{ "version": "1", "type":"NEW_FINDINGS", "findingDetails":[{ "findingType":"UnauthorizedAccess:IAMUser/ResourceCredentialExfiltration.OutsideAWS", "link":"", "findingDescription":"This finding informs you that a host outside of AWS has attempted to run AWS API operations using temporary AWS credentials that were created on a Lambda resource in your AWS environment." }] }
I opened up a case with AWS and am told this is only a product announcement. You can see this finding type was released just yesterday (https://docs.aws.amazon.com/guardduty/latest/ug/doc-history.html).
If anyone hears differently, would love to know. For now, we're standing down with the understanding that there is no incident.
Super poor wording of email. That just took a few hours of my life I'll never get back.
Product managers are the defacto but they can often always want one more feature before it's "just right" and, therefore, be slow to ship.
Technology leaders know the features intimately well and if they're ready for use but are typically abstracted from the customer.
Who is the person best situated and with the right mentality to say "ship it"?
Azure, you have one job and that's to ALWAYS deploy the infrastructure I request.
Has anyone else experienced this? Is there a work around?