AWS Morning Brief

Corey Quinn
undefined
Jun 23, 2022 • 6min

Bugcrowd Bugs the Crowd

Links:Travis CI continues to be a security nightmare.Implementing IAM Permission Boundaries with AWS SSO using TerraformA user reported a vulnerability to a company through Bugcrowd. The writeup is really worth reviewing.The RSA conference was apparently a super spreader event.Because nobody beats the Wiz, they've got a post up on the secret agents installed by cloud service providers.Partitioning and Isolating Multi-Tenant SaaS Data with Amazon S3Service Notice – Upcoming changes required for AWS Config | AWS Cloud Operations & Migrations BlogHere's a list of best practices for writing Docker images that don't make you regret running them in production environments.
undefined
Jun 22, 2022 • 16min

Should I Take a Job at AWS?

Want to give your ears a break and read this as an article? You’re looking for this link.https://www.lastweekinaws.com/blog/should-you-take-a-job-at-aws/Want to watch the full dramatic reenactment of this podcast? Watch the YouTube Video here: https://youtu.be/BCiUulzr9f8Never miss an episodeJoin the Last Week in AWS newsletterSubscribe wherever you get your podcastsHelp the showLeave a reviewShare your feedbackSubscribe wherever you get your podcastsWhat's Corey up to?Follow Corey on Twitter (@quinnypig)See our recent work at the Duckbill GroupApply to work with Corey and the Duckbill Group to help lower your AWS bill
undefined
Jun 21, 2022 • 6min

Add a Mantium

AWS Morning Brief for the week of June 20, 2022 with Corey Quinn.
undefined
Jun 16, 2022 • 7min

Kubernetes Firewalln't

Links:Azure’s continuing security woesThe Meeting Owl videoconference device apparently had significant security problems Brandon Sherman writes about how Temporal structures its access control strategy with regard to AWS This week's S3 Bucket Negligence Award goes to Mobike.  Cloud Functions or Cloud Run launched from any GCP organization can bypass Google Kubernetes Engine (GKE) Authorized Networks restrictionsProof of someone migrating to SSO and disabling IAM users entirely. AWS blog post about IAM policy types: How and when to use themTailscale
undefined
Jun 15, 2022 • 9min

re:Invent Keynote 2026: Analysis

Want to give your ears a break and read this as an article? You’re looking for this link:https://www.lastweekinaws.com/blog/reinvent-keynote-incident/Want to watch the full dramatic reenactment of this podcast? Watch the YouTube Video here: https://youtu.be/NGvLMsf4Wg8Never miss an episodeJoin the Last Week in AWS newsletterSubscribe wherever you get your podcastsHelp the showLeave a reviewShare your feedbackSubscribe wherever you get your podcasts
undefined
Jun 13, 2022 • 6min

Cars 4, featuring "Pixar Tractor on AWS”

AWS Morning Brief for the week of June 13, 2022 with Corey Quinn.
undefined
Jun 9, 2022 • 5min

Azure's Nightmare Year

Links:Nick Jones' review of the AWS Security Model I linked to previously.Microsoft Azure has seen 6 'nightmare' cloud security flaws over the past year. Unsecured Elasticsearch Data Replaced with Ransom NoteAWS Systems Manager announces support for port forwarding to remote hosts using Session Manager When and where to use IAM permissions boundaries Security vulnerability in AWS's Managed Workflows for Apache Airflow
undefined
Jun 8, 2022 • 7min

The Strange, Too Familiar Tale of Uncle Suitcase

Want to give your ears a break and read this as an article? You’re looking for this link.https://www.lastweekinaws.com/blog/the-strange-too-familiar-tale-of-uncle-suitcase/Want to watch the full dramatic reenactment of this podcast? Watch the YouTube Video here: https://youtu.be/x70EypnAH1YNever miss an episodeJoin the Last Week in AWS newsletterSubscribe wherever you get your podcastsHelp the showLeave a reviewShare your feedbackSubscribe wherever you get your podcastsWhat's Corey up to?Follow Corey on Twitter (@quinnypig)See our recent work at the Duckbill GroupApply to work with Corey and the Duckbill Group to help lower your AWS bill
undefined
Jun 6, 2022 • 7min

Googling the AWS CDK V1

AWS Morning Brief for the week of June 6, 2022, with Corey Quinn.
undefined
Jun 2, 2022 • 4min

RSA Prelude

Links:Poisoned Python and PHP packages purloin passwords for AWS accessNo, your cloud environment doesn't need a sandboxSpring 2022 SOC reports are now available with 150 services in scopeCanary Tokens

The AI-powered Podcast Player

Save insights by tapping your headphones, chat with episodes, discover the best highlights - and more!
App store bannerPlay store banner
Get the app