13 items across 5 sections
Part 1 of 4 in the Lambda Security Series. Why "managed" doesn't mean secure: overprivileged execution roles, secrets in environment variables, public function URLs, deprecated runtimes, and event-data injection.
Stop sending your IAM policies, CloudTrail logs, and infrastructure code to third-party APIs. Run LLMs locally with Ollama on Apple Silicon: private, offline, fast. Complete setup guide with AWS security use cases.
A comprehensive AWS security audit checklist covering IAM, S3, networking, logging, and compliance. Follow this step-by-step guide to secure your AWS infrastructure.
Learn the essential AWS IAM best practices to secure your cloud environment. Covers least privilege, MFA, roles, policies, and access management strategies.
Understanding HashiCorp Vault, why traditional credential management is broken, how dynamic secrets work, and hands-on setup of the AWS secrets engine with role-based credential generation.
Part 3 of 16 in the AWS Security Agent: From Zero to Hero series. A field-tested walkthrough of setting up AWS Security Agent: choosing an access method, creating an Agent Space, the two IAM roles, the service principal, and domain verification, including the one-click verification gotcha the docs do not warn you about.
Bedrock AgentCore Policy hits GA, mixing LLM authorship with Cedar policy-as-code, the first AWS service to do that at scale. IAM gets a simplified role-creation flow with inline panels. AWS adds DESC 2026 certification for the UAE.
Security Hub learns to find identity risk that no one is using: unused IAM permissions, roles, and credentials, measured against 90 days of real activity. The Extended plan grows to 21 partners across 9 categories. Secrets Manager Agent picks up pre-fetching and cross-account role assumption, and Amazon Inspector Classic reaches end of support.
Truffle Security reports that more than 9,300 of 10,616 re-tested leaked AWS keys still authenticate, 768 of them with full administrator or root access, some five years after first appearing publicly. Security Hub Extended adds Supply Chain Security as its tenth category. AWS also ships seven security bulletins this week, mostly across OpenSearch Dashboards and FreeRTOS-Kernel.
JetBrains concludes its investigation into a three-week breach of its Cadence CI/CD service, confirming attackers compromised AWS IAM users and credentials and accessed files in JetBrains-owned S3 buckets, alongside PyCharm source code and user data. Four new AWS security bulletins close the month, and AWS opens beta registration for its new AI Business Strategist certification.
Our AWS security experts can help you implement best practices across all these topics.
Contact Us