PLAY PODCASTS
AWS Morning Brief

AWS Morning Brief

718 episodes — Page 5 of 15

Ep 518RSA Beckons to Sell You a Firewall

AWS Morning Brief for the week of April 24, 2023 with Corey Quinn. Links:If you're around tomorrow night (Tuesday) at 6PM, I'll be at The Ramp in SF; let me buy you a drink.Announcing Dev Environment dashboard for Amazon CodeCatalyst (Preview) Amazon DynamoDB now supports up to 50 concurrent table restoresAmazon EC2 supports Ubuntu Pro operating system in a subscription-included modelAmazon EFS now supports up to 10 GiB/s of throughput Increased visibility of your carbon emissions data with AWS Customer Carbon Footprint ToolPython 3.10 runtime now available in AWS Lambda Understanding techniques to reduce AWS Lambda costs in serverless applicationsUse Amazon DynamoDB global tables in DynamoDB Shell Announcing General Availability of Amazon CodeCatalyst

Apr 24, 20234 min

Ep 517Screwing Up the Messaging and Also the RSA Dates

Last week in security news: Creating an AWS Backup Account, Azure had another cross-tenant access vulnerability, Security Hub Hurts My Self-Esteem, and more!Links:Corey hosted a partner panel at AWS Container Day at KubeCon This post on using OIDC to secure your CI/CD pipelines mirrors what I did with GitHub actions a year or so ago.Teri Radichel has a piece on Creating an AWS Backup AccountSlack is conducting an absolute masterclass in how to screw up messaging to your target audience.Azure had another cross-tenant access vulnerabilitySecurity Hub Hurts My Self-EsteemAWS Security Profile: Matt Luttrell, Principal Solutions Architect for AWS IdentityTool of the Week: iamlive

Apr 20, 20234 min

Ep 516Barest Metal Instances

AWS Morning Brief for the week of April 17, 2023 with Corey Quinn. This week is RSA in San Francisco; I'll be haunting the expo hall at some point, so if you're in town say hi.Links:The Last Week in AWS Job Board continues to thrive; thanks for your ongoing support.Amazon Chime SDK updates Service Level AgreementAmazon CodeWhisperer is now generally availableAmazon Connect now enables agents to handle voice calls, chats, and tasks concurrentlyAmazon EC2 Serial Console is now available on EC2 bare metal instances Amazon RDS for MySQL now supports up to 15 read replicas for RDS Multi-AZ deployment option with two readable standby database instancesAWS Graviton2-based Amazon EC2 instances are available in additional regions AWS Ground Station now supports Wideband Digital Intermediate FrequencyAWS Lambda adds support for Node.js 18 in the AWS GovCloud (US) Regions Introducing AWS Lambda response streaming Understanding Amazon DynamoDB latency Announcing New Tools for Building with Generative AI on AWSAWS Now Supports Credentials-fetcher for gMSA on Amazon Linux 2023 AWS investment in South Africa results in economic ripple effect New Global AWS Data Processing Addendum 15 cool things we found inside the Spheres, Amazon’s urban rainforest in downtown Seattle

Apr 17, 20236 min

Ep 515"A Quiet Week" He Says, Tempting Fate

Last week in security news: Logging strategies for security incident response, A Department of Energy report shows some rather serious gaps in security monitoring, A dedicated repository of winners of the S3 Bucket Negligence Awards, and more!Links:Zoom took an outage and the message was clearly AWS generated. Root cause? Misconfigured SCP.A Department of Energy report shows some rather serious gaps in the security monitoring of their cloud environments.Logging strategies for security incident responseReduce triage time for security investigations with Amazon Detective visualizations and export dataTLS inspection configuration for encrypted traffic and AWS Network FirewallA dedicated repository of winners of the S3 Bucket Negligence Awards.

Apr 13, 20233 min

Ep 514LocalStack: Why Local Development for Cloud Workloads Makes Sense

AWS Morning Brief Extras edition for the week of April 12, 2023.Want to give your ears a break and read this as an article? You’re looking for this link.https://www.lastweekinaws.com/blog/localstack-why-local-development-for-cloud-workloads-makes-senseNever miss an episodeJoin the Last Week in AWS newsletterSubscribe wherever you get your podcastsHelp the showLeave a reviewShare your feedbackSubscribe wherever you get your podcastsBuy our merch https://store.lastweekinaws.comWhat's Corey up to?Follow Corey on Twitter (@quinnypig)See our recent work at the Duckbill GroupApply to work with Corey and the Duckbill Group to help lower your AWS bill

Apr 12, 20237 min

Ep 513Your Network Bill is Now Diamonds

AWS Morning Brief for the week of April 10, 2023 with Corey Quinn. Links:Console Toolbar is now generally available for AWS CloudShellAnnouncing CSV Export for AWS Resource Explorer Search ResultsAnnouncing Utilization Notifications for EC2 On-Demand CapacityEverything you need to know about AWS Billing Conductor’s new pricing modelHow to use Amazon CloudWatch to monitor Amazon DynamoDB table size and item count metricsImplement resource counters with Amazon DynamoDBAWS Organizations, moving an organization member account to another organization: Part 3Build secure multi-account multi-VPC connectivity for your applications with Amazon VPC Lattice Higher education cloud financial planning: A former CFO’s perspectiveHow the Think Big for Small Business program helps small businesses win big contractsAmazon started passing out Small Business labels to giant companies.Perfect imperfections: how AWS is innovating on diamond materials for quantum communication with Element Six

Apr 10, 20235 min

Ep 512A Repository of AWS Customer Breaches

Last week in security news: Gain insights and knowledge at AWS re:Inforce 2023, InvalidClientTokenId, a repository of AWS customer breaches, and more!Links:If you're in New York City proper, I hope to see you tonight at 7PM at Vol de NuitWe're hiring an Account Exec to handle media sales for this very podcast. Should you be the person who refers the successful candidate, we'll give you a $3K USD referral fee.Nick Frichette has found an undocumented Amplify API and used it to leak AWS Account IDs.Friend of the newsletter Chris Farris has started an AWS security consulting practice.Gain insights and knowledge at AWS re:Inforce 2023 How to use Amazon GuardDuty and AWS WAF v2 to automatically block suspicious hostsInvalidClientTokenId: The security token included in the request is invalid errorSomeone is curating this repository of AWS customer breaches.

Apr 6, 20233 min

Ep 511Friendship Started with Microservices

AWS Morning Brief for the week of April 3, 2023 with Corey Quinn. Links:Amazon Kendra launches Featured Results AWS Chatbot now supports search of AWS resources and AWS content AWS Copilot adds support for full customization with AWS CDK or YAML overrides AWS re:Post now includes AWS Knowledge Center articlesNew Cost Explorer users now get Cost Anomaly Detection by defaultIntroducing Data on EKS – Modernize Data Workloads on Amazon EKSFriend microservices using Amazon DynamoDB and event filtering

Apr 3, 20234 min

Ep 510GitHub's Bad Key Week

Last week in security news: Github accidentally published its RSA host keys for SSH, Automate IAM credential reports for large AWS Organizations, The Tool of the Week, and more!Links:Sad news; infosec luminary Kelly ‘Aloria’ Lum has regrettably passed away.Automate IAM credential reports for large AWS OrganizationsGithub accidentally published its RSA host keys for SSH.How to use Amazon Macie to reduce the cost of discovering sensitive dataUse backups to recover from security incidentsTool of the Week: Chekov

Mar 30, 20233 min

Ep 509S3 as an Eternal Service

AWS Morning Brief Extras edition for the week of March 29, 2023.Want to give your ears a break and read this as an article? You’re looking for this link.https://www.lastweekinaws.com/blog/s3-as-an-eternal-serviceNever miss an episodeJoin the Last Week in AWS newsletterSubscribe wherever you get your podcastsHelp the showLeave a reviewShare your feedbackSubscribe wherever you get your podcastsBuy our merch https://store.lastweekinaws.comWhat's Corey up to?Follow Corey on Twitter (@quinnypig)See our recent work at the Duckbill GroupApply to work with Corey and the Duckbill Group to help lower your AWS bill

Mar 29, 20236 min

Ep 508Amazon Snizz Bug Gets Fixed

AWS Morning Brief for the week of March 27, 2023 with Corey Quinn. Links:Allow Listing tool for testing new Billing, Cost Management and Account console permissions Amazon CloudWatch Logs adds support for new Amazon VPC Flow Logs metadata Amazon EC2 C6in, M6in, M6idn, R6in, and R6idn metal instances are now availableAmazon SNS (pronounced "Snizz") announces support for setting content-type request headers for HTTP/S notificationsAWS CodeBuild now supports a small GPU machine typeConfiguring .NET Garbage Collection for Amazon ECS and AWS LambdaIntegrating with GitHub Actions – Amazon CodeGuru in your DevSecOps PipelineDelete Empty CloudWatch Log SteamsGrowing AWS internet peering with 400 GbE

Mar 27, 20235 min

Ep 507Y'allbikey Configuration Guide

Last week in security news: The Many Ways to Access DynamoDB, a Yubikey configuration cheatsheet, and more!Links:The Many Ways to Access DynamoDB Scott Piper’s post on redacting AWS account IDs from public postsHow to use Google Workspace as an external identity provider for AWS IAM Identity Center Yubikey configuration cheatsheet

Mar 23, 20234 min

Ep 506Mining Your Data/Currency/Minerals

AWS Morning Brief for the week of March 20, 2023 with Corey Quinn. Links:jobs.lastweekinaws.comAmazon EC2 M1 Mac instances now support in-place operating system updatesAnnouncing Amazon Linux 2023 AWS Chatbot now available in Microsoft Teams Announcing cross-account support for Amazon S3 Multi-Region Access Points Talk about cloud with a non-cloud audience New – Use Amazon S3 Object Lambda with Amazon CloudFront to Tailor Content for End UsersImplementing an event-driven serverless story generation application with ChatGPT and DALL-EThe Future of Mining is in the Cloud

Mar 20, 20235 min

Ep 505The Government Gets It

Last week in security news: U.S. Officials are frustrated with cloud providers, Best Practices For Securing Your Home Network, The Tool of the Week, and more!Links:U.S. officials express significant frustration that cloud providers often up-charge customers to add security protectionsLightspin has a guide to SecDataOps and Vulnerability Management on AWSBest Practices For Securing Your Home Network.IAM Identity Center for AWS environments spanning AWS GovCloud (US) and standard Regions Establishing a data perimeter on AWS: Allow only trusted resources from my organizationHow to use policies to restrict where EC2 instance credentials can be used fromTool of the Week: Nosey Parker

Mar 16, 20234 min

Ep 504AWS's Anti-Competitive Move Hidden in Plain Sight

AWS Morning Brief Extras edition for the week of March 15, 2023.Want to give your ears a break and read this as an article? You’re looking for this link.https://www.lastweekinaws.com/blog/awss-anti-competitive-move-hidden-in-plain-sight/Never miss an episodeJoin the Last Week in AWS newsletterSubscribe wherever you get your podcastsHelp the showLeave a reviewShare your feedbackSubscribe wherever you get your podcastsBuy our merch https://store.lastweekinaws.comWhat's Corey up to?Follow Corey on Twitter (@quinnypig)See our recent work at the Duckbill GroupApply to work with Corey and the Duckbill Group to help lower your AWS bill

Mar 15, 20237 min

Ep 503Bored? See the AWS Job Board

AWS Morning Brief for the week of March 13, 2023 with Corey Quinn. Links:jobs.lastweekinaws.comAmazon EC2 announces the ability to create Amazon Machine Images (AMIs) that can boot on UEFI and Legacy BIOS AWS Application Composer is now generally availableAWS CloudShell now supports the modular variant of AWS Tools for PowerShell AWS Config now supports 18 new resource types AWS Lambda now supports up to 10 GB of ephemeral storage for Lambda functions in 6 additional regions AWS announces new competition structure for the 2023 SeasonAWS Resource Explorer supports 12 new resource typesAnnouncing lower data warehouse base capacity configuration for Amazon Redshift ServerlessMeet the Newest AWS Heroes – March 2023 Subscribe to AWS Daily Feature Updates via Amazon SNSCalculate Amazon DynamoDB reserved capacity recommendations to optimize costsHow to use deletion protection to enhance your Amazon DynamoDB table protection strategy Push notification engagement metrics tracking Build Cloud Operations skills using the new AWS Observability Training

Mar 13, 20235 min

Ep 502LastPass, LastHope, LostPass, LostHope

Last week in security news: Audit Log Wall of Shame, More info on the LastPass breach, the Tool of the Week, and more!Links:Audit Log Wall of ShameSaudi social media app Fayvo apparently had an unsecured databaseMore information has come to light about the LastPass breachThree ways to boost your email security and brand reputation with AWSTool of the week: Trailscraper is an open source project to get useful information out of CloudTrail logs.

Mar 9, 20234 min

Ep 501Happy Fun Podcast That Tells It Like It Is

AWS Morning Brief for the week of March 6, 2023 with Corey Quinn. Links:Amazon Aurora Serverless v1 now supports customer configurable maintenance windowsAmazon CloudWatch Internet Monitor is now generally availableAWS Lambda Powertools for .NET is now generally availableAmazon Neptune Serverless now scales down to 1 NCU to save costs AWS Control Tower announces a progress tracker for landing zone setup and upgradesIn the Works – AWS Region in Malaysia New – Amazon Lightsail for Research with All-in-One Research Environments Announcing Amazon ECS Task Definition Deletion Announcing the end of Windows Installer support for AWS Tools for Windows“Avatar: The Way of Water” and the future of filmmaking A detailed overview of Trusted Advisor Organizational Dashboard

Mar 6, 20236 min

Ep 500Corey Invades Seattle

Last week in security news: US Military emails leaked on an exposed server, How to monitor and query IAM resources at scale, the Tool of the Week, and more!Links:If you're in Seattle, come to Outer Planet Brewing this Sunday at 7PM and let Corey buy you a drink.Aiden Steele writes at length about using a recent enhancement to Systems Manager to pass out a role to all of your EC2 instances.US Military emails leaked on an exposed serverAmazon Detective launches an interactive workshop for investigating potential security issuesHow to monitor and query IAM resources at scale – Part 1 Tool of the week: a break-glass role to limit production access to the AWS console

Mar 2, 20232 min

Ep 499AWS is Asleep at the Lambda Wheel

AWS Morning Brief Extras edition for the week of March 1, 2023.Want to give your ears a break and read this as an article? You’re looking for this link.https://www.lastweekinaws.com/blog/aws-is-asleep-at-the-lambda-wheelNever miss an episodeJoin the Last Week in AWS newsletterSubscribe wherever you get your podcastsHelp the showLeave a reviewShare your feedbackSubscribe wherever you get your podcastsBuy our merch https://store.lastweekinaws.comWhat's Corey up to?Follow Corey on Twitter (@quinnypig)See our recent work at the Duckbill GroupApply to work with Corey and the Duckbill Group to help lower your AWS bill

Mar 1, 20238 min

Ep 498Listening to This Podcast Will Improve Your Hiring Diversity

AWS Morning Brief for the week of February 27, 2023 with Corey Quinn. Links:Amazon OpenSearch Service now lets you schedule service software updates during off-peak hours AWS App Runner now supports HTTP to HTTPS redirectAnnouncing the ability to enable AWS Systems Manager by default across all EC2 instances in an account New: AWS Telco Network Builder – Deploy and Manage Telco NetworksDeveloping portable AWS Lambda functionsUsing Porting Advisor for Graviton Query data with DynamoDB Shell – a command line interface for Amazon DynamoDBAWS and Hugging Face collaborate to make generative AI more accessible and cost efficientBranch Insurance improves hiring diversity and accelerates app development using AWS AppSyncGain compliance insights using the open source community for AWS CloudTrail The true costs of resiliency decisions

Feb 27, 20236 min

Ep 497A Little Security for Everyone

Last week in security news: More security woes for Azure, the AWS Survival Kit, CloudGPT, and more!Links:A security researcher reported a potential account compromise vector to Azure back in 2021. I once again want to draw your attention to the open source AWS Survival Kit. How to visualize IAM Access Analyzer policy validation findings with QuickSight Updated ebook: Protecting your AWS environment from ransomwareChatGPT is all the rage, and of course here's CloudGPT to analyze AWS policies for vulnerabilitiesScott Piper has a great tip for us this week: think of the vendors / partners who have roles in your AWS account.

Feb 23, 20235 min

Ep 496Amazon's Snowball Edge Frustrates This User

AWS Morning Brief Extras edition for the week of February 22, 2023.Want to give your ears a break and read this as an article? You’re looking for this link.https://www.lastweekinaws.com/blog/amazons-snowball-edge-frustrates-this-userNever miss an episodeJoin the Last Week in AWS newsletterSubscribe wherever you get your podcastsHelp the showLeave a reviewShare your feedbackSubscribe wherever you get your podcastsBuy our merch https://store.lastweekinaws.comWhat's Corey up to?Follow Corey on Twitter (@quinnypig)See our recent work at the Duckbill GroupApply to work with Corey and the Duckbill Group to help lower your AWS bill

Feb 22, 20238 min

Ep 495Technical Debt Cash-Out Refinance

Feb 21, 20236 min

Ep 494Attacked S3s and Guilty Pleas

Last week in security news: Ubiquiti inside attacker pleads guilty, Wiz 2023 State of the Cloud report, the tool of the week, and more!Links:That inside attacker who worked at jackass company Ubiquiti pleads guiltyDatadog's security folk discovered an AWS Console rate limit bypassWiz 2023 State of the Cloud reportThe anatomy of ransomware event targeting data residing in Amazon S3 Tool of the week: aws-firewall-factory

Feb 16, 20234 min

Ep 493The Dumbest Dollars a Cloud Provider Can Make (Replay)

AWS Morning Brief Extras edition for the week of February 15, 2023.Want to give your ears a break and read this as an article? You’re looking for this link.https://www.lastweekinaws.com/blog/the-dumbest-dollars-a-cloud-provider-can-make/Never miss an episodeJoin the Last Week in AWS newsletterSubscribe wherever you get your podcastsHelp the showLeave a reviewShare your feedbackSubscribe wherever you get your podcastsBuy our merch https://store.lastweekinaws.comWhat's Corey up to?Follow Corey on Twitter (@quinnypig)See our recent work at the Duckbill GroupApply to work with Corey and the Duckbill Group to help lower your AWS bill

Feb 15, 20236 min

Ep 492Santa's EKS Workshop Massacre

AWS Morning Brief for the week of February 13, 2023 with Corey Quinn. Links:Amazon Chime SDK now offers a Windows client libraryAmazon CloudWatch now supports high resolution metric extraction from structured logsAWS SAM CLI introduces ‘sam list’ command to inspect AWS SAM resources Get cost estimates faster with AWS Pricing Calculator bulk import New – Visualize Your VPC Resources from Amazon VPC Creation Experience Introducing the AWS ProServe Hadoop Migration Delivery Kit TCO tool Introducing the Amazon EKS Workshop Using GitHub Actions with Amazon CodeCatalyst Using Amazon CloudWatch metrics to monitor time to expiration for Reserved Instances

Feb 13, 20234 min

Ep 491Wait did you say "Drone Manufacturer?!"

Links:In this down market, it's good to know that jobs paying six (and rarely, seven!) figure salaries, giving bonuses, and of course including paid time off are still out there. Unfortunately they're working for cybercrime groups.Ian McKay is great--but given his history of creating awesome-yet-horrifying things in AWS I read this piece on Cedar (AWS's new policy language) Popular drone manufacturer CrowdStrike reports on how Adversaries Can Persist with AWS User Federation,How to set up ongoing replication from your third-party secrets manager to AWS Secrets Manager Want to chain roles in a way that works for more than an hour? Role Chain Juggling has you covered.

Feb 9, 20235 min

Ep 490The AWS Community Isn't for Amazonians

Want to give your ears a break and read this as an article? You’re looking for this link.https://www.lastweekinaws.com/blog/the-aws-community-isnt-for-amazoniansNever miss an episodeJoin the Last Week in AWS newsletterSubscribe wherever you get your podcastsHelp the showLeave a reviewShare your feedbackSubscribe wherever you get your podcastsBuy our merch https://store.lastweekinaws.comWhat's Corey up to?Follow Corey on Twitter (@quinnypig)See our recent work at the Duckbill GroupApply to work with Corey and the Duckbill Group to help lower your AWS bill

Feb 8, 20237 min

Ep 489Telling Customers What They Want To Hear

Links:Amazon announced its fourth quarter and FY 2022 results last week; Tim Bray has an analysis that's absolutely worth reading. Amazon CloudWatch now simplifies metric extraction from structured logsAmazon MemoryDB for Redis Announces 99.99% Availability Service Level AgreementAWS CloudTrail Lake now supports ingestion of activity events from non-AWS sourcesAWS announces access of Simple Monthly Calculator estimates in the AWS Pricing Calculator Amazon increases NAT Gateway’s capacity to support concurrent connections to a unique destinationAmazon EMR launches support for Amazon EC2 C7g (Graviton3) instances to improve cost performance for Spark workloads by 7–13%Analyze Amazon S3 storage costs using AWS Cost and Usage Reports, Amazon S3 Inventory, and Amazon Athena AWS shows why physical stores matter more than ever at NRF 2023

Feb 6, 20235 min

Ep 488Azure Improves Slowly

Links:Azure messed up a regular expressionGitHub's blog has a piece on passwordless deployments to the cloudLastPass has now admitted that the attackers stole customers' backups and encryption keyDeploy a dashboard for AWS WAF with minimal effort Thinkst's free service now supports credit card tokens.precloud is a suite of dynamic tests for infrastructure as code.

Feb 2, 20234 min

Ep 487S3 Encryption at Rest Does NOT Solve for Bucket Negligence

Want to give your ears a break and read this as an article? You’re looking for this link.https://www.lastweekinaws.com/blog/s3-encryption-at-rest-does-not-solve-for-bucket-negligence/Never miss an episodeJoin the Last Week in AWS newsletterSubscribe wherever you get your podcastsHelp the showLeave a reviewShare your feedbackSubscribe wherever you get your podcastsBuy our merch https://store.lastweekinaws.comWhat's Corey up to?Follow Corey on Twitter (@quinnypig)See our recent work at the Duckbill GroupApply to work with Corey and the Duckbill Group to help lower your AWS bill

Feb 1, 20238 min

Ep 486Timecode Burn-In, Employee Burn-Out

This episode is sponsored in part by the Google for Startups Cloud ProgramLinks:AWS Purity Test Amazon Detective adds Amazon VPC Flow Logs visualizations for Amazon EKS workloads AWS Elemental MediaLive adds timecode burn-in AWS Pricing Calculator now supports optimized pricing estimation for EC2 Dedicated Hosts Announcing Porting Advisor for Graviton Now Open — AWS Asia Pacific (Melbourne) Region in Australia Amazon OpenSearch Serverless is now generally available!AWS Lambda: Resilience under-the-hood VPC Routing Enhancements and GWLB Deployment PatternsIntroducing AWS Lambda runtime management controls

Jan 30, 20236 min

Ep 485Aspirational Audit Logs

Links:Datadog reports that an undocumented API allowed CloudTrail bypassMailChimp was breached and had customer data exposedFolks can use GitHub Codespaces to host and deliver malware.How to revoke federated users’ active AWS sessionsThe worst backup software known to humankind

Jan 26, 20235 min

Ep 4841000 Access Points of Light

Links:Amazon CloudFront now supports the request header order and header count headersAmazon ECS announces the new default console experience Amazon EFS Supports 1,000 Access Points per File SystemAWS Nitro Enclaves announces support for multiple enclavesAWS Network Optimization Tips Introducing multi-function packager, allowing more than one function per event trigger on Amazon CloudFront Winning the Cat-and-Mouse Race: Staying One Step Ahead of Streaming Free-Riders with GeoGuard and AWS

Jan 23, 20235 min

Ep 483Wait Did You Say Root API Keys?

Links:Join Corey in Phoenix next Sunday at 1PM at Zuzu for a community meet-up.Rackspace continues to trickle the truth out; it's now admitting that attackers accessed customer data Tom Forbes scanned--wait, holy hell, he scanned every package on PyPi and found 57 live AWS keys. In one year we're going to come back and see how accurate the heads of AWS security are with their predictions for cybersecurity in 2023Today's tip of the week is to go fire up your important AWS account(s) and validate that the root user doesn't have API credentials assigned.

Jan 19, 20234 min

Ep 482Four Announcements of the Boring Apocalypse

Links:Join Corey in Phoenix next Sunday at 1PM at Zuzu for a community meet-up.AWS Config supports 22 new resource types Changes to AWS Billing, Cost Management, and Account Consoles PermissionsRun a popular benchmark on Amazon Redshift Serverless easily with AWS Data ExchangeHow to optimize costs for grant-based research projects with AWS

Jan 17, 20236 min

Ep 481Computers Checking Compliance Boxes

This episode is sponsored in part by the Google for Startups Cloud ProgramLinks:CircleCI came out with a security alert urging you to rotate any secrets stored in CircleCI.Another bite at the craptastic LastPass breach response, this article parses their weak-sauce PR statement Over the holidays Slack had some private GitHub code repositories stolen.ACSESSED is another Azure vulnerabilityAmazon S3 Encrypts New Objects By Default Updated whitepaper available: AWS Security Incident Response Guideiamfast analyzes your application code to generate a least-privilege IAM policy.Wiz has come up with and open sourced PEACH, a tenant isolation framework for cloud applications.

Jan 12, 20235 min

Ep 480The Work of Sober Minds

Links:Amazon CloudFront now supports the removal of response headers Amazon SageMaker is now available in AWS Middle East (UAE) RegionAmazon Neptune announces graph-explorer, an open-source visual exploration tool for low-code usersAn elastic deployment of Stable Diffusion with Discord on AWS Measure the Business Impact of Personalize Recommendations How Heineken’s Connected Brewery Ecosystem fuels automation

Jan 9, 20234 min

Ep 479LastStrawPass

inks:AWS Lambda Security Threats and MitigationsLastPass now admits that hackers stole customers’ password vaults.Google WordPress Plug-in Bug McGraw Hill earned this week’s S3 Bucket Negligence Award for exposing 100K students' gradesAnnouncing the new security widget on AWS Console Home Introducing the Security Design of the AWS Nitro System whitepaper Please +1 my request to add support for an ~/.aws/config.d/ directory to the AWS cli.

Dec 29, 20224 min

Ep 478Holiday Replay: Why I Turned Down an AWS Job Offer

This episode originally aired on October 13, 2021Check out a related YouTube Video here: https://youtu.be/BCiUulzr9f8Never miss an episodeJoin the Last Week in AWS newsletterSubscribe wherever you get your podcastsHelp the showLeave a reviewShare your feedbackSubscribe wherever you get your podcastsBuy our merch https://store.lastweekinaws.comWhat's Corey up to?Follow Corey on Twitter (@quinnypig)See our recent work at the Duckbill GroupApply to work with Corey and the Duckbill Group to help lower your AWS bill

Dec 28, 20227 min

Ep 477Soaking the US Navy

Links:Amazon Connect now allows contact center managers to join ongoing calls Amazon OpenSearch Service now supports Amazon Graviton2 (M6g, C6g, R6g, and R6gd) instances in four additional regionsAWS IQ launches public profiles for companies AWS Organizations console adds support to centrally manage region opt-in settings on AWS accountsROSA now provides an AWS Management Console experience for satisfying ROSA prerequisites Amazon EMR Serverless cost estimator AWS Multi-Region Fundamentals - AWS Multi-Region Fundamentals Organize your AWS Serverless code to prevent merge conflicts

Dec 27, 20225 min

Ep 476A Bunch of Vulnerabilities is Called an Embarrassment

Links:Azure's VP of Security Engineering published a post describing their approach to cloud vulnerabilitiesPanther deployed Yubikeys internally and blogged about it.LastPass has (yet again) suffered a breach, and published a no-content advisory that TechCrunch took the time to parse through. Apparently Wiz decided to poke around a bit into IBM "Cloud" and found a bunch of security issues. Prepare for consolidated controls view and consolidated control findings in AWS Security Hub Reported ECR Public Gallery IssueFrom the world of tools: osquery turns your operating system into a database

Dec 22, 20224 min

Ep 475Holiday Replay: The Right and Wrong Way to Interview Engineers

This episode originally aired on July 17, 2020.Want to give your ears a break and read this as an article? You’re looking for this link.https://www.lastweekinaws.com/blog/the_right_and_wrong_way_to_interview_engineers/Never miss an episodeJoin the Last Week in AWS newsletterSubscribe wherever you get your podcastsHelp the showLeave a reviewShare your feedbackSubscribe wherever you get your podcastsBuy our merch https://store.lastweekinaws.comWhat's Corey up to?Follow Corey on Twitter (@quinnypig)See our recent work at the Duckbill GroupApply to work with Corey and the Duckbill Group to help lower your AWS bill

Dec 21, 202212 min

Ep 474Screwing Up the Cloud Economics Math

Links:Introducing concurrent account provisioning operations for AWS Control Tower AWS Cost Anomaly Detection now supports percentage-based thresholdsAWS Trusted Advisor adds new fault tolerance checksHeads-Up: Amazon S3 Security Changes Are Coming in April of 2023 LaunchDarkly’s journey from ingesting 1 TB to 100 TB per day with Amazon Kinesis Data Streams Visualizing the impact of AWS Lambda code updates New: AWS CLI v2 Docker images available on Amazon ECR Public

Dec 19, 20225 min

Ep 473Censoring Myself Out of Pure Self-Interest

Links:Infosys leaked FullAdminAccess AWS keys on PyPi for over a year.Rackspace has suffered a ransomware attack AWS Security Hub now integrates with AWS Control TowerAWS Verified Access Preview — VPN-less Secure Network Access to Corporate ApplicationsThe Open Source Security Index

Dec 15, 20224 min

Ep 472A Multi-Cloud Rant (Holiday Replay)

This episode was originally released on August 20, 2021.Want to give your ears a break and read this as an article? You’re looking for this link.https://www.lastweekinaws.com/blog/a_multicloud_rant/Want to watch a rant about Multi-Cloud? Watch our Multi-Cloud is a Terrible Idea YouTube Video here: https://youtu.be/Mlr7vioQqwgNever miss an episodeJoin the Last Week in AWS newsletterSubscribe wherever you get your podcastsHelp the showLeave a reviewShare your feedbackSubscribe wherever you get your podcastsBuy our merch https://store.lastweekinaws.comWhat's Corey up to?Follow Corey on Twitter (@quinnypig)See our recent work at the Duckbill GroupApply to work with Corey and the Duckbill Group to help lower your AWS bill

Dec 14, 20227 min

Ep 471The Dryer Ate the SOC

Links:Amazon VPC IP Address Manager (IPAM) is now available in the AWS GovCloud (US) RegionsAWS CloudShell is now System and Organization Controls (SOC) compliantEmail delta cost usage report in a multi-account organization using AWS LambdaAWS re:Invent 2022 CEO Keynote through the Cloud Financial Management lensBuild a robust text-based toxicity predictor

Dec 12, 20225 min

Ep 470The Unfulfilled Promise of Serverless

Want to give your ears a break and read this as an article? You’re looking for this link.https://www.lastweekinaws.com/blog/The-Unfulfilled-Promise-of-Serverless/This episode was originally released on November 3, 2021. Never miss an episodeJoin the Last Week in AWS newsletterSubscribe wherever you get your podcastsHelp the showLeave a reviewShare your feedbackSubscribe wherever you get your podcastsBuy our merch https://store.lastweekinaws.comWhat's Corey up to?Follow Corey on Twitter (@quinnypig)See our recent work at the Duckbill GroupApply to work with Corey and the Duckbill Group to help lower your AWS bill

Dec 7, 20226 min

Ep 469re:Invent 2022 Retrospective: Releases & Opinions

Links:VPC Lattice -- network overlay.AWS Supply ChainAWS Application ComposerEventBridge pipesAmazon Security LakeAmazon OpenSearch ServerlessAmazon CodeCatalystAWS Wickr is now availableAWS Backup supports CloudFormation StacksAWS stimface weaver – space sim weaver… screw it. AWS SpiderBro it is.AWS launched a whole bunch of new EC2 instance types and sizes

Dec 5, 202214 min