Cross-account event buses are one of the most powerful integration patterns in AWS, and an easy place to make an access policy mistake. A single overly permissive Allow statement can let principals from outside your organization publish events to your bus. With k9-cdk...
k9 Security launches initial support for automated IAM security review with findings in OCSF format
k9 Security now automates two critical IAM security review processes and produces high-signal findings in Open Cybersecurity Schema Framework (OCSF) format. This new capability significantly enhances your ability to identify and address critical IAM security risks in...
k9 Security Now Resolves Well-Known AWS Account Owners for Enhanced Visibility
Now k9 Security resolves the account owners for external access from well-known accounts, providing greater clarity and context to your AWS resource access reports. This update simplifies how security teams identify and understand external access to their AWS...
Generate least-privilege SQS resource policies with k9-cdk
The k9-cdk now supports generating least-privilege resource policies for Amazon SQS queues with CDK v2. This addition complements the existing S3, KMS, and DynamoDB capabilities, bringing the same simplified approach for securing messaging infrastructure managed by AWS...
Generate least-privilege DynamoDB resource policies with k9-cdk
The k9-cdk now supports generating least-privilege resource policies for Amazon DynamoDB tables, indices, and streams. This addition complements the existing S3 and KMS capabilities, bringing the same simplified approach for securing data to DynamoDB resources managed...
k9 now reports entitlements to Amazon Bedrock APIs
k9 Security now reports IAM principals’ access entitlements to the Amazon Bedrock APIs. The Bedrock APIs allow customers to manage generative AI data resources and create AI-enabled services and agents. k9 reports whether IAM principals may administer, change, or read...
