ZeroHour
Product

CloudTrail

1 mentions in 7 days · 2 in 30 days · 2 total · first seen · last

Timeline

Exploring the new AWS Sign Up experience

Wiz analyzed AWS's new sandboxed sign-up experience, finding it omits CloudTrail, blocks security services, and limits vendor IAM role access.

AWS's new sign-up experience creates three accounts in an Organization sandbox governed by SCPs and RCPs, with a $20/month budget that triggers a spend-limit SCP denying new compute workloads. Wiz found the sandbox lacks organization-level CloudTrail and its FreeTierSCP allowlist denies GuardDuty, Security Hub, Detective, Inspector, Macie, and Access Analyzer, while still permitting IAM users with access keys, public S3 buckets, and IMDSv1 EC2 instances. A remaining RCP blocks all principals outside the Organization, denying cross-account sts:AssumeRole and preventing vendor IAM role integrations until the account is upgraded. Wiz concludes the sandbox prioritizes simplicity and cost control over a strong security posture.

Wiz Blog · 1d agoTools

AWS Console Private Access can block sign-ins to personal accounts

AWS Console Private Access goes GA, letting internet-isolated VPCs reach the console fully over PrivateLink and blocking personal account sign-ins.

AWS Console Private Access became generally available on August 28, allowing the AWS Management Console, sign-in flows, static assets, and console-only APIs to run entirely over PrivateLink endpoints from VPCs with no internet connectivity. Deployment requires three interface endpoints per Region, correct Private DNS and security group settings, and uses aws:PrincipalOrgID policies plus sign-in resource control policies to deny authentication from unexpected networks, which blocks corporate-network users from signing into personal AWS accounts. IAM Identity Center sign-in and consoles for services without PrivateLink support still need internet access, and a misconfigured policy can lock out the whole organization, so AWS recommends an excluded break-glass role; CLI and SDK SigV4 requests bypass these policies and serve as a recovery path.

Help Net Security · 18d agoTools

Appears with

Entities are extracted by the model from each article. Watching an entity keeps it in this browser only (no account); the watchlist page and dashboard alerts use it.