PLAY PODCASTS
AWS Morning Brief

AWS Morning Brief

733 episodes — Page 7 of 15

Ep 433The Harrowing Search for the Elusive Technical Answer

Want to give your ears a break and read this as an article? You’re looking for this link.https://www.lastweekinaws.com/blog/the-harrowing-search-for-the-elusive-technical-answerWant to watch the full dramatic reenactment of this podcast? Watch the YouTube Video here: https://youtu.be/mZDquxNO09s\\Never miss an episodeJoin the Last Week in AWS newsletterSubscribe wherever you get your podcastsHelp the showLeave a reviewShare your feedbackSubscribe wherever you get your podcastsBuy our merch https://store.lastweekinaws.comWhat's Corey up to?Follow Corey on Twitter (@quinnypig)See our recent work at the Duckbill GroupApply to work with Corey and the Duckbill Group to help lower your AWS bill

Sep 7, 20229 min

Ep 43226.5 AWS Regions

AWS Morning Brief for the week of September 5, 2022 with Corey Quinn.

Sep 6, 20226 min

Ep 431The Spiritual Alignment of Cloud Economics

Links:Last week LastPass reported (yet another) security issue, wherein their source code was stolen. Finally: an honest recap of fwd:cloudsec and re:Inforce 2022 from someone who had the stomach to sit through the entirety of the latter.The Register reports on a growing trend of using AWS resources to hide phishing attacks.Expanded eligibility for the free MFA security key program How to centralize findings and automate deletion for unused IAM rolesIdentifying publicly accessible resources with Amazon VPC Network Access Analyzer The tool of the week: popeye is a Kubernetes cluster resource sanitizer.

Sep 1, 20224 min

Ep 430How Google Cloud and AWS Approach Customer Carbon Emissions

Want to give your ears a break and read this as an article? You’re looking for this link.https://www.lastweekinaws.com/blog/how-google-cloud-and-aws-approach-customer-carbon-emissionsWant to watch the full dramatic reenactment of this podcast? Watch the YouTube Video here: https://youtu.be/eyO1DqP9LhYNever miss an episodeJoin the Last Week in AWS newsletterSubscribe wherever you get your podcastsHelp the showLeave a reviewShare your feedbackSubscribe wherever you get your podcastsBuy our merch https://store.lastweekinaws.comWhat's Corey up to?Follow Corey on Twitter (@quinnypig)See our recent work at the Duckbill GroupApply to work with Corey and the Duckbill Group to help lower your AWS bill

Aug 31, 20228 min

Ep 429The Root Beer Conference

AWS Morning Brief for the week of August 29, 2022 with Corey Quinn.

Aug 29, 20227 min

Ep 428Rumors All Atwitter

Links:Fascinating allegations have come from Twitter's former CISO about an alleged trashfire approach to security intrinsic to their culture.Microsoft employees exposed their own Azure credentials via GitHubA fascinating discovery by the folks at WizHow to detect suspicious activity in your AWS account by using private decoy resources Remember to opt out of AWS AI data usage.

Aug 25, 20225 min

Ep 427Amazon SageMaker is Responsible for My Surprise Bill

Want to give your ears a break and read this as an article? You’re looking for this link. https://www.lastweekinaws.com/blog/sagemaker_is_responsible_for_my_surprise_bill/Want to watch the full dramatic reenactment of this podcast? Watch the YouTube Video here: https://youtu.be/LCZjSZhRAjsNever miss an episodeJoin the Last Week in AWS newsletterSubscribe wherever you get your podcastsHelp the showLeave a reviewShare your feedbackSubscribe wherever you get your podcastsBuy our merch https://store.lastweekinaws.comWhat's Corey up to?Follow Corey on Twitter (@quinnypig)See our recent work at the Duckbill GroupApply to work with Corey and the Duckbill Group to help lower your AWS bill

Aug 24, 202210 min

Ep 426Low Tech Earthquake Detection

AWS Morning Brief for the week of August 22, 2022 with Corey Quinn.

Aug 22, 20227 min

Ep 425Trivy-al Releases

Links:Apparently there's been some dependency confusion in AWS CodeArtifact.PlatformQ wins this week's S3 Bucket Negligence Award Found an interesting article that suggests that ransomware in AWS isn't a purely theoretical concern.Protocol interview with AWS CISO CJ Moses about his cloud security challenges.AWS co-announces release of the Open Cybersecurity Schema Framework (OCSF) projectTrivy is a security scanner for vulnerabilities in container images, Git repositories, filesystems, and various bits of configuration.

Aug 18, 20224 min

Ep 424An Unexpected Love Letter to Azure

Want to give your ears a break and read this as an article? You’re looking for this link.https://www.lastweekinaws.com/blog/an_unexpected_love_letter_to_azure/Want to watch the full dramatic reenactment of this podcast? Watch the YouTube Video here: https://youtu.be/NIsF_NS1B0kNever miss an episodeJoin the Last Week in AWS newsletterSubscribe wherever you get your podcastsHelp the showLeave a reviewShare your feedbackSubscribe wherever you get your podcastsBuy our merch https://store.lastweekinaws.comWhat's Corey up to?Follow Corey on Twitter (@quinnypig)See our recent work at the Duckbill GroupApply to work with Corey and the Duckbill Group to help lower your AWS bill

Aug 17, 20228 min

Ep 423AWS Private 5G v2

AWS Morning Brief for the week of August 15, 2022 with Corey Quinn.

Aug 15, 20227 min

Ep 422Twilio's Insecure Text Message Issue

Links:Twilio's disclosure of an Employee and Customer Account Compromise. Update of AWS Security Reference Architecture is now availableAs the linked tweet says: "If you check out the AWS docs on IAM policy parsing order there is a flowchart that shows you can get an Allow outcome before the boundary policy is evaluated." IAM-Deescalate: is an open source tool to help users reduce the risk of privilege escalation.

Aug 11, 20225 min

Ep 421Cadence Is Culture: Why Amazonians Need to Overload Us at re:Invent

Want to give your ears a break and read this as an article? You’re looking for this link.https://www.lastweekinaws.com/blog/why_amazon_cant_end_the_release_tidal_wave/Want to watch the full dramatic reenactment of this podcast? Watch the YouTube Video here: https://youtu.be/eKMxBNF5N-kNever miss an episodeJoin the Last Week in AWS newsletterSubscribe wherever you get your podcastsHelp the showLeave a reviewShare your feedbackSubscribe wherever you get your podcastsWhat's Corey up to?Follow Corey on Twitter (@quinnypig)See our recent work at the Duckbill GroupApply to work with Corey and the Duckbill Group to help lower your AWS bill

Aug 10, 20229 min

Ep 420Very Tired Lambda Pricing

AWS Morning Brief for the week of August 8, 2022 with Corey Quinn.

Aug 8, 20227 min

Ep 419Single Sign On, Multiple Names

Links:35K GitHub repos had been compromised by malware. GitHub security issued a response within 24 hours showing what their findings indicate and clarifying the situation.Scale your workforce access management with AWS IAM Identity Center (previously known as AWS SSO)Welcoming the AWS Customer Incident Response Team - Surprisingly this doesn't require a paid support plan.iamlive generates IAM policies from AWS calls via client-side monitoring

Aug 4, 20224 min

Ep 418Are AWS account IDs sensitive information?

Want to give your ears a break and read this as an article? You’re looking for this link.Never miss an episodeJoin the Last Week in AWS newsletterSubscribe wherever you get your podcastsHelp the showLeave a reviewShare your feedbackSubscribe wherever you get your podcastsWhat's Corey up to?Follow Corey on Twitter (@quinnypig)See our recent work at the Duckbill GroupApply to work with Corey and the Duckbill Group to help lower your AWS bill

Aug 3, 20227 min

Ep 417Crappy Clone of a Fast Database

AWS Morning Brief for the week of August 1, 2022 with Corey Quinn.

Aug 1, 20226 min

Ep 416Never Gonna Shut Me Up

Want to watch the full dramatic reenactment of this podcast? Watch the YouTube Video here: https://youtu.be/Q2Zpg5jQe-QNever miss an episodeJoin the Last Week in AWS newsletterSubscribe wherever you get your podcastsHelp the showLeave a reviewShare your feedbackSubscribe wherever you get your podcastsWhat's Corey up to?Follow Corey on Twitter (@quinnypig)See our recent work at the Duckbill GroupApply to work with Corey and the Duckbill Group to help lower your AWS bill

Jul 28, 20224 min

Ep 415The Mental Breakdown of Auto-Remediation

Links:The Nigerian government scores this week's S3 Bucket Negligence AwardNew Air-Gap Attack Uses SATA Cable as an Antenna to Transfer Radio SignalsAutomatically block suspicious DNS activity with Amazon GuardDuty and Route 53 Resolver DNS FirewallUse Security Hub custom actions to remediate S3 resources based on Macie discovery results There has been significant improvement to the AWS IAM documentation around IAM best practices.Artillery lets you use Lambdas for open source load testing.

Jul 27, 20225 min

Ep 414New Cloudscape Cloudscrapes

AWS Morning Brief for the week of July 25, 2022 with Corey Quinn.

Jul 25, 20227 min

Ep 413AWS's Disclosure Improvements

Links:Things I wish I knew about AWS WAF - Bot Control How to Protect Your Data from Ransomware with S3 Object LockIt seems that Experian has learned nothing from its string of data breachesThe Makati city government is the winner of this week's S3 Bucket Negligence award.A quick overview of AWS principals, identity-based policies, and resource-based policies.Eligible customers can now order a free MFA security keyReported EKS IAM Authenticator Issue I found a handy script that someone beat together that makes it easy as pie to use AWS Roles Anywhere.

Jul 21, 20225 min

Ep 412Azure's Security Vulnerabilities are Out of Control

Want to give your ears a break and read this as an article? You’re looking for this link.https://www.lastweekinaws.com/blog/azures_vulnerabilities_are_quackWant to watch the full dramatic reenactment of this podcast? Watch the YouTube Video here: https://youtu.be/5iTxtBnCPysNever miss an episodeJoin the Last Week in AWS newsletterSubscribe wherever you get your podcastsHelp the showLeave a reviewShare your feedbackSubscribe wherever you get your podcastsWhat's Corey up to?Follow Corey on Twitter (@quinnypig)See our recent work at the Duckbill GroupApply to work with Corey and the Duckbill Group to help lower your AWS bill

Jul 20, 20228 min

Ep 411Immortal AWS Accounts, the Methuselah Pattern

AWS Morning Brief for the week of July 18th, 2022 with Corey Quinn.

Jul 18, 20227 min

Ep 410AWS Bakery: Rolls Everywhere

Links:My article on the dangers of chatbots led someone to share this concern-affirming tale. Extend AWS IAM roles to workloads outside of AWS with IAM Roles Anywhere How to tune TLS for hybrid post-quantum cryptography with Kyber hasIAMfailedopenyet.com is a site that triggers a Lambda function on every invocation that attempts to access something it cannot.

Jul 14, 20225 min

Ep 409My Security Posture

Want to give your ears a break and read this as an article? You’re looking for this link.https://www.lastweekinaws.com/blog/coreys-security-posture-2022Want to watch the full dramatic reenactment of this podcast? Watch the YouTube Video here: https://youtu.be/dHDY69hIvvkNever miss an episodeJoin the Last Week in AWS newsletterSubscribe wherever you get your podcastsHelp the showLeave a reviewShare your feedbackSubscribe wherever you get your podcastsWhat's Corey up to?Follow Corey on Twitter (@quinnypig)See our recent work at the Duckbill GroupApply to work with Corey and the Duckbill Group to help lower your AWS bill

Jul 13, 202214 min

Ep 408How I Spent My Summer Vacation and College Tuition

AWS Morning Brief for the week of July 11, 2022 with Corey Quinn.

Jul 11, 20225 min

Ep 407Azure Insecurity Templates

Links:The most recently reported Azure vulnerabilityAmazon Photos exposes customers to riskI (re)discovered Scott Piper's work on Lesser Known Techniques for Attacking AWS Environments.PyPi python packages get caught sending stolen AWS keys to unsecured sites.TLS 1.2 to become the minimum TLS protocol level for all AWS API endpoints GuardDuty has new findings CloudFormation Guard had a new release.

Jul 7, 20224 min

Ep 406The ChatOps Issue That No One's Chatting About

Want to give your ears a break and read this as an article? You’re looking for this link:https://www.lastweekinaws.com/blog/the-chatops-issue-no-ones-chatting-aboutWant to watch the full dramatic reenactment of this podcast? Watch the YouTube Video here: https://youtu.be/eBKZ71OLjG8Never miss an episodeJoin the Last Week in AWS newsletterSubscribe wherever you get your podcastsHelp the showLeave a reviewShare your feedbackSubscribe wherever you get your podcastsWhat's Corey up to?Follow Corey on Twitter (@quinnypig)See our recent work at the Duckbill GroupApply to work with Corey and the Duckbill Group to help lower your AWS bill

Jul 6, 20228 min

Ep 405Mr. Selipsky's Geography Class

AWS Morning Brief for the week of July 4th, 2022 with Corey Quinn.

Jul 5, 20227 min

Ep 404Enter Your Passwordle

Links: Azure has another security issue around its Synapse offering; this one was discovered by Tenable.Sysdig has a dive into the real threats to SSH on EC2.Tailscale has announced the ability to support Tailscale SSH.Chris Farris has a treatise on the The Philosphy of Prevention when it comes to cloud security.Google Cloud CISO Phil Venables asks whether security analogies are counterproductive. A security issue of sorts was discovered around sts:GetSessionToken Role Chaining in AWSThe person responsible for the giant Capital One hack that took advantage of a series of small AWS misconfigurations has been convicted.Rogue GitHub apps could have hijacked countless repos for a week or two earlier this year.Wickr for Government achieves FedRAMP Ready designationIt takes an open source project like trackiam to collate IAM actions, AWS APIs, and managed policies from all over the placePasswordle lets you guess commonly used passwords.

Jun 30, 20225 min

Ep 4039 Ways AWS Made Me Headdesk When Using The CDK

Want to give your ears a break and read this as an article? You’re looking for this link.https://www.lastweekinaws.com/blog/9-ways-aws-cdk-headdeskWant to watch the full dramatic reenactment of this podcast? Watch the YouTube Video here: https://youtu.be/3Mf3_l6iEtA Never miss an episodeJoin the Last Week in AWS newsletterSubscribe wherever you get your podcastsHelp the showLeave a reviewShare your feedbackSubscribe wherever you get your podcastsWhat's Corey up to?Follow Corey on Twitter (@quinnypig)See our recent work at the Duckbill GroupApply to work with Corey and the Duckbill Group to help lower your AWS bill

Jun 29, 202216 min

Ep 402Concerning Your DeepRacer's Extended Warranty

AWS Morning Brief for the week of June 27, 2022 with Corey Quinn.

Jun 27, 20226 min

Ep 401Bugcrowd Bugs the Crowd

Links:Travis CI continues to be a security nightmare.Implementing IAM Permission Boundaries with AWS SSO using TerraformA user reported a vulnerability to a company through Bugcrowd. The writeup is really worth reviewing.The RSA conference was apparently a super spreader event.Because nobody beats the Wiz, they've got a post up on the secret agents installed by cloud service providers.Partitioning and Isolating Multi-Tenant SaaS Data with Amazon S3Service Notice – Upcoming changes required for AWS Config | AWS Cloud Operations & Migrations BlogHere's a list of best practices for writing Docker images that don't make you regret running them in production environments.

Jun 23, 20226 min

Ep 400Should I Take a Job at AWS?

Want to give your ears a break and read this as an article? You’re looking for this link.https://www.lastweekinaws.com/blog/should-you-take-a-job-at-aws/Want to watch the full dramatic reenactment of this podcast? Watch the YouTube Video here: https://youtu.be/BCiUulzr9f8Never miss an episodeJoin the Last Week in AWS newsletterSubscribe wherever you get your podcastsHelp the showLeave a reviewShare your feedbackSubscribe wherever you get your podcastsWhat's Corey up to?Follow Corey on Twitter (@quinnypig)See our recent work at the Duckbill GroupApply to work with Corey and the Duckbill Group to help lower your AWS bill

Jun 22, 202215 min

Ep 399Add a Mantium

AWS Morning Brief for the week of June 20, 2022 with Corey Quinn.

Jun 21, 20226 min

Ep 398Kubernetes Firewalln't

Links:Azure’s continuing security woesThe Meeting Owl videoconference device apparently had significant security problems Brandon Sherman writes about how Temporal structures its access control strategy with regard to AWS This week's S3 Bucket Negligence Award goes to Mobike. Cloud Functions or Cloud Run launched from any GCP organization can bypass Google Kubernetes Engine (GKE) Authorized Networks restrictionsProof of someone migrating to SSO and disabling IAM users entirely. AWS blog post about IAM policy types: How and when to use themTailscale

Jun 16, 20226 min

Ep 397re:Invent Keynote 2026: Analysis

Want to give your ears a break and read this as an article? You’re looking for this link:https://www.lastweekinaws.com/blog/reinvent-keynote-incident/Want to watch the full dramatic reenactment of this podcast? Watch the YouTube Video here: https://youtu.be/NGvLMsf4Wg8Never miss an episodeJoin the Last Week in AWS newsletterSubscribe wherever you get your podcastsHelp the showLeave a reviewShare your feedbackSubscribe wherever you get your podcasts

Jun 15, 20228 min

Ep 396Cars 4, featuring "Pixar Tractor on AWS”

AWS Morning Brief for the week of June 13, 2022 with Corey Quinn.

Jun 13, 20226 min

Ep 395Azure's Nightmare Year

Links:Nick Jones' review of the AWS Security Model I linked to previously.Microsoft Azure has seen 6 'nightmare' cloud security flaws over the past year. Unsecured Elasticsearch Data Replaced with Ransom NoteAWS Systems Manager announces support for port forwarding to remote hosts using Session Manager When and where to use IAM permissions boundaries Security vulnerability in AWS's Managed Workflows for Apache Airflow

Jun 9, 20225 min

Ep 394The Strange, Too Familiar Tale of Uncle Suitcase

Want to give your ears a break and read this as an article? You’re looking for this link.https://www.lastweekinaws.com/blog/the-strange-too-familiar-tale-of-uncle-suitcase/Want to watch the full dramatic reenactment of this podcast? Watch the YouTube Video here: https://youtu.be/x70EypnAH1YNever miss an episodeJoin the Last Week in AWS newsletterSubscribe wherever you get your podcastsHelp the showLeave a reviewShare your feedbackSubscribe wherever you get your podcastsWhat's Corey up to?Follow Corey on Twitter (@quinnypig)See our recent work at the Duckbill GroupApply to work with Corey and the Duckbill Group to help lower your AWS bill

Jun 8, 20226 min

Ep 393Googling the AWS CDK V1

AWS Morning Brief for the week of June 6, 2022, with Corey Quinn.

Jun 6, 20226 min

Ep 392RSA Prelude

Links:Poisoned Python and PHP packages purloin passwords for AWS accessNo, your cloud environment doesn't need a sandboxSpring 2022 SOC reports are now available with 150 services in scopeCanary Tokens

Jun 2, 20224 min

Ep 391The Aurora Serverless Road Not Taken

Want to give your ears a break and read this as an article? You’re looking for this link.https://www.lastweekinaws.com/blog/the-aurora-serverless-road-not-taken/Never miss an episodeJoin the Last Week in AWS newsletterSubscribe wherever you get your podcastsHelp the showLeave a reviewShare your feedbackSubscribe wherever you get your podcastsWhat's Corey up to?Follow Corey on Twitter (@quinnypig)See our recent work at the Duckbill GroupApply to work with Corey and the Duckbill Group to help lower your AWS bill

Jun 1, 20227 min

Ep 390Amazon Basics NXP Chips from Annapurna Labs

AWS Morning Brief for the week of May 30, 2022 with Corey Quinn.

May 30, 20225 min

Ep 389Security Model Citizen Development

Links:Google Cloud Build deep diveAndrea Brancaleoni found an ELB header security issueAn article on You Can't Opt Out of Citizen Development DOJ Announces It Won’t Prosecute White Hat Security ResearchersChoosing the right certificate revocation method in ACM Private CAa somewhat... controversial AWS Security Maturity Model AWS API calls that return credentials on GitHub

May 26, 20225 min

Ep 388An AWS Free Tier Bill Shock: Your Next Steps

Want to give your ears a break and read this as an article? You’re looking for this link.https://www.lastweekinaws.com/blog/an-aws-free-tier-bill-shock-your-next-stepsNever miss an episodeJoin the Last Week in AWS newsletterSubscribe wherever you get your podcastsHelp the showLeave a reviewShare your feedbackSubscribe wherever you get your podcastsWhat's Corey up to?Follow Corey on Twitter (@quinnypig)See our recent work at the Duckbill GroupApply to work with Corey and the Duckbill Group to help lower your AWS bill

May 25, 20229 min

Ep 387Amazon's Original Risk Store

AWS Morning Brief for the week of May 23, 2022 with Corey Quinn.

May 23, 20224 min

Ep 386F5 Exploit the Exact Opposite of Refreshing

Links:"Hacking the Cloud" is a community-built encyclopedia npm dependency confusion attack.Windows Event LogsF5 appliance (software or hardware) full remote code execution with privileged accessWiz has a blog post up about securing AWS Lambda function URLsBuild a strong identity foundation that uses your existing on-premises Active DirectoryHow to use new Amazon GuardDuty EKS Protection findingsPoro (an open source project) scans for publicly accessible assets in your AWS environment

May 19, 20225 min

Ep 385Fixing the AWS Free Tier is No Longer Optional

Want to give your ears a break and read this as an article? You’re looking for this link.https://www.lastweekinaws.com/blog/an-aws-free-tier-bill-shock-your-next-steps/Never miss an episodeJoin the Last Week in AWS newsletterSubscribe wherever you get your podcastsHelp the showLeave a reviewShare your feedbackSubscribe wherever you get your podcastsWhat's Corey up to?Follow Corey on Twitter (@quinnypig)See our recent work at the Duckbill GroupApply to work with Corey and the Duckbill Group to help lower your AWS bill

May 18, 20227 min

Ep 384Amazon Data Fencing

AWS Morning Brief for the week of May 16, 2022 with Corey Quinn.

May 16, 20224 min