S3 Block Public Access Launches (Nov 2018): The Feature That Should Have Existed Day One
In November 2018, AWS launched S3 Block Public Access, a set of four settings that override bucket policies and access control lists to prevent public...
In November 2018, AWS launched S3 Block Public Access, a set of four settings that override bucket policies and access control lists to prevent public...
Account-level S3 Block Public Access protects every bucket in an account. With AWS Organizations, you can apply it everywhere and prevent anyone from...
Use this checklist to audit S3 public access across your AWS organization.
The short version: In 2018, AWS added a setting that prevents cloud storage from being made public at all. Turned on across an account, it stops the most...
At re:Invent in November 2018, AWS announced previews of two services that reshaped multi-account security: AWS Security Hub and AWS Control Tower.
A multi-account AWS landing zone separates workloads, centralizes security tools and protects logs. Here is how to design one using AWS's own reference...
AWS Security Hub can produce hundreds of failed controls on day one. This checklist helps you triage them without drowning.
The short version: AWS recommends running your cloud as many separate accounts — one per application or environment — instead of one big account. In 2018,...
In February 2018, researchers at RedLock disclosed that attackers had broken into Tesla's cloud environment and used it to mine cryptocurrency.
An exposed Kubernetes dashboard gave attackers a path into Tesla's cloud in 2018. Here is how to secure Kubernetes management interfaces and cluster...
Cryptojacking — using stolen cloud resources to mine cryptocurrency — is one of the most common outcomes of a cloud compromise. It is also one of the most...
The short version: In 2018, attackers broke into Tesla's cloud through an unprotected management console and used its computers to mine cryptocurrency....
In November 2017, Uber disclosed that a year earlier attackers had stolen personal data on about 57 million riders and drivers, including the driver's...
Long-lived AWS access keys in source code have caused breaches at companies of every size, from Uber in 2016 to the extortion campaigns of the 2020s. Here...
Leaked AWS access keys are often used within minutes of exposure. Detecting misuse quickly limits how much an attacker can do.
The short version: Uber's 2016 breach began with cloud passwords left in a code repository. What made it infamous was the cover-up: the company paid the...
In November 2017, UpGuard researchers found three Amazon S3 buckets configured for public access that contained billions of social media posts collected as...
AWS Config continuously evaluates resource settings against rules. For S3, a handful of rules catches most of the misconfigurations behind past data...
Most S3 misconfigurations begin with a configuration change. Monitoring those changes in near real time catches exposures within minutes rather than months.
The short version: In 2017, cloud storage tied to US military programs was found open to the public. If defense organizations can make this mistake, any...
At re:Invent in November 2017, AWS launched Amazon GuardDuty, a managed threat detection service. With one click, it began analyzing an account's activity...
Amazon GuardDuty should be enabled in every account and every region you use. With AWS Organizations, you can do that in an afternoon. Here is how.
GuardDuty generates findings; your team turns them into decisions. This runbook gives small security teams a consistent way to triage GuardDuty findings.
The short version: Amazon GuardDuty, launched in 2017, watches your AWS accounts for signs of attack and costs relatively little. The decision is not really...