<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>IAMTrail - All Changes</title>
    <link>https://iamtrail.com</link>
    <description>All IAMTrail changes in one feed - discoveries, IAM policies, endpoints, and GuardDuty announcements. An unofficial archive by zoph.io.</description>
    <language>en-us</language>
    <lastBuildDate>Fri, 07 Aug 2026 22:04:32 GMT</lastBuildDate>
    <ttl>60</ttl>
    <atom:link href="https://iamtrail.com/feeds/all.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>AWSManagedBudgetsSpendLimitManagementAccess: scope changed, no action added or removed (v2)</title>
      <link>https://iamtrail.com/policies/AWSManagedBudgetsSpendLimitManagementAccess/</link>
      <guid isPermaLink="false">https://github.com/zoph-io/IAMTrail/commit/45fb963e15518645a830a3efef688089e23ea30b</guid>
      <pubDate>Fri, 07 Aug 2026 22:03:45 GMT</pubDate>
      <category>IAM Policy</category>
      <description><![CDATA[<p>Scope changed, no action added or removed in AWSManagedBudgetsSpendLimitManagementAccess (v2).</p>]]></description>
    </item>
    <item>
      <title>AmazonSageMakerJobRuntimeAccess: 2 actions added (v2)</title>
      <link>https://iamtrail.com/policies/AmazonSageMakerJobRuntimeAccess/</link>
      <guid isPermaLink="false">https://github.com/zoph-io/IAMTrail/commit/a1bfeb652f29a0bf55114b0defacee6a061079c7</guid>
      <pubDate>Fri, 07 Aug 2026 19:03:19 GMT</pubDate>
      <category>IAM Policy</category>
      <category>kms</category>
      <description><![CDATA[<p>Actions added: kms:Decrypt, kms:GenerateDataKey</p>]]></description>
    </item>
    <item>
      <title>CloudWatchAutomaticDashboardsAccess: 2 actions added (v5)</title>
      <link>https://iamtrail.com/policies/CloudWatchAutomaticDashboardsAccess/</link>
      <guid isPermaLink="false">https://github.com/zoph-io/IAMTrail/commit/07450004696414b7959af28cb6c66c768741b661</guid>
      <pubDate>Fri, 07 Aug 2026 11:03:54 GMT</pubDate>
      <category>IAM Policy</category>
      <category>lambda</category>
      <description><![CDATA[<p>Actions added: lambda:GetFunctionConfiguration, lambda:ListTags</p>]]></description>
    </item>
    <item>
      <title>New policy: AmazonODBNetworkAdmin (24 actions)</title>
      <link>https://iamtrail.com/policies/AmazonODBNetworkAdmin/</link>
      <guid isPermaLink="false">https://github.com/zoph-io/IAMTrail/commit/e76778f36a1ea4b02a0e2fbb593921f89b03da0f</guid>
      <pubDate>Fri, 07 Aug 2026 02:03:32 GMT</pubDate>
      <category>IAM Policy</category>
      <category>ec2</category>
      <category>iam</category>
      <category>odb</category>
      <description><![CDATA[<p><strong>Permissions management</strong>: ec2:CreateOdbNetworkPeering, ec2:DeleteOdbNetworkPeering, ec2:ModifyOdbNetworkPeering, iam:CreateServiceLinkedRole</p>
<p>Actions added: ec2:CreateOdbNetworkPeering, ec2:DeleteOdbNetworkPeering, ec2:DescribeAvailabilityZones, ec2:DescribeVpcs, ec2:ModifyOdbNetworkPeering, iam:CreateServiceLinkedRole, odb:CreateOdbNetwork, odb:CreateOdbPeeringConnection and 16 more</p>]]></description>
    </item>
    <item>
      <title>New policy: AmazonODBReadOnlyAccess (32 actions)</title>
      <link>https://iamtrail.com/policies/AmazonODBReadOnlyAccess/</link>
      <guid isPermaLink="false">https://github.com/zoph-io/IAMTrail/commit/a3c5672055f6b7b7caa8799d9e4e9d59adc40209</guid>
      <pubDate>Fri, 07 Aug 2026 02:03:32 GMT</pubDate>
      <category>IAM Policy</category>
      <category>ec2</category>
      <category>odb</category>
      <description><![CDATA[<p>Actions added: ec2:DescribeAvailabilityZones, ec2:DescribeVpcs, odb:GetAutonomousDatabase, odb:GetAutonomousDatabaseBackup, odb:GetCloudAutonomousVmCluster, odb:GetCloudExadataInfrastructure, odb:GetCloudExadataInfrastructureUnallocatedResources, odb:GetCloudVmCluster and 24 more</p>]]></description>
    </item>
    <item>
      <title>New policy: AmazonODBAutonomousVmClusterAdmin (21 actions)</title>
      <link>https://iamtrail.com/policies/AmazonODBAutonomousVmClusterAdmin/</link>
      <guid isPermaLink="false">https://github.com/zoph-io/IAMTrail/commit/6720f5e3c4074c4fda4034a735b31c129d4ac2f4</guid>
      <pubDate>Fri, 07 Aug 2026 02:03:31 GMT</pubDate>
      <category>IAM Policy</category>
      <category>ec2</category>
      <category>odb</category>
      <description><![CDATA[<p>Actions added: ec2:DescribeAvailabilityZones, odb:CreateCloudAutonomousVmCluster, odb:CreateOutboundIntegration, odb:DeleteCloudAutonomousVmCluster, odb:GetCloudAutonomousVmCluster, odb:GetCloudExadataInfrastructure, odb:GetCloudExadataInfrastructureUnallocatedResources, odb:GetOciOnboardingStatus and 13 more</p>]]></description>
    </item>
    <item>
      <title>New policy: AmazonODBExadataInfrastructureAdmin (21 actions)</title>
      <link>https://iamtrail.com/policies/AmazonODBExadataInfrastructureAdmin/</link>
      <guid isPermaLink="false">https://github.com/zoph-io/IAMTrail/commit/086246263af4a31242bb266b94c366f433a1efb6</guid>
      <pubDate>Fri, 07 Aug 2026 02:03:31 GMT</pubDate>
      <category>IAM Policy</category>
      <category>ec2</category>
      <category>iam</category>
      <category>odb</category>
      <description><![CDATA[<p><strong>Permissions management</strong>: iam:CreateServiceLinkedRole</p>
<p>Actions added: ec2:DescribeAvailabilityZones, iam:CreateServiceLinkedRole, odb:CreateCloudExadataInfrastructure, odb:DeleteCloudExadataInfrastructure, odb:DeleteResourcePolicy, odb:GetCloudExadataInfrastructure, odb:GetCloudExadataInfrastructureUnallocatedResources, odb:GetDbServer and 13 more</p>]]></description>
    </item>
    <item>
      <title>AWSManagedSettingsAdminAccess: scope changed, no action added or removed (v3)</title>
      <link>https://iamtrail.com/policies/AWSManagedSettingsAdminAccess/</link>
      <guid isPermaLink="false">https://github.com/zoph-io/IAMTrail/commit/2567942b9554ae0e684bcbc08933473fbb086210</guid>
      <pubDate>Fri, 07 Aug 2026 01:03:38 GMT</pubDate>
      <category>IAM Policy</category>
      <description><![CDATA[<p>Scope changed, no action added or removed in AWSManagedSettingsAdminAccess (v3).</p>]]></description>
    </item>
    <item>
      <title>Endpoint changes: 1 service expansion</title>
      <link>https://iamtrail.com/endpoints/</link>
      <guid isPermaLink="false">https://github.com/boto/botocore/commit/01ee98096bef1201cfe10e7b72c920fa0ce63b1e</guid>
      <pubDate>Fri, 07 Aug 2026 00:07:48 GMT</pubDate>
      <category>Endpoints</category>
      <category>aws</category>
      <description><![CDATA[<p>1 service expansion in the AWS endpoint data.</p>
<ul>
<li>cassandra expanded to ca-west-1 [aws]</li>
</ul>]]></description>
    </item>
    <item>
      <title>AgentRegistryFullAccess: 3 never-before-seen actions</title>
      <link>https://iamtrail.com/policies/AgentRegistryFullAccess/</link>
      <guid isPermaLink="false">https://github.com/zoph-io/IAMTrail/commit/e9769e1a9b0155ce1a97a1af7cd6095f488ec719</guid>
      <pubDate>Thu, 06 Aug 2026 19:03:26 GMT</pubDate>
      <category>IAM Policy</category>
      <category>bedrock-agentcore</category>
      <category>iam</category>
      <category>kms</category>
      <category>secretsmanager</category>
      <description><![CDATA[<p><strong>3 never-before-seen actions</strong>: bedrock-agentcore:CreateWorkloadIdentity, bedrock-agentcore:DeleteWorkloadIdentity, bedrock-agentcore:GetResourceOauth2Token</p>
<p><strong>Permissions management</strong>: iam:CreateServiceLinkedRole, iam:PassRole</p>
<p>Actions added: bedrock-agentcore:CreateWorkloadIdentity, bedrock-agentcore:DeleteWorkloadIdentity, bedrock-agentcore:GetResourceOauth2Token, bedrock-agentcore:GetWorkloadAccessToken, bedrock-agentcore:GetWorkloadIdentity, bedrock-agentcore:ListOauth2CredentialProviders, iam:CreateServiceLinkedRole, iam:ListRoles and 3 more</p>]]></description>
    </item>
    <item>
      <title>AgentRegistryReadOnlyAccess: new AWS service agent-registry</title>
      <link>https://iamtrail.com/policies/AgentRegistryReadOnlyAccess/</link>
      <guid isPermaLink="false">https://github.com/zoph-io/IAMTrail/commit/4f5b0e06bbacc7e96407116b758c6d4e3b7a6807</guid>
      <pubDate>Thu, 06 Aug 2026 19:03:26 GMT</pubDate>
      <category>IAM Policy</category>
      <category>agent-registry</category>
      <description><![CDATA[<p><strong>New AWS service agent-registry</strong>: agent-registry. Never seen in any AWS managed policy before.</p>
<p>Actions added: agent-registry:GetDiscoverableRegistryRecord, agent-registry:GetRegistry, agent-registry:GetRegistryRecord, agent-registry:InvokeRegistryMcp, agent-registry:ListDiscoverableRegistryRecords, agent-registry:ListRegistries, agent-registry:ListRegistryRecords, agent-registry:ListTagsForResource and 1 more</p>]]></description>
    </item>
    <item>
      <title>AWSBackupAccessPointOperatorAccess: 6 never-before-seen actions</title>
      <link>https://iamtrail.com/policies/AWSBackupAccessPointOperatorAccess/</link>
      <guid isPermaLink="false">https://github.com/zoph-io/IAMTrail/commit/a4c4b788b632301a2cd93ec6a2de9e8a1fb9800c</guid>
      <pubDate>Thu, 06 Aug 2026 17:03:13 GMT</pubDate>
      <category>IAM Policy</category>
      <category>backup</category>
      <category>kms</category>
      <category>s3</category>
      <description><![CDATA[<p><strong>6 never-before-seen actions</strong>: backup:ListBackupAccessPoints, backup:ListBackupAccessPointsByRecoveryPoint, backup:ListBackupAccessPointsByResource, s3:CreateAccessPoint, s3:DeleteAccessPoint, s3:PutAccessPointPolicy</p>
<p><strong>Permissions management</strong>: s3:PutAccessPointPolicy</p>
<p>Actions added: backup:CreateBackupAccessPoint, backup:DeleteBackupAccessPoint, backup:DescribeBackupAccessPoint, backup:ListBackupAccessPoints, backup:ListBackupAccessPointsByRecoveryPoint, backup:ListBackupAccessPointsByResource, kms:Decrypt, s3:CreateAccessPoint and 3 more</p>]]></description>
    </item>
    <item>
      <title>AWSTransformNetworkMigrationAgentPolicy: 25 never-before-seen actions</title>
      <link>https://iamtrail.com/policies/AWSTransformNetworkMigrationAgentPolicy/</link>
      <guid isPermaLink="false">https://github.com/zoph-io/IAMTrail/commit/9efdcaf98e810ba450213b0eb68f88411e7ad881</guid>
      <pubDate>Thu, 06 Aug 2026 16:04:22 GMT</pubDate>
      <category>IAM Policy</category>
      <category>cloudformation</category>
      <category>directconnect</category>
      <category>ec2</category>
      <category>elasticloadbalancing</category>
      <category>globalaccelerator</category>
      <category>iam</category>
      <category>kms</category>
      <category>lambda</category>
      <category>logs</category>
      <category>mgn</category>
      <description><![CDATA[<p><strong>25 never-before-seen actions</strong>: mgn:CreateNetworkMigrationDefinition, mgn:DeleteNetworkMigrationDefinition, mgn:GetNetworkMigrationDefinition, mgn:ListNetworkMigrationAnalyses, mgn:ListNetworkMigrationAnalysisResults, mgn:ListNetworkMigrationCodeGenerationSegments, mgn:ListNetworkMigrationCodeGenerations, mgn:ListNetworkMigrationDefinitions and 17 more</p>
<p><strong>Permissions management</strong>: iam:AttachRolePolicy, iam:CreateRole, iam:CreateServiceLinkedRole, iam:DeleteRole, iam:DeleteRolePolicy, iam:DetachRolePolicy, iam:PassRole, ram:AssociateResourceShare and 6 more</p>
<p>Actions added: cloudformation:CreateStack, cloudformation:DeleteStack, cloudformation:DescribeStackEvents, cloudformation:DescribeStackResources, cloudformation:DescribeStacks, cloudformation:GetTemplateSummary, cloudformation:ListStackResources, cloudformation:ListStacks and 213 more</p>]]></description>
    </item>
    <item>
      <title>AWSTransformServerMigrationAgentPolicy: 30 never-before-seen actions</title>
      <link>https://iamtrail.com/policies/AWSTransformServerMigrationAgentPolicy/</link>
      <guid isPermaLink="false">https://github.com/zoph-io/IAMTrail/commit/ceedd66de8d6094b9707b9e5dacaa4ab89f4ccee</guid>
      <pubDate>Thu, 06 Aug 2026 16:04:22 GMT</pubDate>
      <category>IAM Policy</category>
      <category>ec2</category>
      <category>fsx</category>
      <category>iam</category>
      <category>kms</category>
      <category>mgn</category>
      <category>organizations</category>
      <category>s3</category>
      <category>secretsmanager</category>
      <category>servicequotas</category>
      <category>ssm</category>
      <description><![CDATA[<p><strong>30 never-before-seen actions</strong>: mgn:AssociateApplications, mgn:AssociateSourceServers, mgn:CreateApplication, mgn:CreateWave, mgn:DeleteApplication, mgn:DeleteWave, mgn:DisassociateApplications, mgn:DisassociateSourceServers and 22 more</p>
<p><strong>Permissions management</strong>: iam:PassRole</p>
<p>Actions added: ec2:AttachVolume, ec2:AuthorizeSecurityGroupEgress, ec2:CreateLaunchTemplateVersion, ec2:CreateSecurityGroup, ec2:CreateSnapshot, ec2:CreateTags, ec2:CreateVolume, ec2:DeleteLaunchTemplateVersions and 117 more</p>]]></description>
    </item>
    <item>
      <title>AWSTransformLandingZoneAgentPolicy: 5 never-before-seen actions</title>
      <link>https://iamtrail.com/policies/AWSTransformLandingZoneAgentPolicy/</link>
      <guid isPermaLink="false">https://github.com/zoph-io/IAMTrail/commit/f3d85ddc72017e84b39d2de4bb8b88a35ff22116</guid>
      <pubDate>Thu, 06 Aug 2026 16:04:21 GMT</pubDate>
      <category>IAM Policy</category>
      <category>cloudformation</category>
      <category>controltower</category>
      <category>organizations</category>
      <category>s3</category>
      <category>servicecatalog</category>
      <description><![CDATA[<p><strong>5 never-before-seen actions</strong>: controltower:EnableBaseline, controltower:EnableControl, controltower:GetBaseline, controltower:TagResource, organizations:CreateOrganizationalUnit</p>
<p>Actions added: cloudformation:CreateChangeSet, cloudformation:CreateStack, cloudformation:DescribeChangeSet, cloudformation:DescribeStackEvents, cloudformation:DescribeStacks, cloudformation:ExecuteChangeSet, cloudformation:GetTemplate, cloudformation:ListChangeSets and 53 more</p>]]></description>
    </item>
    <item>
      <title>New policy: AWSAgentRegistryServiceRolePolicy (1 action)</title>
      <link>https://iamtrail.com/policies/AWSAgentRegistryServiceRolePolicy/</link>
      <guid isPermaLink="false">https://github.com/zoph-io/IAMTrail/commit/e5d232872ad2eb59814468de52e86a24ac3fe12e</guid>
      <pubDate>Thu, 06 Aug 2026 15:03:39 GMT</pubDate>
      <category>IAM Policy</category>
      <category>cloudwatch</category>
      <description><![CDATA[<p>Actions added: cloudwatch:PutMetricData</p>]]></description>
    </item>
    <item>
      <title>BedrockAgentCoreRuntimeInstancesOperatorRolePolicy: scope changed, no action added or removed (v2)</title>
      <link>https://iamtrail.com/policies/BedrockAgentCoreRuntimeInstancesOperatorRolePolicy/</link>
      <guid isPermaLink="false">https://github.com/zoph-io/IAMTrail/commit/4369cdc422a80519ad664e3bb4371c4b9860164f</guid>
      <pubDate>Thu, 06 Aug 2026 11:03:34 GMT</pubDate>
      <category>IAM Policy</category>
      <description><![CDATA[<p>Scope changed, no action added or removed in BedrockAgentCoreRuntimeInstancesOperatorRolePolicy (v2).</p>]]></description>
    </item>
    <item>
      <title>3 never-before-seen actions on Amazon S3 (s3)</title>
      <link>https://iamtrail.com/discoveries/</link>
      <guid isPermaLink="false">iamtrail:discovery:actions:2026-08-06:s3</guid>
      <pubDate>Thu, 06 Aug 2026 00:00:00 GMT</pubDate>
      <category>Discovery</category>
      <category>Never-before-seen action</category>
      <category>s3</category>
      <description><![CDATA[<p>3 never-before-seen actions on <strong>Amazon S3 (s3)</strong>, first seen in AWSBackupAccessPointOperatorAccess.</p>
<p><strong>Permissions management</strong>: s3:PutAccessPointPolicy</p>
<p>s3:CreateAccessPoint, s3:DeleteAccessPoint, s3:PutAccessPointPolicy</p>]]></description>
    </item>
    <item>
      <title>1 never-before-seen action: organizations:CreateOrganizationalUnit</title>
      <link>https://iamtrail.com/actions/b3JnYW5pemF0aW9uczpDcmVhdGVPcmdhbml6YXRpb25hbFVuaXQ/</link>
      <guid isPermaLink="false">iamtrail:discovery:actions:2026-08-06:organizations</guid>
      <pubDate>Thu, 06 Aug 2026 00:00:00 GMT</pubDate>
      <category>Discovery</category>
      <category>Never-before-seen action</category>
      <category>organizations</category>
      <description><![CDATA[<p>1 never-before-seen action on <strong>AWS Organizations (organizations)</strong>, first seen in AWSTransformLandingZoneAgentPolicy.</p>
<p>organizations:CreateOrganizationalUnit</p>]]></description>
    </item>
    <item>
      <title>55 never-before-seen actions on AWS Application Migration Service (mgn)</title>
      <link>https://iamtrail.com/discoveries/</link>
      <guid isPermaLink="false">iamtrail:discovery:actions:2026-08-06:mgn</guid>
      <pubDate>Thu, 06 Aug 2026 00:00:00 GMT</pubDate>
      <category>Discovery</category>
      <category>Never-before-seen action</category>
      <category>mgn</category>
      <description><![CDATA[<p>55 never-before-seen actions on <strong>AWS Application Migration Service (mgn)</strong>, first seen in AWSTransformServerMigrationAgentPolicy, AWSTransformNetworkMigrationAgentPolicy.</p>
<p>mgn:AssociateApplications, mgn:AssociateSourceServers, mgn:CreateApplication, mgn:CreateNetworkMigrationDefinition, mgn:CreateWave, mgn:DeleteApplication, mgn:DeleteNetworkMigrationDefinition, mgn:DeleteWave and 47 more</p>]]></description>
    </item>
    <item>
      <title>4 never-before-seen actions on AWS Control Tower (controltower)</title>
      <link>https://iamtrail.com/discoveries/</link>
      <guid isPermaLink="false">iamtrail:discovery:actions:2026-08-06:controltower</guid>
      <pubDate>Thu, 06 Aug 2026 00:00:00 GMT</pubDate>
      <category>Discovery</category>
      <category>Never-before-seen action</category>
      <category>controltower</category>
      <description><![CDATA[<p>4 never-before-seen actions on <strong>AWS Control Tower (controltower)</strong>, first seen in AWSTransformLandingZoneAgentPolicy.</p>
<p>controltower:EnableBaseline, controltower:EnableControl, controltower:GetBaseline, controltower:TagResource</p>]]></description>
    </item>
    <item>
      <title>3 never-before-seen actions on Amazon Bedrock Agentcore (bedrock-agentcore)</title>
      <link>https://iamtrail.com/discoveries/</link>
      <guid isPermaLink="false">iamtrail:discovery:actions:2026-08-06:bedrock-agentcore</guid>
      <pubDate>Thu, 06 Aug 2026 00:00:00 GMT</pubDate>
      <category>Discovery</category>
      <category>Never-before-seen action</category>
      <category>bedrock-agentcore</category>
      <description><![CDATA[<p>3 never-before-seen actions on <strong>Amazon Bedrock Agentcore (bedrock-agentcore)</strong>, first seen in AgentRegistryFullAccess.</p>
<p>bedrock-agentcore:CreateWorkloadIdentity, bedrock-agentcore:DeleteWorkloadIdentity, bedrock-agentcore:GetResourceOauth2Token</p>]]></description>
    </item>
    <item>
      <title>3 never-before-seen actions on AWS Backup (backup)</title>
      <link>https://iamtrail.com/discoveries/</link>
      <guid isPermaLink="false">iamtrail:discovery:actions:2026-08-06:backup</guid>
      <pubDate>Thu, 06 Aug 2026 00:00:00 GMT</pubDate>
      <category>Discovery</category>
      <category>Never-before-seen action</category>
      <category>backup</category>
      <description><![CDATA[<p>3 never-before-seen actions on <strong>AWS Backup (backup)</strong>, first seen in AWSBackupAccessPointOperatorAccess.</p>
<p>backup:ListBackupAccessPoints, backup:ListBackupAccessPointsByRecoveryPoint, backup:ListBackupAccessPointsByResource</p>]]></description>
    </item>
    <item>
      <title>New AWS service agent-registry</title>
      <link>https://iamtrail.com/discoveries/</link>
      <guid isPermaLink="false">iamtrail:discovery:service:agent-registry</guid>
      <pubDate>Thu, 06 Aug 2026 00:00:00 GMT</pubDate>
      <category>Discovery</category>
      <category>New AWS service</category>
      <category>agent-registry</category>
      <description><![CDATA[<p><strong>agent-registry</strong> appeared in an AWS managed IAM policy for the first time, in AgentRegistryReadOnlyAccess.</p>
<p>9 actions on this prefix are now tracked.</p>]]></description>
    </item>
    <item>
      <title>AWSIAMRoleManagerServiceRolePolicy: 1 action added (v2). Permissions management: iam:CreateServiceLinkedRole</title>
      <link>https://iamtrail.com/policies/AWSIAMRoleManagerServiceRolePolicy/</link>
      <guid isPermaLink="false">https://github.com/zoph-io/IAMTrail/commit/956bf538f03dcaced1ac4dea864bc0ce6a5536d9</guid>
      <pubDate>Wed, 05 Aug 2026 20:03:25 GMT</pubDate>
      <category>IAM Policy</category>
      <category>iam</category>
      <description><![CDATA[<p><strong>Permissions management</strong>: iam:CreateServiceLinkedRole</p>
<p>Actions added: iam:CreateServiceLinkedRole</p>]]></description>
    </item>
    <item>
      <title>BatchServiceRolePolicy: 4 never-before-seen actions</title>
      <link>https://iamtrail.com/policies/BatchServiceRolePolicy/</link>
      <guid isPermaLink="false">https://github.com/zoph-io/IAMTrail/commit/5a3ee017141b8dcaa5842035ea331a248929f901</guid>
      <pubDate>Wed, 05 Aug 2026 18:03:38 GMT</pubDate>
      <category>IAM Policy</category>
      <category>ecs</category>
      <description><![CDATA[<p><strong>4 never-before-seen actions</strong>: ecs:CreateCapacityProvider, ecs:DeleteCapacityProvider, ecs:PutClusterCapacityProviders, ecs:UpdateCapacityProvider</p>
<p>Actions added: ecs:CreateCapacityProvider, ecs:DeleteCapacityProvider, ecs:DescribeCapacityProviders, ecs:PutClusterCapacityProviders, ecs:UntagResource, ecs:UpdateCapacityProvider, ecs:UpdateCluster</p>]]></description>
    </item>
    <item>
      <title>New policy: AIDevOpsConstellationAccessPolicy (11 actions)</title>
      <link>https://iamtrail.com/policies/AIDevOpsConstellationAccessPolicy/</link>
      <guid isPermaLink="false">https://github.com/zoph-io/IAMTrail/commit/c97f656d548fdcbe80a997e07ff25c74d4246e16</guid>
      <pubDate>Wed, 05 Aug 2026 17:03:23 GMT</pubDate>
      <category>IAM Policy</category>
      <category>aidevops</category>
      <description><![CDATA[<p>Actions added: aidevops:CreateBacklogTask, aidevops:GetAgentSpace, aidevops:GetAsset, aidevops:GetAssetContent, aidevops:GetAssetFile, aidevops:GetBacklogTask, aidevops:ListAssetFiles, aidevops:ListAssets and 3 more</p>]]></description>
    </item>
    <item>
      <title>BedrockAgentCoreRuntimeInstancesInstanceRolePolicy: 1 never-before-seen action</title>
      <link>https://iamtrail.com/policies/BedrockAgentCoreRuntimeInstancesInstanceRolePolicy/</link>
      <guid isPermaLink="false">https://github.com/zoph-io/IAMTrail/commit/993af0cf6aa5aabf112ae7409f6a05872e60a63a</guid>
      <pubDate>Wed, 05 Aug 2026 14:03:50 GMT</pubDate>
      <category>IAM Policy</category>
      <category>bedrock-agentcore</category>
      <description><![CDATA[<p><strong>1 never-before-seen action</strong>: bedrock-agentcore:PutSystemLogEvents</p>
<p>Actions added: bedrock-agentcore:PutSystemLogEvents</p>]]></description>
    </item>
    <item>
      <title>BedrockAgentCoreRuntimeInstancesOperatorRolePolicy: 1 never-before-seen action</title>
      <link>https://iamtrail.com/policies/BedrockAgentCoreRuntimeInstancesOperatorRolePolicy/</link>
      <guid isPermaLink="false">https://github.com/zoph-io/IAMTrail/commit/3989ecd1eae49ef31aaa59b77256df331bcde25d</guid>
      <pubDate>Wed, 05 Aug 2026 12:03:38 GMT</pubDate>
      <category>IAM Policy</category>
      <category>autoscaling</category>
      <category>ec2</category>
      <category>events</category>
      <category>iam</category>
      <description><![CDATA[<p><strong>1 never-before-seen action</strong>: autoscaling:LaunchInstances</p>
<p><strong>Permissions management</strong>: iam:CreateServiceLinkedRole, iam:PassRole</p>
<p>Actions added: autoscaling:CompleteLifecycleAction, autoscaling:CreateAutoScalingGroup, autoscaling:DescribeAutoScalingGroups, autoscaling:DescribeAutoScalingInstances, autoscaling:LaunchInstances, autoscaling:PutLifecycleHook, autoscaling:UpdateAutoScalingGroup, ec2:AttachNetworkInterface and 26 more</p>]]></description>
    </item>
    <item>
      <title>New policy: AWSBedrockAgentCoreRuntimeInstancesServiceRolePolicy (16 actions)</title>
      <link>https://iamtrail.com/policies/AWSBedrockAgentCoreRuntimeInstancesServiceRolePolicy/</link>
      <guid isPermaLink="false">https://github.com/zoph-io/IAMTrail/commit/1af1cfbba1fdef5cf0e68d5bd5d4f15a553e08bd</guid>
      <pubDate>Wed, 05 Aug 2026 10:03:45 GMT</pubDate>
      <category>IAM Policy</category>
      <category>autoscaling</category>
      <category>ec2</category>
      <category>events</category>
      <description><![CDATA[<p>Actions added: autoscaling:CompleteLifecycleAction, autoscaling:DeleteAutoScalingGroup, autoscaling:DescribeAutoScalingGroups, ec2:DeleteLaunchTemplate, ec2:DeleteLaunchTemplateVersions, ec2:DeleteVolume, ec2:DescribeInstanceStatus, ec2:DescribeInstances and 8 more</p>]]></description>
    </item>
    <item>
      <title>4 never-before-seen actions on Amazon Elastic Container Service (ecs)</title>
      <link>https://iamtrail.com/discoveries/</link>
      <guid isPermaLink="false">iamtrail:discovery:actions:2026-08-05:ecs</guid>
      <pubDate>Wed, 05 Aug 2026 00:00:00 GMT</pubDate>
      <category>Discovery</category>
      <category>Never-before-seen action</category>
      <category>ecs</category>
      <description><![CDATA[<p>4 never-before-seen actions on <strong>Amazon Elastic Container Service (ecs)</strong>, first seen in BatchServiceRolePolicy.</p>
<p>ecs:CreateCapacityProvider, ecs:DeleteCapacityProvider, ecs:PutClusterCapacityProviders, ecs:UpdateCapacityProvider</p>]]></description>
    </item>
    <item>
      <title>Endpoint changes: 1 service expansion</title>
      <link>https://iamtrail.com/endpoints/</link>
      <guid isPermaLink="false">https://github.com/boto/botocore/commit/93d5c8eae611ab4015cfda40e8603ea55d06dbe2</guid>
      <pubDate>Fri, 31 Jul 2026 09:10:49 GMT</pubDate>
      <category>Endpoints</category>
      <category>aws</category>
      <description><![CDATA[<p>1 service expansion in the AWS endpoint data.</p>
<ul>
<li>vpc-lattice expanded to ap-southeast-5 [aws]</li>
</ul>]]></description>
    </item>
    <item>
      <title>Endpoint changes: 1 new service</title>
      <link>https://iamtrail.com/endpoints/</link>
      <guid isPermaLink="false">https://github.com/boto/botocore/commit/19725482fcb759e090f2c7763770d062364cfcfc</guid>
      <pubDate>Wed, 29 Jul 2026 19:26:25 GMT</pubDate>
      <category>Endpoints</category>
      <category>aws-iso</category>
      <category>aws-iso-b</category>
      <description><![CDATA[<p>1 new service in the AWS endpoint data.</p>
<ul>
<li>emr-serverless (1 endpoint) [aws-iso]</li>
<li>emr-serverless (1 endpoint) [aws-iso-b]</li>
</ul>]]></description>
    </item>
    <item>
      <title>Endpoint changes: 1 new service</title>
      <link>https://iamtrail.com/endpoints/</link>
      <guid isPermaLink="false">https://github.com/boto/botocore/commit/107fce163ec6a5232f2c37c2aae7dcb2bf01715e</guid>
      <pubDate>Mon, 27 Jul 2026 19:44:08 GMT</pubDate>
      <category>Endpoints</category>
      <category>aws-iso</category>
      <description><![CDATA[<p>1 new service in the AWS endpoint data.</p>
<ul>
<li>appstream2 (2 endpoints) [aws-iso]</li>
</ul>]]></description>
    </item>
    <item>
      <title>Endpoint changes: 3 new services</title>
      <link>https://iamtrail.com/endpoints/</link>
      <guid isPermaLink="false">https://github.com/boto/botocore/commit/10c539e0d89099fe7cb16e779fc25ef86c452a92</guid>
      <pubDate>Fri, 24 Jul 2026 19:38:44 GMT</pubDate>
      <category>Endpoints</category>
      <category>aws-iso</category>
      <category>aws-iso-b</category>
      <category>aws-iso-e</category>
      <description><![CDATA[<p>3 new services in the AWS endpoint data.</p>
<ul>
<li>compute-optimizer (1 endpoint) [aws-iso]</li>
<li>cost-optimization-hub (1 endpoint) [aws-iso]</li>
<li>compute-optimizer (1 endpoint) [aws-iso-b]</li>
<li>cost-optimization-hub (1 endpoint) [aws-iso-b]</li>
<li>rolesanywhere (1 endpoint) [aws-iso-e]</li>
</ul>]]></description>
    </item>
    <item>
      <title>Endpoint changes: 1 new service, 2 service expansions</title>
      <link>https://iamtrail.com/endpoints/</link>
      <guid isPermaLink="false">https://github.com/boto/botocore/commit/770567f78fceecb4e20d777d1de8a0b4913d2316</guid>
      <pubDate>Wed, 22 Jul 2026 19:35:47 GMT</pubDate>
      <category>Endpoints</category>
      <category>aws</category>
      <category>aws-eusc</category>
      <description><![CDATA[<p>1 new service, 2 service expansions in the AWS endpoint data.</p>
<ul>
<li>drs expanded to ap-east-2, ap-southeast-5, ap-southeast-7, mx-central-1 [aws]</li>
<li>omics expanded to ap-northeast-1, us-east-2 [aws]</li>
<li>redshift-serverless (1 endpoint) [aws-eusc]</li>
</ul>]]></description>
    </item>
    <item>
      <title>Endpoint changes: 1 new service, 2 service expansions</title>
      <link>https://iamtrail.com/endpoints/</link>
      <guid isPermaLink="false">https://github.com/boto/botocore/commit/dad7113e65e5062b5787511255bf3bb2b16df019</guid>
      <pubDate>Sat, 18 Jul 2026 03:11:18 GMT</pubDate>
      <category>Endpoints</category>
      <category>aws-eusc</category>
      <category>aws-iso</category>
      <category>aws-iso-b</category>
      <description><![CDATA[<p>1 new service, 2 service expansions in the AWS endpoint data.</p>
<ul>
<li>guardduty expanded to us-iso-west-1 [aws-iso]</li>
<li>backup expanded to us-isob-west-1 [aws-iso-b]</li>
<li>emr-serverless (1 endpoint) [aws-eusc]</li>
</ul>]]></description>
    </item>
    <item>
      <title>GuardDuty New Finding: UnauthorizedAccess:IAMUser/ResourceCredentialExfiltration.InsideAWS</title>
      <link>https://iamtrail.com/guardduty/</link>
      <guid isPermaLink="false">iamtrail:guardduty:2026-07-17T14:49:35Z:NEW_FINDINGS:unauthorizedaccess-iamuser-resourcecredentialexfiltration-insideaws</guid>
      <pubDate>Fri, 17 Jul 2026 14:49:35 GMT</pubDate>
      <category>GuardDuty</category>
      <category>New Finding</category>
      <description><![CDATA[<p>This finding informs you that a host within AWS has attempted to run AWS API operations using temporary AWS credentials that were created on an ECS resource in your AWS environment.</p>]]></description>
    </item>
    <item>
      <title>GuardDuty New Finding: UnauthorizedAccess:IAMUser/ResourceCredentialExfiltration.OutsideAWS</title>
      <link>https://iamtrail.com/guardduty/</link>
      <guid isPermaLink="false">iamtrail:guardduty:2026-07-17T14:49:35Z:NEW_FINDINGS:unauthorizedaccess-iamuser-resourcecredentialexfiltration-outsideaws</guid>
      <pubDate>Fri, 17 Jul 2026 14:49:35 GMT</pubDate>
      <category>GuardDuty</category>
      <category>New Finding</category>
      <description><![CDATA[<p>This finding informs you that a host outside of AWS has attempted to run AWS API operations using temporary AWS credentials that were created on an ECS resource in your AWS environment.</p>]]></description>
    </item>
    <item>
      <title>Endpoint changes: 1 service expansion</title>
      <link>https://iamtrail.com/endpoints/</link>
      <guid isPermaLink="false">https://github.com/boto/botocore/commit/31af253ee49bea34214380b92e7d0152d5f69fa4</guid>
      <pubDate>Fri, 17 Jul 2026 03:21:31 GMT</pubDate>
      <category>Endpoints</category>
      <category>aws-iso-b</category>
      <description><![CDATA[<p>1 service expansion in the AWS endpoint data.</p>
<ul>
<li>storagegateway expanded to us-isob-west-1 [aws-iso-b]</li>
</ul>]]></description>
    </item>
    <item>
      <title>GuardDuty New Feature: Amazon GuardDuty now offers AI Protection, expanding threat detection to AWS AI services including Amazon Bedrock and...</title>
      <link>https://iamtrail.com/guardduty/</link>
      <guid isPermaLink="false">iamtrail:guardduty:2026-07-14T20:37:24Z:NEW_FEATURES:amazon-guardduty-now-offers-ai-protection-expanding-threat-detection-to-aws-ai-s</guid>
      <pubDate>Tue, 14 Jul 2026 20:37:24 GMT</pubDate>
      <category>GuardDuty</category>
      <category>New Feature</category>
      <description><![CDATA[<p>Amazon GuardDuty now offers AI Protection, expanding threat detection to AWS AI services including Amazon Bedrock and Amazon SageMaker. As organizations rapidly adopt AI, security teams may lack visibility into threats specifically targeting AI workloads, such as anomalous model invocations, cost harvesting attacks, and prompt injection attempts. GuardDuty AI Protection continuously monitors these workloads so security teams can detect and respond to AI-specific threats without manual configuration or custom tooling.

GuardDuty AI Protection analyzes both CloudTrail management and data events from AWS AI services to identify suspicious activity, including unusual invocation patterns, cost harvesting attacks where threat actors force AI resources to consume excessive GPU time and tokens, and prompt injection attempts through integration with Amazon Bedrock Guardrails. AI Protection introduces three new finding types: Impact:IAMUser/AnomalousModelInvocation, Impact:IAMUser/CostHarvesting, and Impact:IAMUser/PromptInjection.Direct. GuardDuty AI Protection can be enabled with a few steps in the GuardDuty or Security Hub console, and using AWS Organizations, can be centrally enabled for all accounts in an organization.</p>]]></description>
    </item>
    <item>
      <title>Endpoint changes: 1 service expansion</title>
      <link>https://iamtrail.com/endpoints/</link>
      <guid isPermaLink="false">https://github.com/boto/botocore/commit/e8a69b4d1a7500ed3d8b623939ad8f7fb7bd9b92</guid>
      <pubDate>Mon, 13 Jul 2026 19:38:10 GMT</pubDate>
      <category>Endpoints</category>
      <category>aws</category>
      <description><![CDATA[<p>1 service expansion in the AWS endpoint data.</p>
<ul>
<li>wisdom expanded to af-south-1 [aws]</li>
</ul>]]></description>
    </item>
    <item>
      <title>Endpoint changes: 1 service expansion</title>
      <link>https://iamtrail.com/endpoints/</link>
      <guid isPermaLink="false">https://github.com/boto/botocore/commit/601925e542e1cd3fcf2a861cbc0d1c0dbfacd92e</guid>
      <pubDate>Fri, 10 Jul 2026 19:42:33 GMT</pubDate>
      <category>Endpoints</category>
      <category>aws</category>
      <description><![CDATA[<p>1 service expansion in the AWS endpoint data.</p>
<ul>
<li>aps expanded to ap-southeast-6 [aws]</li>
</ul>]]></description>
    </item>
    <item>
      <title>Endpoint changes: 1 new service</title>
      <link>https://iamtrail.com/endpoints/</link>
      <guid isPermaLink="false">https://github.com/boto/botocore/commit/7cf1bc425813bb6af501b9d80a23790ee8265e57</guid>
      <pubDate>Mon, 06 Jul 2026 20:06:44 GMT</pubDate>
      <category>Endpoints</category>
      <category>aws-iso-e</category>
      <category>aws-iso-f</category>
      <description><![CDATA[<p>1 new service in the AWS endpoint data.</p>
<ul>
<li>health (1 endpoint) [aws-iso-e]</li>
<li>health (1 endpoint) [aws-iso-f]</li>
</ul>]]></description>
    </item>
    <item>
      <title>Endpoint changes: 1 service expansion</title>
      <link>https://iamtrail.com/endpoints/</link>
      <guid isPermaLink="false">https://github.com/boto/botocore/commit/420c5848eac57be3c4dcc5c9b1f36085de397695</guid>
      <pubDate>Fri, 03 Jul 2026 03:53:26 GMT</pubDate>
      <category>Endpoints</category>
      <category>aws</category>
      <description><![CDATA[<p>1 service expansion in the AWS endpoint data.</p>
<ul>
<li>codepipeline expanded to ap-southeast-6 [aws]</li>
</ul>]]></description>
    </item>
    <item>
      <title>GuardDuty New Feature: Amazon GuardDuty now offers AI-powered investigations in public preview, a new capability that automatically analyzes...</title>
      <link>https://iamtrail.com/guardduty/</link>
      <guid isPermaLink="false">iamtrail:guardduty:2026-06-22T23:38:51Z:NEW_FEATURES:amazon-guardduty-now-offers-ai-powered-investigations-in-public-preview-a-new-ca</guid>
      <pubDate>Mon, 22 Jun 2026 23:38:51 GMT</pubDate>
      <category>GuardDuty</category>
      <category>New Feature</category>
      <description><![CDATA[<p>Amazon GuardDuty now offers AI-powered investigations in public preview, a new capability that automatically analyzes GuardDuty findings and accounts to help you quickly distinguish true threats from benign findings. Each investigation delivers a structured summary in minutes with confidence-scored disposition, MITRE ATT&amp;CK technique classification, and actionable recommendations. You can initiate investigations from the GuardDuty console, CLI, API, or AWS MCP Server. This feature is available in 10 AWS Regions: US East (N. Virginia), US East (Ohio), US West (Oregon), Canada (Central), Europe (Frankfurt), Europe (Ireland), Europe (London), Europe (Paris), Europe (Stockholm), and Asia Pacific (Tokyo). To learn more, visit the Amazon GuardDuty User Guide.</p>]]></description>
    </item>
    <item>
      <title>GuardDuty New Feature: Amazon GuardDuty has increased the Malware Protection for S3 archive extraction quotas. The maximum number of files...</title>
      <link>https://iamtrail.com/guardduty/</link>
      <guid isPermaLink="false">iamtrail:guardduty:2026-06-09T22:59:33Z:NEW_FEATURES:amazon-guardduty-has-increased-the-malware-protection-for-s3-archive-extraction-</guid>
      <pubDate>Tue, 09 Jun 2026 22:59:33 GMT</pubDate>
      <category>GuardDuty</category>
      <category>New Feature</category>
      <description><![CDATA[<p>Amazon GuardDuty has increased the Malware Protection for S3 archive extraction quotas. The maximum number of files that can be extracted and analyzed from an archive has increased from 10,000 to 100,000, and the maximum archive depth levels have increased from 5 to 100.</p>]]></description>
    </item>
    <item>
      <title>GuardDuty Updated Finding: Persistence:Kubernetes/ContainerWithSensitiveMount</title>
      <link>https://iamtrail.com/guardduty/</link>
      <guid isPermaLink="false">iamtrail:guardduty:2026-05-30T05:10:55Z:UPDATED_FINDINGS:persistence-kubernetes-containerwithsensitivemount</guid>
      <pubDate>Sat, 30 May 2026 05:10:55 GMT</pubDate>
      <category>GuardDuty</category>
      <category>Updated Finding</category>
      <description><![CDATA[<p>This finding type is replaced by Persistence:Kubernetes/AnomalousBehavior.WorkloadDeployed!ContainerWithSensitiveMount, which provides enhanced detection coverage using anomaly-based machine learning.</p>]]></description>
    </item>
    <item>
      <title>GuardDuty Updated Finding: PrivilegeEscalation:Kubernetes/PrivilegedContainer</title>
      <link>https://iamtrail.com/guardduty/</link>
      <guid isPermaLink="false">iamtrail:guardduty:2026-05-30T05:10:55Z:UPDATED_FINDINGS:privilegeescalation-kubernetes-privilegedcontainer</guid>
      <pubDate>Sat, 30 May 2026 05:10:55 GMT</pubDate>
      <category>GuardDuty</category>
      <category>Updated Finding</category>
      <description><![CDATA[<p>This finding type is replaced by PrivilegeEscalation:Kubernetes/AnomalousBehavior.WorkloadDeployed!PrivilegedContainer, which provides enhanced detection coverage using anomaly-based machine learning.</p>]]></description>
    </item>
    <item>
      <title>GuardDuty New Feature: Amazon GuardDuty Malware Protection for AWS Backup now supports malware scanning for S3 continuous backups, also known...</title>
      <link>https://iamtrail.com/guardduty/</link>
      <guid isPermaLink="false">iamtrail:guardduty:2026-05-27T00:04:06Z:NEW_FEATURES:amazon-guardduty-malware-protection-for-aws-backup-now-supports-malware-scanning</guid>
      <pubDate>Wed, 27 May 2026 00:04:06 GMT</pubDate>
      <category>GuardDuty</category>
      <category>New Feature</category>
      <description><![CDATA[<p>Amazon GuardDuty Malware Protection for AWS Backup now supports malware scanning for S3 continuous backups, also known as point-in-time recovery (PITR). You can now scan S3 continuous backup recovery points for malware, enabling you to confidently restore S3 data to any second within your retention period knowing the recovery point is clean. You can enable this capability even if GuardDuty foundational data sources are not enabled in your account.</p>]]></description>
    </item>
  </channel>
</rss>