure></div><p></p><p></p><p></p><p></p><p></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://aws-cloudsec.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://aws-cloudsec.com/subscribe?"><span>Subscribe now</span></a></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://aws-cloudsec.com/p/issue-102?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://aws-cloudsec.com/p/issue-102?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share</span></a></p><p></p></li></ol><p></p><p></p>]]></content:encoded></item><item><title><![CDATA[Issue 101]]></title><description><![CDATA[7 days of Cloud Security, recapped in 7 minutes or less!]]></description><link>https://aws-cloudsec.com/p/issue-101</link><guid isPermaLink="false">https://aws-cloudsec.com/p/issue-101</guid><dc:creator><![CDATA[AWS-CloudSec Weekly Newsletter]]></dc:creator><pubDate>Wed, 11 Jun 2025 18:48:24 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe69a553d-ed82-4e57-a892-09bd3c3e3c56_1200x1200.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p><strong>This week TLDR i.e. 1 minute version </strong>(For executives):</p><ol><li><p>Amazon VPC Route Server announces logging enhancements. </p></li><li><p>AWS Site-to-Site VPN introduces three new capabilities for enhanced security.</p></li><li><p>AWS KMS launches on-demand key rotation for imported keys.</p></li><li><p>AWS Network Firewall launches new monitoring dashboard.  </p></li><li><p>Announcing ASN match support for AWS WAF. </p><p></p></li></ol><p><strong>Trending in Cloud &amp; Cyber Security</strong>:</p><ol><li><p>AWS Security Blogs &amp; Bulletins:</p><ul><li><p>Bulletin: CVE-2025-5688 - Out of Bounds Write in FreeRTOS-Plus-TCP. <a href="https://aws.amazon.com/security/security-bulletins/AWS-2025-012/">Link</a>. </p></li><li><p>Building secure foundations: A guide to network and infrastructure security at AWS re:Inforce 2025. <a href="https://aws.amazon.com/blogs/security/building-secure-foundations-a-guide-to-network-and-infrastructure-security-at-aws-reinforce-2025/">Link</a>.</p></li><li><p>Implementing just-in-time privileged access to AWS with Microsoft Entra and AWS IAM Identity Center. <a href="https://aws.amazon.com/blogs/security/implementing-just-in-time-privileged-access-to-aws-with-microsoft-entra-and-aws-iam-identity-center/">Link.</a> </p></li><li><p>How to use on-demand rotation for AWS KMS imported keys. <a href="https://aws.amazon.com/blogs/security/how-to-use-on-demand-rotation-for-aws-kms-imported-keys/">Link</a>. </p></li></ul></li><li><p>General security blogs, articles, reports &amp; trending news/advisories:</p><ul><li><p>Bruteforcing the phone number of any Google user. <a href="https://brutecat.com/articles/leaking-google-phones">Link</a>. </p></li><li><p>Newly identified wiper malware &#8220;PathWiper&#8221; targets critical infrastructure in Ukraine by Jacob Finn, Dmytro Korzhevin, Asheer Malhotra. <a href="https://blog.talosintelligence.com/pathwiper-targets-ukraine/">Link</a>. </p></li><li><p>Follow the Smoke | China-nexus Threat Actors Hammer At the Doors of Top Tier Targets. <a href="https://www.sentinelone.com/labs/follow-the-smoke-china-nexus-threat-actors-hammer-at-the-doors-of-top-tier-targets/">Link</a>. </p></li><li><p>Official Root Cause Analysis (RCA) for SentinelOne Global Service Interruption. <a href="https://www.sentinelone.com/blog/update-on-may-29-outage/">Link</a>. </p></li><li><p>BladedFeline: Whispering in the dark. <a href="https://www.welivesecurity.com/en/eset-research/bladedfeline-whispering-dark/">Link</a>. </p></li><li><p>Lumma Infostealer &#8211; Down but Not Out? <a href="https://blog.checkpoint.com/security/lumma-infostealer-down-but-not-out/">Link</a>. </p></li><li><p>Malicious Ruby Gems Exfiltrate Telegram Tokens and Messages Following Vietnam Ban by Kirill Boychenko. <a href="https://socket.dev/blog/malicious-ruby-gems-exfiltrate-telegram-tokens-and-messages-following-vietnam-ban">Link</a>. </p></li><li><p>AMOS Variant Distributed Via Clickfix In Spectrum-Themed Dynamic Delivery Campaign By Russian Speaking Hackers by Koushik Pal. <a href="https://www.cloudsek.com/blog/amos-variant-distributed-via-clickfix-in-spectrum-themed-dynamic-delivery-campaign-by-russian-speaking-hackers">Link</a>. </p></li><li><p>Orca 2025 State of Cloud Security Report: Cloud Risks Surge Amid Expanding AI Adoption. <a href="https://orca.security/resources/blog/cloud-security-risks-ai-2025/">Link</a>. </p></li><li><p>FBI Advisory: Alert Number: I-060325-PSA on NFT Airdrop Defrauding Techniques. <a href="https://www.ic3.gov/PSA/2025/PSA250603">Link</a>. </p></li><li><p>The Cost of a Call: From Voice Phishing to Data Extortion. <a href="https://cloud.google.com/blog/topics/threat-intelligence/voice-phishing-data-extortion">Link</a>. </p></li><li><p>Cyber criminals bribed and recruited a group of rogue overseas support agents to steal Coinbase customer data. <a href="https://www.coinbase.com/blog/protecting-our-customers-standing-up-to-extortionists">Link.</a> </p></li><li><p>Victoria&#8217;s Secret &amp; Co. Security Incident Involving Information Technology Systems. <a href="https://www.globenewswire.com/news-release/2025/06/03/3092718/0/en/Victoria-s-Secret-Co-Provides-First-Quarter-2025-Preliminary-Results-and-Update-on-Security-Incident-Involving-Information-Technology-Systems.html">Link</a>. </p></li><li><p>Microsoft &amp; Crowdstrike partner on threat actor naming. <a href="https://www.microsoft.com/en-us/security/blog/2025/06/02/announcing-a-new-strategic-collaboration-to-bring-clarity-to-threat-actor-naming/">Link</a>. </p></li></ul><p></p></li></ol><p><strong>This week Long i.e. 3-5 minutes version </strong>(For architects &amp; engineers):</p><ol><li><p>Amazon VPC Route Server has added new network metrics to monitor BGP and BFD sessions, troubleshoot connectivity, and view network health in real-time. This update enables faster, independent diagnosis of network issues, with flexible log delivery to CloudWatch, S3, and more. <a href="https://aws.amazon.com/about-aws/whats-new/2025/06/amazon-vpc-route-server-logging-enhancements/">Link</a>. For example, here are my log delivery options:</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!N152!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F45bcf066-1708-4f75-aa96-0fb4c7f83581_2392x926.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!N152!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F45bcf066-1708-4f75-aa96-0fb4c7f83581_2392x926.png 424w, https://substackcdn.com/image/fetch/$s_!N152!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F45bcf066-1708-4f75-aa96-0fb4c7f83581_2392x926.png 848w, https://substackcdn.com/image/fetch/$s_!N152!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F45bcf066-1708-4f75-aa96-0fb4c7f83581_2392x926.png 1272w, https://substackcdn.com/image/fetch/$s_!N152!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F45bcf066-1708-4f75-aa96-0fb4c7f83581_2392x926.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!N152!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F45bcf066-1708-4f75-aa96-0fb4c7f83581_2392x926.png" width="2392" height="926" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/45bcf066-1708-4f75-aa96-0fb4c7f83581_2392x926.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:926,&quot;width&quot;:2392,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:173704,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://aws-cloudsec.com/i/165625660?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6bf594cf-0bb3-42b0-9a76-64bc28740e09_2392x926.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!N152!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F45bcf066-1708-4f75-aa96-0fb4c7f83581_2392x926.png 424w, https://substackcdn.com/image/fetch/$s_!N152!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F45bcf066-1708-4f75-aa96-0fb4c7f83581_2392x926.png 848w, https://substackcdn.com/image/fetch/$s_!N152!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F45bcf066-1708-4f75-aa96-0fb4c7f83581_2392x926.png 1272w, https://substackcdn.com/image/fetch/$s_!N152!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F45bcf066-1708-4f75-aa96-0fb4c7f83581_2392x926.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div></li><li><p>AWS Site-to-Site VPN is introducing three new features: a) Secrets Manager integration hides pre-shared keys in API responses. b) A new API tracks VPN encryption details and c) A "recommended" config option promotes best-practice security settings. <a href="https://aws.amazon.com/about-aws/whats-new/2025/06/aws-site-to-site-vpn-three-capabilities-enhanced-security/">Link</a>.  CLI references <a href="https://docs.aws.amazon.com/cli/latest/reference/ec2/">HERE</a> and here are my configs:</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!c1v9!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa33f8170-b595-49ca-af4e-9a76f9e49190_1962x808.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!c1v9!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa33f8170-b595-49ca-af4e-9a76f9e49190_1962x808.png 424w, https://substackcdn.com/image/fetch/$s_!c1v9!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa33f8170-b595-49ca-af4e-9a76f9e49190_1962x808.png 848w, https://substackcdn.com/image/fetch/$s_!c1v9!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa33f8170-b595-49ca-af4e-9a76f9e49190_1962x808.png 1272w, https://substackcdn.com/image/fetch/$s_!c1v9!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa33f8170-b595-49ca-af4e-9a76f9e49190_1962x808.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!c1v9!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa33f8170-b595-49ca-af4e-9a76f9e49190_1962x808.png" width="1962" height="808" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/a33f8170-b595-49ca-af4e-9a76f9e49190_1962x808.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:808,&quot;width&quot;:1962,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:137789,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://aws-cloudsec.com/i/165625660?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8bc6ac8f-e28a-4549-9ba7-7bb2dfe06283_1962x808.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!c1v9!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa33f8170-b595-49ca-af4e-9a76f9e49190_1962x808.png 424w, https://substackcdn.com/image/fetch/$s_!c1v9!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa33f8170-b595-49ca-af4e-9a76f9e49190_1962x808.png 848w, https://substackcdn.com/image/fetch/$s_!c1v9!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa33f8170-b595-49ca-af4e-9a76f9e49190_1962x808.png 1272w, https://substackcdn.com/image/fetch/$s_!c1v9!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa33f8170-b595-49ca-af4e-9a76f9e49190_1962x808.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!7g1S!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7a256e5e-475b-47d9-b731-895b4a60cde6_1962x158.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!7g1S!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7a256e5e-475b-47d9-b731-895b4a60cde6_1962x158.png 424w, https://substackcdn.com/image/fetch/$s_!7g1S!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7a256e5e-475b-47d9-b731-895b4a60cde6_1962x158.png 848w, https://substackcdn.com/image/fetch/$s_!7g1S!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7a256e5e-475b-47d9-b731-895b4a60cde6_1962x158.png 1272w, https://substackcdn.com/image/fetch/$s_!7g1S!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7a256e5e-475b-47d9-b731-895b4a60cde6_1962x158.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!7g1S!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7a256e5e-475b-47d9-b731-895b4a60cde6_1962x158.png" width="1456" height="117" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/7a256e5e-475b-47d9-b731-895b4a60cde6_1962x158.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:117,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:63495,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://aws-cloudsec.com/i/165625660?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7a256e5e-475b-47d9-b731-895b4a60cde6_1962x158.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!7g1S!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7a256e5e-475b-47d9-b731-895b4a60cde6_1962x158.png 424w, https://substackcdn.com/image/fetch/$s_!7g1S!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7a256e5e-475b-47d9-b731-895b4a60cde6_1962x158.png 848w, https://substackcdn.com/image/fetch/$s_!7g1S!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7a256e5e-475b-47d9-b731-895b4a60cde6_1962x158.png 1272w, https://substackcdn.com/image/fetch/$s_!7g1S!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7a256e5e-475b-47d9-b731-895b4a60cde6_1962x158.png 1456w" sizes="100vw" fetchpriority="high"></picture><div></div></div></a></figure></div></li><li><p>AWS Key Management Service (KMS) now supports on-demand rotation of symmetric encryption keys with imported key material (BYOK), enabling periodic key rotation, without changing the key identifier. <a href="https://aws.amazon.com/about-aws/whats-new/2025/06/aws-kms-on-demand-key-rotation-imported-keys/">Link</a>. Well explained in <a href="https://aws.amazon.com/blogs/security/how-to-use-on-demand-rotation-for-aws-kms-imported-keys/">THIS</a> blog. For example, here is my on-demand rotation option and remaining rotation counts:</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!8mgh!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3b8582f7-de4c-4494-8d48-f7e1929dbc7d_2466x602.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!8mgh!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3b8582f7-de4c-4494-8d48-f7e1929dbc7d_2466x602.png 424w, https://substackcdn.com/image/fetch/$s_!8mgh!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3b8582f7-de4c-4494-8d48-f7e1929dbc7d_2466x602.png 848w, https://substackcdn.com/image/fetch/$s_!8mgh!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3b8582f7-de4c-4494-8d48-f7e1929dbc7d_2466x602.png 1272w, https://substackcdn.com/image/fetch/$s_!8mgh!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3b8582f7-de4c-4494-8d48-f7e1929dbc7d_2466x602.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!8mgh!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3b8582f7-de4c-4494-8d48-f7e1929dbc7d_2466x602.png" width="2466" height="602" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/3b8582f7-de4c-4494-8d48-f7e1929dbc7d_2466x602.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:602,&quot;width&quot;:2466,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:152538,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://aws-cloudsec.com/i/165625660?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F65bae268-1716-4ec1-9b8e-468cb829a661_2466x602.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!8mgh!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3b8582f7-de4c-4494-8d48-f7e1929dbc7d_2466x602.png 424w, https://substackcdn.com/image/fetch/$s_!8mgh!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3b8582f7-de4c-4494-8d48-f7e1929dbc7d_2466x602.png 848w, https://substackcdn.com/image/fetch/$s_!8mgh!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3b8582f7-de4c-4494-8d48-f7e1929dbc7d_2466x602.png 1272w, https://substackcdn.com/image/fetch/$s_!8mgh!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3b8582f7-de4c-4494-8d48-f7e1929dbc7d_2466x602.png 1456w" sizes="100vw" fetchpriority="high"></picture><div></div></div></a></figure></div></li><li><p>AWS Network Firewall launched a new monitoring dashboard, providing enhanced visibility into network traffic patterns and activities for better management and troubleshooting. The dashboard offers insights into:</p><p>Top traffic flows, TLS Server Name Indication (SNI), HTTP Host headers,Long- lived TCP flows and Failed TCP handshakes. <a href="https://aws.amazon.com/about-aws/whats-new/2025/06/aws-network-firewall-monitoring-dashboard/">Link</a>. For example, here is my config:</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!EEXl!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff6106032-c17f-4ef2-af72-15f52c753433_2862x1160.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!EEXl!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff6106032-c17f-4ef2-af72-15f52c753433_2862x1160.png 424w, https://substackcdn.com/image/fetch/$s_!EEXl!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff6106032-c17f-4ef2-af72-15f52c753433_2862x1160.png 848w, https://substackcdn.com/image/fetch/$s_!EEXl!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff6106032-c17f-4ef2-af72-15f52c753433_2862x1160.png 1272w, https://substackcdn.com/image/fetch/$s_!EEXl!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff6106032-c17f-4ef2-af72-15f52c753433_2862x1160.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!EEXl!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff6106032-c17f-4ef2-af72-15f52c753433_2862x1160.png" width="2862" height="1160" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/f6106032-c17f-4ef2-af72-15f52c753433_2862x1160.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1160,&quot;width&quot;:2862,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:215083,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://aws-cloudsec.com/i/165625660?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F005a56c0-7c3a-45c8-b7d8-f45f57021e3d_2862x1160.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!EEXl!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff6106032-c17f-4ef2-af72-15f52c753433_2862x1160.png 424w, https://substackcdn.com/image/fetch/$s_!EEXl!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff6106032-c17f-4ef2-af72-15f52c753433_2862x1160.png 848w, https://substackcdn.com/image/fetch/$s_!EEXl!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff6106032-c17f-4ef2-af72-15f52c753433_2862x1160.png 1272w, https://substackcdn.com/image/fetch/$s_!EEXl!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff6106032-c17f-4ef2-af72-15f52c753433_2862x1160.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div></li><li><p>AWS WAF has added support for matching incoming requests against Autonomous System Numbers (ASNs), allowing you to mitigate risks from malicious actors Comply with regulatory requirements Optimize web application performance and availability. The new ASN Match Statement integrates with existing WAF rules. <a href="https://aws.amazon.com/about-aws/whats-new/2025/06/asn-match-aws-waf/">Link</a>. For example, here&#8217;s my config:</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!sE4Q!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F101aca82-09df-4bad-b3b1-e6ae000e0e71_1292x1048.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!sE4Q!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F101aca82-09df-4bad-b3b1-e6ae000e0e71_1292x1048.png 424w, https://substackcdn.com/image/fetch/$s_!sE4Q!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F101aca82-09df-4bad-b3b1-e6ae000e0e71_1292x1048.png 848w, https://substackcdn.com/image/fetch/$s_!sE4Q!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F101aca82-09df-4bad-b3b1-e6ae000e0e71_1292x1048.png 1272w, https://substackcdn.com/image/fetch/$s_!sE4Q!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F101aca82-09df-4bad-b3b1-e6ae000e0e71_1292x1048.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!sE4Q!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F101aca82-09df-4bad-b3b1-e6ae000e0e71_1292x1048.png" width="1292" height="1048" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/101aca82-09df-4bad-b3b1-e6ae000e0e71_1292x1048.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1048,&quot;width&quot;:1292,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:129008,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://aws-cloudsec.com/i/165625660?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd8fd8309-1c91-4333-9f22-6232f0c10c7f_1292x1048.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!sE4Q!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F101aca82-09df-4bad-b3b1-e6ae000e0e71_1292x1048.png 424w, https://substackcdn.com/image/fetch/$s_!sE4Q!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F101aca82-09df-4bad-b3b1-e6ae000e0e71_1292x1048.png 848w, https://substackcdn.com/image/fetch/$s_!sE4Q!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F101aca82-09df-4bad-b3b1-e6ae000e0e71_1292x1048.png 1272w, https://substackcdn.com/image/fetch/$s_!sE4Q!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F101aca82-09df-4bad-b3b1-e6ae000e0e71_1292x1048.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p> </p><p></p><p></p><p></p><p></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://aws-cloudsec.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://aws-cloudsec.com/subscribe?"><span>Subscribe now</span></a></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://aws-cloudsec.com/p/issue-101?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://aws-cloudsec.com/p/issue-101?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share</span></a></p><p></p></li></ol><p></p><p></p>]]></content:encoded></item><item><title><![CDATA[Issue 99 & 100]]></title><description><![CDATA[7 days of Cloud Security, recapped in 7 minutes or less!]]></description><link>https://aws-cloudsec.com/p/issue-99-and-100</link><guid isPermaLink="false">https://aws-cloudsec.com/p/issue-99-and-100</guid><dc:creator><![CDATA[AWS-CloudSec Weekly Newsletter]]></dc:creator><pubDate>Tue, 03 Jun 2025 21:07:52 GMT</pubDate><enclosure url="https://substack-post-media.s3.amazonaws.com/public/images/b235c4df-9fce-436c-9663-ecf7fb17699c_480x360.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p><strong>This week TLDR i.e. 1 minute version </strong>(For executives):</p><ol><li><p>AWS Security Hub now supports NIST SP 800-171 Revision 2. </p></li><li><p>CloudTrail Lake now supports event enrichment and expanded event size. </p></li><li><p>Announcing Red Hat Enterprise Linux for AWS. </p></li><li><p>Amazon S3 Express One Zone now supports granular access controls with S3 Access Points.</p><p></p></li></ol><p><strong>Trending in Cloud &amp; Cyber Security</strong>:</p><ol><li><p>AWS Security Blogs &amp; Bulletins:</p><ul><li><p>N/A this week. </p></li></ul></li><li><p>General security blogs, articles, reports &amp; trending news/advisories:</p><ul><li><p>CloudTrail Logging Evasion: Where Policy&#8239;Size Matters by Abian Morina. <a href="https://permiso.io/blog/cloudtrail-logging-evasion-where-policy-size-matters">Link</a>. </p></li><li><p>PumaBot: Novel Botnet Targeting IoT Surveillance Devices. <a href="https://www.darktrace.com/blog/pumabot-novel-botnet-targeting-iot-surveillance-devices">Link</a>. </p></li><li><p>Mark Your Calendar: APT41 Innovative Tactics. <a href="https://cloud.google.com/blog/topics/threat-intelligence/apt41-innovative-tactics">Link</a>. </p></li><li><p>Safari Vulnerability Enables Attackers to Steal Credentials with Fullscreen BitM Attacks. <a href="https://labs.sqrx.com/fullscreen-bitm-f2634a91e6a5">Link</a>. </p></li><li><p>Sublime Email Threat Research Report. <a href="https://cdn.prod.website-files.com/6734d4696c8f76142b33121b/682d1e71b07b124b8550be76_Sublime-Security_Threat-Report_Q1-2025.pdf">Link</a>. </p></li><li><p>CloudRec: open source multi-cloud security posture management (CSPM) platform. GitHub <a href="https://github.com/antgroup/CloudRec">Link</a>. (Important note: Ant Group is a company based in China).</p></li></ul><p></p></li></ol><p><strong>This week Long i.e. 3-5 minutes version </strong>(For architects &amp; engineers):</p><ol><li><p>AWS Security Hub now supports NIST SP 800-171 Rev. 2, a U.S. cybersecurity framework for protecting sensitive information in non-federal systems. <a href="https://aws.amazon.com/about-aws/whats-new/2025/05/aws-security-hub-nist-sp-800-171-revision-2/">Link</a>. Here is the option in my console:</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!ogEp!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1b5456f2-0acd-493b-984a-fe4680a95689_2286x418.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!ogEp!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1b5456f2-0acd-493b-984a-fe4680a95689_2286x418.png 424w, https://substackcdn.com/image/fetch/$s_!ogEp!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1b5456f2-0acd-493b-984a-fe4680a95689_2286x418.png 848w, https://substackcdn.com/image/fetch/$s_!ogEp!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1b5456f2-0acd-493b-984a-fe4680a95689_2286x418.png 1272w, https://substackcdn.com/image/fetch/$s_!ogEp!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1b5456f2-0acd-493b-984a-fe4680a95689_2286x418.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!ogEp!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1b5456f2-0acd-493b-984a-fe4680a95689_2286x418.png" width="1456" height="266" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/1b5456f2-0acd-493b-984a-fe4680a95689_2286x418.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:266,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:368081,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://aws-cloudsec.com/i/165008109?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1b5456f2-0acd-493b-984a-fe4680a95689_2286x418.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!ogEp!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1b5456f2-0acd-493b-984a-fe4680a95689_2286x418.png 424w, https://substackcdn.com/image/fetch/$s_!ogEp!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1b5456f2-0acd-493b-984a-fe4680a95689_2286x418.png 848w, https://substackcdn.com/image/fetch/$s_!ogEp!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1b5456f2-0acd-493b-984a-fe4680a95689_2286x418.png 1272w, https://substackcdn.com/image/fetch/$s_!ogEp!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1b5456f2-0acd-493b-984a-fe4680a95689_2286x418.png 1456w" sizes="100vw" fetchpriority="high"></picture><div></div></div></a></figure></div></li><li><p>AWS CloudTrail Lake now offers event enrichment for easier activity categorization and analysis, and expanded event size (up to 1 MB, from the 256 KB limit) for more detailed API action visibility. <a href="https://aws.amazon.com/about-aws/whats-new/2025/05/cloudtrail-lake-event-enrichment-expanded-event-size/">Link</a>. For example, here&#8217;s my query for a specific principal tag:</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!HN7b!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F358ab765-214d-4b2e-8b66-bc6c5c3c74ee_1890x596.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!HN7b!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F358ab765-214d-4b2e-8b66-bc6c5c3c74ee_1890x596.png 424w, https://substackcdn.com/image/fetch/$s_!HN7b!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F358ab765-214d-4b2e-8b66-bc6c5c3c74ee_1890x596.png 848w, https://substackcdn.com/image/fetch/$s_!HN7b!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F358ab765-214d-4b2e-8b66-bc6c5c3c74ee_1890x596.png 1272w, https://substackcdn.com/image/fetch/$s_!HN7b!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F358ab765-214d-4b2e-8b66-bc6c5c3c74ee_1890x596.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!HN7b!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F358ab765-214d-4b2e-8b66-bc6c5c3c74ee_1890x596.png" width="1890" height="596" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/358ab765-214d-4b2e-8b66-bc6c5c3c74ee_1890x596.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:596,&quot;width&quot;:1890,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:167270,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://aws-cloudsec.com/i/165008109?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F387c5ed8-8d23-405b-8bac-894698eaac04_1890x596.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!HN7b!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F358ab765-214d-4b2e-8b66-bc6c5c3c74ee_1890x596.png 424w, https://substackcdn.com/image/fetch/$s_!HN7b!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F358ab765-214d-4b2e-8b66-bc6c5c3c74ee_1890x596.png 848w, https://substackcdn.com/image/fetch/$s_!HN7b!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F358ab765-214d-4b2e-8b66-bc6c5c3c74ee_1890x596.png 1272w, https://substackcdn.com/image/fetch/$s_!HN7b!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F358ab765-214d-4b2e-8b66-bc6c5c3c74ee_1890x596.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div></li><li><p>Red Hat Enterprise Linux (RHEL) for AWS is now generally available, starting with RHEL 10. This offering combines Red Hat's enterprise Linux with native AWS integration. Key features include pre-tuned images, Amazon CloudWatch telemetry, integrated AWS CLI, container-native tooling, enhanced security, and optimized networking with ENA support. <a href="https://aws.amazon.com/about-aws/whats-new/2025/05/red-hat-enterprise-linux-aws/">Link</a>. For example, here are my options in the EC2 launch console:</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!2XoI!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbd68da7f-0ee3-4858-a0dd-e66401551ab5_2388x958.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!2XoI!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbd68da7f-0ee3-4858-a0dd-e66401551ab5_2388x958.png 424w, https://substackcdn.com/image/fetch/$s_!2XoI!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbd68da7f-0ee3-4858-a0dd-e66401551ab5_2388x958.png 848w, https://substackcdn.com/image/fetch/$s_!2XoI!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbd68da7f-0ee3-4858-a0dd-e66401551ab5_2388x958.png 1272w, https://substackcdn.com/image/fetch/$s_!2XoI!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbd68da7f-0ee3-4858-a0dd-e66401551ab5_2388x958.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!2XoI!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbd68da7f-0ee3-4858-a0dd-e66401551ab5_2388x958.png" width="1456" height="584" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/bd68da7f-0ee3-4858-a0dd-e66401551ab5_2388x958.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:584,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:867629,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://aws-cloudsec.com/i/165008109?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbd68da7f-0ee3-4858-a0dd-e66401551ab5_2388x958.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!2XoI!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbd68da7f-0ee3-4858-a0dd-e66401551ab5_2388x958.png 424w, https://substackcdn.com/image/fetch/$s_!2XoI!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbd68da7f-0ee3-4858-a0dd-e66401551ab5_2388x958.png 848w, https://substackcdn.com/image/fetch/$s_!2XoI!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbd68da7f-0ee3-4858-a0dd-e66401551ab5_2388x958.png 1272w, https://substackcdn.com/image/fetch/$s_!2XoI!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbd68da7f-0ee3-4858-a0dd-e66401551ab5_2388x958.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div></li><li><p>Amazon S3 Express One Zone now supports granular access control via S3 Access Points which allows refined access based on prefixes or API actions, enabling tailored policies for teams, applications, or individuals. Each access point offers a unique hostname, customizable permissions, and VPC restrictions, facilitating use cases like write-only data ingestion, read-only analytics, and restricted cross-account sharing. <a href="https://aws.amazon.com/about-aws/whats-new/2025/05/amazon-s3-express-one-zone-granular-access-controls-access-points/">Link</a>. For example, here&#8217;s my permission boundary using prefix:</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!YJdQ!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F208968ec-e003-4bf8-b151-75f04014cbe3_1202x292.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!YJdQ!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F208968ec-e003-4bf8-b151-75f04014cbe3_1202x292.png 424w, https://substackcdn.com/image/fetch/$s_!YJdQ!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F208968ec-e003-4bf8-b151-75f04014cbe3_1202x292.png 848w, https://substackcdn.com/image/fetch/$s_!YJdQ!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F208968ec-e003-4bf8-b151-75f04014cbe3_1202x292.png 1272w, https://substackcdn.com/image/fetch/$s_!YJdQ!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F208968ec-e003-4bf8-b151-75f04014cbe3_1202x292.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!YJdQ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F208968ec-e003-4bf8-b151-75f04014cbe3_1202x292.png" width="1202" height="292" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/208968ec-e003-4bf8-b151-75f04014cbe3_1202x292.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:292,&quot;width&quot;:1202,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:69266,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://aws-cloudsec.com/i/165008109?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff92d34d7-c3a7-4711-b163-680bf5a082ba_1202x292.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!YJdQ!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F208968ec-e003-4bf8-b151-75f04014cbe3_1202x292.png 424w, https://substackcdn.com/image/fetch/$s_!YJdQ!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F208968ec-e003-4bf8-b151-75f04014cbe3_1202x292.png 848w, https://substackcdn.com/image/fetch/$s_!YJdQ!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F208968ec-e003-4bf8-b151-75f04014cbe3_1202x292.png 1272w, https://substackcdn.com/image/fetch/$s_!YJdQ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F208968ec-e003-4bf8-b151-75f04014cbe3_1202x292.png 1456w" sizes="100vw" fetchpriority="high"></picture><div></div></div></a></figure></div><p> </p><p></p><p></p><p></p><p></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://aws-cloudsec.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://aws-cloudsec.com/subscribe?"><span>Subscribe now</span></a></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://aws-cloudsec.com/p/issue-99-and-100?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://aws-cloudsec.com/p/issue-99-and-100?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share</span></a></p><p></p></li></ol><p></p><p></p>]]></content:encoded></item><item><title><![CDATA[Issue 98]]></title><description><![CDATA[7 days of Cloud Security, recapped in 7 minutes or less!]]></description><link>https://aws-cloudsec.com/p/issue-98</link><guid isPermaLink="false">https://aws-cloudsec.com/p/issue-98</guid><dc:creator><![CDATA[AWS-CloudSec Weekly Newsletter]]></dc:creator><pubDate>Wed, 28 May 2025 20:49:47 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F15838bce-c9b4-4b0c-b508-f95a721fd7ca_1200x1200.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p><strong>This week TLDR i.e. 1 minute version </strong>(For executives):</p><ol><li><p>AWS Secrets Manager announces support for cost allocation tags for secrets.</p></li><li><p>AWS Organizations now supports Internet Protocol Version 6 (IPv6). </p></li><li><p>Amazon EC2 Mac instances now support configurable System Integrity Protection (SIP) settings.</p><p></p></li></ol><p><strong>Trending in Cloud &amp; Cyber Security</strong>:</p><ol><li><p>AWS Security Blogs &amp; Bulletins:</p><ul><li><p>Bulletin: CVE-2025-5279 - Issue with Amazon Redshift Python Connector and the BrowserAzureOAuth2CredentialsProvider plugin. <a href="https://aws.amazon.com/security/security-bulletins/AWS-2025-011/">Link</a>. </p></li><li><p>Navigating the threat detection and incident response track at re:Inforce 2025. <a href="https://aws.amazon.com/blogs/security/navigating-the-threat-detection-and-incident-response-track-at-reinforce-2025/">Link</a>. </p></li><li><p>Elevate your AI security: Must-see re:Inforce 2025 sessions. <a href="https://aws.amazon.com/blogs/security/reinforce-2025-genai-sessions/">Link</a>. </p></li><li><p>How to use the new AWS Secrets Manager Cost Allocation Tags feature. <a href="https://aws.amazon.com/blogs/security/how-to-use-the-new-aws-secrets-manager-cost-allocation-tags-feature/">Link</a>. </p></li></ul></li><li><p>General security blogs, articles, reports &amp; trending news/advisories:</p><ul><li><p>AWS Built a Security Tool. It Introduced a Security Risk by Eliav Livneh. <a href="https://www.token.security/blog/aws-built-a-security-tool-it-introduced-a-security-risk">Link</a>. </p></li><li><p>Cloudy with a Chance of Hijacking Forgotten DNS Records Enable Scam Actor by Jacques Portal, Ren&#233;e Burton. <a href="https://blogs.infoblox.com/threat-intelligence/cloudy-with-a-chance-of-hijacking-forgotten-dns-records-enable-scam-actor/">Link</a>. </p></li><li><p>CISA Advisory: Russian GRU Targeting Western Logistics Entities and Technology Companies. <a href="https://www.cisa.gov/news-events/cybersecurity-advisories/aa25-141a">Link</a>. </p></li><li><p>Justice Department Seizes Domains Behind Major Information-Stealing Malware Operation. <a href="https://www.justice.gov/opa/pr/justice-department-seizes-domains-behind-major-information-stealing-malware-operation">Link</a>. </p></li><li><p>Cloudflare participates in global operation to disrupt Lumma Stealer. <a href="https://www.cloudflare.com/threat-intelligence/research/report/cloudflare-participates-in-joint-operation-to-disrupt-lumma-stealer/">Link</a>. </p></li><li><p>Cloud CISO Perspectives: How Google Cloud&#8217;s security team helps build securely. <a href="https://cloud.google.com/blog/products/identity-security/cloud-ciso-perspectives-how-google-cloud-security-team-helps-build-securely">Link</a>. </p></li><li><p>A python in disguise: unpacking PyInstaller malware on macOS. <a href="https://www.jamf.com/blog/pyinstaller-malware-jamf-threat-labs/">Link</a>. </p></li><li><p>Remote Prompt Injection in GitLab Duo Leads to Source Code Theft by Omer Mayraz. <a href="https://www.legitsecurity.com/blog/remote-prompt-injection-in-gitlab-duo">Link</a>. </p></li><li><p>Adidas data breach. <a href="http://Data Security Information">Link</a>. </p></li><li><p>Matlab disclosed ransomware attack. <a href="https://status.mathworks.com/incidents/h1fjvcr72n87">Link</a>. </p></li><li><p>Zscaler announced Acquisition of Red Canary. <a href="https://www.zscaler.com/press/zscaler-accelerate-innovation-ai-powered-security-operations-acquisition-red-canary">Link</a>. </p></li><li><p>Mandiant: BitM Up! Session Stealing in Seconds Using the Browser-in-the-Middle Technique. <a href="https://cloud.google.com/blog/topics/threat-intelligence/session-stealing-browser-in-the-middle">Link</a>. </p></li><li><p>Worcester College Student to Plead Guilty to Cyber Extortions. <a href="https://www.justice.gov/usao-ma/pr/worcester-college-student-plead-guilty-cyber-extortions">Link</a>. </p></li></ul></li></ol><p></p><p><strong>This week Long i.e. 3-5 minutes version </strong>(For architects &amp; engineers):</p><ol><li><p>AWS Secrets Manager now allows you to allocate and monitor costs associated with their secret usage. <a href="https://aws.amazon.com/about-aws/whats-new/2025/05/aws-secrets-manager-cost-allocation-tags-secrets/">Link</a>. Well explained in <a href="https://aws.amazon.com/blogs/security/how-to-use-the-new-aws-secrets-manager-cost-allocation-tags-feature/">THIS</a> blog. For example, here&#8217;s my tag:</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!yJNh!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb675bf2b-68c1-477c-8520-077966dd63ba_2752x950.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!yJNh!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb675bf2b-68c1-477c-8520-077966dd63ba_2752x950.png 424w, https://substackcdn.com/image/fetch/$s_!yJNh!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb675bf2b-68c1-477c-8520-077966dd63ba_2752x950.png 848w, https://substackcdn.com/image/fetch/$s_!yJNh!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb675bf2b-68c1-477c-8520-077966dd63ba_2752x950.png 1272w, https://substackcdn.com/image/fetch/$s_!yJNh!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb675bf2b-68c1-477c-8520-077966dd63ba_2752x950.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!yJNh!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb675bf2b-68c1-477c-8520-077966dd63ba_2752x950.png" width="2752" height="950" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/b675bf2b-68c1-477c-8520-077966dd63ba_2752x950.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:950,&quot;width&quot;:2752,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:143507,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://aws-cloudsec.com/i/164646892?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa8ed2ea7-6917-4028-b4ac-124441ca2119_2752x950.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!yJNh!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb675bf2b-68c1-477c-8520-077966dd63ba_2752x950.png 424w, https://substackcdn.com/image/fetch/$s_!yJNh!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb675bf2b-68c1-477c-8520-077966dd63ba_2752x950.png 848w, https://substackcdn.com/image/fetch/$s_!yJNh!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb675bf2b-68c1-477c-8520-077966dd63ba_2752x950.png 1272w, https://substackcdn.com/image/fetch/$s_!yJNh!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb675bf2b-68c1-477c-8520-077966dd63ba_2752x950.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!ypoy!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdb40b24b-e77f-4714-9e98-a2931f28ca97_3022x628.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!ypoy!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdb40b24b-e77f-4714-9e98-a2931f28ca97_3022x628.png 424w, https://substackcdn.com/image/fetch/$s_!ypoy!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdb40b24b-e77f-4714-9e98-a2931f28ca97_3022x628.png 848w, https://substackcdn.com/image/fetch/$s_!ypoy!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdb40b24b-e77f-4714-9e98-a2931f28ca97_3022x628.png 1272w, https://substackcdn.com/image/fetch/$s_!ypoy!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdb40b24b-e77f-4714-9e98-a2931f28ca97_3022x628.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!ypoy!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdb40b24b-e77f-4714-9e98-a2931f28ca97_3022x628.png" width="3022" height="628" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/db40b24b-e77f-4714-9e98-a2931f28ca97_3022x628.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:628,&quot;width&quot;:3022,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:199889,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://aws-cloudsec.com/i/164646892?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0804fd03-e08e-4873-8824-380bfc838252_3022x628.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!ypoy!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdb40b24b-e77f-4714-9e98-a2931f28ca97_3022x628.png 424w, https://substackcdn.com/image/fetch/$s_!ypoy!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdb40b24b-e77f-4714-9e98-a2931f28ca97_3022x628.png 848w, https://substackcdn.com/image/fetch/$s_!ypoy!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdb40b24b-e77f-4714-9e98-a2931f28ca97_3022x628.png 1272w, https://substackcdn.com/image/fetch/$s_!ypoy!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdb40b24b-e77f-4714-9e98-a2931f28ca97_3022x628.png 1456w" sizes="100vw" fetchpriority="high"></picture><div></div></div></a></figure></div></li><li><p>AWS Organizations now supports Internet Protocol version 6 (IPv6) through new dual-stack endpoints, allowing you to connect over the public internet using IPv6, IPv4, or dual-stack clients. Existing IPv4-only endpoints will continue to be available to ensure backward compatibility. <a href="https://aws.amazon.com/about-aws/whats-new/2025/05/aws-organizations-internet-protocol-version-6/">Link</a>. Here&#8217;s my endpoint:</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!ZBEy!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F81c961cd-6301-445f-b04c-027448f7d9a7_2360x914.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!ZBEy!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F81c961cd-6301-445f-b04c-027448f7d9a7_2360x914.png 424w, https://substackcdn.com/image/fetch/$s_!ZBEy!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F81c961cd-6301-445f-b04c-027448f7d9a7_2360x914.png 848w, https://substackcdn.com/image/fetch/$s_!ZBEy!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F81c961cd-6301-445f-b04c-027448f7d9a7_2360x914.png 1272w, https://substackcdn.com/image/fetch/$s_!ZBEy!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F81c961cd-6301-445f-b04c-027448f7d9a7_2360x914.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!ZBEy!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F81c961cd-6301-445f-b04c-027448f7d9a7_2360x914.png" width="2360" height="914" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/81c961cd-6301-445f-b04c-027448f7d9a7_2360x914.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:914,&quot;width&quot;:2360,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:185349,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://aws-cloudsec.com/i/164646892?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F28fe0a29-0f2b-4ab6-83a0-e55faed14241_2360x914.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!ZBEy!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F81c961cd-6301-445f-b04c-027448f7d9a7_2360x914.png 424w, https://substackcdn.com/image/fetch/$s_!ZBEy!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F81c961cd-6301-445f-b04c-027448f7d9a7_2360x914.png 848w, https://substackcdn.com/image/fetch/$s_!ZBEy!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F81c961cd-6301-445f-b04c-027448f7d9a7_2360x914.png 1272w, https://substackcdn.com/image/fetch/$s_!ZBEy!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F81c961cd-6301-445f-b04c-027448f7d9a7_2360x914.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div></li><li><p>You can now configure System Integrity Protection (SIP) on EC2 Mac instances which allows temporary SIP disablement for testing, installing system extensions, managing drivers, and optimizing development while maintaining security. <a href="https://aws.amazon.com/about-aws/whats-new/2025/05/amazon-ec2-mac-instances-configurable-sip-settings/">Link</a>. Well explained in <a href="https://aws.amazon.com/blogs/aws/configure-system-integrity-protection-sip-on-amazon-ec2-mac-instances/">THIS</a> blog. </p><p></p><p></p><p></p><p></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://aws-cloudsec.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://aws-cloudsec.com/subscribe?"><span>Subscribe now</span></a></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://aws-cloudsec.com/p/issue-98?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://aws-cloudsec.com/p/issue-98?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share</span></a></p><p></p></li></ol><p></p><p></p>]]></content:encoded></item><item><title><![CDATA[Issue 97]]></title><description><![CDATA[7 days of Cloud Security, recapped in 7 minutes or less!]]></description><link>https://aws-cloudsec.com/p/issue-97</link><guid isPermaLink="false">https://aws-cloudsec.com/p/issue-97</guid><dc:creator><![CDATA[AWS-CloudSec Weekly Newsletter]]></dc:creator><pubDate>Wed, 21 May 2025 16:09:46 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F15838bce-c9b4-4b0c-b508-f95a721fd7ca_1200x1200.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p><strong>This week TLDR i.e. 1 minute version </strong>(For executives):</p><ol><li><p>Amazon Elastic Container Registry (ECR) supports image replication between the AWS GovCloud (US) Region. </p></li><li><p>AWS CodeBuild adds support for new IAM condition keys. </p></li><li><p>DynamoDB local is now accessible on AWS CloudShell. </p></li><li><p>Amazon Inspector enhances container security by mapping ECR images to running containers. </p></li><li><p>Amazon Cognito now supports OIDC prompt parameter. </p><p></p></li></ol><p><strong>Trending in Cloud &amp; Cyber Security</strong>:</p><ol><li><p>AWS Security Blogs &amp; Bulletins:</p><ul><li><p>Introducing the AWS User Guide to Governance, Risk and Compliance for Responsible AI Adoption within Financial Services Industries. <a href="https://aws.amazon.com/blogs/security/introducing-the-aws-user-guide-to-governance-risk-and-compliance-for-responsible-ai-adoption-within-financial-services-industries/">Link</a>. </p></li></ul></li><li><p>General security blogs, articles, reports &amp; trending news/advisories:</p><ul><li><p>Threat modeling Cloud Service providers in 2025 by Chris Farris. <a href="https://www.chrisfarris.com/post/threat-model-2025/">Link</a>. </p></li><li><p>Root in prod: The most important security analysis you will never do on your AWS accounts by Daniel Grzelak. <a href="https://www.plerion.com/blog/root-in-prod">Link</a>. </p></li><li><p>KeePass trojanised in advanced malware campaign. Full report <a href="https://labs.withsecure.com/publications/keepass-trojanised-in-advanced-malware-campaign">HERE</a>. </p></li><li><p>Introducing Docker Hardened Images. <a href="https://www.docker.com/blog/introducing-docker-hardened-images/">Link</a>. </p></li><li><p>Coinbase security incident details. <a href="http://Protecting Our Customers - Standing Up to Extortionists">Link</a>.</p></li></ul></li></ol><p></p><p><strong>This week Long i.e. 3-5 minutes version </strong>(For architects &amp; engineers):</p><ol><li><p>Amazon Elastic Container Registry (ECR) now supports replicating images from private ECR repositories across accounts and/or regions within the AWS GovCloud (US) Regions. This capability reduces startup time for applications by enabling faster, in-region image pulls, minimizing latency &amp; supports backup and disaster recovery objectives. <a href="https://aws.amazon.com/about-aws/whats-new/2025/05/amazon-ecr-image-replication-aws-govcloud-us-region/">Link</a>. Here&#8217;s my sample replication configuration:</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!iWLU!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7363659b-1c79-4050-b078-e68b1ae354fe_2998x688.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!iWLU!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7363659b-1c79-4050-b078-e68b1ae354fe_2998x688.png 424w, https://substackcdn.com/image/fetch/$s_!iWLU!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7363659b-1c79-4050-b078-e68b1ae354fe_2998x688.png 848w, https://substackcdn.com/image/fetch/$s_!iWLU!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7363659b-1c79-4050-b078-e68b1ae354fe_2998x688.png 1272w, https://substackcdn.com/image/fetch/$s_!iWLU!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7363659b-1c79-4050-b078-e68b1ae354fe_2998x688.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!iWLU!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7363659b-1c79-4050-b078-e68b1ae354fe_2998x688.png" width="2998" height="688" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/7363659b-1c79-4050-b078-e68b1ae354fe_2998x688.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:688,&quot;width&quot;:2998,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:197524,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://aws-cloudsec.com/i/163952780?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F71eaf668-e351-4319-a1e3-90498e8432d8_2998x688.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!iWLU!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7363659b-1c79-4050-b078-e68b1ae354fe_2998x688.png 424w, https://substackcdn.com/image/fetch/$s_!iWLU!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7363659b-1c79-4050-b078-e68b1ae354fe_2998x688.png 848w, https://substackcdn.com/image/fetch/$s_!iWLU!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7363659b-1c79-4050-b078-e68b1ae354fe_2998x688.png 1272w, https://substackcdn.com/image/fetch/$s_!iWLU!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7363659b-1c79-4050-b078-e68b1ae354fe_2998x688.png 1456w" sizes="100vw" fetchpriority="high"></picture><div></div></div></a></figure></div></li><li><p>AWS CodeBuild added support for new IAM condition keys for more precise access control over resource-modifying APIs. These keys let you enforce policies on VPC settings, buildspecs, and compute types&#8212;helping align CodeBuild usage with organizational security and compliance standards. <a href="https://aws.amazon.com/about-aws/whats-new/2025/05/aws-codebuild-iam-condition-keys/">Link</a>. Here&#8217;s my sample policy:</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!aa-z!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6ee72c6f-d929-4f67-914e-e220118ca0e1_1672x658.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!aa-z!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6ee72c6f-d929-4f67-914e-e220118ca0e1_1672x658.png 424w, https://substackcdn.com/image/fetch/$s_!aa-z!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6ee72c6f-d929-4f67-914e-e220118ca0e1_1672x658.png 848w, https://substackcdn.com/image/fetch/$s_!aa-z!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6ee72c6f-d929-4f67-914e-e220118ca0e1_1672x658.png 1272w, https://substackcdn.com/image/fetch/$s_!aa-z!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6ee72c6f-d929-4f67-914e-e220118ca0e1_1672x658.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!aa-z!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6ee72c6f-d929-4f67-914e-e220118ca0e1_1672x658.png" width="1456" height="573" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/6ee72c6f-d929-4f67-914e-e220118ca0e1_1672x658.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:573,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:108241,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://aws-cloudsec.com/i/163952780?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6ee72c6f-d929-4f67-914e-e220118ca0e1_1672x658.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!aa-z!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6ee72c6f-d929-4f67-914e-e220118ca0e1_1672x658.png 424w, https://substackcdn.com/image/fetch/$s_!aa-z!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6ee72c6f-d929-4f67-914e-e220118ca0e1_1672x658.png 848w, https://substackcdn.com/image/fetch/$s_!aa-z!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6ee72c6f-d929-4f67-914e-e220118ca0e1_1672x658.png 1272w, https://substackcdn.com/image/fetch/$s_!aa-z!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6ee72c6f-d929-4f67-914e-e220118ca0e1_1672x658.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div></li><li><p>Amazon DynamoDB local is now generally available in AWS CloudShell. This lets you develop and test DynamoDB apps locally, at no cost, without affecting production. Just use the <code>dynamodb-local</code> alias in CloudShell; no downloads or setup needed. To run CLI commands, use <code>--endpoint-url http://localhost:8000</code>. <a href="https://aws.amazon.com/about-aws/whats-new/2025/05/dynamo-db-local-accessible-aws-cloudshell/">Link</a>.  For example, I created a DynamoDB table locally in my cloudshell using:</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!IxGw!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5a5a00b7-5209-4c19-b700-99606d4d5290_1276x846.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!IxGw!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5a5a00b7-5209-4c19-b700-99606d4d5290_1276x846.png 424w, https://substackcdn.com/image/fetch/$s_!IxGw!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5a5a00b7-5209-4c19-b700-99606d4d5290_1276x846.png 848w, https://substackcdn.com/image/fetch/$s_!IxGw!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5a5a00b7-5209-4c19-b700-99606d4d5290_1276x846.png 1272w, https://substackcdn.com/image/fetch/$s_!IxGw!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5a5a00b7-5209-4c19-b700-99606d4d5290_1276x846.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!IxGw!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5a5a00b7-5209-4c19-b700-99606d4d5290_1276x846.png" width="1276" height="846" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/5a5a00b7-5209-4c19-b700-99606d4d5290_1276x846.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:846,&quot;width&quot;:1276,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:127020,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://aws-cloudsec.com/i/163952780?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5a5a00b7-5209-4c19-b700-99606d4d5290_1276x846.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!IxGw!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5a5a00b7-5209-4c19-b700-99606d4d5290_1276x846.png 424w, https://substackcdn.com/image/fetch/$s_!IxGw!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5a5a00b7-5209-4c19-b700-99606d4d5290_1276x846.png 848w, https://substackcdn.com/image/fetch/$s_!IxGw!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5a5a00b7-5209-4c19-b700-99606d4d5290_1276x846.png 1272w, https://substackcdn.com/image/fetch/$s_!IxGw!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5a5a00b7-5209-4c19-b700-99606d4d5290_1276x846.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div></li><li><p>Amazon Inspector now links Amazon ECR images to running ECS tasks and EKS pods, helping you identify which images are actively used and to prioritize patching the most critical, in-use images. You can view image usage, last used time, and associated clusters via the Inspector console or API. Findings are updated automatically and sent to EventBridge. You can also adjust how long images are monitored after last use by setting the ECR re-scan duration. <a href="https://aws.amazon.com/about-aws/whats-new/2025/05/amazon-inspector-container-security-images/">Link</a>.  For example, here&#8217;s one of my ECR images that hasn&#8217;t been used recently and has findings:</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!IPBK!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff1ee5704-838c-4bb1-adc7-712cbecc0e3e_2564x668.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!IPBK!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff1ee5704-838c-4bb1-adc7-712cbecc0e3e_2564x668.png 424w, https://substackcdn.com/image/fetch/$s_!IPBK!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff1ee5704-838c-4bb1-adc7-712cbecc0e3e_2564x668.png 848w, https://substackcdn.com/image/fetch/$s_!IPBK!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff1ee5704-838c-4bb1-adc7-712cbecc0e3e_2564x668.png 1272w, https://substackcdn.com/image/fetch/$s_!IPBK!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff1ee5704-838c-4bb1-adc7-712cbecc0e3e_2564x668.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!IPBK!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff1ee5704-838c-4bb1-adc7-712cbecc0e3e_2564x668.png" width="2564" height="668" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/f1ee5704-838c-4bb1-adc7-712cbecc0e3e_2564x668.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:668,&quot;width&quot;:2564,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:105502,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://aws-cloudsec.com/i/163952780?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff1aa542c-dccc-4415-b346-db04127d10d9_2564x668.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!IPBK!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff1ee5704-838c-4bb1-adc7-712cbecc0e3e_2564x668.png 424w, https://substackcdn.com/image/fetch/$s_!IPBK!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff1ee5704-838c-4bb1-adc7-712cbecc0e3e_2564x668.png 848w, https://substackcdn.com/image/fetch/$s_!IPBK!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff1ee5704-838c-4bb1-adc7-712cbecc0e3e_2564x668.png 1272w, https://substackcdn.com/image/fetch/$s_!IPBK!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff1ee5704-838c-4bb1-adc7-712cbecc0e3e_2564x668.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div></li><li><p>Amazon Cognito now supports the OpenID Connect (OIDC) <code>prompt</code> parameter in Managed Login, allowing finer control over authentication flows. Apps can use <code>login</code> to force re-authentication or <code>none</code> for silent checks. Cognito also supports <code>select_account</code> and <code>consent</code> prompts for federated sign-ins. The <code>login</code> prompt lets apps require users to re-authenticate for sensitive actions without ending their session. The <code>none</code> prompt enables silent session checks, ideal for seamless single sign-on across apps using the same Cognito user pool. <a href="https://aws.amazon.com/about-aws/whats-new/2025/05/amazon-cognito-oidc-prompt-parameter/">Link</a>. </p><p></p><p></p><p></p><p></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://aws-cloudsec.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://aws-cloudsec.com/subscribe?"><span>Subscribe now</span></a></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://aws-cloudsec.com/p/issue-97?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://aws-cloudsec.com/p/issue-97?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share</span></a></p><p></p></li></ol><p></p><p></p>]]></content:encoded></item><item><title><![CDATA[Issue 96]]></title><description><![CDATA[7 days of Cloud Security, recapped in 7 minutes or less!]]></description><link>https://aws-cloudsec.com/p/issue-96</link><guid isPermaLink="false">https://aws-cloudsec.com/p/issue-96</guid><dc:creator><![CDATA[AWS-CloudSec Weekly Newsletter]]></dc:creator><pubDate>Wed, 14 May 2025 20:56:29 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F15838bce-c9b4-4b0c-b508-f95a721fd7ca_1200x1200.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p><strong>This week TLDR i.e. 1 minute version </strong>(For executives):</p><ol><li><p>Amazon GuardDuty Malware Protection for EC2 now available in AWS GovCloud (US) Regions. </p></li><li><p>Amazon VPC adds CloudTrail logging for VPC resources created by default. </p><p></p></li></ol><p><strong>Trending in Cloud &amp; Cyber Security</strong>:</p><ol><li><p>AWS Security Blogs &amp; Bulletins:</p><ul><li><p>Protect against advanced DNS threats with Amazon Route 53 Resolver DNS Firewall. <a href="https://aws.amazon.com/blogs/security/protect-against-advanced-dns-threats-with-amazon-route-53-resolver-dns-firewall/">Link</a>. </p></li><li><p>How to manage migration of hsm1.medium CloudHSM clusters to hsm2m.medium. <a href="https://aws.amazon.com/blogs/security/how-to-manage-migration-of-hsm1-medium-cloudhsm-clusters-to-hsm2m-medium/">Link</a>. </p></li><li><p>Implementing safety guardrails for applications using Amazon SageMaker. <a href="https://aws.amazon.com/blogs/security/implementing-safety-guardrails-for-applications-using-amazon-sagemaker/">Link</a>. </p></li><li><p>Monitoring and optimizing the cost of the unused access analyzer in IAM Access Analyzer. <a href="https://aws.amazon.com/blogs/security/monitoring-and-optimizing-the-cost-of-the-unused-access-analyzer-in-iam-access-analyzer/">Link</a>. </p></li><li><p>Mapping AWS security services to MITRE frameworks for threat detection and mitigation. <a href="https://aws.amazon.com/blogs/security/mapping-aws-security-services-to-mitre-frameworks-for-threat-detection-and-mitigation/">Link</a>. </p></li></ul></li><li><p>General security blogs, articles, reports &amp; trending news/advisories:</p><ul><li><p>Amazon S3 Bucket Name Squatting by Costas Kourmpoglou. <a href="https://www.reply.com/spike-reply/en/blog/s3-bucket-name-squatting">Link</a>.</p></li><li><p>The Russian Open Source Project That We Can&#8217;t Live Without. <a href="https://huntedlabs.com/the-russian-open-source-project-that-we-cant-live-without/">Link</a>. </p></li><li><p>Schedule Security Scanning with a Serverless Fanout Pattern by Rich Mogull. <a href="https://slaw.securosis.com/p/schedule-security-scanning-with-a-serverless-fanout-pattern">Link.</a> </p></li><li><p>Tales from the cloud trenches: The Attacker doth persist too much, methinks by Martin McCloskey. <a href="https://securitylabs.datadoghq.com/articles/tales-from-the-cloud-trenches-the-attacker-doth-persist-too-much/">Link</a>.</p></li><li><p>China-Nexus Nation State Actors Exploit SAP NetWeaver (CVE-2025-31324) to Target Critical Infrastructures by Arda B&#252;y&#252;kkaya. <a href="https://blog.eclecticiq.com/china-nexus-nation-state-actors-exploit-sap-netweaver-cve-2025-31324-to-target-critical-infrastructures">Link</a>. </p></li><li><p>Google Threat Intelligence: COLDRIVER Using New Malware To Steal Documents From Western Targets and NGOs. <a href="https://cloud.google.com/blog/topics/threat-intelligence/coldriver-steal-documents-western-targets-ngos">Link</a>. </p></li><li><p>FBI PSA: Cyber Criminal Proxy Services Exploiting End of Life Routers. <a href="https://www.ic3.gov/PSA/2025/PSA250507">Link</a>. </p></li><li><p>Wiz: Cloud Hunting Games. <a href="http://The Cloud Hunting Games">Link</a>. </p></li><li><p>Microsoft: Top MSRC 2025 Q1 Security Researchers. <a href="https://msrc.microsoft.com/blog/2025/05/congratulations-to-the-top-msrc-2025-q1-security-researchers/">Link</a>. </p></li><li><p>TA406 Pivots to the Front by Greg Lesnewich, Saher Naumaan, Mark Kelly. <a href="https://www.proofpoint.com/us/blog/threat-insight/ta406-pivots-front">Link</a>. </p></li><li><p>Orca Security Acquires Opus to Bring Agentic AI to CNAPP. <a href="https://orca.security/resources/blog/orca-security-acquires-opus-agentic-ai-cnapp/">Link</a>. </p></li></ul><p></p></li></ol><p><strong>This week Long i.e. 3-5 minutes version </strong>(For architects &amp; engineers):</p><ol><li><p>AWS now offers Amazon GuardDuty Malware Protection for EC2 in AWS GovCloud (US) Regions, allowing you to to detect potential malware by scanning EBS volumes attached to EC2 instances and container workloads. <a href="https://aws.amazon.com/about-aws/whats-new/2025/05/amazon-guardduty-malware-protection-ec2-aws-govcloud-us-regions/">Link</a>. Here&#8217;s my gov console.</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!i81t!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2d72a585-a1c1-4aab-8ca3-b3a00e7df1ef_2238x502.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!i81t!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2d72a585-a1c1-4aab-8ca3-b3a00e7df1ef_2238x502.png 424w, https://substackcdn.com/image/fetch/$s_!i81t!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2d72a585-a1c1-4aab-8ca3-b3a00e7df1ef_2238x502.png 848w, https://substackcdn.com/image/fetch/$s_!i81t!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2d72a585-a1c1-4aab-8ca3-b3a00e7df1ef_2238x502.png 1272w, https://substackcdn.com/image/fetch/$s_!i81t!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2d72a585-a1c1-4aab-8ca3-b3a00e7df1ef_2238x502.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!i81t!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2d72a585-a1c1-4aab-8ca3-b3a00e7df1ef_2238x502.png" width="1456" height="327" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/2d72a585-a1c1-4aab-8ca3-b3a00e7df1ef_2238x502.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:327,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:118589,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://aws-cloudsec.com/i/163552595?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2d72a585-a1c1-4aab-8ca3-b3a00e7df1ef_2238x502.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!i81t!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2d72a585-a1c1-4aab-8ca3-b3a00e7df1ef_2238x502.png 424w, https://substackcdn.com/image/fetch/$s_!i81t!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2d72a585-a1c1-4aab-8ca3-b3a00e7df1ef_2238x502.png 848w, https://substackcdn.com/image/fetch/$s_!i81t!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2d72a585-a1c1-4aab-8ca3-b3a00e7df1ef_2238x502.png 1272w, https://substackcdn.com/image/fetch/$s_!i81t!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2d72a585-a1c1-4aab-8ca3-b3a00e7df1ef_2238x502.png 1456w" sizes="100vw" fetchpriority="high"></picture><div></div></div></a></figure></div></li><li><p>Amazon VPC adds CloudTrail logging for VPC resources created by default. Previously, CloudTrail logs only captured resources explicitly created by <em>customers</em>, requiring manual tracking of default resources for audit purposes. With this update, CloudTrail now logs events related to the automatic creation or deletion of <em>default</em> resources&#8212;such as Security Groups, Network ACLs, and Route Tables&#8212;when a VPC is created or deleted. <a href="https://aws.amazon.com/about-aws/whats-new/2025/05/amazon-vpc-cloudtrail-logging-resources-default/">Link</a>. Here&#8217;s my CloudTrail for a default VPC creation:</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!m8zs!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9fd9f3e6-e8ce-4473-82cb-e2ab9e9c5ed5_1218x1224.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!m8zs!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9fd9f3e6-e8ce-4473-82cb-e2ab9e9c5ed5_1218x1224.png 424w, https://substackcdn.com/image/fetch/$s_!m8zs!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9fd9f3e6-e8ce-4473-82cb-e2ab9e9c5ed5_1218x1224.png 848w, https://substackcdn.com/image/fetch/$s_!m8zs!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9fd9f3e6-e8ce-4473-82cb-e2ab9e9c5ed5_1218x1224.png 1272w, https://substackcdn.com/image/fetch/$s_!m8zs!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9fd9f3e6-e8ce-4473-82cb-e2ab9e9c5ed5_1218x1224.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!m8zs!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9fd9f3e6-e8ce-4473-82cb-e2ab9e9c5ed5_1218x1224.png" width="1218" height="1224" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/9fd9f3e6-e8ce-4473-82cb-e2ab9e9c5ed5_1218x1224.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1224,&quot;width&quot;:1218,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:243024,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://aws-cloudsec.com/i/163552595?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0842a33f-7d52-44f0-ac1c-bc7d00993dd0_1218x1224.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!m8zs!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9fd9f3e6-e8ce-4473-82cb-e2ab9e9c5ed5_1218x1224.png 424w, https://substackcdn.com/image/fetch/$s_!m8zs!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9fd9f3e6-e8ce-4473-82cb-e2ab9e9c5ed5_1218x1224.png 848w, https://substackcdn.com/image/fetch/$s_!m8zs!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9fd9f3e6-e8ce-4473-82cb-e2ab9e9c5ed5_1218x1224.png 1272w, https://substackcdn.com/image/fetch/$s_!m8zs!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9fd9f3e6-e8ce-4473-82cb-e2ab9e9c5ed5_1218x1224.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p> </p><p></p><p></p><p></p><p></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://aws-cloudsec.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://aws-cloudsec.com/subscribe?"><span>Subscribe now</span></a></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://aws-cloudsec.com/p/issue-96?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://aws-cloudsec.com/p/issue-96?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share</span></a></p><p></p></li></ol><p></p><p></p>]]></content:encoded></item><item><title><![CDATA[Issue 95]]></title><description><![CDATA[7 days of Cloud Security, recapped in 7 minutes or less!]]></description><link>https://aws-cloudsec.com/p/issue-95</link><guid isPermaLink="false">https://aws-cloudsec.com/p/issue-95</guid><dc:creator><![CDATA[AWS-CloudSec Weekly Newsletter]]></dc:creator><pubDate>Wed, 07 May 2025 22:03:18 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F15838bce-c9b4-4b0c-b508-f95a721fd7ca_1200x1200.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p><strong>This week TLDR i.e. 1 minute version </strong>(For executives):</p><ol><li><p>Amazon Verified Permissions now supports policy store tagging. <a href="https://aws.amazon.com/about-aws/whats-new/2025/05/amazon-verified-permissions-policy-store-tagging/">Link</a>.</p></li><li><p>Amazon Cognito adds enhanced context support for machine-to-machine (M2M) authorization flows. <a href="https://aws.amazon.com/about-aws/whats-new/2025/04/amazon-cognito-context-machine-to-machine-flows/">Link</a>. </p></li><li><p>Resource control policies (RCPs) are now available in the AWS GovCloud (US) Regions. <a href="https://aws.amazon.com/about-aws/whats-new/2025/05/resource-control-policies-aws-govcloud-us-regions/">Link</a>. </p><p></p></li></ol><p><strong>Trending in Cloud &amp; Cyber Security</strong>:</p><ol><li><p>AWS Security Blogs &amp; Bulletins:</p><ul><li><p>Bulletin: CVE-2025-4318 - Input validation issue in AWS Amplify Studio UI component properties. <a href="https://aws.amazon.com/security/security-bulletins/AWS-2025-010/">Link</a>. </p></li><li><p>Use an Amazon Bedrock powered chatbot with Amazon Security Lake to help investigate incidents. <a href="https://aws.amazon.com/blogs/security/use-an-amazon-bedrock-powered-chatbot-with-amazon-security-lake-to-help-investigate-incidents/">Link</a>. </p></li><li><p>How to use AWS Transfer Family and GuardDuty for malware protection. <a href="https://aws.amazon.com/blogs/security/how-to-use-aws-transfer-family-and-guardduty-for-malware-protection/">Link</a>. </p></li></ul></li><li><p>General security blogs, articles, reports &amp; trending news/advisories:</p><ul><li><p>Why Recreating an IAM Role Doesn't Restore Trust: A Gotcha in Role ARN by Nick Frichette. <a href="https://hackingthe.cloud/aws/general-knowledge/why_recreating_an_iam_role_doesnt_restore_trust_a_gotcha_in_role_arns/">Link</a>. </p></li><li><p>CloudWatch Dashboard (Over)Sharing: How bugs in Amazon CloudWatch and Cognito allowed attackers to see beyond Dashboards by Leonidas Tsaousis. <a href="https://labs.withsecure.com/publications/cloudwatch-dashboard">Link</a>. </p></li><li><p>TheWizards APT group uses SLAAC spoofing to perform adversary-in-the-middle attacks by Facundo Mu&#241;oz. <a href="https://www.welivesecurity.com/en/eset-research/thewizards-apt-group-slaac-spoofing-adversary-in-the-middle-attacks/">Link</a>. </p></li><li><p>FBI: Phishing Domains Associated with LabHost PhaaS Platform Users. PDF <a href="https://www.ic3.gov/CSA/2025/250429.pdf">Link</a>. </p></li><li><p>Pushing passkeys forward: Microsoft&#8217;s latest updates for simpler, safer sign-ins. <a href="https://www.microsoft.com/en-us/security/blog/2025/05/01/pushing-passkeys-forward-microsofts-latest-updates-for-simpler-safer-sign-ins/">Link</a>. </p></li><li><p>Bring Your Own Installer: Bypassing SentinelOne Through Agent Version Change Interruption. <a href="https://www.aon.com/en/insights/cyber-labs/bring-your-own-installer-bypassing-sentinelone">Link</a>. </p></li><li><p>Shifty Business: Encryption in Amazon Redshift, Secure Defaults, and How to Shiftily Create Unencrypted Redshift Clusters by Jason Kao. <a href="https://www.fogsecurity.io/blog/shifty-business-redshift-encryption-aws">Link</a>. </p></li><li><p>Cloud Incident Readiness: Critical infrastructure for cloud incident response. <a href="https://www.invictus-ir.com/news/cloud-incident-readiness-critical-infrastructure-for-cloud-incident-response">Link</a>. </p></li><li><p>TrailAlerts: Take Control of Cloud Detection in AWS by Adan. <a href="https://medium.com/@adan.alvarez/trailalerts-take-control-of-cloud-detection-in-aws-9e7761f49509">Link</a>. </p></li><li><p>Presentation: Cloud Attack Emulation: Leveraging the Attacker&#8217;s Advantage for Effective Defense. <a href="https://www.infoq.com/presentations/cloud-attack-emulation/">Link</a>. </p></li><li><p>Datadog acquires Eppo. <a href="https://www.datadoghq.com/blog/datadog-acquires-eppo/">Link</a>. </p></li></ul></li></ol><p></p><p><strong>This week Long i.e. 3-5 minutes version </strong>(For architects &amp; engineers):</p><ol><li><p>Amazon Verified Permissions now supports tagging of Policy Stores, enabling tag-based IAM access control and cost allocation. You can restrict access using tags (e.g., by tenant) and leverage cost allocation tags for chargeback. Tagging also improves policy store discoverability in the console. <a href="https://aws.amazon.com/about-aws/whats-new/2025/05/amazon-verified-permissions-policy-store-tagging/">Link</a>. Here&#8217;s my sample CLI for tagging:</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!yNjh!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcf19c10a-5718-44ec-8be7-98d8f2dfd211_1548x362.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!yNjh!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcf19c10a-5718-44ec-8be7-98d8f2dfd211_1548x362.png 424w, https://substackcdn.com/image/fetch/$s_!yNjh!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcf19c10a-5718-44ec-8be7-98d8f2dfd211_1548x362.png 848w, https://substackcdn.com/image/fetch/$s_!yNjh!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcf19c10a-5718-44ec-8be7-98d8f2dfd211_1548x362.png 1272w, https://substackcdn.com/image/fetch/$s_!yNjh!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcf19c10a-5718-44ec-8be7-98d8f2dfd211_1548x362.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!yNjh!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcf19c10a-5718-44ec-8be7-98d8f2dfd211_1548x362.png" width="1548" height="362" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/cf19c10a-5718-44ec-8be7-98d8f2dfd211_1548x362.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:362,&quot;width&quot;:1548,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:228958,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://aws-cloudsec.com/i/162908306?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd307112d-d781-4675-82dd-bd46b9b8e279_1548x362.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!yNjh!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcf19c10a-5718-44ec-8be7-98d8f2dfd211_1548x362.png 424w, https://substackcdn.com/image/fetch/$s_!yNjh!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcf19c10a-5718-44ec-8be7-98d8f2dfd211_1548x362.png 848w, https://substackcdn.com/image/fetch/$s_!yNjh!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcf19c10a-5718-44ec-8be7-98d8f2dfd211_1548x362.png 1272w, https://substackcdn.com/image/fetch/$s_!yNjh!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcf19c10a-5718-44ec-8be7-98d8f2dfd211_1548x362.png 1456w" sizes="100vw" fetchpriority="high"></picture><div></div></div></a></figure></div></li><li><p>Amazon Cognito now supports passing custom context in OAuth 2.0 client credentials flow, letting you tailor M2M access tokens based on details like environment or app name. Use <code>ClientMetadata</code> with Lambda triggers to adjust scopes and claims for better access control and rate limiting. <a href="https://aws.amazon.com/about-aws/whats-new/2025/04/amazon-cognito-context-machine-to-machine-flows/">Link</a>. </p></li><li><p>Resource control policies (RCPs) are now available in the AWS GovCloud (US) Regions. <a href="https://aws.amazon.com/about-aws/whats-new/2025/05/resource-control-policies-aws-govcloud-us-regions/">Link</a>. I see that option in my Gov AWS console now:</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!FRcu!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb373bd77-5a04-480a-8061-597c6c0050e2_2704x416.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!FRcu!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb373bd77-5a04-480a-8061-597c6c0050e2_2704x416.png 424w, https://substackcdn.com/image/fetch/$s_!FRcu!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb373bd77-5a04-480a-8061-597c6c0050e2_2704x416.png 848w, https://substackcdn.com/image/fetch/$s_!FRcu!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb373bd77-5a04-480a-8061-597c6c0050e2_2704x416.png 1272w, https://substackcdn.com/image/fetch/$s_!FRcu!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb373bd77-5a04-480a-8061-597c6c0050e2_2704x416.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!FRcu!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb373bd77-5a04-480a-8061-597c6c0050e2_2704x416.png" width="1456" height="224" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/b373bd77-5a04-480a-8061-597c6c0050e2_2704x416.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:224,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:156757,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://aws-cloudsec.com/i/162908306?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb373bd77-5a04-480a-8061-597c6c0050e2_2704x416.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!FRcu!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb373bd77-5a04-480a-8061-597c6c0050e2_2704x416.png 424w, https://substackcdn.com/image/fetch/$s_!FRcu!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb373bd77-5a04-480a-8061-597c6c0050e2_2704x416.png 848w, https://substackcdn.com/image/fetch/$s_!FRcu!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb373bd77-5a04-480a-8061-597c6c0050e2_2704x416.png 1272w, https://substackcdn.com/image/fetch/$s_!FRcu!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb373bd77-5a04-480a-8061-597c6c0050e2_2704x416.png 1456w" sizes="100vw" fetchpriority="high"></picture><div></div></div></a></figure></div><p> </p><p></p><p></p><p></p><p></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://aws-cloudsec.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://aws-cloudsec.com/subscribe?"><span>Subscribe now</span></a></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://aws-cloudsec.com/p/issue-95?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://aws-cloudsec.com/p/issue-95?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share</span></a></p><p></p></li></ol><p></p><p></p>]]></content:encoded></item><item><title><![CDATA[Issue 94]]></title><description><![CDATA[7 days of Cloud Security, recapped in 7 minutes or less!]]></description><link>https://aws-cloudsec.com/p/issue-94</link><guid isPermaLink="false">https://aws-cloudsec.com/p/issue-94</guid><dc:creator><![CDATA[AWS-CloudSec Weekly Newsletter]]></dc:creator><pubDate>Tue, 29 Apr 2025 21:11:40 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F15838bce-c9b4-4b0c-b508-f95a721fd7ca_1200x1200.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p><strong>This week TLDR i.e. 1 minute version </strong>(For executives):</p><ol><li><p>Automated HTTP validated public certificates with Amazon CloudFront. </p></li><li><p>Amazon Cognito now supports refresh token rotation. </p></li><li><p>Amazon EBS now supports additional resource-level permissions for copying EBS snapshots.</p></li><li><p>AWS Account Management now supports IAM-based account name updates.  </p><p></p></li></ol><p><strong>Trending in Cloud &amp; Cyber Security</strong>:</p><ol><li><p>AWS Security Blogs &amp; Bulletins:</p><ul><li><p>How to import existing AWS Organizations SCPs and RCPs to CloudFormation. <a href="https://aws.amazon.com/blogs/security/how-to-import-existing-aws-organizations-scps-and-rcps-to-cloudformation/">Link</a>. </p></li></ul></li><li><p>General security blogs, articles, reports &amp; trending news/advisories:</p><ul><li><p>Top Tier Target: What it takes to defend a cybersecurity company from today&#8217;s adversaries by Tom Hegel, Aleksandar Milenkoski &amp; Jim Walter. <a href="https://www.sentinelone.com/labs/top-tier-target-what-it-takes-to-defend-a-cybersecurity-company-from-todays-adversaries/">Link</a>. </p></li><li><p>Phishing for Codes: Russian Threat Actors Target Microsoft 365 OAuth Workflows by Charlie Gardner, Josh Duke, Matthew Meltzer, Sean Koessel, Steven Adair, Tom Lancaster. <a href="https://www.volexity.com/blog/2025/04/22/phishing-for-codes-russian-threat-actors-target-microsoft-365-oauth-workflows/">Link</a>.</p></li><li><p>FBI Releases Annual Internet Crime Report. <a href="https://www.ic3.gov/AnnualReport/Reports/2024_IC3Report.pdf">Link</a>. </p></li><li><p>How the April 28, 2025, power outage in Portugal and Spain impacted Internet traffic and connectivity by David Belson. <a href="https://blog.cloudflare.com/how-power-outage-in-portugal-spain-impacted-internet/">Link</a>. </p></li><li><p>WhatsApp advanced chat privacy feature. <a href="https://blog.whatsapp.com/introducing-advanced-chat-privacy">Link</a>. </p></li><li><p>Mandiant M-Trends 2025 report. <a href="https://services.google.com/fh/files/misc/m-trends-2025-en.pdf">Link</a>. </p></li><li><p>Operation SyncHole: Lazarus APT goes back to the well by Sojun Ryu,</p><p>Vasily Berdnikov. <a href="https://securelist.com/operation-synchole-watering-hole-attacks-by-lazarus/116326/">Link</a>. </p></li><li><p>Palo Alto Networks Announces Intent to Acquire Protect AI, a Game-Changing Security for AI Company. <a href="https://www.paloaltonetworks.com/company/press/2025/palo-alto-networks-announces-intent-to-acquire-protect-ai--a-game-changing-security-for-ai-company">Link</a>. </p></li><li><p>Hello 0-Days, My Old Friend: A 2024 Zero-Day Exploitation Analysis by Google Threat Intelligence Group. <a href="https://cloud.google.com/blog/topics/threat-intelligence/2024-zero-day-trends">Link</a>. </p></li><li><p>Phantom DNS Query to GCP VM Metadata Service in My AWS Workload Revealed by Route 53 Resolver Logging by Gabriel Ko. <a href="https://dev.to/aws-builders/phantom-dns-query-to-gcp-vm-metadata-service-in-my-aws-workload-revealed-by-route-53-resolver-3c75">Link</a>. </p></li><li><p>Datadog: State of DevSecOps report. <a href="https://www.datadoghq.com/state-of-devsecops/">Link</a>. </p></li><li><p>An open letter to third-party suppliers by Patrick Opet, Chief Information Security Officer. <a href="https://www.jpmorgan.com/technology/technology-blog/open-letter-to-our-suppliers">Link</a>.  </p></li><li><p>Shadow Roles: AWS Defaults Can Open the Door to Service Takeover</p><p>Security Threat, Yakir KadkodaOfek Itach. <a href="https://www.aquasec.com/blog/shadow-roles-aws-defaults-lead-to-service-takeover/">Link</a>. </p></li></ul></li></ol><p><strong>This week Long i.e. 3-5 minutes version </strong>(For architects &amp; engineers):</p><ol><li><p>AWS Certificate Manager (ACM) now offers automated public TLS certificates for Amazon CloudFront. Customers can simply check a box to have ACM automatically request, issue, associate, and renew certificates for their CloudFront distributions, streamlining the setup of secure applications. Manual certificate management remains an option. <a href="https://aws.amazon.com/about-aws/whats-new/2025/04/automated-http-validated-public-certificates-amazon-cloudfront/">Link</a>. </p></li><li><p>Amazon Cognito now supports OAuth 2.0 refresh token rotation for user pool clients. This feature enhances security by automatically replacing refresh tokens at regular intervals, limiting the risk of token compromise, while maintaining access without requiring re-authentication for users. <a href="https://aws.amazon.com/about-aws/whats-new/2025/04/amazon-cognito-refresh-token-rotation/">Link</a>. Here&#8217;s my config:</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!7t7a!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa3c1262f-d596-4384-9d4e-e1179c02fe82_1806x458.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!7t7a!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa3c1262f-d596-4384-9d4e-e1179c02fe82_1806x458.png 424w, https://substackcdn.com/image/fetch/$s_!7t7a!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa3c1262f-d596-4384-9d4e-e1179c02fe82_1806x458.png 848w, https://substackcdn.com/image/fetch/$s_!7t7a!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa3c1262f-d596-4384-9d4e-e1179c02fe82_1806x458.png 1272w, https://substackcdn.com/image/fetch/$s_!7t7a!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa3c1262f-d596-4384-9d4e-e1179c02fe82_1806x458.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!7t7a!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa3c1262f-d596-4384-9d4e-e1179c02fe82_1806x458.png" width="1456" height="369" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/a3c1262f-d596-4384-9d4e-e1179c02fe82_1806x458.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:369,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:112876,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://aws-cloudsec.com/i/162359744?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa3c1262f-d596-4384-9d4e-e1179c02fe82_1806x458.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!7t7a!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa3c1262f-d596-4384-9d4e-e1179c02fe82_1806x458.png 424w, https://substackcdn.com/image/fetch/$s_!7t7a!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa3c1262f-d596-4384-9d4e-e1179c02fe82_1806x458.png 848w, https://substackcdn.com/image/fetch/$s_!7t7a!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa3c1262f-d596-4384-9d4e-e1179c02fe82_1806x458.png 1272w, https://substackcdn.com/image/fetch/$s_!7t7a!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa3c1262f-d596-4384-9d4e-e1179c02fe82_1806x458.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div></li><li><p>Amazon EBS now supports additional resource-level permissions for copying snapshots with more granular control over who can perform copy operations. You can also apply six EC2-specific condition keys&#8212;such as <code>ec2:Encrypted</code> and <code>ec2:VolumeSize</code>&#8212;plus global condition keys to fine-tune access permissions for the CopySnapshot actions. <a href="https://aws.amazon.com/about-aws/whats-new/2025/04/amazon-ebs-additional-resource-level-permissions-copying-eb-snapshots/">Link</a>.  Well explained in <a href="https://aws.amazon.com/blogs/storage/enhancing-resource-level-permissions-for-copying-amazon-ebs-snapshots/">THIS</a> blog. You can use the script in the git to analyze your existing IAM policies. <a href="https://github.com/awslabs/amazon-ebs-permission-analyzer">GitHub Link</a>. </p></li><li><p>AWS launched a new account management API that allows you to update account names using authorized IAM principals&#8212;no root access required. AWS Organizations customers can now centrally manage account names across their organization using the management or delegated admin accounts. The API is also available through the AWS CLI and SDK. <a href="https://aws.amazon.com/about-aws/whats-new/2025/04/aws-account-management-iam-based-name-updates/">Link</a>.  Please note that management account can only be managed using the standalone context from the management account. Here is my sample CLI:</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!PFuj!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F76ca76a9-c719-402f-a231-4f03bbaa7a84_2098x122.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!PFuj!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F76ca76a9-c719-402f-a231-4f03bbaa7a84_2098x122.png 424w, https://substackcdn.com/image/fetch/$s_!PFuj!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F76ca76a9-c719-402f-a231-4f03bbaa7a84_2098x122.png 848w, https://substackcdn.com/image/fetch/$s_!PFuj!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F76ca76a9-c719-402f-a231-4f03bbaa7a84_2098x122.png 1272w, https://substackcdn.com/image/fetch/$s_!PFuj!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F76ca76a9-c719-402f-a231-4f03bbaa7a84_2098x122.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!PFuj!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F76ca76a9-c719-402f-a231-4f03bbaa7a84_2098x122.png" width="2098" height="122" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/76ca76a9-c719-402f-a231-4f03bbaa7a84_2098x122.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:122,&quot;width&quot;:2098,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:102438,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://aws-cloudsec.com/i/162359744?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe559f08b-e9da-489e-8d83-dc5b3982ed54_2098x122.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!PFuj!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F76ca76a9-c719-402f-a231-4f03bbaa7a84_2098x122.png 424w, https://substackcdn.com/image/fetch/$s_!PFuj!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F76ca76a9-c719-402f-a231-4f03bbaa7a84_2098x122.png 848w, https://substackcdn.com/image/fetch/$s_!PFuj!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F76ca76a9-c719-402f-a231-4f03bbaa7a84_2098x122.png 1272w, https://substackcdn.com/image/fetch/$s_!PFuj!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F76ca76a9-c719-402f-a231-4f03bbaa7a84_2098x122.png 1456w" sizes="100vw" fetchpriority="high"></picture><div></div></div></a></figure></div><p> </p><p></p><p></p><p></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://aws-cloudsec.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://aws-cloudsec.com/subscribe?"><span>Subscribe now</span></a></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://aws-cloudsec.com/p/issue-94?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://aws-cloudsec.com/p/issue-94?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share</span></a></p><p></p></li></ol><p></p><p></p>]]></content:encoded></item><item><title><![CDATA[Issue 93]]></title><description><![CDATA[7 days of Cloud Security, recapped in 7 minutes or less!]]></description><link>https://aws-cloudsec.com/p/issue-93</link><guid isPermaLink="false">https://aws-cloudsec.com/p/issue-93</guid><dc:creator><![CDATA[AWS-CloudSec Weekly Newsletter]]></dc:creator><pubDate>Tue, 22 Apr 2025 21:05:31 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F15838bce-c9b4-4b0c-b508-f95a721fd7ca_1200x1200.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p><strong>This week TLDR i.e. 1 minute version </strong>(For executives):</p><ol><li><p>AWS STS global endpoint now serves requests locally in regions enabled by default. </p></li><li><p>Amazon Verified Permissions now supports policy store deletion protection. </p></li><li><p>AWS Security Incident Response now supports integration with AWS PrivateLink.</p></li><li><p>Amazon SES now supports logging email sending events through AWS CloudTrail. </p><p></p></li></ol><p><strong>Trending in Cloud &amp; Cyber Security</strong>:</p><ol><li><p>AWS Security Blogs &amp; Bulletins:</p><ul><li><p>Bulletin: CVE-2025-3857 - Infinite loop condition in Amazon.IonDotnet. <a href="https://aws.amazon.com/security/security-bulletins/AWS-2025-009/">Link</a>. </p></li><li><p>How to help prevent hotlinking using referer checking, AWS WAF, and Amazon CloudFront. <a href="https://aws.amazon.com/blogs/security/how-to-prevent-hotlinking-by-using-aws-waf-amazon-cloudfront-and-referer-checking/">Link</a>. </p></li><li><p>How to support OpenID AuthZEN requests with Amazon Verified Permissions. <a href="https://aws.amazon.com/blogs/security/how-to-support-openid-authzen-requests-with-amazon-verified-permissions/">Link</a>. </p></li></ul></li><li><p>General security blogs, articles, reports &amp; trending news/advisories:</p><ul><li><p>How to measure Well-Architected maturity? <a href="https://hedrange.com/2025/04/15/how-to-measure-well-architected-maturity/">Link</a>. </p></li><li><p>CheatSheet: Amazon S3 Ransomware attack. <a href="https://cybr.com/mp-files/amazon-s3-ransomware-attacks-cheat-sheet.jpg/">Link</a>. </p></li><li><p>Secure Cross-Account Access is Tricky. Four Common Dangerous Misconceptions by Eliav Livneh. <a href="https://www.token.security/blog/secure-cross-account-access-is-tricky-four-common-dangerous-misconceptions?">Link</a>. </p></li><li><p>CVE Foundation Launched to Secure the Future of the CVE Program. <a href="https://www.thecvefoundation.org/home">Link</a>. </p></li><li><p>BPFDoor&#8217;s Hidden Controller Used Against Asia, Middle East Targets by Fernando Merc&#234;s. <a href="https://www.trendmicro.com/en_us/research/25/d/bpfdoor-hidden-controller.html">Link</a>. </p></li><li><p>Google: update on use of country code top-level domains. <a href="https://blog.google/products/search/country-code-top-level-domains/">Link</a>. </p></li><li><p>CISA Releases Guidance on Credential Risks Associated with Potential Legacy Oracle Cloud Compromise. <a href="https://www.cisa.gov/news-events/alerts/2025/04/16/cisa-releases-guidance-credential-risks-associated-potential-legacy-oracle-cloud-compromise">Link</a>. </p></li><li><p>Latest Mustang Panda Arsenal: PAKLOG, CorKLOG, and SplatCloak by Sudeep Singh. <a href="https://www.zscaler.com/blogs/security-research/latest-mustang-panda-arsenal-paklog-corklog-and-splatcloak-p2#introduction">Link</a>.</p></li><li><p>30+ hidden browser extensions put 4million users at risk of cookie theft by </p><p>John Tuckner. <a href="https://secureannex.com/blog/searching-for-something-unknow/">Link</a>.</p></li><li><p>Cisco Webex App Client-Side Remote Code Execution Vulnerability. <a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-webex-app-client-rce-ufyMMYLC">Link</a>. </p></li><li><p>Tool: Know Your Enemies: Identify third-party vendors with access to your resources. <a href="https://github.com/zoph-io/kye">GitHub Link</a>. </p><p></p></li></ul></li></ol><p><strong>This week Long i.e. 3-5 minutes version </strong>(For architects &amp; engineers):</p><ol><li><p>AWS Security Token Service (STS) now routes all requests to the global endpoint (<code>sts.amazonaws.com</code>) through the same AWS Region as your workloads, improving both latency and fault isolation. Previously served exclusively from US East (N. Virginia), requests are now handled locally&#8212;for example, applications in US West (Oregon) will have their STS calls processed within that Region. <a href="https://aws.amazon.com/about-aws/whats-new/2025/04/aws-sts-global-endpoint-requests-locally-regions-default/">Link</a>. More details @ <a href="https://aws.amazon.com/blogs/security/announcing-upcoming-changes-to-the-aws-security-token-service-global-endpoint/">HERE</a>. For example, this is my CloudTrail logs for my STS request with the details:</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!2jew!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F13b159de-e0cb-48a9-92f2-825cf887f54f_1362x170.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!2jew!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F13b159de-e0cb-48a9-92f2-825cf887f54f_1362x170.png 424w, https://substackcdn.com/image/fetch/$s_!2jew!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F13b159de-e0cb-48a9-92f2-825cf887f54f_1362x170.png 848w, https://substackcdn.com/image/fetch/$s_!2jew!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F13b159de-e0cb-48a9-92f2-825cf887f54f_1362x170.png 1272w, https://substackcdn.com/image/fetch/$s_!2jew!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F13b159de-e0cb-48a9-92f2-825cf887f54f_1362x170.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!2jew!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F13b159de-e0cb-48a9-92f2-825cf887f54f_1362x170.png" width="1362" height="170" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/13b159de-e0cb-48a9-92f2-825cf887f54f_1362x170.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:170,&quot;width&quot;:1362,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:36480,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://aws-cloudsec.com/i/161892964?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F13b159de-e0cb-48a9-92f2-825cf887f54f_1362x170.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!2jew!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F13b159de-e0cb-48a9-92f2-825cf887f54f_1362x170.png 424w, https://substackcdn.com/image/fetch/$s_!2jew!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F13b159de-e0cb-48a9-92f2-825cf887f54f_1362x170.png 848w, https://substackcdn.com/image/fetch/$s_!2jew!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F13b159de-e0cb-48a9-92f2-825cf887f54f_1362x170.png 1272w, https://substackcdn.com/image/fetch/$s_!2jew!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F13b159de-e0cb-48a9-92f2-825cf887f54f_1362x170.png 1456w" sizes="100vw" fetchpriority="high"></picture><div></div></div></a></figure></div></li><li><p>You can now enable deletion protection for Amazon Verified Permissions policy stores to prevent them from being deleted by any user. Deletion protection is enabled by default for new policy stores created via the AWS Console. You can turn it on or off using the AWS Console, CLI, or API. To delete a protected policy store, you must first explicitly disable deletion protection. <a href="https://aws.amazon.com/about-aws/whats-new/2025/04/amazon-verified-permissions-policy-store-deletion-protection/">Link</a>. Here&#8217;s my option on the Verified Permissions console:</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Hqfo!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff88ac333-fb54-469d-83a6-1bf578ff025e_1846x268.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Hqfo!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff88ac333-fb54-469d-83a6-1bf578ff025e_1846x268.png 424w, https://substackcdn.com/image/fetch/$s_!Hqfo!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff88ac333-fb54-469d-83a6-1bf578ff025e_1846x268.png 848w, https://substackcdn.com/image/fetch/$s_!Hqfo!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff88ac333-fb54-469d-83a6-1bf578ff025e_1846x268.png 1272w, https://substackcdn.com/image/fetch/$s_!Hqfo!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff88ac333-fb54-469d-83a6-1bf578ff025e_1846x268.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Hqfo!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff88ac333-fb54-469d-83a6-1bf578ff025e_1846x268.png" width="1456" height="211" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/f88ac333-fb54-469d-83a6-1bf578ff025e_1846x268.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:211,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:36069,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://aws-cloudsec.com/i/161892964?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff88ac333-fb54-469d-83a6-1bf578ff025e_1846x268.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!Hqfo!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff88ac333-fb54-469d-83a6-1bf578ff025e_1846x268.png 424w, https://substackcdn.com/image/fetch/$s_!Hqfo!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff88ac333-fb54-469d-83a6-1bf578ff025e_1846x268.png 848w, https://substackcdn.com/image/fetch/$s_!Hqfo!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff88ac333-fb54-469d-83a6-1bf578ff025e_1846x268.png 1272w, https://substackcdn.com/image/fetch/$s_!Hqfo!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff88ac333-fb54-469d-83a6-1bf578ff025e_1846x268.png 1456w" sizes="100vw" fetchpriority="high"></picture><div></div></div></a></figure></div></li><li><p>AWS introduced AWS Security Incident Response integration with AWS PrivateLink, allowing managing service access directly from within their Amazon VPC, without exposing traffic to the public internet, enhancing security during the handling and recovery of sensitive incidents. <a href="https://aws.amazon.com/about-aws/whats-new/2025/04/aws-security-incident-response-integration-privatelink/">Link</a>. </p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!N7WQ!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fca074055-67b6-4b51-9ff2-5ae93a5f4767_2470x292.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!N7WQ!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fca074055-67b6-4b51-9ff2-5ae93a5f4767_2470x292.png 424w, https://substackcdn.com/image/fetch/$s_!N7WQ!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fca074055-67b6-4b51-9ff2-5ae93a5f4767_2470x292.png 848w, https://substackcdn.com/image/fetch/$s_!N7WQ!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fca074055-67b6-4b51-9ff2-5ae93a5f4767_2470x292.png 1272w, https://substackcdn.com/image/fetch/$s_!N7WQ!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fca074055-67b6-4b51-9ff2-5ae93a5f4767_2470x292.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!N7WQ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fca074055-67b6-4b51-9ff2-5ae93a5f4767_2470x292.png" width="1456" height="172" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/ca074055-67b6-4b51-9ff2-5ae93a5f4767_2470x292.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:172,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:69248,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://aws-cloudsec.com/i/161892964?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fca074055-67b6-4b51-9ff2-5ae93a5f4767_2470x292.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!N7WQ!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fca074055-67b6-4b51-9ff2-5ae93a5f4767_2470x292.png 424w, https://substackcdn.com/image/fetch/$s_!N7WQ!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fca074055-67b6-4b51-9ff2-5ae93a5f4767_2470x292.png 848w, https://substackcdn.com/image/fetch/$s_!N7WQ!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fca074055-67b6-4b51-9ff2-5ae93a5f4767_2470x292.png 1272w, https://substackcdn.com/image/fetch/$s_!N7WQ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fca074055-67b6-4b51-9ff2-5ae93a5f4767_2470x292.png 1456w" sizes="100vw" fetchpriority="high"></picture><div></div></div></a></figure></div></li><li><p>Amazon Simple Email Service (SES) now supports logging email sending events directly to AWS CloudTrail (data events). You can track actions taken via the SES APIs by users, roles, or AWS services. This eliminates the need for custom-built solutions to store and manage event data, offering a built-in, searchable, and downloadable event history for easier integration into existing workflows. <a href="https://aws.amazon.com/about-aws/whats-new/2025/04/amazon-ses-logging-email-sending-events-aws-cloudtrail/">Link</a>. Here&#8217;s my CloudTrail for an event, although a lot of details are hidden. (Please Note: Email sending activity via SES SMTP Interface is not logged to CloudTrail events).</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!GPm1!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7d670b18-4d36-4d6d-850e-337db73088ae_2490x1488.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!GPm1!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7d670b18-4d36-4d6d-850e-337db73088ae_2490x1488.png 424w, https://substackcdn.com/image/fetch/$s_!GPm1!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7d670b18-4d36-4d6d-850e-337db73088ae_2490x1488.png 848w, https://substackcdn.com/image/fetch/$s_!GPm1!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7d670b18-4d36-4d6d-850e-337db73088ae_2490x1488.png 1272w, https://substackcdn.com/image/fetch/$s_!GPm1!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7d670b18-4d36-4d6d-850e-337db73088ae_2490x1488.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!GPm1!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7d670b18-4d36-4d6d-850e-337db73088ae_2490x1488.png" width="2490" height="1488" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/7d670b18-4d36-4d6d-850e-337db73088ae_2490x1488.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1488,&quot;width&quot;:2490,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:373144,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://aws-cloudsec.com/i/161892964?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0d43c843-1534-450a-a309-45bf037a6e34_2490x1488.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!GPm1!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7d670b18-4d36-4d6d-850e-337db73088ae_2490x1488.png 424w, https://substackcdn.com/image/fetch/$s_!GPm1!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7d670b18-4d36-4d6d-850e-337db73088ae_2490x1488.png 848w, https://substackcdn.com/image/fetch/$s_!GPm1!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7d670b18-4d36-4d6d-850e-337db73088ae_2490x1488.png 1272w, https://substackcdn.com/image/fetch/$s_!GPm1!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7d670b18-4d36-4d6d-850e-337db73088ae_2490x1488.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p> </p><p></p><p></p><p></p><p></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://aws-cloudsec.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://aws-cloudsec.com/subscribe?"><span>Subscribe now</span></a></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://aws-cloudsec.com/p/issue-93?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://aws-cloudsec.com/p/issue-93?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share</span></a></p><p></p></li></ol><p></p><p></p>]]></content:encoded></item><item><title><![CDATA[Issue 92]]></title><description><![CDATA[7 days of Cloud Security, recapped in 7 minutes or less!]]></description><link>https://aws-cloudsec.com/p/issue-92</link><guid isPermaLink="false">https://aws-cloudsec.com/p/issue-92</guid><dc:creator><![CDATA[AWS-CloudSec Weekly Newsletter]]></dc:creator><pubDate>Tue, 15 Apr 2025 21:30:35 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F15838bce-c9b4-4b0c-b508-f95a721fd7ca_1200x1200.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p><strong>This week TLDR i.e. 1 minute version </strong>(For executives):</p><ol><li><p>AWS Control Tower now has 223 new AWS Config rules. </p></li><li><p>IAM Identity Center releases new SDK plugin to streamline token exchange with an external Identity Provider. </p><p></p></li></ol><p><strong>Trending in Cloud &amp; Cyber Security</strong>:</p><ol><li><p>AWS Security Blogs &amp; Bulletins:</p><ul><li><p>Enhanced Network Security Control: Flow Management with AWS Network Firewall. <a href="https://aws.amazon.com/blogs/security/enhanced-network-security-control-flow-management-with-aws-network-firewall/">Link</a>. </p></li><li><p>Automating AWS Private CA audit reports and certificate expiration alerts. <a href="https://aws.amazon.com/blogs/security/automating-aws-private-ca-audit-reports-and-certificate-expiration-alerts/">Link</a>. </p></li></ul></li><li><p>General security blogs, articles, reports &amp; trending news/advisories:</p><ul><li><p>IAM Role Trust Policies: Misconfigurations Hiding in Plain Sight by Eliav Livneh. <a href="https://www.token.security/blog/iam-role-trust-policies-misconfigurations-hiding-in-plain-sight">Link</a>. </p></li><li><p>Campaign Targets Amazon EC2 Instance Metadata via SSRF by Merlyn Albery-Speyer. <a href="https://www.f5.com/labs/articles/threat-intelligence/campaign-targets-amazon-ec2-instance-metadata-via-ssrf">Link</a>. </p></li><li><p>Gaining Long-Term AWS Access with CodeBuild and GitHub by Adan. <a href="https://medium.com/@adan.alvarez/gaining-long-term-aws-access-with-codebuild-and-github-873324638784">Link</a>. </p></li><li><p>The Future of Cloud &amp; Security Operations: Analyzing PANW&#8217;s Cortex Cloud Bet by Francis Odum. <a href="https://softwareanalyst.substack.com/p/the-future-of-cloud-and-security">Link</a>. </p></li></ul></li></ol><p></p><p><strong>This week Long i.e. 3-5 minutes version </strong>(For architects &amp; engineers):</p><ol><li><p>AWS Control Tower now supports 223 additional managed Config rules in the Control Catalog, covering use cases such as security, cost optimization, durability, and operations. This update allows you to search, discover, enable, and manage these new rules directly within AWS Control Tower, enabling broader governance across your multi-account environment. <a href="https://aws.amazon.com/about-aws/whats-new/2025/04/new-aws-config-rules-control-tower/">Link</a>. </p></li><li><p>IAM Identity Center has introduced a new SDK plugin that streamlines AWS resource authorization for applications using external identity providers (IdPs) like Microsoft EntraID, Okta, and others. Supporting trusted identity propagation (TIP), the plugin simplifies the process of exchanging external IdP tokens for IAM Identity Center tokens. These tokens enable fine-grained access to AWS resources&#8212;such as Amazon S3&#8212;based on user and group memberships defined in the external IdP. <a href="https://aws.amazon.com/about-aws/whats-new/2025/04/iam-identity-center-sdk-plugin-streamline-token-exchange-external-identity-provider/">Link</a>. </p><p></p><p></p><p></p><p></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://aws-cloudsec.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://aws-cloudsec.com/subscribe?"><span>Subscribe now</span></a></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://aws-cloudsec.com/p/issue-92?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://aws-cloudsec.com/p/issue-92?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share</span></a></p><p></p></li></ol><p></p><p></p>]]></content:encoded></item><item><title><![CDATA[Issue 91]]></title><description><![CDATA[7 days of Cloud Security, recapped in 7 minutes or less!]]></description><link>https://aws-cloudsec.com/p/issue-91</link><guid isPermaLink="false">https://aws-cloudsec.com/p/issue-91</guid><dc:creator><![CDATA[AWS-CloudSec Weekly Newsletter]]></dc:creator><pubDate>Tue, 08 Apr 2025 21:33:33 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F15838bce-c9b4-4b0c-b508-f95a721fd7ca_1200x1200.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p><strong>This week TLDR i.e. 1 minute version </strong>(For executives):</p><ol><li><p>Amazon Security Lake now supports Internet Protocol Version 6 (IPv6). </p></li><li><p>AWS CDK L2 Construct for Amazon Cognito Identity Pools now generally available.</p></li><li><p>IAM Identity Center extends sessions and TIP management capabilities for customers with Microsoft AD. </p></li><li><p>Amazon Security Lake achieves FedRamp High and Moderate authorization. </p><p></p></li></ol><p><strong>Trending in Cloud &amp; Cyber Security</strong>:</p><ol><li><p>AWS Security Blogs &amp; Bulletins:</p><ul><li><p>ML-KEM post-quantum TLS now supported in AWS KMS, ACM, and Secrets Manager. <a href="https://aws.amazon.com/blogs/security/ml-kem-post-quantum-tls-now-supported-in-aws-kms-acm-and-secrets-manager/">Link</a>. </p></li><li><p>Planning for your IAM Roles Anywhere deployment. <a href="https://aws.amazon.com/blogs/security/planning-for-your-iam-roles-anywhere-deployment/">Link</a>. </p></li></ul></li><li><p>General security blogs, articles, reports &amp; trending news/advisories:</p><ul><li><p>Path Traversal Vulnerability in AWS SSM Agent's Plugin ID Validation by Elad Beber. <a href="https://cymulate.com/blog/aws-ssm-agent-plugin-id-path-traversal/">Link</a>. </p></li><li><p>Tool: The STS OIDC Driver: request temporary AWS security credentials for an IAM role, using ID tokens, from your OpenID Connect(OIDC) provider. <a href="https://github.com/awslabs/StsOidcDriver">GitHub Link</a>. </p></li><li><p>OH-MY-DC: OIDC Misconfigurations in CI/CD by Aviad Hahami. <a href="https://unit42.paloaltonetworks.com/oidc-misconfigurations-in-ci-cd/">Link</a>. </p></li><li><p>The Complexity of Detecting Amazon S3 and KMS Ransomware by Jason Kao. <a href="https://www.fogsecurity.io/blog/how-to-detect-amazon-s3-ransomware">Link</a>. </p></li><li><p>Google Threat Intelligence: DPRK IT Workers Expanding in Scope and Scale. <a href="https://cloud.google.com/blog/topics/threat-intelligence/dprk-it-workers-expanding-scope-scale">Link</a>. </p></li><li><p>Verizon: Hacking call records of million of Americans by Evan Connelly. <a href="https://evanconnelly.github.io/post/hacking-call-records/">Link</a>. </p></li></ul><p></p></li></ol><p><strong>This week Long i.e. 3-5 minutes version </strong>(For architects &amp; engineers):</p><ol><li><p>Amazon Security Lake now supports Internet Protocol version 6 (IPv6) through new dual-stack endpoints. <a href="https://aws.amazon.com/about-aws/whats-new/2025/04/amazon-security-lake-internet-protocol-version-6/">Link</a>. For example, here&#8217;s my option:</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!wB8G!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4830068c-589f-4730-b445-053799bcf7b3_1888x890.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!wB8G!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4830068c-589f-4730-b445-053799bcf7b3_1888x890.png 424w, https://substackcdn.com/image/fetch/$s_!wB8G!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4830068c-589f-4730-b445-053799bcf7b3_1888x890.png 848w, https://substackcdn.com/image/fetch/$s_!wB8G!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4830068c-589f-4730-b445-053799bcf7b3_1888x890.png 1272w, https://substackcdn.com/image/fetch/$s_!wB8G!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4830068c-589f-4730-b445-053799bcf7b3_1888x890.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!wB8G!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4830068c-589f-4730-b445-053799bcf7b3_1888x890.png" width="1456" height="686" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/4830068c-589f-4730-b445-053799bcf7b3_1888x890.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:686,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:177180,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://aws-cloudsec.com/i/160888107?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4830068c-589f-4730-b445-053799bcf7b3_1888x890.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!wB8G!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4830068c-589f-4730-b445-053799bcf7b3_1888x890.png 424w, https://substackcdn.com/image/fetch/$s_!wB8G!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4830068c-589f-4730-b445-053799bcf7b3_1888x890.png 848w, https://substackcdn.com/image/fetch/$s_!wB8G!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4830068c-589f-4730-b445-053799bcf7b3_1888x890.png 1272w, https://substackcdn.com/image/fetch/$s_!wB8G!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4830068c-589f-4730-b445-053799bcf7b3_1888x890.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div></li><li><p>AWS has announced the general availability of the AWS Cloud Development Kit (AWS CDK) Level 2 (L2) construct for Amazon Cognito Identity Pools. This new library allows developers to define and deploy Identity Pool resources programmatically using familiar programming languages, simplifying the process of providing users with secure access to AWS services within applications. <a href="https://aws.amazon.com/about-aws/whats-new/2025/04/aws-cdk-l2-construct-cognito-identity-pools/">Link</a>. You can find the details <a href="https://docs.aws.amazon.com/cdk/api/v2/docs/aws-cdk-lib.aws_cognito_identitypool-readme.html">HERE</a>. </p></li><li><p>AWS IAM Identity Center (aka AWS SSO) has enhanced session management and trusted identity propagation (TIP) features for Microsoft Active Directory (AD) as identity source. With this release, if you are integrating Microsoft AD with IAM Identity Center, you can now: (a) set session durations for AWS applications and the AWS access portal, ranging from 15 minutes up to 90 days; (b) view and terminate active user sessions; (c) configure an extended 90-day session specifically for Amazon Q Developer Pro while maintaining shorter durations for other AWS applications; and (d) enable trusted identity propagation (TIP) from business intelligence tools that authenticate users through third-party identity providers to AWS services like Amazon Redshift and Amazon Q Business. <a href="https://aws.amazon.com/about-aws/whats-new/2025/04/iam-identity-center-sessions-tip-capabilities-microsoft-ad/">Link</a>. (Note: I did not have an active AD to demo this feature) </p></li><li><p>Amazon Security Lake has achieved FedRAMP High authorization in AWS GovCloud (US) Region and FedRAMP Moderate in the US East and US West Regions. <a href="https://aws.amazon.com/about-aws/whats-new/2025/04/amazon-security-lake-fedramp-high-moderate-authorization/">Link</a>. </p><p></p><p></p><p></p><p></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://aws-cloudsec.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://aws-cloudsec.com/subscribe?"><span>Subscribe now</span></a></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://aws-cloudsec.com/p/issue-91?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://aws-cloudsec.com/p/issue-91?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share</span></a></p><p></p></li></ol><p></p><p></p>]]></content:encoded></item><item><title><![CDATA[Issue 89 & 90]]></title><description><![CDATA[7 days of Cloud Security, recapped in 7 minutes or less!]]></description><link>https://aws-cloudsec.com/p/issue-89-and-90</link><guid isPermaLink="false">https://aws-cloudsec.com/p/issue-89-and-90</guid><dc:creator><![CDATA[AWS-CloudSec Weekly Newsletter]]></dc:creator><pubDate>Tue, 01 Apr 2025 23:59:00 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe69a553d-ed82-4e57-a892-09bd3c3e3c56_1200x1200.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p><strong>This week TLDR i.e. 1 minute version </strong>(For executives):</p><ol><li><p>AWS Network Firewall introduces new flow management feature. </p></li><li><p>AWS Amplify Hosting announces Web Application Firewall Protection in general availability. </p></li><li><p>AWS Network Firewall adds pass action rule alerts and JA4 filtering. </p></li><li><p>AWS Identity and Access Management now supports dual-stack (IPv4 and IPv6) environments and AWS Resource Access Manager (RAM) now supports Internet Protocol Version 6 (IPv6).</p><p></p></li></ol><p><strong>Trending in Cloud &amp; Cyber Security</strong>:</p><ol><li><p>AWS Security Blogs &amp; Bulletins:</p><ul><li><p>Bulletin1: Issue with the AWS CDK CLI and custom credential plugins (CVE-2025-2598). <a href="https://aws.amazon.com/security/security-bulletins/AWS-2025-005/">Link</a>. </p></li><li><p>Bulletin2: Issue with tough, versions prior to 0.20.0 (Multiple CVEs). <a href="https://aws.amazon.com/security/security-bulletins/AWS-2025-007/">Link</a>. </p></li><li><p>Bulletin3: Issue with AWS SAM CLI (CVE-2025-3047, CVE-2025-3048). <a href="https://aws.amazon.com/security/security-bulletins/AWS-2025-008/">Link</a>. </p></li><li><p>Bulletin4: Issues with Kubernetes ingress-nginx controller (Multiple CVEs). <a href="https://aws.amazon.com/security/security-bulletins/AWS-2025-006/">Link</a>.</p></li><li><p>Effectively implementing resource control policies in a multi-account environment. <a href="https://aws.amazon.com/blogs/security/effectively-implementing-resource-controls-policies-in-a-multi-account-environment/">Link</a>. </p></li><li><p>Enhancing cloud security in AI/ML: The little pickle story. <a href="https://aws.amazon.com/blogs/security/enhancing-cloud-security-in-ai-ml-the-little-pickle-story/">Link</a>. </p></li></ul></li><li><p>General security blogs, articles, reports &amp; trending news/advisories:</p><ul><li><p>How I Fell in Love With Cloud Security (And Why You Should Care) by Sena Yakut. <a href="https://senayakut.com/how-i-fell-in-love-with-cloud-security-and-why-you-should-care-ab57d19dbcdc">Link</a>. </p></li><li><p>Cloud Threats on the Rise: Alert Trends Show Intensified Attacker Focus on IAM, Exfiltration by Nathaniel Quist. <a href="https://unit42.paloaltonetworks.com/2025-cloud-security-alert-trends/">Link</a>. </p></li><li><p>Cloud Incident Readiness: Key logs for cloud incidents. <a href="https://www.invictus-ir.com/news/cloud-incident-readiness-key-logs-for-cloud-incidents">Link</a>. </p></li><li><p>Cyber chiefs unveil new roadmap for post-quantum cryptography migration</p><p>New guidance from the NCSC. <a href="https://www.ncsc.gov.uk/news/pqc-migration-roadmap-unveiled">Link</a>. </p></li><li><p>Operation FishMedley: ESET researchers detail a global espionage operation by FishMonger. <a href="https://www.welivesecurity.com/en/eset-research/operation-fishmedley/">Link</a>. </p></li><li><p>Shedding light on the ABYSSWORKER driver: MEDUSA ransomware attack-chain to disable anti-malware tools. <a href="https://www.elastic.co/security-labs/abyssworker">Link</a>. </p></li><li><p>Protecting Remote Desktops at Scale with Cloudflare Access by Mike Borkenstein. <a href="https://blog.cloudflare.com/protecting-remote-desktops-at-scale-with-cloudflare-access/">Link</a>. </p></li><li><p>GitHub Actions Supply Chain Attack: A Targeted Attack on Coinbase Expanded to the Widespread tj-actions/changed-files by Omer Gil, Aviad Hahami, Asi Greenholts and Yaron Avital. <a href="https://unit42.paloaltonetworks.com/github-actions-supply-chain-attack/">Link</a>. </p></li><li><p>New Phishing Campaign Uses Browser-in-the-Browser Attacks to Target Video Gamers/Counter-Strike 2 Players. <a href="https://www.silentpush.com/blog/browser-in-the-browser-attacks/">Link</a>. </p></li><li><p>VMware Tools for Windows update addresses an authentication bypass vulnerability (CVE-2025-22230). <a href="https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/25518">Link</a>. </p></li><li><p>Creating immutable users through a bug in Entra ID restricted administrative units by Katie Knowles. <a href="https://securitylabs.datadoghq.com/articles/creating-immutable-users-entra-id-administrative-units/">Link</a>. </p></li><li><p>Qualys TRU Discovers Three Bypasses of Ubuntu Unprivileged User Namespace Restrictions by Saeed Abbasi. <a href="https://blog.qualys.com/vulnerabilities-threat-research/2025/03/27/qualys-tru-discovers-three-bypasses-of-ubuntu-unprivileged-user-namespace-restrictions">Link</a>. </p></li><li><p>OpenAI: Security on the Path to AGI, increases reward. <a href="https://openai.com/index/security-on-the-path-to-agi/">Link.</a></p></li><li><p>New in Gmail: Making end-to-end encrypted emails easy to use for all organizations. <a href="https://workspace.google.com/blog/identity-and-security/gmail-easy-end-to-end-encryption-all-businesses">Link</a>. Please note the date of the release. </p></li><li><p>Hacking AWS Lambda Functions - S3 File Upload Injection by Teemu. <a href="https://www.nordhero.com/posts/hacking-lambda-functions-with-s3-file-upload/">Link</a>. </p></li><li><p>The 'IngressNightmare' vulnerabilities in the Kubernetes Ingress NGINX Controller: Overview, detection, and remediation by Christophe Tafani-Dereeper, Matt Muir, Frederic Baguelin, Frederic Baguelin, Andy Giron and Adrian Korn. <a href="https://securitylabs.datadoghq.com/articles/ingress-nightmare-vulnerabilities-overview-and-remediation/">Link</a>.</p></li><li><p>How to use the new CloudTrail network activity events for AWS VPC Endpoints by Rami McCarthy, Scott Piper. <a href="https://www.wiz.io/blog/aws-vpc-endpoint-cloudtrail">Link</a>. </p></li><li><p>Uncovering Hidden Threats: Hunting Non-Human Identities in GitHub by </p><p>Idan Cohen , Ariel Szarf. <a href="https://www.mitiga.io/blog/uncovering-hidden-threats-hunting-non-human-identities-in-github">Link</a>. </p><p>Setting Up AWS Firewall Manager Used For Auditing Security Groups in AWS Organization accounts by Joseph Ndambombi Honpah. <a href="https://medium.com/@honpahj/setting-up-aws-firewall-manager-used-for-auditing-security-groups-in-aws-organization-accounts-6be406907363">Link.</a> </p><p></p></li></ul></li></ol><p><strong>This week Long i.e. 3-5 minutes version </strong>(For architects &amp; engineers):</p><ol><li><p>AWS introduced a new flow management feature for AWS Network Firewall, enabling you to monitor and control active network flows. This feature includes two key functions: Flow Capture, which provides point-in-time snapshots of active flows, and Flow Flush, which allows selective termination of specific connections. With these capabilities, you can now analyze and manage network flows based on parameters such as source/destination IP addresses, ports, and protocols, offering greater control over their network traffic. <a href="https://aws.amazon.com/about-aws/whats-new/2025/03/aws-network-firewall-flow-management-feature/">Link</a>. Here&#8217;s my StartFlow Capture sample config:</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!FtEe!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1ca7efc6-db3e-4d66-82c0-869e92ffdf2e_2316x1210.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!FtEe!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1ca7efc6-db3e-4d66-82c0-869e92ffdf2e_2316x1210.png 424w, https://substackcdn.com/image/fetch/$s_!FtEe!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1ca7efc6-db3e-4d66-82c0-869e92ffdf2e_2316x1210.png 848w, https://substackcdn.com/image/fetch/$s_!FtEe!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1ca7efc6-db3e-4d66-82c0-869e92ffdf2e_2316x1210.png 1272w, https://substackcdn.com/image/fetch/$s_!FtEe!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1ca7efc6-db3e-4d66-82c0-869e92ffdf2e_2316x1210.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!FtEe!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1ca7efc6-db3e-4d66-82c0-869e92ffdf2e_2316x1210.png" width="1456" height="761" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/1ca7efc6-db3e-4d66-82c0-869e92ffdf2e_2316x1210.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:761,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:206414,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://aws-cloudsec.com/i/160338844?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1ca7efc6-db3e-4d66-82c0-869e92ffdf2e_2316x1210.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!FtEe!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1ca7efc6-db3e-4d66-82c0-869e92ffdf2e_2316x1210.png 424w, https://substackcdn.com/image/fetch/$s_!FtEe!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1ca7efc6-db3e-4d66-82c0-869e92ffdf2e_2316x1210.png 848w, https://substackcdn.com/image/fetch/$s_!FtEe!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1ca7efc6-db3e-4d66-82c0-869e92ffdf2e_2316x1210.png 1272w, https://substackcdn.com/image/fetch/$s_!FtEe!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1ca7efc6-db3e-4d66-82c0-869e92ffdf2e_2316x1210.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div></li><li><p>AWS Amplify Hosting now offers Web Application Firewall (WAF) Protection in general availability. The integration provides full access to AWS WAF&#8217;s capabilities, including managed rules to defend against common web threats like SQL injection and cross-site scripting (XSS). You can also create custom rules, set up rate-based protections against DDoS attacks, and implement geo-blocking to restrict traffic from specific regions. <a href="https://aws.amazon.com/about-aws/whats-new/2025/03/aws-amplify-hosting-web-application-firewall-protection/">Link</a>. For example, here&#8217;s my WAF config:</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!fa0H!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2faf9ce2-d55a-4c80-8bca-751ea7d8f93c_2454x736.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!fa0H!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2faf9ce2-d55a-4c80-8bca-751ea7d8f93c_2454x736.png 424w, https://substackcdn.com/image/fetch/$s_!fa0H!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2faf9ce2-d55a-4c80-8bca-751ea7d8f93c_2454x736.png 848w, https://substackcdn.com/image/fetch/$s_!fa0H!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2faf9ce2-d55a-4c80-8bca-751ea7d8f93c_2454x736.png 1272w, https://substackcdn.com/image/fetch/$s_!fa0H!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2faf9ce2-d55a-4c80-8bca-751ea7d8f93c_2454x736.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!fa0H!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2faf9ce2-d55a-4c80-8bca-751ea7d8f93c_2454x736.png" width="2454" height="736" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/2faf9ce2-d55a-4c80-8bca-751ea7d8f93c_2454x736.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:736,&quot;width&quot;:2454,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:190488,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://aws-cloudsec.com/i/160338844?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F462b7764-17c2-483f-b83f-047a4a3fd225_2454x736.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!fa0H!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2faf9ce2-d55a-4c80-8bca-751ea7d8f93c_2454x736.png 424w, https://substackcdn.com/image/fetch/$s_!fa0H!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2faf9ce2-d55a-4c80-8bca-751ea7d8f93c_2454x736.png 848w, https://substackcdn.com/image/fetch/$s_!fa0H!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2faf9ce2-d55a-4c80-8bca-751ea7d8f93c_2454x736.png 1272w, https://substackcdn.com/image/fetch/$s_!fa0H!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2faf9ce2-d55a-4c80-8bca-751ea7d8f93c_2454x736.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div></li><li><p>AWS introduced new features for AWS Network Firewall, including alert generation for traffic matching pass action rules and JA4 fingerprinting support in firewall rules. The ability to generate alert log events for traffic matching pass action rules enhances network visibility without requiring an additional alert action rule before the pass rule. This helps detect anomalies or potential security threats in traffic that would otherwise be allowed without further inspection. Additionally, JA4 filtering rules enable AWS Network Firewall to analyze traffic using JA4 fingerprints, which identify client and server applications. <a href="https://aws.amazon.com/about-aws/whats-new/2025/03/aws-network-firewall-pass-action-rule-alerts-ja4-filtering/">Link</a>. For example, here&#8217;s my config:</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Fgr5!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0c8de268-20c1-4cc1-89f6-42cd1eb84e77_884x436.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Fgr5!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0c8de268-20c1-4cc1-89f6-42cd1eb84e77_884x436.png 424w, https://substackcdn.com/image/fetch/$s_!Fgr5!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0c8de268-20c1-4cc1-89f6-42cd1eb84e77_884x436.png 848w, https://substackcdn.com/image/fetch/$s_!Fgr5!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0c8de268-20c1-4cc1-89f6-42cd1eb84e77_884x436.png 1272w, https://substackcdn.com/image/fetch/$s_!Fgr5!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0c8de268-20c1-4cc1-89f6-42cd1eb84e77_884x436.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Fgr5!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0c8de268-20c1-4cc1-89f6-42cd1eb84e77_884x436.png" width="884" height="436" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/0c8de268-20c1-4cc1-89f6-42cd1eb84e77_884x436.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:436,&quot;width&quot;:884,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:73936,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://aws-cloudsec.com/i/160338844?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0c8de268-20c1-4cc1-89f6-42cd1eb84e77_884x436.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!Fgr5!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0c8de268-20c1-4cc1-89f6-42cd1eb84e77_884x436.png 424w, https://substackcdn.com/image/fetch/$s_!Fgr5!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0c8de268-20c1-4cc1-89f6-42cd1eb84e77_884x436.png 848w, https://substackcdn.com/image/fetch/$s_!Fgr5!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0c8de268-20c1-4cc1-89f6-42cd1eb84e77_884x436.png 1272w, https://substackcdn.com/image/fetch/$s_!Fgr5!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0c8de268-20c1-4cc1-89f6-42cd1eb84e77_884x436.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div></li><li><p>AWS Identity and Access Management now supports dual-stack (IPv4 and IPv6) environments and AWS Resource Access Manager (RAM) now supports Internet Protocol Version 6 (IPv6). <a href="https://aws.amazon.com/about-aws/whats-new/2025/03/aws-identity-access-management-dual-stack-ipv4-ipv6-environments/">Link1</a> and <a href="https://aws.amazon.com/about-aws/whats-new/2025/03/aws-ram-supports-ipv6/">Link2</a>. </p><p></p><p></p><p></p><p></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://aws-cloudsec.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://aws-cloudsec.com/subscribe?"><span>Subscribe now</span></a></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://aws-cloudsec.com/p/issue-89-and-90?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://aws-cloudsec.com/p/issue-89-and-90?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share</span></a></p><p></p></li></ol><p></p><p></p>]]></content:encoded></item><item><title><![CDATA[Issue 88]]></title><description><![CDATA[7 days of Cloud Security, recapped in 7 minutes or less!]]></description><link>https://aws-cloudsec.com/p/issue-88</link><guid isPermaLink="false">https://aws-cloudsec.com/p/issue-88</guid><dc:creator><![CDATA[AWS-CloudSec Weekly Newsletter]]></dc:creator><pubDate>Tue, 18 Mar 2025 22:15:20 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F15838bce-c9b4-4b0c-b508-f95a721fd7ca_1200x1200.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p><strong>This week TLDR i.e. 1 minute version </strong>(For executives):</p><ol><li><p>Amazon EC2 Allowed AMIs now integrates with AWS Config.</p></li><li><p>AWS WAF now supports URI fragment field matching. </p></li><li><p>Amazon Inspector expands ECR support for minimal container base images and enhanced detections. </p></li><li><p>Amazon GuardDuty Malware Protection for S3 now available in AWS GovCloud (US) Regions.</p></li><li><p>AWS Service Reference Information now supports resources and condition keys.</p></li><li><p>AWS Verified Access achieves FedRAMP High and Moderate authorization. </p><p></p></li></ol><p><strong>Trending in Cloud &amp; Cyber Security</strong>:</p><ol><li><p>AWS Security Blogs &amp; Bulletins:</p><ul><li><p>Manage authorization within a containerized workload using Amazon Verified Permissions. <a href="https://aws.amazon.com/blogs/security/manage-authorization-within-a-containerized-workload-using-amazon-verified-permissions/">Link</a>. </p></li><li><p>Secure cloud innovation starts at re:Inforce 2025. <a href="https://aws.amazon.com/blogs/security/secure-cloud-innovation-starts-at-reinforce-2025/">Link</a>. </p></li><li><p>AWS KMS CloudWatch metrics help you better track and understand how your KMS keys are being used. <a href="https://aws.amazon.com/blogs/security/aws-kms-cloudwatch-metrics-help-you-better-track-and-understand-how-your-kms-keys-are-being-used/">Link</a>. </p></li></ul></li><li><p>General security blogs, articles, reports &amp; trending news/advisories:</p><ul><li><p>GitLab critical security patch. <a href="https://about.gitlab.com/releases/2025/03/12/patch-release-gitlab-17-9-2-released/">Link</a>. </p></li><li><p>Inside BRUTED: Black Basta (RaaS) Members Used Automated Brute Forcing Framework to Target Edge Network Devices by Arda B&#252;y&#252;kkaya. <a href="https://blog.eclecticiq.com/inside-bruted-black-basta-raas-members-used-automated-brute-forcing-framework-to-target-edge-network-devices">Link</a>. </p></li><li><p>Harden-Runner detection: tj-actions/changed-files action is compromised by Varun Sharma. <a href="https://www.stepsecurity.io/blog/harden-runner-detection-tj-actions-changed-files-action-is-compromised">Link</a>. </p></li><li><p>Wiz to Join Google Cloud. <a href="https://www.wiz.io/blog/wiz-joining-google">Link</a>. </p></li><li><p>NEW: Open Cloud Security Conference. <a href="https://www.opencloudsecurity.org/post/announcing-the-open-cloud-security-conference">Link</a>. </p></li></ul></li></ol><p></p><p><strong>This week Long i.e. 3-5 minutes version </strong>(For architects &amp; engineers):</p><ol><li><p>&#8216;<code>Allowed AMIs</code>&#8217;, an AWS account-wide EC2 setting that restricts AMI usage, now integrates with AWS Config, which allows you to automatically track and detect instances launched with unapproved AMIs using a new AWS Config rule. <a href="https://aws.amazon.com/about-aws/whats-new/2025/03/amazon-ec2-allowed-amis-integrates-aws-config/">Link</a>. For example, this is my rule:</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!HP3N!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5311729f-e7b0-485d-a823-f6f60d9bc385_2590x820.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!HP3N!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5311729f-e7b0-485d-a823-f6f60d9bc385_2590x820.png 424w, https://substackcdn.com/image/fetch/$s_!HP3N!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5311729f-e7b0-485d-a823-f6f60d9bc385_2590x820.png 848w, https://substackcdn.com/image/fetch/$s_!HP3N!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5311729f-e7b0-485d-a823-f6f60d9bc385_2590x820.png 1272w, https://substackcdn.com/image/fetch/$s_!HP3N!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5311729f-e7b0-485d-a823-f6f60d9bc385_2590x820.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!HP3N!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5311729f-e7b0-485d-a823-f6f60d9bc385_2590x820.png" width="1456" height="461" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/5311729f-e7b0-485d-a823-f6f60d9bc385_2590x820.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:461,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:189135,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://aws-cloudsec.com/i/159367880?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5311729f-e7b0-485d-a823-f6f60d9bc385_2590x820.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!HP3N!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5311729f-e7b0-485d-a823-f6f60d9bc385_2590x820.png 424w, https://substackcdn.com/image/fetch/$s_!HP3N!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5311729f-e7b0-485d-a823-f6f60d9bc385_2590x820.png 848w, https://substackcdn.com/image/fetch/$s_!HP3N!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5311729f-e7b0-485d-a823-f6f60d9bc385_2590x820.png 1272w, https://substackcdn.com/image/fetch/$s_!HP3N!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5311729f-e7b0-485d-a823-f6f60d9bc385_2590x820.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div></li><li><p>AWS WAF now supports URI fragment field matching, allowing you to inspect and match content within the URI fragment alongside the existing URI path support. This feature enhances security by enabling more precise rule creation based on the portion of the URL after the "#" symbol. For instance, if your login page includes a dynamic fragment like "foo://login.aspx#myFragment," you can create a rule that permits only requests containing the "myFragment" fragment while blocking others. This allows for targeted security measures, such as restricting access to sensitive areas, identifying unauthorized attempts, and improving bot detection by analyzing fragment patterns used by malicious actors. <a href="https://aws.amazon.com/about-aws/whats-new/2025/03/aws-waf-uri-fragment-field-matching/">Link</a>. For example, here&#8217;s my  rule:</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!TrrB!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4b20b948-cda0-422e-bf07-71a11f259190_1096x912.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!TrrB!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4b20b948-cda0-422e-bf07-71a11f259190_1096x912.png 424w, https://substackcdn.com/image/fetch/$s_!TrrB!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4b20b948-cda0-422e-bf07-71a11f259190_1096x912.png 848w, https://substackcdn.com/image/fetch/$s_!TrrB!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4b20b948-cda0-422e-bf07-71a11f259190_1096x912.png 1272w, https://substackcdn.com/image/fetch/$s_!TrrB!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4b20b948-cda0-422e-bf07-71a11f259190_1096x912.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!TrrB!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4b20b948-cda0-422e-bf07-71a11f259190_1096x912.png" width="1096" height="912" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/4b20b948-cda0-422e-bf07-71a11f259190_1096x912.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:912,&quot;width&quot;:1096,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:134741,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://aws-cloudsec.com/i/159367880?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4b20b948-cda0-422e-bf07-71a11f259190_1096x912.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!TrrB!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4b20b948-cda0-422e-bf07-71a11f259190_1096x912.png 424w, https://substackcdn.com/image/fetch/$s_!TrrB!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4b20b948-cda0-422e-bf07-71a11f259190_1096x912.png 848w, https://substackcdn.com/image/fetch/$s_!TrrB!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4b20b948-cda0-422e-bf07-71a11f259190_1096x912.png 1272w, https://substackcdn.com/image/fetch/$s_!TrrB!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4b20b948-cda0-422e-bf07-71a11f259190_1096x912.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div></li><li><p>Amazon Inspector now supports scanning for scratch, distroless (Debian/Ubuntu-based), and Chainguard images, expanding security coverage for minimal and security-focused container bases. Additionally, ECR scanning now includes ecosystems like Go toolchain, Oracle JDK &amp; JRE, Apache Tomcat, WordPress, and more, helping you detect vulnerabilities in third-party software. These enhancements are also available via the Amazon Inspector SBOM Scan API.<a href="https://aws.amazon.com/about-aws/whats-new/2025/03/amazon-inspector-container-base-images-enhanced-detections/">Link</a>. </p></li><li><p>AWS announced the availability of Amazon GuardDuty Malware Protection for Amazon S3 in AWS GovCloud (US) regions. This expansion enables scanning of newly uploaded S3 objects for malware, viruses, and other threats, allowing you to detect and isolate suspicious files. <a href="https://aws.amazon.com/about-aws/whats-new/2025/03/amazon-guardduty-malware-protection-s3-govcloud/">Link</a>. Here&#8217;s my Gov console:</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!zVHu!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F64ff3f1b-8df5-42e7-a63e-c5d17695c4e1_2714x638.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!zVHu!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F64ff3f1b-8df5-42e7-a63e-c5d17695c4e1_2714x638.png 424w, https://substackcdn.com/image/fetch/$s_!zVHu!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F64ff3f1b-8df5-42e7-a63e-c5d17695c4e1_2714x638.png 848w, https://substackcdn.com/image/fetch/$s_!zVHu!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F64ff3f1b-8df5-42e7-a63e-c5d17695c4e1_2714x638.png 1272w, https://substackcdn.com/image/fetch/$s_!zVHu!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F64ff3f1b-8df5-42e7-a63e-c5d17695c4e1_2714x638.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!zVHu!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F64ff3f1b-8df5-42e7-a63e-c5d17695c4e1_2714x638.png" width="1456" height="342" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/64ff3f1b-8df5-42e7-a63e-c5d17695c4e1_2714x638.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:342,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:212256,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://aws-cloudsec.com/i/159367880?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F64ff3f1b-8df5-42e7-a63e-c5d17695c4e1_2714x638.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!zVHu!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F64ff3f1b-8df5-42e7-a63e-c5d17695c4e1_2714x638.png 424w, https://substackcdn.com/image/fetch/$s_!zVHu!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F64ff3f1b-8df5-42e7-a63e-c5d17695c4e1_2714x638.png 848w, https://substackcdn.com/image/fetch/$s_!zVHu!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F64ff3f1b-8df5-42e7-a63e-c5d17695c4e1_2714x638.png 1272w, https://substackcdn.com/image/fetch/$s_!zVHu!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F64ff3f1b-8df5-42e7-a63e-c5d17695c4e1_2714x638.png 1456w" sizes="100vw" fetchpriority="high"></picture><div></div></div></a></figure></div></li><li><p>AWS now includes resources and condition keys in service reference information, offering a more comprehensive view of service permissions. This enhancement simplifies policy management automation by allowing you to retrieve available actions across AWS services from machine-readable files. <a href="https://aws.amazon.com/about-aws/whats-new/2025/03/aws-service-reference-information-resources-condition-keys/">Link</a>. For example, this is the reference for Cloudtrail:</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!ArGn!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc31c0d5c-fd89-4296-9698-a6d653af6da1_2450x588.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!ArGn!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc31c0d5c-fd89-4296-9698-a6d653af6da1_2450x588.png 424w, https://substackcdn.com/image/fetch/$s_!ArGn!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc31c0d5c-fd89-4296-9698-a6d653af6da1_2450x588.png 848w, https://substackcdn.com/image/fetch/$s_!ArGn!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc31c0d5c-fd89-4296-9698-a6d653af6da1_2450x588.png 1272w, https://substackcdn.com/image/fetch/$s_!ArGn!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc31c0d5c-fd89-4296-9698-a6d653af6da1_2450x588.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!ArGn!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc31c0d5c-fd89-4296-9698-a6d653af6da1_2450x588.png" width="1456" height="349" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/c31c0d5c-fd89-4296-9698-a6d653af6da1_2450x588.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:349,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:197718,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://aws-cloudsec.com/i/159367880?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc31c0d5c-fd89-4296-9698-a6d653af6da1_2450x588.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!ArGn!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc31c0d5c-fd89-4296-9698-a6d653af6da1_2450x588.png 424w, https://substackcdn.com/image/fetch/$s_!ArGn!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc31c0d5c-fd89-4296-9698-a6d653af6da1_2450x588.png 848w, https://substackcdn.com/image/fetch/$s_!ArGn!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc31c0d5c-fd89-4296-9698-a6d653af6da1_2450x588.png 1272w, https://substackcdn.com/image/fetch/$s_!ArGn!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc31c0d5c-fd89-4296-9698-a6d653af6da1_2450x588.png 1456w" sizes="100vw" fetchpriority="high"></picture><div></div></div></a></figure></div></li><li><p>AWS Verified Access achieved FedRAMP High and Moderate authorization. <a href="https://aws.amazon.com/about-aws/whats-new/2025/03/aws-verified-access-fedramp-high-moderate-authorization/">Link</a>.</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!mPJ7!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fec3a78f3-a589-4938-94fe-738727fa43b3_2142x200.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!mPJ7!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fec3a78f3-a589-4938-94fe-738727fa43b3_2142x200.png 424w, https://substackcdn.com/image/fetch/$s_!mPJ7!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fec3a78f3-a589-4938-94fe-738727fa43b3_2142x200.png 848w, https://substackcdn.com/image/fetch/$s_!mPJ7!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fec3a78f3-a589-4938-94fe-738727fa43b3_2142x200.png 1272w, https://substackcdn.com/image/fetch/$s_!mPJ7!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fec3a78f3-a589-4938-94fe-738727fa43b3_2142x200.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!mPJ7!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fec3a78f3-a589-4938-94fe-738727fa43b3_2142x200.png" width="1456" height="136" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/ec3a78f3-a589-4938-94fe-738727fa43b3_2142x200.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:136,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:54680,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://aws-cloudsec.com/i/159367880?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fec3a78f3-a589-4938-94fe-738727fa43b3_2142x200.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!mPJ7!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fec3a78f3-a589-4938-94fe-738727fa43b3_2142x200.png 424w, https://substackcdn.com/image/fetch/$s_!mPJ7!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fec3a78f3-a589-4938-94fe-738727fa43b3_2142x200.png 848w, https://substackcdn.com/image/fetch/$s_!mPJ7!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fec3a78f3-a589-4938-94fe-738727fa43b3_2142x200.png 1272w, https://substackcdn.com/image/fetch/$s_!mPJ7!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fec3a78f3-a589-4938-94fe-738727fa43b3_2142x200.png 1456w" sizes="100vw" fetchpriority="high"></picture><div></div></div></a></figure></div><p> </p><p></p><p></p><p></p><p></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://aws-cloudsec.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://aws-cloudsec.com/subscribe?"><span>Subscribe now</span></a></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://aws-cloudsec.com/p/issue-88?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://aws-cloudsec.com/p/issue-88?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share</span></a></p><p></p></li></ol><p></p><p></p>]]></content:encoded></item><item><title><![CDATA[Issue 86 & 87]]></title><description><![CDATA[7 days of Cloud Security, recapped in 7 minutes or less!]]></description><link>https://aws-cloudsec.com/p/issue-86-and-87</link><guid isPermaLink="false">https://aws-cloudsec.com/p/issue-86-and-87</guid><dc:creator><![CDATA[AWS-CloudSec Weekly Newsletter]]></dc:creator><pubDate>Tue, 11 Mar 2025 20:38:28 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F15838bce-c9b4-4b0c-b508-f95a721fd7ca_1200x1200.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p><strong>This week TLDR i.e. 1 minute version </strong>(For executives):</p><ol><li><p>AWS Network Firewall simplifies policy management with enhanced console features. </p></li><li><p>Amazon RDS now provides visibility into IAM DB Authentication metrics and logs.</p></li><li><p>AWS WAF now supports PCI DSS4.0 compliance protection with partner solutions. </p></li><li><p>AWS WAF adds JA4 fingerprinting and aggregation on JA3 and JA4 fingerprints for rate-based rules.</p></li><li><p>Amazon EKS now envelope encrypts all Kubernetes API data by default.</p></li><li><p>IAM Access Analyzer now supports Internet Protocol Version 6 (IPv6). </p></li><li><p>Amazon Cognito now supports access token customization for machine-to-machine (M2M) authorization flows. </p><p></p></li></ol><p><strong>Trending in Cloud &amp; Cyber Security</strong>:</p><ol><li><p>AWS Security Blogs &amp; Bulletins:</p><ul><li><p>Bulletin: Issue with Temporary elevated access management (TEAM) CVE-2025-1969. <a href="https://aws.amazon.com/security/security-bulletins/AWS-2025-004/">Link</a>. </p></li><li><p>NEW AWS Heroes 2025. <a href="https://aws.amazon.com/blogs/aws/new-year-new-heroes-march-2025/">Link</a>. </p></li></ul></li><li><p>General security blogs, articles, reports &amp; trending news/advisories:</p><ul><li><p>Securing Datadog&#8217;s cloud infrastructure: Our playbook and methodology by Tim Ginda. <a href="https://www.datadoghq.com/blog/cloud-security-playbook/">Link</a>.</p></li><li><p>Research finds 12,000 &#8216;Live&#8217; API Keys and Passwords in DeepSeek's Training Data by Joe Leon. <a href="https://trufflesecurity.com/blog/research-finds-12-000-live-api-keys-and-passwords-in-deepseek-s-training-data">Link</a>. </p></li><li><p>JavaGhost&#8217;s Persistent Phishing Attacks From the Cloud by Margaret Kelley. <a href="https://unit42.paloaltonetworks.com/javaghost-cloud-phishing/">Link</a>.</p></li><li><p>Call It What You Want: Threat Actor Delivers Highly Targeted Multistage Polyglot Malware by Joshua Miller and Kyle Cucci. <a href="https://www.proofpoint.com/us/blog/threat-insight/call-it-what-you-want-threat-actor-delivers-highly-targeted-multistage-polyglot">Link</a>. </p></li><li><p>Camera off: Akira deploys ransomware via webcam by Gavin Hull, Cameron Trivella and Jon Seland. <a href="https://www.s-rminform.com/latest-thinking/camera-off-akira-deploys-ransomware-via-webcam">Link</a>. </p></li><li><p>Shrinking the haystack: The six phases of cloud threat detection by Brian Davis. <a href="https://redcanary.com/blog/threat-detection/cloud-threat-detection/">Link</a>. </p></li></ul></li></ol><p></p><p><strong>This week Long i.e. 3-5 minutes version </strong>(For architects &amp; engineers):</p><ol><li><p>AWS Network Firewall introduced enhanced console capabilities to streamline rule management and policy configuration. Notable improvements include the ability to adjust rule priority directly from the console without requiring deletion and recreation, pre-filled fields for adding descriptions and signature IDs in rules, a default "Alert Established" selection for comprehensive connection logging, and automatic "Reject" action selection in the Stream Exception Policy configuration.  <a href="https://aws.amazon.com/about-aws/whats-new/2025/02/aws-network-firewall-policy-management-console-features/">Link</a>. For example, I was able to adjust priority from the console:</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!UFsI!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F70b9c022-c9c2-4ebf-97fc-3ab6867b7d67_2558x924.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!UFsI!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F70b9c022-c9c2-4ebf-97fc-3ab6867b7d67_2558x924.png 424w, https://substackcdn.com/image/fetch/$s_!UFsI!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F70b9c022-c9c2-4ebf-97fc-3ab6867b7d67_2558x924.png 848w, https://substackcdn.com/image/fetch/$s_!UFsI!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F70b9c022-c9c2-4ebf-97fc-3ab6867b7d67_2558x924.png 1272w, https://substackcdn.com/image/fetch/$s_!UFsI!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F70b9c022-c9c2-4ebf-97fc-3ab6867b7d67_2558x924.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!UFsI!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F70b9c022-c9c2-4ebf-97fc-3ab6867b7d67_2558x924.png" width="2558" height="924" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/70b9c022-c9c2-4ebf-97fc-3ab6867b7d67_2558x924.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:924,&quot;width&quot;:2558,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:189671,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://aws-cloudsec.com/i/158843232?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdd0f248d-727f-4e89-919c-b9b44eb7d7b5_2558x924.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!UFsI!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F70b9c022-c9c2-4ebf-97fc-3ab6867b7d67_2558x924.png 424w, https://substackcdn.com/image/fetch/$s_!UFsI!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F70b9c022-c9c2-4ebf-97fc-3ab6867b7d67_2558x924.png 848w, https://substackcdn.com/image/fetch/$s_!UFsI!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F70b9c022-c9c2-4ebf-97fc-3ab6867b7d67_2558x924.png 1272w, https://substackcdn.com/image/fetch/$s_!UFsI!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F70b9c022-c9c2-4ebf-97fc-3ab6867b7d67_2558x924.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div></li><li><p>Amazon RDS IAM Database Authentication (IAM DB Auth) now offers enhanced observability with metrics and logs, helping diagnose authentication issues. Users can track errors related to IAM policies, expired tokens, throttling, and more. Metrics are available in Amazon CloudWatch, and error logs can be exported via the RDS Export to CloudWatch Logs feature for deeper insights into connection failures. <a href="https://aws.amazon.com/about-aws/whats-new/2025/02/amazon-rds-visibility-iam-db-authentication-metrics-logs/">Link</a>. For example, here&#8217;s my configuration for the log:</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!82zK!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F86768ced-c074-4be0-add8-b08213217187_1944x910.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!82zK!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F86768ced-c074-4be0-add8-b08213217187_1944x910.png 424w, https://substackcdn.com/image/fetch/$s_!82zK!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F86768ced-c074-4be0-add8-b08213217187_1944x910.png 848w, https://substackcdn.com/image/fetch/$s_!82zK!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F86768ced-c074-4be0-add8-b08213217187_1944x910.png 1272w, https://substackcdn.com/image/fetch/$s_!82zK!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F86768ced-c074-4be0-add8-b08213217187_1944x910.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!82zK!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F86768ced-c074-4be0-add8-b08213217187_1944x910.png" width="1456" height="682" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/86768ced-c074-4be0-add8-b08213217187_1944x910.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:682,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:169457,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://aws-cloudsec.com/i/158843232?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F86768ced-c074-4be0-add8-b08213217187_1944x910.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!82zK!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F86768ced-c074-4be0-add8-b08213217187_1944x910.png 424w, https://substackcdn.com/image/fetch/$s_!82zK!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F86768ced-c074-4be0-add8-b08213217187_1944x910.png 848w, https://substackcdn.com/image/fetch/$s_!82zK!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F86768ced-c074-4be0-add8-b08213217187_1944x910.png 1272w, https://substackcdn.com/image/fetch/$s_!82zK!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F86768ced-c074-4be0-add8-b08213217187_1944x910.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div></li><li><p>AWS WAF's new partner solutions page  now simplifies discovering and implementing PCI DSS v4.0 compliance solutions. <a href="https://aws.amazon.com/about-aws/whats-new/2025/03/aws-waf-pci-compliance-protection-partner-solutions/">Link</a>. For example, here&#8217;s one such solution with the filter in my AWS marketplace console:</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!NBgN!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbf381ed8-2eef-4b10-be03-6d903ebc56b5_2428x452.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!NBgN!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbf381ed8-2eef-4b10-be03-6d903ebc56b5_2428x452.png 424w, https://substackcdn.com/image/fetch/$s_!NBgN!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbf381ed8-2eef-4b10-be03-6d903ebc56b5_2428x452.png 848w, https://substackcdn.com/image/fetch/$s_!NBgN!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbf381ed8-2eef-4b10-be03-6d903ebc56b5_2428x452.png 1272w, https://substackcdn.com/image/fetch/$s_!NBgN!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbf381ed8-2eef-4b10-be03-6d903ebc56b5_2428x452.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!NBgN!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbf381ed8-2eef-4b10-be03-6d903ebc56b5_2428x452.png" width="2428" height="452" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/bf381ed8-2eef-4b10-be03-6d903ebc56b5_2428x452.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:452,&quot;width&quot;:2428,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:107457,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://aws-cloudsec.com/i/158843232?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5d578b34-854d-46f9-a4eb-5841c92ffe3e_2428x452.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!NBgN!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbf381ed8-2eef-4b10-be03-6d903ebc56b5_2428x452.png 424w, https://substackcdn.com/image/fetch/$s_!NBgN!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbf381ed8-2eef-4b10-be03-6d903ebc56b5_2428x452.png 848w, https://substackcdn.com/image/fetch/$s_!NBgN!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbf381ed8-2eef-4b10-be03-6d903ebc56b5_2428x452.png 1272w, https://substackcdn.com/image/fetch/$s_!NBgN!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbf381ed8-2eef-4b10-be03-6d903ebc56b5_2428x452.png 1456w" sizes="100vw" fetchpriority="high"></picture><div></div></div></a></figure></div></li><li><p>AWS WAF now supports JA4 fingerprinting for incoming requests, allowing you to permit trusted clients or block malicious ones. Additionally, both JA4 and JA3 fingerprints can now be used as aggregation keys in WAF's rate-based rules, enabling better monitoring and control of request rates based on client fingerprints. <a href="https://aws.amazon.com/about-aws/whats-new/2025/03/aws-waf-ja4-fingerprinting-aggregation-ja3-ja4-fingerprints-rate-based-rules/">Link</a>. For example, here are my options for JA4 and JA3 fingerprints as aggregation keys within my WAF's rate-based rule:</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!OUO4!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F34866112-9e77-4105-aa56-8bd3bc16706f_1150x654.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!OUO4!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F34866112-9e77-4105-aa56-8bd3bc16706f_1150x654.png 424w, https://substackcdn.com/image/fetch/$s_!OUO4!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F34866112-9e77-4105-aa56-8bd3bc16706f_1150x654.png 848w, https://substackcdn.com/image/fetch/$s_!OUO4!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F34866112-9e77-4105-aa56-8bd3bc16706f_1150x654.png 1272w, https://substackcdn.com/image/fetch/$s_!OUO4!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F34866112-9e77-4105-aa56-8bd3bc16706f_1150x654.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!OUO4!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F34866112-9e77-4105-aa56-8bd3bc16706f_1150x654.png" width="1150" height="654" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/34866112-9e77-4105-aa56-8bd3bc16706f_1150x654.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:654,&quot;width&quot;:1150,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:86930,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://aws-cloudsec.com/i/158843232?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F34866112-9e77-4105-aa56-8bd3bc16706f_1150x654.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!OUO4!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F34866112-9e77-4105-aa56-8bd3bc16706f_1150x654.png 424w, https://substackcdn.com/image/fetch/$s_!OUO4!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F34866112-9e77-4105-aa56-8bd3bc16706f_1150x654.png 848w, https://substackcdn.com/image/fetch/$s_!OUO4!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F34866112-9e77-4105-aa56-8bd3bc16706f_1150x654.png 1272w, https://substackcdn.com/image/fetch/$s_!OUO4!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F34866112-9e77-4105-aa56-8bd3bc16706f_1150x654.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div></li><li><p>Amazon Elastic Kubernetes Service (EKS) now enables default envelope encryption for all Kubernetes API data in clusters running Kubernetes version 1.28 or later. Previously, Amazon EKS offered optional envelope encryption using the Kubernetes KMS provider v1. Now, this encryption is enabled by default for all objects in the Kubernetes API. By default, AWS owns the encryption keys, but you also have the option to create or import externally generated keys into AWS KMS for use in your cluster&#8217;s managed Kubernetes control plane. <a href="https://aws.amazon.com/about-aws/whats-new/2025/03/amazon-eks-envelope-encrypts-kubernetes-api-data-default/">Link</a>. For example, this is my option:</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Jjsw!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F31da1c8c-fdd4-4362-901a-f9a93a552c33_1792x428.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Jjsw!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F31da1c8c-fdd4-4362-901a-f9a93a552c33_1792x428.png 424w, https://substackcdn.com/image/fetch/$s_!Jjsw!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F31da1c8c-fdd4-4362-901a-f9a93a552c33_1792x428.png 848w, https://substackcdn.com/image/fetch/$s_!Jjsw!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F31da1c8c-fdd4-4362-901a-f9a93a552c33_1792x428.png 1272w, https://substackcdn.com/image/fetch/$s_!Jjsw!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F31da1c8c-fdd4-4362-901a-f9a93a552c33_1792x428.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Jjsw!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F31da1c8c-fdd4-4362-901a-f9a93a552c33_1792x428.png" width="1792" height="428" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/31da1c8c-fdd4-4362-901a-f9a93a552c33_1792x428.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:428,&quot;width&quot;:1792,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:98674,&quot;alt&quot;:&quot;&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" title="" srcset="https://substackcdn.com/image/fetch/$s_!Jjsw!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F31da1c8c-fdd4-4362-901a-f9a93a552c33_1792x428.png 424w, https://substackcdn.com/image/fetch/$s_!Jjsw!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F31da1c8c-fdd4-4362-901a-f9a93a552c33_1792x428.png 848w, https://substackcdn.com/image/fetch/$s_!Jjsw!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F31da1c8c-fdd4-4362-901a-f9a93a552c33_1792x428.png 1272w, https://substackcdn.com/image/fetch/$s_!Jjsw!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F31da1c8c-fdd4-4362-901a-f9a93a552c33_1792x428.png 1456w" sizes="100vw" fetchpriority="high"></picture><div></div></div></a></figure></div></li><li><p>AWS Identity and Access Manager (IAM) Access Analyzer now supports IPv6 through new dual-stack endpoints. Existing IPv4-only endpoints will remain available for backward compatibility. The new dual-stack domains can be accessed from the internet or within an Amazon Virtual Private Cloud (VPC) via AWS PrivateLink. <a href="https://aws.amazon.com/about-aws/whats-new/2025/03/iam-access-analyzer-supports-ipv6/">Link</a>. For example, here&#8217;s my option:</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!rG8W!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff3435edd-e2ab-4ee5-9a8a-0f43c53a2e12_2164x1396.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!rG8W!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff3435edd-e2ab-4ee5-9a8a-0f43c53a2e12_2164x1396.png 424w, https://substackcdn.com/image/fetch/$s_!rG8W!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff3435edd-e2ab-4ee5-9a8a-0f43c53a2e12_2164x1396.png 848w, https://substackcdn.com/image/fetch/$s_!rG8W!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff3435edd-e2ab-4ee5-9a8a-0f43c53a2e12_2164x1396.png 1272w, https://substackcdn.com/image/fetch/$s_!rG8W!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff3435edd-e2ab-4ee5-9a8a-0f43c53a2e12_2164x1396.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!rG8W!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff3435edd-e2ab-4ee5-9a8a-0f43c53a2e12_2164x1396.png" width="2164" height="1396" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/f3435edd-e2ab-4ee5-9a8a-0f43c53a2e12_2164x1396.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1396,&quot;width&quot;:2164,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:263272,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://aws-cloudsec.com/i/158843232?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbac23af5-e77a-42a7-a3b1-3ba3f2d7af18_2164x1396.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!rG8W!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff3435edd-e2ab-4ee5-9a8a-0f43c53a2e12_2164x1396.png 424w, https://substackcdn.com/image/fetch/$s_!rG8W!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff3435edd-e2ab-4ee5-9a8a-0f43c53a2e12_2164x1396.png 848w, https://substackcdn.com/image/fetch/$s_!rG8W!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff3435edd-e2ab-4ee5-9a8a-0f43c53a2e12_2164x1396.png 1272w, https://substackcdn.com/image/fetch/$s_!rG8W!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff3435edd-e2ab-4ee5-9a8a-0f43c53a2e12_2164x1396.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div></li><li><p>Amazon Cognito now allows you to customize access tokens for machine-to-machine (M2M) flows, enabling fine-grained authorization for applications, APIs, and workloads. Now, you can define custom claims and scopes in access tokens, providing better control over how automated systems interact with resources. <a href="https://aws.amazon.com/about-aws/whats-new/2025/03/amazon-cognito-access-token-m2m-authorization-flows/">Link</a>. Please note: Access token customization for M2M authorization is available to Essentials or Plus tiers. For example, here is my configuration:</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Ousa!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbd6a0ca8-7e21-4424-86a4-b3487ce188d4_2584x972.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Ousa!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbd6a0ca8-7e21-4424-86a4-b3487ce188d4_2584x972.png 424w, https://substackcdn.com/image/fetch/$s_!Ousa!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbd6a0ca8-7e21-4424-86a4-b3487ce188d4_2584x972.png 848w, https://substackcdn.com/image/fetch/$s_!Ousa!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbd6a0ca8-7e21-4424-86a4-b3487ce188d4_2584x972.png 1272w, https://substackcdn.com/image/fetch/$s_!Ousa!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbd6a0ca8-7e21-4424-86a4-b3487ce188d4_2584x972.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Ousa!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbd6a0ca8-7e21-4424-86a4-b3487ce188d4_2584x972.png" width="1456" height="548" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/bd6a0ca8-7e21-4424-86a4-b3487ce188d4_2584x972.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:548,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:229079,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://aws-cloudsec.com/i/158843232?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbd6a0ca8-7e21-4424-86a4-b3487ce188d4_2584x972.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!Ousa!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbd6a0ca8-7e21-4424-86a4-b3487ce188d4_2584x972.png 424w, https://substackcdn.com/image/fetch/$s_!Ousa!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbd6a0ca8-7e21-4424-86a4-b3487ce188d4_2584x972.png 848w, https://substackcdn.com/image/fetch/$s_!Ousa!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbd6a0ca8-7e21-4424-86a4-b3487ce188d4_2584x972.png 1272w, https://substackcdn.com/image/fetch/$s_!Ousa!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbd6a0ca8-7e21-4424-86a4-b3487ce188d4_2584x972.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p> </p><p></p><p></p><p></p><p></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://aws-cloudsec.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://aws-cloudsec.com/subscribe?"><span>Subscribe now</span></a></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://aws-cloudsec.com/p/issue-86-and-87?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://aws-cloudsec.com/p/issue-86-and-87?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share</span></a></p><p></p></li></ol><p></p><p></p>]]></content:encoded></item><item><title><![CDATA[Issue 85]]></title><description><![CDATA[7 days of Cloud Security, recapped in 7 minutes or less!]]></description><link>https://aws-cloudsec.com/p/issue-85</link><guid isPermaLink="false">https://aws-cloudsec.com/p/issue-85</guid><dc:creator><![CDATA[AWS-CloudSec Weekly Newsletter]]></dc:creator><pubDate>Tue, 25 Feb 2025 23:19:23 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe69a553d-ed82-4e57-a892-09bd3c3e3c56_1200x1200.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p></p><p><strong>This week TLDR i.e. 1 minute version </strong>(For executives):</p><ol><li><p>AWS WAF enhances Data Protection and logging experience. </p></li><li><p>AWS Network Firewall introduces automated domain lists and insights.</p></li><li><p>Announcing fine-grained access control via AWS Lake Formation with EMR on EKS.</p></li><li><p>Certificate-Based Authentication is now available on Amazon AppStream 2.0 multi-session fleets.</p></li><li><p>Amazon Verified Permissions now supports the Cedar JSON entity format.</p><p></p></li></ol><p><strong>Trending in Cloud &amp; Cyber Security</strong>:</p><ol><li><p>AWS Security Blogs &amp; Bulletins:</p><ul><li><p>Four ways to grant cross-account access in AWS. <a href="https://aws.amazon.com/blogs/security/four-ways-to-grant-cross-account-access-in-aws/">Link</a>.</p></li><li><p>From log analysis to rule creation: How AWS Network Firewall automates domain-based security for outbound traffic. <a href="https://aws.amazon.com/blogs/security/from-log-analysis-to-rule-creation-how-aws-network-firewall-automates-domain-based-security-for-outbound-traffic/">Link</a>. </p></li><li><p>Connect your on-premises Kubernetes cluster to AWS APIs using IAM Roles Anywhere. <a href="https://aws.amazon.com/blogs/security/connect-your-on-premises-kubernetes-cluster-to-aws-apis-using-iam-roles-anywhere/">Link</a>. </p></li></ul></li><li><p>General security blogs, articles, reports &amp; trending news/advisories:</p><ul><li><p>State of cloud remediation by Idan Perez, Michael St.Onge and Joseph Barringhaus. <a href="https://tamnoon.io/state-of-cloud-remediation/">Link</a>. </p></li><li><p>Locked Out, Dropboxed In: When BEC threats innovate. <a href="https://www.invictus-ir.com/news/locked-out-dropboxed-in-when-bec-threats-innovate">Link</a>. </p></li><li><p>Removing Jeff Bezos From My Bed by Dylan Ayrey and Jake King. <a href="https://trufflesecurity.com/blog/removing-jeff-bezos-from-my-bed">Link</a>. </p></li><li><p>Abusing AWS Serverless Image Handler by Karim El-Melhaoui. <a href="https://www.o3c.no/knowledge/abusing-aws-serverless-image-handler">Link</a>. </p></li><li><p>Secure RDS authentication using SSO and ephemeral login token. <a href="https://www.bgigurtsis.com/2025/02/securingrds.html">Link</a>. </p></li><li><p>Seeing what your Resource Control Policies (RCPs) are going to break by Michael Kirchner. <a href="https://medium.com/@michael.kirchner/seeing-what-your-resource-control-policies-rcps-are-going-to-break-2dfeddbd8782">Link</a>. </p></li><li><p>Processing 23 Billion Rows of ALIEN TXTBASE Stealer Logs by Tory Hunt. <a href="https://www.troyhunt.com/processing-23-billion-rows-of-alien-txtbase-stealer-logs/">Link</a>. </p></li><li><p>An inside look at NSA (Equation Group) TTPs from China&#8217;s lense. <a href="https://www.inversecos.com/2025/02/an-inside-look-at-nsa-equation-group.html">Link</a>. </p></li><li><p>Signals of Trouble: Multiple Russia-Aligned Threat Actors Actively Targeting Signal Messenger. <a href="https://cloud.google.com/blog/topics/threat-intelligence/russia-targeting-signal-messenger/">Link</a>. </p></li><li><p>FortiSandbox 5.0 Detects Evolving Snake Keylogger Variant by Kevin Su. <a href="https://www.fortinet.com/blog/threat-research/fortisandbox-detects-evolving-snake-keylogger-variant">Link</a>. </p></li><li><p>Meet NailaoLocker: a ransomware distributed in Europe by ShadowPad and PlugX backdoors by Marine Pichon, Alexis Bonnefoi. <a href="https://www.orangecyberdefense.com/global/blog/cert-news/meet-nailaolocker-a-ransomware-distributed-in-europe-by-shadowpad-and-plugx-backdoors">Link</a>. </p></li><li><p>DMARC for PCI DSS 4.0 mandatory from 2025 by Ahona Rudra. <a href="https://powerdmarc.com/dmarc-pci-dss-compliance/">Link</a>. </p></li><li><p>Deceptive Development targets freelance developers by Mat&#283;j Harv&#225;nek. <a href="https://www.welivesecurity.com/en/eset-research/deceptivedevelopment-targets-freelance-developers/">Link</a>.</p></li><li><p>Weathering the storm: In the midst of a Typhoon by Cisco Talos. <a href="https://blog.talosintelligence.com/salt-typhoon-analysis/">Link</a>. </p></li><li><p>Apple pulls iCloud end-to-end encryption feature in the UK. <a href="https://www.apple.com/privacy/government-information-requests/">Link</a>.</p></li><li><p>Google announced quantum-safe digital signatures in Cloud KMS. <a href="https://cloud.google.com/blog/products/identity-security/announcing-quantum-safe-digital-signatures-in-cloud-kms">Link</a>. </p></li><li><p>North Korean Unauthorized Activity Involving ETH Cold Wallet $1.5 billion ByBit crypto heist. <a href="https://announcements.bybit.com/article/incident-update---eth-cold-wallet-incident-blt292c0454d26e9140/">Link</a>. </p></li></ul></li></ol><p></p><p><strong>This week Long i.e. 3-5 minutes version </strong>(For architects &amp; engineers):</p><ol><li><p>AWS WAF enhanced its Data Protection features with new controls for sensitive data in logs, which allow you to implement customized safeguards for sensitive information, such as passwords, API keys, authentication tokens, and other confidential data, across specific fields like headers, parameters, and body content. You can configure data protection at the web ACL level to apply across all output destinations or limit it to logging, affecting only the data AWS WAF sends to the designated logging destination. Protection can be enforced through substitution, which replaces content with "<code>REDACTED</code>," or hashing for enhanced security. <a href="https://aws.amazon.com/about-aws/whats-new/2025/02/aws-waf-data-protection-logging-experience/">Link</a>. Here&#8217;s my sample data protection rule set at WebACL&#8217;s page &#8220;logging and metrics&#8221; section.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!8is3!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fedbaace9-df8d-41a0-97a2-0c0c2ca8ec6a_2600x902.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!8is3!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fedbaace9-df8d-41a0-97a2-0c0c2ca8ec6a_2600x902.png 424w, https://substackcdn.com/image/fetch/$s_!8is3!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fedbaace9-df8d-41a0-97a2-0c0c2ca8ec6a_2600x902.png 848w, https://substackcdn.com/image/fetch/$s_!8is3!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fedbaace9-df8d-41a0-97a2-0c0c2ca8ec6a_2600x902.png 1272w, https://substackcdn.com/image/fetch/$s_!8is3!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fedbaace9-df8d-41a0-97a2-0c0c2ca8ec6a_2600x902.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!8is3!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fedbaace9-df8d-41a0-97a2-0c0c2ca8ec6a_2600x902.png" width="1456" height="505" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/edbaace9-df8d-41a0-97a2-0c0c2ca8ec6a_2600x902.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:505,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:256171,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://aws-cloudsec.com/i/157894508?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fedbaace9-df8d-41a0-97a2-0c0c2ca8ec6a_2600x902.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!8is3!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fedbaace9-df8d-41a0-97a2-0c0c2ca8ec6a_2600x902.png 424w, https://substackcdn.com/image/fetch/$s_!8is3!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fedbaace9-df8d-41a0-97a2-0c0c2ca8ec6a_2600x902.png 848w, https://substackcdn.com/image/fetch/$s_!8is3!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fedbaace9-df8d-41a0-97a2-0c0c2ca8ec6a_2600x902.png 1272w, https://substackcdn.com/image/fetch/$s_!8is3!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fedbaace9-df8d-41a0-97a2-0c0c2ca8ec6a_2600x902.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div></li><li><p>AWS Network Firewall now supports automated domain lists and insights, improving network traffic visibility and streamlining firewall rule configuration. This feature analyzes HTTP and HTTPS traffic logs from the past 30 days, identifying frequently accessed domains. With these insights, you can quickly create rules based on observed network traffic patterns. <a href="https://aws.amazon.com/about-aws/whats-new/2025/02/aws-network-firewall-automated-domain-lists/">Link</a>. Here is the setting for my network firewall. </p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!RLuW!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F330fd9bd-d5fd-4d67-b752-4a1d419f9598_2048x712.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!RLuW!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F330fd9bd-d5fd-4d67-b752-4a1d419f9598_2048x712.png 424w, https://substackcdn.com/image/fetch/$s_!RLuW!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F330fd9bd-d5fd-4d67-b752-4a1d419f9598_2048x712.png 848w, https://substackcdn.com/image/fetch/$s_!RLuW!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F330fd9bd-d5fd-4d67-b752-4a1d419f9598_2048x712.png 1272w, https://substackcdn.com/image/fetch/$s_!RLuW!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F330fd9bd-d5fd-4d67-b752-4a1d419f9598_2048x712.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!RLuW!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F330fd9bd-d5fd-4d67-b752-4a1d419f9598_2048x712.png" width="1456" height="506" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/330fd9bd-d5fd-4d67-b752-4a1d419f9598_2048x712.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:506,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:171981,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://aws-cloudsec.com/i/157894508?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F330fd9bd-d5fd-4d67-b752-4a1d419f9598_2048x712.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!RLuW!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F330fd9bd-d5fd-4d67-b752-4a1d419f9598_2048x712.png 424w, https://substackcdn.com/image/fetch/$s_!RLuW!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F330fd9bd-d5fd-4d67-b752-4a1d419f9598_2048x712.png 848w, https://substackcdn.com/image/fetch/$s_!RLuW!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F330fd9bd-d5fd-4d67-b752-4a1d419f9598_2048x712.png 1272w, https://substackcdn.com/image/fetch/$s_!RLuW!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F330fd9bd-d5fd-4d67-b752-4a1d419f9598_2048x712.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div></li><li><p>AWS announced the general availability of fine-grained data access control (FGAC) in AWS Lake Formation for Apache Spark on Amazon EMR on EKS which allows enforcing comprehensive FGAC policies&#8212;including database, table, column, row, and cell-level controls&#8212;on data lake tables from EMR on EKS Spark jobs. <a href="https://aws.amazon.com/about-aws/whats-new/2025/02/fine-grained-control-aws-lake-formation-emr-eks/">Link</a>.</p></li><li><p>Amazon AppStream 2.0 introduced certificate-based authentication (CBA) support for multi-session fleets running Microsoft Windows and joined to an Active Directory. This feature enables administrators to maximize the cost benefits of the multi-session model while improving user access and security. <a href="https://aws.amazon.com/about-aws/whats-new/2025/02/certificate-based-authentication-amazon-appstream-2-0-multi-session-fleets/">Link</a>. </p></li><li><p>Amazon Verified Permissions now supports the same JSON format for entity and context data as the Cedar SDK, making authorization requests easier for developers. This update brings the Amazon Verified Permissions API in closer alignment with the open-source Cedar SDK. As a result, transitioning between the SDK and Amazon Verified Permissions is now more seamless. <a href="https://aws.amazon.com/about-aws/whats-new/2025/02/amazon-verified-permissions-cedar-json-entity-format/">Link</a>. Find JSON entity <a href="https://docs.cedarpolicy.com/auth/entities-syntax.html">HERE</a>. </p><p></p><p></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://invary.com/" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Oy16!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F73bf36af-d79b-497e-922c-3aef0908c21b_1146x338.png 424w, https://substackcdn.com/image/fetch/$s_!Oy16!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F73bf36af-d79b-497e-922c-3aef0908c21b_1146x338.png 848w, https://substackcdn.com/image/fetch/$s_!Oy16!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F73bf36af-d79b-497e-922c-3aef0908c21b_1146x338.png 1272w, https://substackcdn.com/image/fetch/$s_!Oy16!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F73bf36af-d79b-497e-922c-3aef0908c21b_1146x338.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Oy16!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F73bf36af-d79b-497e-922c-3aef0908c21b_1146x338.png" width="1146" height="338" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/73bf36af-d79b-497e-922c-3aef0908c21b_1146x338.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:338,&quot;width&quot;:1146,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:97149,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:&quot;https://invary.com/&quot;,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!Oy16!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F73bf36af-d79b-497e-922c-3aef0908c21b_1146x338.png 424w, https://substackcdn.com/image/fetch/$s_!Oy16!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F73bf36af-d79b-497e-922c-3aef0908c21b_1146x338.png 848w, https://substackcdn.com/image/fetch/$s_!Oy16!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F73bf36af-d79b-497e-922c-3aef0908c21b_1146x338.png 1272w, https://substackcdn.com/image/fetch/$s_!Oy16!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F73bf36af-d79b-497e-922c-3aef0908c21b_1146x338.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p></p><p></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://aws-cloudsec.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://aws-cloudsec.com/subscribe?"><span>Subscribe now</span></a></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://aws-cloudsec.com/p/issue-85?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://aws-cloudsec.com/p/issue-85?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share</span></a></p><p></p></li></ol><p></p><p></p>]]></content:encoded></item><item><title><![CDATA[Issue 84]]></title><description><![CDATA[7 days of Cloud Security, recapped in 7 minutes or less!]]></description><link>https://aws-cloudsec.com/p/issue-84</link><guid isPermaLink="false">https://aws-cloudsec.com/p/issue-84</guid><dc:creator><![CDATA[AWS-CloudSec Weekly Newsletter]]></dc:creator><pubDate>Wed, 19 Feb 2025 01:18:11 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe69a553d-ed82-4e57-a892-09bd3c3e3c56_1200x1200.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p><strong>This week TLDR i.e. 1 minute version </strong>(For executives):</p><ol><li><p>Amazon Inspector enhances the security engine for container images scanning. </p></li><li><p>AWS CloudTrail network activity events for VPC endpoints now generally available.</p><p></p></li></ol><p><strong>Trending in Cloud &amp; Cyber Security</strong>:</p><ol><li><p>AWS Security Blogs &amp; Bulletins:</p><ul><li><p>How to restrict Amazon S3 bucket access to a specific IAM role? <a href="https://aws.amazon.com/blogs/security/how-to-restrict-amazon-s3-bucket-access-to-a-specific-iam-role/">Link</a>. </p></li><li><p>Introducing the AWS Trust Center. <a href="https://aws.amazon.com/blogs/security/introducing-the-aws-trust-center/">Link</a>. </p></li></ul></li><li><p>General security blogs, articles, reports &amp; trending news/advisories:</p><ul><li><p>whoAMI: A cloud image name confusion attack by Seth Art. <a href="https://securitylabs.datadoghq.com/articles/whoami-a-cloud-image-name-confusion-attack/">Link</a>. </p></li><li><p>Uncovering a Hidden CloudTrail Bug by Tracing AWS AssumeRole Chains in a Graph Database by Or Aspir. <a href="https://medium.com/@oraspir/uncovering-a-hidden-cloudtrail-bug-by-tracing-aws-assumerole-chains-in-a-graph-database-8ff55405c73d">Link</a>. </p></li><li><p>Tool: Cloud Trail Discover cheat sheet. <a href="https://traildiscover.cloud/">Link</a>. </p></li><li><p>Find Hidden AWS Resources With Effective Wordlists by Daniel Grzelak. <a href="https://www.plerion.com/blog/find-hidden-aws-resources-with-effective-wordlists">Link</a>.</p></li><li><p>Chinese Entanglement | DLL Hijacking in the Asian Gambling Sector by  Aleksandar Milenkoski. <a href="https://www.sentinelone.com/labs/chinese-entanglement-dll-hijacking-in-the-asian-gambling-sector/">Link</a>. </p></li><li><p>North Korean Threat Actors Observed Exploiting Trusted Platforms for Targeted Attacks by Den Iuzvyk, Tim Peck. <a href="https://www.securonix.com/blog/analyzing-deepdrive-north-korean-threat-actors-observed-exploiting-trusted-platforms-for-targeted-attacks/">Link</a>. </p></li><li><p>New Phishing Campaign Abuses Webflow, SEO, and Fake CAPTCHAs by Jan Michael Alcantara. <a href="https://www.netskope.com/blog/new-phishing-campaign-abuses-webflow-seo-and-fake-captchas">Link</a>. </p></li><li><p>CyberArk snaps up Zilla Security for up to $175M. <a href="https://techcrunch.com/2025/02/13/cyberark-snaps-up-zilla-security-for-up-to-175m/">Link</a>. </p></li><li><p>Storm-2372 conducts device code phishing campaign by Microsoft Threat Intelligence. <a href="https://www.microsoft.com/en-us/security/blog/2025/02/13/storm-2372-conducts-device-code-phishing-campaign/">Link</a>. </p></li><li><p>Oh, Auth 2.0! Device Code Phishing in Google Cloud and Azure by Matt Kiely. <a href="https://www.huntress.com/blog/oh-auth-2-0-device-code-phishing-in-google-cloud-and-azure">Link</a>. </p></li></ul></li></ol><p> </p><p><strong>This week Long i.e. 3-5 minutes version </strong>(For architects &amp; engineers):</p><ol><li><p>Amazon Inspector has upgraded the engine that powers container image scanning for Amazon Elastic Container Registry (ECR), which now offers a more comprehensive view of vulnerabilities in third-party dependencies within container images. Note: The new engine reassesses all existing resources, so you may notice some findings being closed while new vulnerabilities are identified based on the updated dependency collection. <a href="https://aws.amazon.com/about-aws/whats-new/2025/02/amazon-inspector-security-engine-container-images-scanning/">Link</a>. </p></li><li><p>AWS announced general availability of network activity events for Amazon Virtual Private Cloud (Amazon VPC) endpoints in AWS CloudTrail, which enables you to log and monitor AWS API activity passing through your VPC endpoints. Previously, VPC endpoint policies could restrict access from external accounts, there was no built-in capability to log denied actions or identify when external credentials were used at a VPC endpoint. <a href="https://aws.amazon.com/blogs/aws/aws-cloudtrail-network-activity-events-for-vpc-endpoints-now-generally-available/">Link</a>. For example, this is my config:</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!m2qI!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F79ad80f5-2fb1-4fc6-bfae-c3d5aa66c798_2444x1364.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!m2qI!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F79ad80f5-2fb1-4fc6-bfae-c3d5aa66c798_2444x1364.png 424w, https://substackcdn.com/image/fetch/$s_!m2qI!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F79ad80f5-2fb1-4fc6-bfae-c3d5aa66c798_2444x1364.png 848w, https://substackcdn.com/image/fetch/$s_!m2qI!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F79ad80f5-2fb1-4fc6-bfae-c3d5aa66c798_2444x1364.png 1272w, https://substackcdn.com/image/fetch/$s_!m2qI!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F79ad80f5-2fb1-4fc6-bfae-c3d5aa66c798_2444x1364.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!m2qI!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F79ad80f5-2fb1-4fc6-bfae-c3d5aa66c798_2444x1364.png" width="2444" height="1364" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/79ad80f5-2fb1-4fc6-bfae-c3d5aa66c798_2444x1364.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1364,&quot;width&quot;:2444,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:257999,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!m2qI!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F79ad80f5-2fb1-4fc6-bfae-c3d5aa66c798_2444x1364.png 424w, https://substackcdn.com/image/fetch/$s_!m2qI!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F79ad80f5-2fb1-4fc6-bfae-c3d5aa66c798_2444x1364.png 848w, https://substackcdn.com/image/fetch/$s_!m2qI!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F79ad80f5-2fb1-4fc6-bfae-c3d5aa66c798_2444x1364.png 1272w, https://substackcdn.com/image/fetch/$s_!m2qI!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F79ad80f5-2fb1-4fc6-bfae-c3d5aa66c798_2444x1364.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p></p><p></p><p></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://invary.com/" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Oy16!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F73bf36af-d79b-497e-922c-3aef0908c21b_1146x338.png 424w, https://substackcdn.com/image/fetch/$s_!Oy16!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F73bf36af-d79b-497e-922c-3aef0908c21b_1146x338.png 848w, https://substackcdn.com/image/fetch/$s_!Oy16!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F73bf36af-d79b-497e-922c-3aef0908c21b_1146x338.png 1272w, https://substackcdn.com/image/fetch/$s_!Oy16!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F73bf36af-d79b-497e-922c-3aef0908c21b_1146x338.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Oy16!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F73bf36af-d79b-497e-922c-3aef0908c21b_1146x338.png" width="1146" height="338" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/73bf36af-d79b-497e-922c-3aef0908c21b_1146x338.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:338,&quot;width&quot;:1146,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:97149,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:&quot;https://invary.com/&quot;,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!Oy16!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F73bf36af-d79b-497e-922c-3aef0908c21b_1146x338.png 424w, https://substackcdn.com/image/fetch/$s_!Oy16!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F73bf36af-d79b-497e-922c-3aef0908c21b_1146x338.png 848w, https://substackcdn.com/image/fetch/$s_!Oy16!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F73bf36af-d79b-497e-922c-3aef0908c21b_1146x338.png 1272w, https://substackcdn.com/image/fetch/$s_!Oy16!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F73bf36af-d79b-497e-922c-3aef0908c21b_1146x338.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p></p><p></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://aws-cloudsec.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://aws-cloudsec.com/subscribe?"><span>Subscribe now</span></a></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://aws-cloudsec.com/p/issue-84?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://aws-cloudsec.com/p/issue-84?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share</span></a></p><p></p></li></ol><p></p><p></p>]]></content:encoded></item><item><title><![CDATA[Issue 83]]></title><description><![CDATA[7 days of Cloud Security, recapped in 7 minutes or less!]]></description><link>https://aws-cloudsec.com/p/issue-83</link><guid isPermaLink="false">https://aws-cloudsec.com/p/issue-83</guid><dc:creator><![CDATA[AWS-CloudSec Weekly Newsletter]]></dc:creator><pubDate>Tue, 11 Feb 2025 23:42:04 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe69a553d-ed82-4e57-a892-09bd3c3e3c56_1200x1200.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p><strong>This week TLDR i.e. 1 minute version </strong>(For executives):</p><ol><li><p>AWS IAM announces support for encrypted SAML assertions. </p></li><li><p>AWS Verified Access launches Zero Trust access to resources over non-HTTP(S) protocols. </p></li><li><p>Amazon GuardDuty Malware Protection for S3 announces price reduction. </p></li><li><p>AWS IAM Identity Center now offers improved error messages and AWS CloudTrail logging for provisioning issues.</p></li><li><p>AWS WAF Console adds new top insights visualizations in additional regions.</p></li><li><p>AWS Secrets and Configuration Provider now integrates with Pod Identity for Amazon EKS.</p><p></p></li></ol><p><strong>Trending in Cloud &amp; Cyber Security</strong>:</p><ol><li><p>AWS Security Blogs &amp; Bulletins:</p><ul><li><p>Implementing least privilege access for Amazon Bedrock. <a href="https://aws.amazon.com/blogs/security/implementing-least-privilege-access-for-amazon-bedrock/">Link</a>. </p></li><li><p>Enhancing telecom security with AWS. <a href="https://aws.amazon.com/blogs/security/enhancing-telecom-security-with-aws/">Link.</a> </p></li><li><p>Announcing ASCP integration with Pod Identity: Enhanced security for secrets management in Amazon EKS. <a href="https://aws.amazon.com/blogs/security/announcing-ascp-integration-with-pod-identity-enhanced-security-for-secrets-management-in-amazon-eks/">Link</a>. </p></li><li><p>How AWS Network Firewall session state replication maximizes high availability for your application traffic. <a href="https://aws.amazon.com/blogs/security/how-aws-network-firewall-session-state-replication-maximizes-high-availability-for-your-application-traffic/">Link</a>. </p></li></ul></li><li><p>General security blogs, articles, reports &amp; trending news/advisories:</p><ul><li><p>Tool: STS SAML Driver: SAML authentication handler for AWS STS that allows you to get temporary credentials using SAML to the AWS CLI. <a href="https://github.com/awslabs/StsSamlDriver">Link</a>. </p></li><li><p>GitHub: AWS Resource control policy examples. <a href="https://github.com/aws-samples/resource-control-policy-examples">Link</a>. </p></li><li><p>AWS IAM User Enumeration by Nate Wilson. <a href="https://rhinosecuritylabs.com/research/unauthenticated-username-enumeration-in-aws/">Link</a>. </p></li><li><p>How Adversaries Exploit Unmonitored Cloud Regions to Evade Detection by Permiso Team. <a href="https://permiso.io/blog/how-threat-actors-leverage-unsupported-cloud-regions">Link</a>. </p></li><li><p>The Complete Guide to Cloud-Native Ransomware Protection in Amazon S3 and KMS by Jason Kao. <a href="https://www.fogsecurity.io/blog/the-complete-guide-to-ransomware-protection-in-s3-and-kms">Link</a>. </p></li><li><p>Take my money: OCR crypto stealers in Google Play and App Store. <a href="https://securelist.com/sparkcat-stealer-in-app-store-and-google-play/115385/">Link</a><strong>. </strong></p></li><li><p>Bitcoin to the moon: Trump endorsing, scammers exploiting. <a href="https://www.cloudflare.com/threat-intelligence/research/report/bitcoin-to-the-moon-trump-endorsing-scammers-exploiting/">Link</a>. </p></li><li><p>Persistent Threats from the Kimsuky Group Using RDP Wrapper. <a href="https://asec.ahnlab.com/en/86098/">Link</a>. </p></li><li><p>Wiz: The State of AI in the Cloud 2025. <a href="https://www.wiz.io/state-of-ai-in-the-cloud">Link</a>. </p></li><li><p>Brave Browser: Using custom scriptlets to make the Web work the way you want. <a href="https://brave.com/privacy-updates/32-custom-scriptlets/">Link</a>. </p></li><li><p>20 AWS influencers to follow right now by Danny Aspinall. <a href="https://www.tenthrevolution.com/blog/20-aws-influencers-to-follow/">Link</a>. </p></li><li><p>Apple patch for &#8220;extremely sophisticated attack&#8221;. <a href="https://support.apple.com/en-us/122174">Link</a>. </p></li><li><p>Securing the Identity Attack Surface: A Deep Dive into the New Battlefield of Identity Security by Francis. <a href="https://softwareanalyst.substack.com/p/securing-the-identity-attack-surface">Link</a>. </p></li><li><p>Drata Acquires SafeBase. <a href="https://safebase.io/blog/drata-acquires-safebase">Link</a>. </p></li></ul></li></ol><p></p><p><strong>This week Long i.e. 3-5 minutes version </strong>(For architects &amp; engineers):</p><ol><li><p>AWS IAM now supports encrypted SAML assertions, enhancing security for federated single sign-on (SSO). SAML, a widely used open standard, allows identity providers (IdPs) to authenticate users and applications for AWS access. With this update, you can configure your IdP to encrypt SAML assertions before they are sent to IAM, ensuring protection against exposure when transmitted through intermediaries, like a web browsers. <a href="https://aws.amazon.com/about-aws/whats-new/2025/02/aws-iam-encrypted-saml-assertions/">Link</a>. For example, here&#8217;s the option for my identify provider.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!-YVW!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F64c6d199-5e04-43c8-a2a3-7a75e6794b0a_2424x1090.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!-YVW!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F64c6d199-5e04-43c8-a2a3-7a75e6794b0a_2424x1090.png 424w, https://substackcdn.com/image/fetch/$s_!-YVW!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F64c6d199-5e04-43c8-a2a3-7a75e6794b0a_2424x1090.png 848w, https://substackcdn.com/image/fetch/$s_!-YVW!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F64c6d199-5e04-43c8-a2a3-7a75e6794b0a_2424x1090.png 1272w, https://substackcdn.com/image/fetch/$s_!-YVW!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F64c6d199-5e04-43c8-a2a3-7a75e6794b0a_2424x1090.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!-YVW!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F64c6d199-5e04-43c8-a2a3-7a75e6794b0a_2424x1090.png" width="1456" height="655" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/64c6d199-5e04-43c8-a2a3-7a75e6794b0a_2424x1090.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:655,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:265340,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!-YVW!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F64c6d199-5e04-43c8-a2a3-7a75e6794b0a_2424x1090.png 424w, https://substackcdn.com/image/fetch/$s_!-YVW!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F64c6d199-5e04-43c8-a2a3-7a75e6794b0a_2424x1090.png 848w, https://substackcdn.com/image/fetch/$s_!-YVW!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F64c6d199-5e04-43c8-a2a3-7a75e6794b0a_2424x1090.png 1272w, https://substackcdn.com/image/fetch/$s_!-YVW!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F64c6d199-5e04-43c8-a2a3-7a75e6794b0a_2424x1090.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div></li><li><p>AWS Verified Access now supports secure access to resources using protocols like TCP, SSH, and RDP. This update enables VPN-less access to corporate applications and resources by leveraging AWS zero trust principles. It simplifies security operations by eliminating the need for separate access and connectivity solutions for non-HTTP(S) resources on AWS. <a href="https://aws.amazon.com/about-aws/whats-new/2025/02/aws-verified-access-zero-trust-resources-non-https-protocols/">Link</a>. For example, this is an example for a connection for RDS.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!5FDv!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa0062c06-5ff8-40e4-8ecc-e3c3d7955118_1514x1080.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!5FDv!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa0062c06-5ff8-40e4-8ecc-e3c3d7955118_1514x1080.png 424w, https://substackcdn.com/image/fetch/$s_!5FDv!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa0062c06-5ff8-40e4-8ecc-e3c3d7955118_1514x1080.png 848w, https://substackcdn.com/image/fetch/$s_!5FDv!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa0062c06-5ff8-40e4-8ecc-e3c3d7955118_1514x1080.png 1272w, https://substackcdn.com/image/fetch/$s_!5FDv!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa0062c06-5ff8-40e4-8ecc-e3c3d7955118_1514x1080.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!5FDv!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa0062c06-5ff8-40e4-8ecc-e3c3d7955118_1514x1080.png" width="1514" height="1080" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/a0062c06-5ff8-40e4-8ecc-e3c3d7955118_1514x1080.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1080,&quot;width&quot;:1514,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:133192,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!5FDv!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa0062c06-5ff8-40e4-8ecc-e3c3d7955118_1514x1080.png 424w, https://substackcdn.com/image/fetch/$s_!5FDv!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa0062c06-5ff8-40e4-8ecc-e3c3d7955118_1514x1080.png 848w, https://substackcdn.com/image/fetch/$s_!5FDv!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa0062c06-5ff8-40e4-8ecc-e3c3d7955118_1514x1080.png 1272w, https://substackcdn.com/image/fetch/$s_!5FDv!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa0062c06-5ff8-40e4-8ecc-e3c3d7955118_1514x1080.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div></li><li><p>Amazon GuardDuty Malware Protection for S3 is reducing the price for the data scanned dimension by 85%, lowering the cost in US East (N. Virginia) from $0.60 to $0.09 per GB. The pricing for objects evaluated remains unchanged. <a href="https://aws.amazon.com/about-aws/whats-new/2025/02/amazon-guardduty-malware-protection-s3-price-reduction/">Link</a>. You can find pricing details <a href="https://aws.amazon.com/guardduty/pricing/">HERE</a>. </p></li><li><p>AWS IAM Identity Center now offers enhanced error messages to simplify troubleshooting during user and group synchronization using SCIM or configurable AD sync. This is helpful in automated monitoring and auditing errors. <a href="https://aws.amazon.com/about-aws/whats-new/2025/02/aws-iam-identity-center-error-messages-cloudtrail-logging-provisioning-issues/">Link</a>. I don&#8217;t have a sync app but you can find CloudTrial logs examples <a href="https://docs.aws.amazon.com/singlesignon/latest/userguide/scim-logging-using-cloudtrail.html">HERE</a>. </p></li><li><p>AWS WAF&#8217;s console dashboard in the AWS GovCloud (US) Regions now features enhanced visualizations, providing deeper insights into top traffic sources. If you have CloudWatch logging destinations, you can access a new top insights section within the all traffic dashboard, offering richer visibility. <a href="https://aws.amazon.com/about-aws/whats-new/2025/02/aws-waf-console-top-insights-visualizations-additional-regions/">Link</a>. </p></li><li><p>AWS Secrets Manager now supports AWS Secrets and Configuration Provider (ASCP) integration with Amazon EKS Pod Identity, simplifying IAM authentication for retrieving secrets and parameters. This enhancement enables more efficient and secure IAM permission management for Kubernetes applications, allowing granular access control using role session tags. <a href="https://aws.amazon.com/about-aws/whats-new/2025/02/aws-secrets-configuration-provider-pod-identity-eks/">Link</a>. Well explained in <a href="https://aws.amazon.com/blogs/security/announcing-ascp-integration-with-pod-identity-enhanced-security-for-secrets-management-in-amazon-eks/">THIS</a> blog. </p><p></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://invary.com/" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Oy16!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F73bf36af-d79b-497e-922c-3aef0908c21b_1146x338.png 424w, https://substackcdn.com/image/fetch/$s_!Oy16!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F73bf36af-d79b-497e-922c-3aef0908c21b_1146x338.png 848w, https://substackcdn.com/image/fetch/$s_!Oy16!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F73bf36af-d79b-497e-922c-3aef0908c21b_1146x338.png 1272w, https://substackcdn.com/image/fetch/$s_!Oy16!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F73bf36af-d79b-497e-922c-3aef0908c21b_1146x338.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Oy16!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F73bf36af-d79b-497e-922c-3aef0908c21b_1146x338.png" width="1146" height="338" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/73bf36af-d79b-497e-922c-3aef0908c21b_1146x338.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:338,&quot;width&quot;:1146,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:97149,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:&quot;https://invary.com/&quot;,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!Oy16!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F73bf36af-d79b-497e-922c-3aef0908c21b_1146x338.png 424w, https://substackcdn.com/image/fetch/$s_!Oy16!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F73bf36af-d79b-497e-922c-3aef0908c21b_1146x338.png 848w, https://substackcdn.com/image/fetch/$s_!Oy16!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F73bf36af-d79b-497e-922c-3aef0908c21b_1146x338.png 1272w, https://substackcdn.com/image/fetch/$s_!Oy16!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F73bf36af-d79b-497e-922c-3aef0908c21b_1146x338.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p></p><p></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://aws-cloudsec.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://aws-cloudsec.com/subscribe?"><span>Subscribe now</span></a></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://aws-cloudsec.com/p/issue-83?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://aws-cloudsec.com/p/issue-83?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share</span></a></p><p></p></li></ol><p></p><p></p>]]></content:encoded></item></channel></rss>