AWS Notes
5.82K subscribers
550 photos
44 videos
10 files
2.93K links
AWS Notes — Amazon Web Services Educational and Information Channel

Chat: https://xn--r1a.website/aws_notes_chat

Contacts: @apple_rom, https://www.linkedin.com/in/roman-siewko/
Download Telegram
RCP (Resource control policies) examples:

https://github.com/aws-samples/data-perimeter-policy-examples/tree/main/resource_control_policies

identity_perimeter_rcp – Enforces identity perimeter controls on resources within your Organizations organization.
network_perimeter_rcp – Enforces network perimeter controls on resources within your Organizations organization.
data_perimeter_governance_rcp – Includes controls for protecting data perimeter controls’ dependencies, such as session tags used to control their scope.

Note that the RCP policy do not grant any permissions; they only restrict access by explicitly denying specific data access patterns. You still have to grant appropriate permissions with explicit Allow statements in identity-based or resource-based policies.

#RCP #security
👍2🔥1
Comparison of different WAFs

◽️ AWS WAF
◽️ CloudFlare WAF
◽️ Google Cloud Armor
◽️ F5
◽️ Fortinet FortiWeb
◽️ Imperva Cloud WAF
◽️ Microsoft Azure WAF
◽️ NGINX ModSecurity
◽️ open-appsec

https://www.openappsec.io/post/best-waf-solutions-in-2024-2025-real-world-comparison

To make it easier to understand, I have added clearer captions to the graph.

#security
👍10
AWS Trust Center — single source of truth for security and compliance.

https://aws.amazon.com/trust-center/

Like Amazon Builders' Library but for security.

#security
🔥5👍3
IngressNightmare — сразу несколько уязвимостей NGINX Controller for Kubernetes доступом к секретам всего и везде без авторизации:

https://www.wiz.io/blog/ingress-nginx-kubernetes-vulnerabilities

◽️ Кто пострадал — обладатели NGINX Controller версий до 1.12.1/1.11.5. Для устранения нужно срочно обновиться на последнюю версию.

◽️ Кто не пострадал — пользователи EKS:

EKS does not provide or install the ingress-nginx controller and is not affected by these issues.

Официальный отчёт о уязвимости Kubernetes:

https://kubernetes.io/blog/2025/03/24/ingress-nginx-cve-2025-1974/

#Kubernetes #security
😁5👍2
Multi-party approval — когда нужно реализовать подтверждение на операцию в AWS от нескольких человек:

https://docs.aws.amazon.com/mpa/latest/userguide/

#security #organizations
👍174
AWS WAF vs CVE-2025-55182 (React2Shell)

https://aws.amazon.com/blogs/security/china-nexus-cyber-threat-groups-rapidly-exploit-react2shell-vulnerability-cve-2025-55182/

CVE-2025-55182 - злобная уязвимость, при попытке раскатать защиту от которой, намедни прилёг CloudFlare.

Стоит поскорее обновить свои реактивные ресурсы.

В случае использования AWS WAF с дефолтным AWSManagedRulesKnownBadInputsRuleSet можно не переживать (но всё равно обновиться).

#security
4
Б — безопасность.

#AI #security #пятничное
😁48🤣12😱1💯1