Use AWS WAF to Mitigate OWASP’s Top 10 Web Application Vulnerabilities

Today, AWS WAF released a new security whitepaper: Use AWS WAF to Mitigate OWASP’s Top 10 Web Application Vulnerabilities. This whitepaper describes how you can use AWS WAF, a web application firewall, to address the top application security flaws as named by the Open Web Application Security Project (OWASP). Using AWS WAF, you can write rules to match patterns of exploitation attempts in HTTP/S requests and block requests from reaching your web servers. This whitepaper discusses manifestations of these security vulnerabilities, AWS WAF–based mitigation strategies, and other AWS services or solutions that can help address these threats.
Quelle: aws.amazon.com

AWS Config Tracks Changes to AWS CloudFormation Stacks

AWS Config now supports tracking changes to AWS CloudFormation stacks. A CloudFormation stack is a collection of AWS resources that you can manage as a single unit. With this release, you can now deep dive into the historical configuration of your CloudFormation stacks and review all changes that occurred to them. For example, you can now determine how your stack policies were changed or what updates were made to the resources within the stack. You can also receive Amazon Simple Notification Service (Amazon SNS) notifications when those changes occur. In addition, you can run a new managed Config rule to check whether your CloudFormation stacks are sending event notifications to an Amazon SNS topic.
Quelle: aws.amazon.com

Now You Can Configure Password Policies to Help Meet Your Security Standards with AWS Directory Service for Microsoft Active Directory

Starting today, you can use AWS Directory Service for Microsoft Active Directory (Enterprise Edition), also known as AWS Microsoft AD, to help enforce password policies that meet your security standards. AWS has added five password policies to your AWS Microsoft AD directory, and you can configure and manage these policies to enforce different security requirements for different user groups.
Quelle: aws.amazon.com

New Information in the AWS IAM Console Helps You Adhere to IAM Best Practices

Today, we made it easier for you to follow AWS Identity and Access Management (IAM) best practices by adding additional information in the Users section of the IAM console. This new information in the IAM user table helps you monitor user activity in your AWS account and identify access keys and passwords that should be rotated regularly. It also enables you to better audit users’ MFA device usage, and gives you better visibility into users’ group memberships. This information is available in all AWS regions today.
Quelle: aws.amazon.com

AWS CloudFormation coverage updates for Amazon API Gateway, Amazon EC2, Amazon EMR, Amazon DynamoDB and more

You can now provision the following AWS resources using CloudFormation.

AWS::ApiGateway::DomainName

Use the AWS::ApiGateway::DomainName resource to specify a custom, friendly URL for your API that’s deployed to Amazon API Gateway.

AWS::EC2::EgressOnlyInternetGateway

Create an egress-only Internet gateway for your VPC with the AWS::EC2::EgressOnlyInternetGateway resource.

AWS::EMR::InstanceFleetConfig

Configure a spot instance fleet for an Amazon EMR cluster using the InstanceFleetConfig resource.

Quelle: aws.amazon.com

Amazon WorkMail Now Allows You to Configure Email Flow Rules

Starting today, you can now use email flow rules to filter inbound email traffic for your Amazon WorkMail organizations. This helps you reduce email from unwanted senders, route suspicious mail to junk folders, and make sure important messages are successfully delivered.
Email flow rules can be applied based on specific email addresses, or entire email domains. You can configure email flow rules from the Amazon WorkMail console.
You can use email flow rules in all AWS Regions where WorkMail is offered, and at no additional charge. To learn more, please see Managing Email Flows.
Quelle: aws.amazon.com