![Twilio's Insecure Text Message Issue - podcast episode cover](https://img.transistor.fm/2nTnZCKlaiDe_iTzYilY-7yIWdUyeKnI3PP47M9BjMg/rs:fill:3000:3000:1/q:60/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS9lcGlz/b2RlLzk4NDA5NC8x/NjYwMTU3ODk3LWFy/dHdvcmsuanBn.jpg)
Episode description
Links:
- Twilio's disclosure of an Employee and Customer Account Compromise.
- Update of AWS Security Reference Architecture is now available
- As the linked tweet says: "If you check out the AWS docs on IAM policy parsing order there is a flowchart that shows you can get an Allow outcome before the boundary policy is evaluated."
- IAM-Deescalate: is an open source tool to help users reduce the risk of privilege escalation.