PLAY PODCASTS
AWS Morning Brief

AWS Morning Brief

733 episodes — Page 4 of 15

Ep 583The New Frontier of Cloud Economics: Why AWS Costs Are a Weighty Issue

AWS Morning Brief Extras edition for the week of October 25, 2023.Want to give your ears a break and read this as an article? You’re looking for this link.https://www.lastweekinaws.com/blog/the-new-frontier-of-cloud-economics-why-aws-costs-are-a-weighty-issueNever miss an episodeJoin the Last Week in AWS newsletterSubscribe wherever you get your podcastsHelp the showLeave a reviewShare your feedbackSubscribe wherever you get your podcastsBuy our merch https://store.lastweekinaws.comWhat's Corey up to?Follow Corey on Twitter (@quinnypig)See our recent work at the Duckbill GroupApply to work with Corey and the Duckbill Group to help lower your AWS bill

Oct 25, 20233 min

Ep 582The Pets-Not-Cattle Steer-ing Committee

AWS Morning Brief for the week of October 23, 2023, with Corey Quinn. Links:Introducing Amazon EC2 R7i instancesAWS announces Amazon Redshift integration with Visual Studio CodeAWS announces member account level credit sharing preferencesCloudWatch launches out-of-the-box alarm recommendations for AWS servicesLeapfrog from CentOS 7.9 to Red Hat Enterprise Linux 8.9 with Convert2RHEL and Leapp Utilities on AWSEnhance your security posture by storing Amazon Redshift admin credentials without human intervention using AWS Secrets Manager integrationArchive to cold storage with Amazon DynamoDB Keeping an eye on your cattle using AI technology Top 10 unforgettable moments from AWS GenAI Day Stellantis: driving innovation by investing in employees’ digital skills

Oct 23, 20234 min

Ep 581Delegate, Delegate, Delegate...

Last week in security news: Delegating permission set management and account assignment in AWS IAM Identity Center, How AWS protects customers from DDoS events, The Tip of the Week, and more!Links:Rhino Security has a two part post that talks about how they find Cognito misconfigurationsDelegating permission set management and account assignment in AWS IAM Identity Center How AWS protects customers from DDoS events Now available: Building a scalable vulnerability management program on AWSIssue with Amazon WorkSpaces Windows Client Version 5.9 and 5.10The Tip of the Week is to delegate as much as humanly possible to accounts that aren't the management account for the org. As more services gain the ability to delegate management to designated accounts, it gets easier to restrict access to it

Oct 19, 20233 min

Ep 580Cloud Institute for the Criminally Underpaid

AWS Morning Brief for the week of October 16, 2023 with Corey Quinn. Links:New Amazon CloudWatch metric monitors EC2 instance reachability to EBS volumesAnnouncing AWS Lambda’s support for Internet Protocol Version 6 (IPv6) for outbound connections in VPC Announcing new AWS Network Load Balancer (NLB) availability and performance capabilities Two billion downloads of Terraform AWS Provider shows value of IaC for infrastructure managementWhy purpose-built artificial intelligence chips may be key to your generative AI strategyHow Zalando migrated their shopping carts to Amazon DynamoDB from Apache Cassandra Unlocking cost-optimization: Open Raven’s journey with Amazon Aurora I/O-Optimized leads to 60% savingsHow does Cloud enable the transformation of Bank finance functions? AWS Cloud Institute: Virtual training program for cloud developers

Oct 16, 20236 min

Ep 579Better Late Than Even Later

Last week in security news: AWS Firewall Manager supports referencing of Security Groups, Secure by Design: AWS to enhance MFA requirements in 2024, You Can't Control Your Data in the Cloud, and more!Links:You Can't Control Your Data in the CloudChris Farris leaked 7 IAM keys in public (intentionally!Chris Farris also writes Security Hub gives me imposter syndromeGoogle is stuffing previously widely available security offerings into incredibly expensive paid-for tiers.AWS Firewall Manager supports referencing of Security GroupsSecure by Design: AWS to enhance MFA requirements in 2024 Reported TorchServe Issue (CVE-2023-43654)Tip of the week: patch the embargoed libcurl high-severity issue that was made public after this recording but before publishing.

Oct 12, 20234 min

Ep 578The Cloud Devil You Know

Want to give your ears a break and read this as an article? You’re looking for this link.https://www.lastweekinaws.com/blog/the-cloud-devil-you-know/Never miss an episodeJoin the Last Week in AWS newsletterSubscribe wherever you get your podcastsHelp the showLeave a reviewShare your feedbackSubscribe wherever you get your podcastsBuy our merch https://store.lastweekinaws.comWhat's Corey up to?Follow Corey on Twitter (@quinnypig)See our recent work at the Duckbill GroupApply to work with Corey and the Duckbill Group to help lower your AWS bill

Oct 11, 20237 min

Ep 577AWS Big Bag of Hammers

AWS Morning Brief for the week of October 10, 2023 with Corey Quinn. Links:Sponsor re:QuinnventAmazon DataZone is now generally availableAmazon EC2 Hibernate now supports more operating systems Lambda test events are now available in AWS SAM CLI Simplify data transfer: Google BigQuery to Amazon S3 using Amazon AppFlowComing November 2023: A new analysis experience on Amazon QuickSightImplement auto-increment with Amazon DynamoDBThe Future of Personal Digital Records: Unlocking Security and Efficiency through Blockchain and Smart ContractsSlack elevates media pipeline with AWS Elemental MediaConvert and Amazon TranscribeIntegrate multiple Microsoft Entra ID tenants with AWS IAM Identity CenterBuilding high-throughput satellite data downlink architectures with AWS Ground Station WideBand DigIF and Amphinicy Blink SDR Save the Date: Join AWS at the Reality Capture Network Conference, Oct 17 – Oct 19, 2023

Oct 10, 20236 min

Ep 576Email Vendor Selection Influences Security

Last week in security news: When It Comes to Email Security, The Cloud You Pick Matters, Enable external pipeline deployments to AWS Cloud by using IAM Roles Anywhere, How AWS threat intelligence deters threat actors, and more!Links:When It Comes to Email Security, The Cloud You Pick MattersEnable external pipeline deployments to AWS Cloud by using IAM Roles AnywhereGet the full benefits of IMDSv2 and disable IMDSv1 across your AWS infrastructure How AWS threat intelligence deters threat actorsOverhauling AWS Account Access with Terraform

Oct 5, 20233 min

Ep 575Incrementally Making Massive Improvements

AWS Morning Brief for the week of October 2, 2023, with Corey Quinn. Links:Amazon Chime adds Waiting Room capability to further secure your meetingsAmazon CloudFront announces security recommendations Amazon DocumentDB (with MongoDB compatibility) supports in-place major version upgradeAmazon EC2 Serial Console now available in additional AWS Regions AWS Application Composer now supports all 1000+ AWS CloudFormation resourcesDynamoDB global tables is now available in all AWS Regions Announcing incremental export to S3 for Amazon DynamoDBAmazon Bedrock Is Now Generally Available – Build and Scale Generative AI Applications with Foundation Models How to import existing resources into AWS CDK StacksIntroducing dual-stack and IPv6-only support for Amazon Route 53 Resolver Endpoints

Oct 2, 20233 min

Ep 574Cheating on your CI Tests

Last week in security news: Accelerating development with AWS CDK plugin – CfnGuardValidator, This week's S3 Bucket Negligence Award is brought to you by PwC Nigeria, The volkswagen open source tool, and more!Links:Last week I talked about AWS Management Console Access incorrectly. My thanks to Timothy Ingalls on the Last Week in AWS community Slack for flagging this for me. Gold star for you!This week's S3 Bucket Negligence Award is brought to you by PwC Nigeria.FusionAuth has a great dive into their annual SOC 2 vendor selection process.My beloved Retool has a post talking about how an MFA failure mode led to a small number of customers being exposed. Accelerating development with AWS CDK plugin – CfnGuardValidator How to implement cryptographic modules to secure private keys used with IAM Roles Anywhere Tool of the week: The volkswagen open source tool detects when your tests are being run in a CI server, and makes them pass.

Sep 28, 20233 min

Ep 573VirtuSwap's Giant Panda Accelerato

AWS Morning Brief for the week of September 25, 2023, with Corey Quinn. Links:Today Corey is hosting a drink-up at 6 PM in Seattle at Outer Planet Brewing. If you're in town / free, come on by; let him buy you a beer.Later this week Corey will be hosting an AMA on 9/27 @ noon PDT over on YouTube. Bring questions!Accenture Extends Generative AI Capabilities to Accelerate Adoption and Value on AWS New – Amazon EC2 M2 Pro Mac Instances Built on Apple Silicon M2 Pro Mac Mini Computers How Chime Financial uses AWS to build a serverless stream analytics platform and defeat fraudsters Centralizing management of AWS Lambda layers across multiple AWS AccountsHandle traffic spikes with Amazon DynamoDB provisioned capacityStreamline interstate Department of Motor Vehicles collaboration with Private Blockchain How to host your Unreal Engine game for under $1 per player with Amazon GameLift How United Airlines built a cost-efficient Optical Character Recognition active learning pipelineHow VirtuSwap accelerates their pandas ... -based trading simulations with an Amazon SageMaker Studio custom container and AWS GPU instancesProvision sandbox accounts with budget limits to reduce costs using AWS Control TowerReducing the Scope of Impact with Cell-Based Architecture - Reducing the Scope of Impact with Cell-Based ArchitectureFrom Massage Therapist to Cloud Associate with AWS Academy

Sep 25, 20235 min

Ep 572Longer Sessions Are All Right By Me

Last week in security news: AWS IAM Identity Center session duration limit increases from 7 to 90 days, Access accounts with AWS Management Console PrivatAccess, A dive through using Amazon Athena in Incident Response, and more!Links:This is an esoteric Firefox/Yubikey compatibility bug that I went blindly stumbling into and has been resolved.Chris Farris has a post up about deploying AWS Backup. In preparation for re:Invent, the MGM had a massive cybersecurity issueAmazon EC2 now supports Block Public Access for Amazon Machine ImagesAWS IAM Identity Center session duration limit increases from 7 to 90 daysAWS Identity and Access Management provides action last accessed information for more than 140 services Access accounts with AWS Management Console Private Access A dive through using Amazon Athena in Incident Response. This is important! Corey will be hosting an AMA on 9/27 @ noon PDT over on Twitch. Bring questions!

Sep 21, 20233 min

Ep 571Seeing the Benefits of a Cloud Career

AWS Morning Brief for the week of September 18, 2023 with Corey Quinn. Links:Amazon SNS FIFO topics now support message delivery to Amazon SQS Standard queuesAnnouncing API Gateway console refresh Cost Anomaly Detection increases custom anomaly monitor limit to 500Custom notifications are now available for AWS Chatbot How to Integrate Amazon CloudWatch Alarms with Atlassian Confluence Knowledge Articles Building a secure webhook forwarder using an AWS Lambda extension and TailscaleDeploy Generative AI Models on Amazon EKSTroubleshoot networking issues during database migration with the AWS DMS diagnostic support AMI Using AWS CloudFormation and AWS Cloud Development Kit to provision multicloud resourcesCombining content moderation services with graph databases & analytics to reduce community toxicityAWS Private Certificate AuthorityRetail Partner Conversations: How Rokt is impacting the future of retail Simplify access to internal information using Retrieval Augmented Generation and LangChain Agents How to view Azure costs using Amazon QuickSight Centralized Dashboard for AWS Config and AWS Security Hub Benefits of Domain Registration with Amazon Route 53 Use Bring your own IP addresses (BYOIP) and RFC 8805 for localization of Internet contentUsing NAT Gateways with multiple-Amazon VPCs at scale Navigating change: From ophthalmologist to AWS Cloud expert

Sep 18, 20234 min

Ep 569Overscoped Role? No, It's the Children Who Are Wrong

Last week in security news: Corey reported an over-scoped role to AWS security, The bad LastPass breach got even worse, How to enforce DNS name constraints in AWS Private CA, and more!Links:I reported an over-scoped role to AWS security; the response from the SageMaker Canvas team was that it's working as intended.The bad LastPass breach that continues to get worse once again somehow got worse.Microsoft has published a rather thorough postmortem about how their signing key was leaked.A security newsletter features a scam that I reported via Twitter.Google has gone from paragon of security to apparently now sharing aspects of your browsing history with websites in Chrome,Establishing a data perimeter on AWS: Allow access to company data only from expected networks How to enforce DNS name constraints in AWS Private CA Tool of the week: ThreatMapper hunts for threats in your production platforms, and ranks these threats based on their risk-of-exploit.

Sep 14, 20233 min

Ep 570Why Your CPU-Based Utilization Metric Is Absolute Nonsense

AWS Morning Brief Extras edition for the week of September 13, 2023.Want to give your ears a break and read this as an article? You’re looking for this link.https://www.lastweekinaws.com/blog/why-your-cpu-based-utilisation-metric-is-absolute-nonsense/Never miss an episodeJoin the Last Week in AWS newsletterSubscribe wherever you get your podcastsHelp the showLeave a reviewShare your feedbackSubscribe wherever you get your podcastsBuy our merch https://store.lastweekinaws.comWhat's Corey up to?Follow Corey on Twitter (@quinnypig)See our recent work at the Duckbill GroupApply to work with Corey and the Duckbill Group to help lower your AWS bill

Sep 13, 20234 min

Ep 568AWS Guild Dinner & Tournament

AWS Morning Brief for the week of September 11, 2023, with Corey Quinn. Links:Amazon Aurora and Amazon RDS announces Extended Support for MySQL and PostgreSQL databasesAmazon CloudWatch adds Amazon EKS control plane logs as Vended LogsAmazon CloudWatch Logs announces regular expression filter pattern syntax supportAs SwiftOnSecurity pointed out a week or two ago, a lot of folks can now discover firsthand just how many of their rules allow all 10* trafficIntroducing Amazon EC2 R7iz instances AWS Marketplace now supports AWS CloudTrail to improve procurement activity monitoring AWS Step Functions launches enhanced error handlingAWS Trusted Advisor adds 1 new fault tolerance checkAnnouncing daily disbursements for AWS Marketplace sellers Embracing FinOps to Maximize Cloud Value and Control Costs with the Deloitte FinOps Framework Transforming Aviation Maintenance with the Infosys Generative AI Solution Built on Amazon Bedrock How Vercel Shipped Cron Jobs in 2 Months Using Amazon EventBridge SchedulerHow contact center leaders can prepare for generative AI A Culture of Resilience How generative AI is energizing the beauty industryMigrating AWS Direct Connect to a new locationReduce the security and compliance risks of messaging apps with AWS Wickr AWS Guild Tournament builds cloud skills and innovative customer solutionsFrom chocolate sales to a career in cloud with training from AWS re/StartAmazon to Discontinue Honeycode App-Building Service

Sep 11, 20236 min

Ep 567Feeding the Snakes Barracuda

Last week in security news: Barracuda thought it drove 0-day hackers out of customers’ networks, A terrific guide for getting started with AWS security research, “Zukey” or “Amazon Basics Yubikey”, and more!Links:Barracuda thought it drove 0-day hackers out of customers’ networks.A terrific guide for getting started with AWS security research. Amazon Basics YubikeyTwo real-life examples of why limiting permissions works: Lessons from AWS CIRTValidate IAM policies by using IAM Policy Validator for AWS CloudFormation and GitHub ActionsFrom the world of tools: wapalyzer

Sep 7, 20232 min

Ep 566Degenerative AI

Last Week In AWS for the week of September 4, 2023, with Corey Quinn. Links:Amazon QuickSight adds scheduled and programmatic export to Excel format Amazon S3 now supports multivalue answer in response to DNS queriesAWS Backup now supports local time zone selections AWS Lambda Functions powered by AWS Graviton2 now available in 6 additional regions AWS Neuron adds support for Llama 2, GPT-NeoX, and SDXL generative AI models AWS Private CA launches Connector for Active Directory Streamlining Prior Authorization with Treatline’s Generative AI Platform for Healthcare and Insurance ProvidersUpdating AWS CloudFormation Stacks Without Service Disruption to Support Rapid Business InnovationWhy AWS Customers Choose to Procure Software Through Channel Partners in AWS Marketplace Announcing Amazon Managed Service for Apache Flink Renamed from Amazon Kinesis Data AnalyticsDeploy Amazon OpenSearch Serverless with Terraform How AWS AppFabric helps companies overcome tech overload Reinventing the in-store experience with Smart Store solutionsAutomatically generate impressions from findings in radiology reports using generative AI on AWS How MongoDB and AWS Collaborated to Enable Running the Open Source MongoDB Kafka Connector in Managed EnvironmentsEmbracing our broad responsibility for securing digital infrastructure in the European Union

Sep 5, 20235 min

Ep 565Everybody Owns This Podcast So Nobody Does

Last week in security news: How AWS built the Security Guardians program, Network Load Balancers now support Security groups, the Tool of the week, and more!Links:David Linthicum stakes out the position that in a multi-cloud world, centralized cloud security is now a must-have.Network Load Balancers now support Security groups How AWS built the Security Guardians program, a mechanism to distribute security ownershipKubernetes Security Issues (CVE-2023-3676, CVE-2023-3893, CVE-2023-3893) Tool of the week: SSOFixer

Aug 31, 20232 min

Ep 564us-west-1: The Flagship Region That Isn’t

AWS Morning Brief Extras edition for the week of August 30, 2023.Want to give your ears a break and read this as an article? You’re looking for this link.https://www.lastweekinaws.com/blog/us-west-1-the-flagship-region-that-isn-tNever miss an episodeJoin the Last Week in AWS newsletterSubscribe wherever you get your podcastsHelp the showLeave a reviewShare your feedbackSubscribe wherever you get your podcastsBuy our merch https://store.lastweekinaws.comWhat's Corey up to?Follow Corey on Twitter (@quinnypig)See our recent work at the Duckbill GroupApply to work with Corey and the Duckbill Group to help lower your AWS bill

Aug 30, 20236 min

Ep 563AWS Wallet Extractor

AWS Morning Brief for the week of August 28, 2023, with Corey Quinn. Links:Amazon Aurora Global Database introduces Global Database FailoverAmazon ElastiCache for Memcached simplifies creating new clusters in the AWS Management ConsoleImprovements to multi-account management for Amazon GuardDutyAWS Certificate Manager introduces Enterprise Controls to help govern certificate issuanceAWS Cost Explorer announces support for AWS Billing ConductorAWS Microservice Extractor now supports visualizing very large enterprise applicationsAWS re:Post launches an enhanced search experienceAnnouncing AWS ROSA console support for the ROSA with hosted control planes previewEC2 Hibernate now supports Amazon EC2 M7i and M7i-flex instancesManage Cost Allocation Tags with Last-Updated and Last-Used timestamps Protecting an AWS Lambda function URL with Amazon CloudFront and Lambda@Edge Choose AWS Graviton and cloud storage for your Ethereum nodes infrastructure on AWS How Amazon Finance Technologies built an event-driven and scalable remittance service using Amazon DynamoDBUpgrade from Amazon Aurora Serverless v1 to v2 with minimal downtimeNext Big Things for Retail – Generative AI leads the pack but isn’t aloneExplain medical decisions in clinical settings using Amazon SageMaker ClarifyBuild a serverless store finder site using Amazon Location ServiceConfiguring client IP address preservation with a Network Load Balancer in AWS Global Accelerator How to use pulse-level control on OQC’s superconducting quantum computerAWS Digital Sovereignty Pledge: Announcing new dedicated infrastructure options

Aug 28, 20236 min

Ep 562Storing Logs You Never Read

Last week in security news: Short session expiration does not help security, How to use AWS Verified Access logs to write and troubleshoot access policies, This week's S3 Bucket Negligence Award, and more!Links:A UK contractor wins this week's S3 Bucket Negligence Award.What happens when a Zero Day and Access Keys Collide in the Cloud.Short session expiration does not help securityHow to use AWS Verified Access logs to write and troubleshoot access policiesIAMbic purports to be able to alert you to changes to IAM polices via consuming CloudTrail logs

Aug 24, 20232 min

Ep 561SageMaker Podcast HealthOmics

AWS Morning Brief for the week of August 21, 2023 with Corey Quinn. Links:Corey is performing a live Q&A next month; submit your questions here!Amazon Polly launches new Gulf Arabic male NTTS voiceAWS HealthOmics supports cross-account sharing of omics analytics stores New – Amazon EC2 M7a General Purpose Instances Powered by 4th Gen AMD EPYC ProcessorsAmazon OpenSearch Serverless expands support for larger workloads and collections Reduce Lambda cold start times: migrate to AWS SDK for JavaScript v3 Architecting for Resilience in the cloud for critical railway systems How Amazon Shopping uses Amazon Rekognition Content Moderation to review harmful images in product reviewsZero-shot text classification with Amazon SageMaker JumpStartBuild a multi-account access notification system with Amazon EventBridgeGetting Started with CloudWatch agent and collectd Cost considerations and common options for AWS Network Firewall log managementAddressing gender inequity in the technology industry

Aug 21, 20236 min

Ep 560Dunking on Robots For InfoSec Clout

Last week in security news: Cloudonaut has an overview of AWS's security monitoring services, Chris Farris talks about Defining the Sensitive IAM Actions, What’s new in the world of tools, and more!Links:Cloudonaut has an overview of AWS's security monitoring servicesA deep exploration into how you can really screw up integrating GitHub with AWS.Chris Farris talks about Defining the Sensitive IAM Actions.AWS Security Profile: Get to know the AWS Identity Solutions team CVE-2023-20569 - RAS Poisoning - Inception - Paired with CVE-2022-40982 AVID is an AI Vulnerability Database.TinderSec threw up a scanner on GitHub so you can see if you've fallen prey to one of the classic OICD permissions blunders.

Aug 17, 20233 min

Ep 559The Amazon Prime Day 2023 AWS Bill

AWS Morning Brief Extras edition for the week of August 16, 2023.Want to give your ears a break and read this as an article? You’re looking for this link.https://www.lastweekinaws.com/blog/the-amazon-prime-day-2023-aws-bill/Never miss an episodeJoin the Last Week in AWS newsletterSubscribe wherever you get your podcastsHelp the showLeave a reviewShare your feedbackSubscribe wherever you get your podcastsBuy our merch https://store.lastweekinaws.comWhat's Corey up to?Follow Corey on Twitter (@quinnypig)See our recent work at the Duckbill GroupApply to work with Corey and the Duckbill Group to help lower your AWS bill

Aug 16, 202310 min

Ep 558A Call to aRNs

AWS Morning Brief for the week of August 14, 2023, with Corey Quinn. Links:Amazon's approach to RTOAmazon Interactive Video Service announces Real-Time Streaming Amazon MSK Serverless expands availability to three additional AWS RegionsAmazon VPC now supports primary IPv6 address on an elastic network interfaceAWS Artifact launches email notifications Announcing AWS Backup logically air-gapped vault (Preview) Mountpoint for Amazon S3 is now generally available Network Load Balancer now supports security groups Using response streaming with AWS Lambda Web Adapter to optimize performance AWS recognized as a Leader in 2023 Gartner Magic Quadrant for Contact Center as a Service with Amazon Connect

Aug 14, 20235 min

Ep 557Cloud Security Has a Good Week

Last week in security news: People are still discovering some effects of the latest Azure security breach, Introducing the first AWS Security Heroes, How to Receive Alerts When Your IAM Configuration Changes, and more!Links:Following the latest Azure breach, the CEO of Tenable says they can see banking customer credentials even now.Introducing the first AWS Security HeroesHow to Receive Alerts When Your IAM Configuration Changes Perform continuous vulnerability scanning of AWS Lambda functions with Amazon InspectorRecent Software-based Power Side-Channel Security Research You can totally use AWS's SSM agent as post-exploitation RAT malware

Aug 10, 20233 min

Ep 556AWS Begins Charging For Public IPv4 Addresses

AWS Morning Brief Extras edition for the week of August 8, 2023.Want to give your ears a break and read this as an article? You’re looking for this link.https://www.lastweekinaws.com/blog/breaking-aws-begins-charging-for-public-ipv4-addresses/Never miss an episodeJoin the Last Week in AWS newsletterSubscribe wherever you get your podcastsHelp the showLeave a reviewShare your feedbackSubscribe wherever you get your podcastsBuy our merch https://store.lastweekinaws.comWhat's Corey up to?Follow Corey on Twitter (@quinnypig)See our recent work at the Duckbill GroupApply to work with Corey and the Duckbill Group to help lower your AWS bill

Aug 9, 20235 min

Ep 555EC2's Weird Flex

AWS Morning Brief for the week of August 7, 2023 with Corey Quinn. Links:In Amazon's earnings call, Andy Jassy said that every Amazon team is working on Generative AIAmazon Route 53 adds support for 14 additional Top-Level Domains AWS NAT Gateway is now available in the AWS US West Phoenix Local ZoneAmazon EBS announces up to 128 volume attachments per EC2 instanceIntroducing Amazon EC2 M7i-flex and M7i instancesAmazon EventBridge Scheduler adds schedule deletion after completionAWS Application Composer updates: Undo and Redo, Export Canvas, and Local Sync ModeNow Open – AWS Israel (Tel Aviv ) RegionPrime Day 2023 Powered by AWS – All the Numbers Estimate cost savings for the Amazon Aurora I/O-Optimized feature using Amazon CloudWatch Empowering your workforce with Amazon WorkSpaces services and Microsoft 365Exploring Fn::ForEach and Fn::FindInMap enhancements in AWS CloudFormation Identify and optimize public IPv4 address usage on AWS

Aug 7, 20236 min

Ep 554Azure's Customer Contempt

Last week in security news: Patch your Ubuntu cloud workloads, Azure faces backlash following that stolen Microsoft signing key, IAM Roles Anywhere credential helper adds support for OS certificate stores, and more!Links:You almost certainly want to patch your Ubuntu cloud workloadsIf you care about what that stolen Microsoft signing key was capable of, Azure really wishes you would stop askingSenator Wyden is calling for Azure to be held responsible.In a frantic scramble, Azure is expanding access to cloud logging data for free IAM Roles Anywhere credential helper adds support for OS certificate storesCVE-2023-20593This handy script fetches SSO permission assignments.

Aug 3, 20233 min

Ep 553Just a Generative AI Company

AWS Morning Brief for the week of July 31, 2023, with Corey Quinn. Links:The new Amazon Chime 5 on Windows, macOS, and web is coming soon - Amazon Chime Help Center Access and Query are now generally available for Amazon Managed Blockchain AWS Lambda adds support for Python 3.11 AWS Entity Resolution: Match and Link Related Records from Multiple Applications and Data StoresNew – Amazon EC2 P5 Instances Powered by NVIDIA H100 Tensor Core GPUs for Accelerating Generative AI and HPC ApplicationsNew – AWS Public IPv4 Address Charge + Public IP Insights Preview – Enable Foundation Models to Complete Tasks With Agents for Amazon Bedrock Migrating AWS Lambda functions from the Go1.x runtime to the custom runtime on Amazon Linux 2 Introducing Smithy for Python Introducing AWS HealthScribe – automatically generate clinical notes from patient-clinician conversations using AWS HealthScribeAnalyze rodent infestation using Amazon SageMaker geospatial capabilitiesAWS Reaffirms its Commitment to Responsible Generative AI Amazon SageMaker Canvas announces SOME THINGS I AM NOT GOING TO TELL YOU ABOUT

Jul 31, 20237 min

Ep 552Protect Azure DevOps secrets? What a novel idea!

Last week in security news: A Guide to S3 Logging, Optimize AWS Config for AWS Security Hub, Amazon Told Drivers Not to Worry About In-Van Surveillance Cameras. Now Footage Is Leaking Online, and More!Links:Guide to S3 Logging Good on JumpCloud for disclosing a breach by some state-backed APT hacking group, but I learned about it from this article, and I'm a JumpCloud customer.Charlie Bel issued a security roadmap for Microsoft: Protect Azure DevOps secrets is the first item on it. What a novel idea!Amazon Told Drivers Not to Worry About In-Van Surveillance Cameras. Now Footage Is Leaking OnlineYes, the compromised Microsoft key that they glossed over is incredibly important and Microsoft is downplaying it something fierce.Optimize AWS Config for AWS Security Hub to effectively manage your cloud security postureTool of the Week: IAMActionHunter lets you query IAM permission policies

Jul 27, 20233 min

Ep 551Space Heaters Plus DNS Equals Cloud

AWS Morning Brief for the week of July 24 2023 with Corey Quinn. Links:Amazon CodeCatalyst now supports workflows triggered by GitHub pullAmazon S3 Inventory can include ACLs as object metadata in inventory reports Amazon SNS can now deliver mobile push notifications in twelve new regions Introducing Analytics on Amazon Lex AWS Mainframe Modernization service is now PCI DSS Compliant Best Practices for Developing an AWS Co-Sell Program Amazon Route 53 Resolver Now Available on AWS Outposts RackReimagine Software Development With CodeWhisperer as Your AI Coding Companion Orca Security’s journey to a petabyte-scale data lake with Apache Iceberg and AWS Analytics Capture clickstream data using AWS serverless services Amazon Simple Email Service adds email delivery features to revised free tier Service Quota Observability Across Regions and AccountsRemoving Unassociated Elastic IPsNavigating common use cases spanning AWS GovCloud (US) and standard AWS

Jul 24, 20236 min

Ep 550The Logging Tax Auditor

Last week in security news: An Amazon senior security engineer was indicted in a $9M digital currency heist, Microsoft had one heck of a breach, this week’s S3 Bucket Negligence Award, and more!Links:A write-up of someone's experience going through the publicly available flAWS 1&2 labsSigns of the recent Microsoft breach in your account are tied to an enhanced level of license.An Amazon senior security engineer was indicted in a $9M digital currency heistA far-right publisher earned this week's S3 Bucket Negligence AwardAmazon FSx for NetApp ONTAP supports write once, read many (WORM) protection with SnapLock IAM Policies and Bucket Policies and ACLs! Oh, My! (Controlling Access to S3 Resources) was updated.Tool of the week: AWS IAM Data has launched.

Jul 20, 20233 min

Ep 549It's Extremely Likely You Should Not Use GovCloud

AWS Morning Brief Extras edition for the week of July 19, 2023.Want to give your ears a break and read this as an article? You’re looking for this link.https://www.lastweekinaws.com/blog/its-extremely-likely-you-should-not-use-govcloud/Never miss an episodeJoin the Last Week in AWS newsletterSubscribe wherever you get your podcastsHelp the showLeave a reviewShare your feedbackSubscribe wherever you get your podcastsBuy our merch https://store.lastweekinaws.comWhat's Corey up to?Follow Corey on Twitter (@quinnypig)See our recent work at the Duckbill GroupApply to work with Corey and the Duckbill Group to help lower your AWS bill

Jul 19, 20235 min

Ep 548GitHub Actions Done Smartly

AWS Morning Brief for the week of July 17, 2023 with Corey Quinn. Links:Bullying ChatGPT into ranking the US Presidents by absorbencyAWS CodeBuild now supports GitHub ActionsAWS Lambda now detects and stops recursive loops in Lambda functionsAWS Fault Injection Simulator supports chaos engineering experiments on Amazon EKS PodsAWS announces inaugural State and Local Government Champions

Jul 17, 20233 min

Ep 547Avoiding a Git Landmine

Last week in security news: A deep dive into the DomainNetworks Snail Mail Scam by Krebs on Security, Tailscale is putting their terms and conditions on GitHub, The Tool/ Lesson of the Week, and more!Links:A deep dive into who's behind the DomainNetworks Snail Mail Scam by Krebs on Security.Tailscale is putting its terms and conditions on GitHub and invites users to subscribe to see diffs instead of legalese.Three ways to accelerate incident response in the cloud: insights from re:Inforce 2023Tool/ Lesson of the week: git-landmine

Jul 13, 20232 min

Ep 546Extracting Revenue and Also Teeth

AWS Morning Brief for the week of July 10, 2023 with Corey Quinn. Links:Last week I railed against what appeared to be AWS Transfer Family creating a new logging format.Last Week in AWS Job BoardAmazon CloudWatch now supports dashboard variablesAmazon DynamoDB now simplifies and lowers the cost of handling failed conditional writesMountpoint for Amazon S3 adds support for creating new files AWS Systems Manager Parameter Store increases API throughput limit Announcing DynamoDB local version 2.0 Building Generative AI into Marketing Strategies: A Primer How To Build an Email Service on SES Downgrade SQL Server Enterprise edition using AWS Systems Manager Document to reduce costITSkills4U: From dentistry to IT

Jul 10, 20234 min

Ep 545The Horrible Game That Inspired My Bank

Last week in security news: The Password Game, Customer Compliance Guides Now Available on AWS Artifact, The Tool of the Week, and more!Links:The Password GameLastPass has apparently locked customers out due to MFA resets. Customer Compliance Guides now available on AWS ArtifactTool of the Week: findmytakeover

Jul 6, 20232 min

Ep 544S3 Is Not a Backup (Replay)

AWS Morning Brief Extras edition for the week of July 5, 2023.Never miss an episodeJoin the Last Week in AWS newsletterSubscribe wherever you get your podcastsHelp the showLeave a reviewShare your feedbackSubscribe wherever you get your podcastsBuy our merch https://store.lastweekinaws.comWhat's Corey up to?Follow Corey on Twitter (@quinnypig)See our recent work at the Duckbill GroupApply to work with Corey and the Duckbill Group to help lower your AWS bill

Jul 5, 20235 min

Ep 543Amazon Basics Ohio

AWS Morning Brief for the week of July 3, 2023 with Corey Quinn. Links:AWS Lambda simplifies copying environment variables in the console code editorWhat is a spam trap and why you should care?How we learned to program with atoms in 24 hours flat Running an SSH server on AWS RoboMakerNew training series: Starting your Career with AWS CloudAWS to remove 62,000-message Simple Email Service 'always free' tier from August 2023AWS continues to invest in Ohio The INFORM Consumers Act takes effect on June 27. Here's how Amazon is protecting our customers and sellers from bad actors.

Jul 3, 20233 min

Ep 542Infosec Brain Worms

Last week in security news: 'Muddled Libra' Uses Oktapus-Related Smishing to Target Outsourcing Firms, Issue with AWS Directory Service EnableRoleAccess, S3 buckets being used in attacks on npm packages, and more!Links:This collection of best practices for managing root users at scale in AWS is worth a read'Muddled Libra' Uses Oktapus-Related Smishing to Target Outsourcing Firms.1Health is this week's winner of the S3 Bucket Negligence AwardBarracuda advises customers to rip the entire device out, throw it away, and replace it entirely. S3 buckets being used in attacks on npm packagesIssue with AWS Directory Service EnableRoleAccessTool of the week: xeol is an end-of-life package scanner.

Jun 29, 20232 min

Ep 541Amazon Calls Down Regulatory Lightning

AWS Morning Brief for the week of June 26, 2023 with Corey Quinn. Links:The FTC comment period about the business of cloud computing endedAmazon warehouse practices are now the focus of a senate probeThe FTC is suing Amazon for its Prime enrollment dark patternsAmazon’s iRobot acquisition is now the subject of an EU investigationThe launch of Amazon Clinic is being delayed after the senate asked some hard questionsAnnouncing Amazon EC2 Hpc7g instances AWS Lambda supports starting from timestamp for Kafka event sourcesAWS Step Functions launches Versions and Aliases AWS Transfer Family announces structured JSON log format5 Stages to Building a Successful Partner Practice with AWSSay Hello to 176 AWS Competency, Service Delivery, Service Ready, and MSP Partners Added or Renewed in MayHow GoDaddy Implemented a Multi-Region Event-Driven Platform at ScaleNew Amazon EC2 C7gn Instances: Graviton3E Processors and Up To 200 Gbps Network BandwidthFor actual technical depth, my thanks to David Cuthbert in the Last Week in AWS Slack Community for surfacing this AnandTech article.Stream VPC Flow Logs to Datadog via Amazon Kinesis Data FirehoseCreating real-time flood alerts with the cloudUse AWS Private Certificate Authority to issue device attestation certificates for MatterShould I use the hosted UI or create a custom UI in Amazon Cognito? - Trick question, you should use recurring Last Week in AWS sponsor FusionAuth instead. Coming soon: updates to AWS Certified Cloud Practitioner examHow I achieved all six specialty AWS Certifications on first attemptHow to win a $5 Amazon Gift Card, just by signing up for the Amazon News newsletter

Jun 26, 20235 min

Ep 540re:Inforce and fwd:cloudsec with Scott Piper

Last week in security news: Videos from fwd:cloudsec are now available on YouTube, AWS announces AWS Payment Cryptography, Amazon CodeGuru Security is now available in preview, and more!Links:There was lots of great content presented at fwd:cloudsec. The day-long videos are up on YouTube. You can use the schedule to help find the talks you're interested in.In contrast to AWS's "Shared Responsibility Model", I appreciate GCP's "Shared Fate Model" where they put their own skin in the game in ensuring their customers are protected. In their New Cryptomining Protection Program, they offer $1M in what is basically an insurance policy that comes with Security Command Center Premium.Bob McMillan from the WSJ reports that North Korean hackers have stolen more than $3 billion in crypto over the last 5 years, and their heists are now funding fully half of its ballistic missile program.a16z writes Hiring a Chief Information Security Officer.Removing header remapping from Amazon API Gateway, and notes about our work with security researchers - AWS made a breaking change to respond to a security issue. The security researchers that found the issue wrote their side of the story, describing it as AWS API Gateway header smuggling and cache confusion.Issue with AWS Directory Service EnableRoleAccess - AWS released a security bulletin for this issue, which they seem to do at random for security issues. Ben Bridts from Cloudar found and reported this issue which AWS has fixed. He goes into more detail in his blog post and in a talk at fwd:cloudsec.Amazon CloudWatch Logs data protection account level policy configurationAWS WAF Fraud Control launches account creation fraud prevention and reduced pricingAWS announces AWS Payment CryptographyAWS Transfer Family announces quantum-safe key exchange for SFTPAmazon CodeGuru Security is now available in previewAmazon Inspector announces the general availability of Code Scans for AWS Lambda functionAWS announces Software Bill of Materials export capability in Amazon InspectorAmazon EC2 Instance Connect supports SSH and RDP connectivity without public IP addressAmazon GuardDuty enhances console experience with findings summary viewAmazon Detective extends finding groups to Amazon InspectorAmazon S3 announces dual-layer server-side encryption for compliance workloadsAWS CloudTrail Lake launches curated dashboards for visualizing top CloudTrail trendsAWS IAM Identity Center now supports automated user provisioning from Google Workspace

Jun 22, 20237 min

Ep 539FTC Request, Answered: How Cloud Providers Do Business

AWS Morning Brief Extras edition for the week of June 21, 2023.Want to give your ears a break and read this as an article? You’re looking for this link.https://www.lastweekinaws.com/blog/ftc-request-answered-how-cloud-providers-do-businessNever miss an episodeJoin the Last Week in AWS newsletterSubscribe wherever you get your podcastsHelp the showLeave a reviewShare your feedbackSubscribe wherever you get your podcastsBuy our merch https://store.lastweekinaws.comWhat's Corey up to?Follow Corey on Twitter (@quinnypig)See our recent work at the Duckbill GroupApply to work with Corey and the Duckbill Group to help lower your AWS bill

Jun 21, 202313 min

Ep 538Guest Host for re:Inforce Week - Scott Piper!

AWS Morning Brief for the week of June 20th, 2023 with Scott Piper filling in for Corey Quinn. Links:AWS announces scripts to bulk updates policies per new AWS Billing and Cost Management permissions Amazon QuickSight now supports APIs to automate and accelerate assets deploymentAmazon Rekognition improves face search accuracy with user vectorsAWS Config supports recording exclusions by resource typeFalcon 40B foundation model from TII available on SageMaker JumpStartAmazon EMR supports price-capacity-optimized allocation strategy for EC2 Spot InstancesAmazon Verified Permissions is now generally availableAnnouncing Live Tail in Amazon CloudWatch Logs, providing real-time exploration of logsaidansteele/rdsconn

Jun 20, 20234 min

Ep 537Confused DevOps Professional

Last week in security news: CloudFlare had a Confused Deputy Vulnerability, Moving Away from IAM Identity Center, AWS KMS now supports importing asymmetric and HMAC keys, and more!Links:CloudFlare had a Confused Deputy Vulnerability As I move away from IAM Identity Center, I find it interesting that a lot of folks I respect are doing similar things.I was going to drag this otherwise awesome article disclosing the vulnerability they located within AWS CDK's eks.Cluster component.AWS KMS now supports importing asymmetric and HMAC keys Tool/ Tip of the week: List of documented and undocumented AWS API models

Jun 15, 20235 min

Ep 536The Leeches of AWS

AWS Morning Brief for the week of June 12, 2023 with Corey Quinn. Links:AWS CloudTrail Lake now supports selective start or stop ingestion of CloudTrail events AWS Glue for Ray is now generally available AWS Lambda adds support for Ruby 3.2AWS Mainframe Modernization service is now HIPAA eligibleAnnouncing AWS Snowblade for U.S Department of Defense JWCCAWS Trusted Advisor adds new checks for Amazon EFSAnnouncing the general availability of AWS Database Migration Service ServerlessAnnouncing Live Tail in Amazon CloudWatch Logs, providing real-time exploration of logsAWS announces scripts to bulk updates policies per new AWS Billing and Cost Management permissions Drug Analyzer on AWS Provides Analytics That Inform Treatment Decisions and Support New TherapiesSelecting cost effective capacity reservations for your business-critical workloads on Amazon EC2Announcing Container Image Signing with AWS Signer and Amazon EKS How to deploy workloads in a multicloud environment with AWS developer toolsHow businesses can gain ecommerce capabilities to increase sales A Guide to Maintaining a Healthy Email Database Using Amazon IVS for turnkey town hallsAWS’s long-term commitment to VirginiaHow AWS data centers reuse retired hardware

Jun 12, 20237 min

Ep 535A Hole in the S3 Buckets

Last week in security news: Thinkst Canary's Thinkstscapes, Multiple S3 Bucket Negligence Awards, Credit Card Payment Processing on AWS, and more!Links:Thinkst Canary's ThinkstscapesIt's been a while since we've seen a strong, confirmed S3 Bucket Negligence Award, but Toyota has a massive one dating back a decade.Oof, looks like Google's CloudSQL product had a vulnerability that would allow an attacker to escalate to GCP control plane permissions.Holy... Legion malware expands scope to target AWS CloudWatch as well.When it rains, it pours; Capita had an S3 Bucket Negligence Award as well!Credit Card Payment Processing on AWS - Don't do it. Pay Stripe. Amazon Security Lake is now generally availableAnnouncing the AWS Blueprint for Ransomware Defense Get custom data into Amazon Security Lake through ingesting Azure activity logs Tip of the week: When you're starting something new that might turn into a company, use SSO.

Jun 8, 20235 min

Ep 53417 Final Ways to Run Containers on AWS

AWS Morning Brief Extras edition for the week of June 7, 2023.Want to give your ears a break and read this as an article? You’re looking for this link.https://www.lastweekinaws.com/blog/17-final-ways-to-run-containers/Never miss an episodeJoin the Last Week in AWS newsletterSubscribe wherever you get your podcastsHelp the showLeave a reviewShare your feedbackSubscribe wherever you get your podcastsBuy our merch https://store.lastweekinaws.comWhat's Corey up to?Follow Corey on Twitter (@quinnypig)See our recent work at the Duckbill GroupApply to work with Corey and the Duckbill Group to help lower your AWS bill

Jun 7, 20239 min