Issue with AWS SAM CLI (CVE-2025-3047, CVE-2025-3048)
Publication Date: 2025/03/31 08:10 AM PDT
Description
The AWS Serverless Application Model Command Line Interface (A...
https://aws.amazon.com/security/security-bulletins/AWS-2025-008/

Issue with AWS SAM CLI (CVE-2025-3047, CVE-2025-3048)
Publication Date: 2025/03/31 08:10 AM PDT
Description
The AWS Serverless Application Model Command Line Interface (A...
https://aws.amazon.com/security/security-bulletins/AWS-2025-008/
Just got the confirmation that my talk got accepted for #AWS Summit 2025 in #Hamburg
I will talk about crafting an efficient yet simple #serverless #Loadtesting environment
Looking forward to the event 05.06.2025
Some of my colleagues at #AWS have created an open-source serverless #AI assisted #threatmodel solution. You upload architecture diagrams to it, and it uses Claude Sonnet via Amazon Bedrock to analyze it.
I'm not too impressed with the threats it comes up with. But I am very impressed with the amount of typing it saves. Given nothing more than a picture and about 2 minutes of computation, it spits out a very good list of what is depicted in the diagram and the flows between them. To the extent that the diagram is accurate/well-labeled, this solution seems to do a very good job writing out what is depicted.
I deployed this "Threat Designer" app. Then I took the architecture image from this blog post and dropped that picture into it. The image analysis produced some of the list of things you see attached.
This is a specialized, context-aware kind of OCR. I was impressed at boundaries, flows, and assets pulled from a graphic. Could save a lot of typing time. I was not impressed with the threats it identifies. Having said that, it did identify a handful of things I hadn't thought of before, like EventBridge event injection. But the majority of the threats are low value.
I suspect this app is not cheap to run. So caveat deployor.
#cloud #cloudsecurity #appsec #threatmodeling
CookUnity is hiring Engineering Manager, Growth
Job details https://jobsfordevelopers.com/jobs/engineering-manager-growth-at-cookunity-com-dec-19-2024-4107a2?utm_source=mastodon.world&utm_medium=social&utm_campaign=posting
#jobalert #jobsearch #hiring
AWS CloudTrail network activity events for VPC endpoints now generally available
#AWS IAM endpoints now avail over #ipv6
https://aws.amazon.com/about-aws/whats-new/2025/03/aws-identity-access-management-dual-stack-ipv4-ipv6-environments
if your transition to IPv6 is glacially slow, don't worry, AWS is keeping pace with you
Yesterday (Sun 30 Mar 2025) the temperature ranged from 2.4 to 14.5°C and there was no rain. The wind gusted up to 42mph. Sunrise was at 05:45 hrs and sunset at 19:43 hrs.
#aws #weatherstation #weather
How do you use cross-account CodeArtifact repositories
https://stackoverflow.com/questions/67911411/cross-account-access-to-a-codeartifact-repo
Discussions: https://discu.eu/q/https://stackoverflow.com/questions/67911411/cross-account-access-to-a-codeartifact-repo
Free Open Source App (made by me)
https://github.com/notyouritguru/aws-cli-gateway/
Discussions: https://discu.eu/q/https://github.com/notyouritguru/aws-cli-gateway/
"It's five grand a day to miss our S3 exit"
https://world.hey.com/dhh/it-s-five-grand-a-day-to-miss-our-s3-exit-b8293563
Living-off-the-land Dynamic DNS for Route 53
https://www.new23d.com/living-off-the-land-dynamic-dns-for-route-53/
Discussions: https://discu.eu/q/https://www.new23d.com/living-off-the-land-dynamic-dns-for-route-53/
➤ 堅決轉移資料以避免高額成本
✤ https://world.hey.com/dhh/it-s-five-grand-a-day-to-miss-our-s3-exit-b8293563
我們目前每年在AWS S3上花費接近1.5百萬美元,透過Pure Storage替換,以降低成本並達到18 PB,但需要儘快完成轉移,否則將每天支付高昂的費用。
+ 如果未能按時轉移,每天支付五千美元的費用實在驚人!
+ 成本高昂,但為了長遠節省,果斷轉移至Pure Storage是正確選擇。
#AWS S3 雲服務成本計算
PagerDuty is hiring Senior Security Engineer 3, Product & Application Security
Job details https://jobsfordevelopers.com/jobs/senior-security-engineer-3-product-application-security-at-pagerduty-com-mar-18-2025-5eabee?utm_source=mastodon.world&utm_medium=social&utm_campaign=posting
#jobalert #jobsearch #hiring
CLEAR is hiring Staff Software Engineer, Backend (Java)
Job details https://jobsfordevelopers.com/jobs/staff-software-engineer-backend-java-at-clearme-com-jan-9-2025-53c5f9?utm_source=mastodon.world&utm_medium=social&utm_campaign=posting
#jobalert #jobsearch #hiring
Yesterday (Sat 29 Mar 2025) the temperature ranged from 3.7 to 9.7°C with 3.2mm rain. The wind gusted up to 40mph. Sunrise was at 05:47 hrs and sunset at 18:41 hrs.
#aws #weatherstation #weather
Netskope is hiring Staff Engineer, PKI
Job details https://jobsfordevelopers.com/jobs/staff-engineer-pki-at-netskope-com-dec-6-2024-fd382b?utm_source=mastodon.world&utm_medium=social&utm_campaign=posting
#jobalert #jobsearch #hiring
I created a complete Kubernetes deployment and test app as an educational tool for folks to learn Kubernetes
https://github.com/setheliot/eks_demo
Discussions: https://discu.eu/q/https://github.com/setheliot/eks_demo
A Beginner's Guide to Setting Up AWS Alarm Email Alerts using CloudWatch | https://techygeekshome.info/a-beginners-guide-to-setting-up-aws-alarm-email-alerts/?fsp_sid=16077 | #Amazon #AWS #Cloud #CloudWatch #EC2 #Guide #refresh
https://techygeekshome.info/a-beginners-guide-to-setting-up-aws-alarm-email-alerts/?fsp_sid=16077
A Beginner's Guide to Setting Up AWS Alarm Email Alerts using CloudWatch | https://techygeekshome.info/a-beginners-guide-to-setting-up-aws-alarm-email-alerts/?fsp_sid=16076 | #Amazon #AWS #Cloud #CloudWatch #EC2 #Guide #refresh
https://techygeekshome.info/a-beginners-guide-to-setting-up-aws-alarm-email-alerts/?fsp_sid=16076