Logo

dev-resources.site

for different kinds of informations.

Issue 41 of AWS Cloud Security Weekly

Published at
4/23/2024
Categories
security
aws
newsletter
iam
Author
aws-cloudsec
Categories
4 categories in total
security
open
aws
open
newsletter
open
iam
open
Author
12 person written this
aws-cloudsec
open
Issue 41 of AWS Cloud Security Weekly

(This is just the summary of Issue 41 of AWS Cloud Security weekly @ https://aws-cloudsec.com/p/issue-41 << Subscribe for FREE to receive the full version in your inbox weekly).

What happened in AWS CloudSecurity & CyberSecurity last week April 15-April 22, 2024?

  • AWS IAM Identity Center administrators can now set session durations for Amazon CodeWhisperer independently from other IAM Identity Center-integrated applications and the AWS access portal. This allows users of Amazon CodeWhisperer to work in their integrated development environments (IDEs) for up to 90 days without the need to re-authenticate. Previously, the session durations for CodeWhisperer in the IDE had to match those of other IAM Identity Center-integrated applications and the AWS access portal, typically ranging from 15 minutes to 90 days.
  • AWS Identity and Access Management (IAM) Roles Anywhere now lets you set up mapping rules to define which information is extracted from your X.509 end-entity certificates. These mapped details, known as attributes, are used as session tags in IAM policy conditions to allow or deny permissions. Attributes can be extracted from the subject, issuer, or subject alternative name (SAN) fields in the X.509 certificate. By default, all relative distinguished names (RDNs) from the certificate's subject and issuer are mapped, along with the first value of the domain name system (DNS), directory name (DN), and uniform resource identifier (URI) from the certificate's SAN. This new feature allows you to create a custom set of mapping rules and select only a subset of these certificate attributes that suit your business needs. This customization reduces the size and complexity of the tags used in authorization policies. The mapped attributes are linked to your profile. You can define these mapping rules using the put-attribute-mapping or delete-attribute-mapping APIs via the IAM Roles Anywhere console, AWS SDKs, or AWS CLI.

Trending on the news & advisories (Subscribe to the newsletter for details):

  • SEC Consult SA-20240411-0 :: Database Passwords in Server Response in Amazon AWS Glue.
  • PuTTY SSH client flaw allows recovery of cryptographic private keys. Link.
  • Orca- LeakyCLI: AWS and Google Cloud Command-Line Tools Can Expose Sensitive Credentials in Build Logs.
  • Lacework, last valued at $8.3B, is in talks to sell for just $150M to $200M, say sources.
  • UnitedHealth to take up to $1.6 billion hit this year from Change hack.
  • MITRE Response to Cyber Attack in One of Its R&D Networks.
  • CISA Announces Winners of the 5th Annual President’s Cup Cybersecurity Competition. Link.
newsletter Article's
30 articles in total
Favicon
Building an Open-Source AI Newsletter Engine
Favicon
The Observability Digest 36: AI Agents & Security Evolution πŸ€–πŸ”’
Favicon
Break the Code: Un Nuevo Comienzo
Favicon
The Observability Digest #0037: Platform Engineering Surge πŸ”πŸš€
Favicon
Code, Culture & Cognition: 24.43 – Fast, Good or Cheap. Pick Two.
Favicon
State of HTML 2024, Interop 2025, Chrome 129, Firefox 130, Safari 18, TypeScript 5.6, and more | Front End News #111
Favicon
Treasure Hunt - Engineering | Sep 2024
Favicon
πŸ“°AI-Powered Newsletter Creation: Building a Next.js Newsletter Generator with GitHub Copilot
Favicon
SnapNews (build in public)
Favicon
Blog x Newsletter
Favicon
How to Promote a New Newsletter on LinkedIn or X even Without Many Followers
Favicon
js13kGames 2024, Stack Overflow 2024 and State of React 2023 Results, Interop 2024 updates, and more | Front End News #110
Favicon
Back from holidays, CLI and some news
Favicon
Issue 59 of AWS Cloud Security Weekly
Favicon
Joyruns
Favicon
Step-by-Step Guide to Building Your Own AI Newsletter Automation Platform
Favicon
Issue 53 of AWS Cloud Security Weekly
Favicon
Wie ein Newsletter-System dir Zeit sparen kann
Favicon
The Front End Dev Handbook 2024, State of HTML and State of JavaScript 2023 Results, TypeScript 5.5 | Front End News #109
Favicon
Job Adventures - PDF generation | Jun 2024
Favicon
How a newsletter system can save you time
Favicon
Setting Up Listmonk: An Open-Source Newsletter Mailing System
Favicon
Newsletter "What's up devs ?" is born !
Favicon
Quick start to "Deyan with Code"
Favicon
35 Years of Web, Speedometer 3, Chrome 123-124, Firefox 124-125, Vivaldi mobile 6.6, and more | Front End News #108
Favicon
Gamedev.js Weekly newsletter gets… a new website!
Favicon
ABEND dump #10
Favicon
Issue 42 of AWS Cloud Security Weekly
Favicon
Top Productivity Newsletters to Boost Your Efficiency
Favicon
Issue 41 of AWS Cloud Security Weekly

Featured ones: