{"type":"rich","version":"1.0","provider_name":"Transistor","provider_url":"https://transistor.fm","author_name":"Last Week In AWS Podcast","title":" A Hole in the S3 Buckets","html":"<iframe width=\"100%\" height=\"180\" frameborder=\"no\" scrolling=\"no\" seamless src=\"https://share.transistor.fm/e/d0783497\"></iframe>","width":"100%","height":180,"duration":308,"description":"Last week in security news: Thinkst Canary's Thinkstscapes, Multiple S3 Bucket Negligence Awards, Credit Card Payment Processing on AWS, and more!\nLinks:\nThinkst Canary's Thinkstscapes\nIt's been a while since we've seen a strong, confirmed S3 Bucket Negligence Award, but Toyota has a massive one dating back a decade.\nOof, looks like Google's CloudSQL product had a vulnerability that would allow an attacker to escalate to GCP control plane permissions.\nHoly... Legion malware expands scope to target AWS CloudWatch as well.\nWhen it rains, it pours; Capita had an S3 Bucket Negligence Award as well!\nCredit Card Payment Processing on AWS - Don't do it. Pay Stripe. \nAmazon Security Lake is now generally available\nAnnouncing the AWS Blueprint for Ransomware Defense \nGet custom data into Amazon Security Lake through ingesting Azure activity logs \nTip of the week: When you're starting something new that might turn into a company, use SSO.","thumbnail_url":"https://img.transistorcdn.com/PMIkgW48sHRopAuMhIYzsjzhK0RhchBCtpHSuJjoizc/rs:fill:0:0:1/w:400/h:400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS80MDRk/OGFjYTIxMWE1MjQy/YWRkZDhiMDJmMzMy/MDQyMi5wbmc.webp","thumbnail_width":300,"thumbnail_height":300}