dev-resources.site
for different kinds of informations.
Issue 41 of AWS Cloud Security Weekly
Published at
4/23/2024
Categories
security
aws
newsletter
iam
Author
aws-cloudsec
Author
12 person written this
aws-cloudsec
open
(This is just the summary of Issue 41 of AWS Cloud Security weekly @ https://aws-cloudsec.com/p/issue-41 << Subscribe for FREE to receive the full version in your inbox weekly).
What happened in AWS CloudSecurity & CyberSecurity last week April 15-April 22, 2024?
- AWS IAM Identity Center administrators can now set session durations for Amazon CodeWhisperer independently from other IAM Identity Center-integrated applications and the AWS access portal. This allows users of Amazon CodeWhisperer to work in their integrated development environments (IDEs) for up to 90 days without the need to re-authenticate. Previously, the session durations for CodeWhisperer in the IDE had to match those of other IAM Identity Center-integrated applications and the AWS access portal, typically ranging from 15 minutes to 90 days.
- AWS Identity and Access Management (IAM) Roles Anywhere now lets you set up mapping rules to define which information is extracted from your X.509 end-entity certificates. These mapped details, known as attributes, are used as session tags in IAM policy conditions to allow or deny permissions. Attributes can be extracted from the subject, issuer, or subject alternative name (SAN) fields in the X.509 certificate. By default, all relative distinguished names (RDNs) from the certificate's subject and issuer are mapped, along with the first value of the domain name system (DNS), directory name (DN), and uniform resource identifier (URI) from the certificate's SAN. This new feature allows you to create a custom set of mapping rules and select only a subset of these certificate attributes that suit your business needs. This customization reduces the size and complexity of the tags used in authorization policies. The mapped attributes are linked to your profile. You can define these mapping rules using the put-attribute-mapping or delete-attribute-mapping APIs via the IAM Roles Anywhere console, AWS SDKs, or AWS CLI.
Trending on the news & advisories (Subscribe to the newsletter for details):
- SEC Consult SA-20240411-0 :: Database Passwords in Server Response in Amazon AWS Glue.
- PuTTY SSH client flaw allows recovery of cryptographic private keys. Link.
- Orca- LeakyCLI: AWS and Google Cloud Command-Line Tools Can Expose Sensitive Credentials in Build Logs.
- Lacework, last valued at $8.3B, is in talks to sell for just $150M to $200M, say sources.
- UnitedHealth to take up to $1.6 billion hit this year from Change hack.
- MITRE Response to Cyber Attack in One of Its R&D Networks.
- CISA Announces Winners of the 5th Annual Presidentβs Cup Cybersecurity Competition. Link.
newsletter Article's
30 articles in total
Building an Open-Source AI Newsletter Engine
read article
The Observability Digest 36: AI Agents & Security Evolution π€π
read article
Break the Code: Un Nuevo Comienzo
read article
The Observability Digest #0037: Platform Engineering Surge ππ
read article
Code, Culture & Cognition: 24.43 β Fast, Good or Cheap. Pick Two.
read article
State of HTML 2024, Interop 2025, Chrome 129, Firefox 130, Safari 18, TypeScript 5.6, and more | Front End News #111
read article
Treasure Hunt - Engineering | Sep 2024
read article
π°AI-Powered Newsletter Creation: Building a Next.js Newsletter Generator with GitHub Copilot
read article
SnapNews (build in public)
read article
Blog x Newsletter
read article
How to Promote a New Newsletter on LinkedIn or X even Without Many Followers
read article
js13kGames 2024, Stack Overflow 2024 and State of React 2023 Results, Interop 2024 updates, and more | Front End News #110
read article
Back from holidays, CLI and some news
read article
Issue 59 of AWS Cloud Security Weekly
read article
Joyruns
read article
Step-by-Step Guide to Building Your Own AI Newsletter Automation Platform
read article
Issue 53 of AWS Cloud Security Weekly
read article
Wie ein Newsletter-System dir Zeit sparen kann
read article
The Front End Dev Handbook 2024, State of HTML and State of JavaScript 2023 Results, TypeScript 5.5 | Front End News #109
read article
Job Adventures - PDF generation | Jun 2024
read article
How a newsletter system can save you time
read article
Setting Up Listmonk: An Open-Source Newsletter Mailing System
read article
Newsletter "What's up devs ?" is born !
read article
Quick start to "Deyan with Code"
read article
35 Years of Web, Speedometer 3, Chrome 123-124, Firefox 124-125, Vivaldi mobile 6.6, and more | Front End News #108
read article
Gamedev.js Weekly newsletter gets⦠a new website!
read article
ABEND dump #10
read article
Issue 42 of AWS Cloud Security Weekly
read article
Top Productivity Newsletters to Boost Your Efficiency
read article
Issue 41 of AWS Cloud Security Weekly
currently reading
Featured ones: