🔶 Apps can now impersonate human access to AWS via IAM Identity Center
AWS IAM Identity Center now lets server-side apps exchange an IdP-issued OIDC token for user-scoped AWS credentials via CreateTokenWithIAM, ListAccounts, and GetRoleCredentials. Actions are attributed to the user in CloudTrail. Key gaps: no per-app scope restrictions and no application ARN in audit trails.
https://awsteele.com/blog/2026/07/01/apps-can-now-impersonate-human-access-to-aws-via-iam-identity-center.html
#aws
AWS IAM Identity Center now lets server-side apps exchange an IdP-issued OIDC token for user-scoped AWS credentials via CreateTokenWithIAM, ListAccounts, and GetRoleCredentials. Actions are attributed to the user in CloudTrail. Key gaps: no per-app scope restrictions and no application ARN in audit trails.
https://awsteele.com/blog/2026/07/01/apps-can-now-impersonate-human-access-to-aws-via-iam-identity-center.html
#aws
❤1👍1🔥1
🔶 Introducing OAuth Support for AWS MCP Server
AWS MCP Server now supports OAuth-based sign-in using existing AWS credentials (IAM, IAM Identity Center, federated). Includes dynamic client registration, headless token API, new IAM condition keys, token introspection/revocation, and CloudTrail logging for OAuth events.
https://aws.amazon.com/ru/blogs/security/introducing-oauth-support-for-aws-mcp-server
#aws
AWS MCP Server now supports OAuth-based sign-in using existing AWS credentials (IAM, IAM Identity Center, federated). Includes dynamic client registration, headless token API, new IAM condition keys, token introspection/revocation, and CloudTrail logging for OAuth events.
https://aws.amazon.com/ru/blogs/security/introducing-oauth-support-for-aws-mcp-server
#aws
❤1👍1🔥1
🔶 Authenticate legitimate AI agent traffic with AWS WAF Bot Control
AWS WAF Bot Control now supports Web Bot Authentication (WBA), using ed25519 cryptographic signatures (RFC 9421) to verify AI agent identities. It introduces new WAF labels (verified, invalid, expired, unknown_bot) enabling granular allow/block rules, replacing unreliable IP-based bot filtering.
https://aws.amazon.com/ru/blogs/security/authenticate-legitimate-ai-agent-traffic-with-aws-waf-bot-control
#aws
AWS WAF Bot Control now supports Web Bot Authentication (WBA), using ed25519 cryptographic signatures (RFC 9421) to verify AI agent identities. It introduces new WAF labels (verified, invalid, expired, unknown_bot) enabling granular allow/block rules, replacing unreliable IP-based bot filtering.
https://aws.amazon.com/ru/blogs/security/authenticate-legitimate-ai-agent-traffic-with-aws-waf-bot-control
#aws
❤3👍1🔥1
🔶 OIDC tokens can now restrict which AWS roles they assume
AWS STS now supports a new OIDC claim that restricts which role ARNs a token can assume. Enforced before trust policy evaluation. The boolean condition key sts:RoleAuthorizedByIdp enables mandatory enforcement via trust policies or RCPs.
https://awsteele.com/blog/2026/07/13/oidc-tokens-can-restrict-which-aws-roles-they-assume.html
#aws
AWS STS now supports a new OIDC claim that restricts which role ARNs a token can assume. Enforced before trust policy evaluation. The boolean condition key sts:RoleAuthorizedByIdp enables mandatory enforcement via trust policies or RCPs.
https://awsteele.com/blog/2026/07/13/oidc-tokens-can-restrict-which-aws-roles-they-assume.html
#aws
❤2👍1🔥1
🔶🔷🔴 The Two Mitigations for the Service-Account Confused Deputy in the Cloud
Two mitigations exist for cloud service-account confused deputy attacks: for customer-managed identities, an attachment gate (GCP actAs, AWS iam:PassRole, Azure assign/action) controls bind-time authorization; for provider-managed identities, the CSP enforces internal checks, with AWS uniquely exposing this via Forward Access Sessions and condition keys.
https://kattraxler.cloud/the-two-mitigations-for-the-service-account-confused-deputy-in-the-cloud
#aws #azure #gcp
Two mitigations exist for cloud service-account confused deputy attacks: for customer-managed identities, an attachment gate (GCP actAs, AWS iam:PassRole, Azure assign/action) controls bind-time authorization; for provider-managed identities, the CSP enforces internal checks, with AWS uniquely exposing this via Forward Access Sessions and condition keys.
https://kattraxler.cloud/the-two-mitigations-for-the-service-account-confused-deputy-in-the-cloud
#aws #azure #gcp
❤1👍1🔥1
🔶 Introducing Claude apps gateway for AWS
Amazon announced the Claude apps gateway for AWS, a self-hosted control plane that gives organizations a single point of control over access, cost, and policy for Claude Code and Claude Desktop.
https://aws.amazon.com/ru/blogs/machine-learning/introducing-claude-apps-gateway-for-aws
#aws
Amazon announced the Claude apps gateway for AWS, a self-hosted control plane that gives organizations a single point of control over access, cost, and policy for Claude Code and Claude Desktop.
https://aws.amazon.com/ru/blogs/machine-learning/introducing-claude-apps-gateway-for-aws
#aws
❤1👍1🔥1
🔶 Introducing the Amazon GuardDuty investigation agent: on-demand AI-powered threat assessment
Amazon GuardDuty investigation agent (public preview) uses AI to auto-investigate GuardDuty security findings, reducing investigation time from hours to minutes. It returns risk levels, confidence scores, MITRE ATT&CK mappings, and remediation steps via console, CLI, API, or AWS MCP server.
https://aws.amazon.com/ru/blogs/security/introducing-the-amazon-guardduty-investigation-agent-on-demand-ai-powered-threat-assessment
#aws
Amazon GuardDuty investigation agent (public preview) uses AI to auto-investigate GuardDuty security findings, reducing investigation time from hours to minutes. It returns risk levels, confidence scores, MITRE ATT&CK mappings, and remediation steps via console, CLI, API, or AWS MCP server.
https://aws.amazon.com/ru/blogs/security/introducing-the-amazon-guardduty-investigation-agent-on-demand-ai-powered-threat-assessment
#aws
❤1👍1🔥1
🔶 Investigating Persistence Mechanisms in AWS
Rapid7 Labs details four AWS persistence techniques used by attackers: rogue IAM user creation, backdoored assume role policies granting external account access, malicious Lambda functions provisioning privileged users, and federated user sessions that survive key rotation. Includes LEQL detection queries and remediation steps.
https://www.rapid7.com/blog/post/dr-investigating-aws-persistence-mechanisms
#aws
Rapid7 Labs details four AWS persistence techniques used by attackers: rogue IAM user creation, backdoored assume role policies granting external account access, malicious Lambda functions provisioning privileged users, and federated user sessions that survive key rotation. Includes LEQL detection queries and remediation steps.
https://www.rapid7.com/blog/post/dr-investigating-aws-persistence-mechanisms
#aws
❤1👍1🔥1
🔶 HIPAA Security Rule on AWS
AWS released a whitepaper guiding covered entities and business associates on implementing HIPAA Security Rule Technical Safeguards on AWS, covering access control, audit, MFA, encryption, and 2025 NPRM proposed changes, with shared responsibility mapping and ePHI architecture guidance.
https://aws.amazon.com/ru/blogs/security/hipaa-security-rule-on-aws-technical-safeguards-implementation-and-readiness-guidance
#aws
AWS released a whitepaper guiding covered entities and business associates on implementing HIPAA Security Rule Technical Safeguards on AWS, covering access control, audit, MFA, encryption, and 2025 NPRM proposed changes, with shared responsibility mapping and ePHI architecture guidance.
https://aws.amazon.com/ru/blogs/security/hipaa-security-rule-on-aws-technical-safeguards-implementation-and-readiness-guidance
#aws
❤2👍1🔥1