Uploaded December 2021 | Updated September 2026, 1 week ago
At AWS re:Invent 2021, a re-vamped Amazon Inspector was launched. In this video, I take a first look at the service.
We see how to set it up, how to ensure that your EC2 instances and ECR registries are being inspected, and how to handle a vulnerability finding.
Vulnerability management is a critical information security process and one that'll help shut the door on hackers and cybercriminals. This service is strong addition to your cybersecurity toolkit.
Follow Mark on Twitter at twitter.com/marknca
Learn more about what happened at AWS re:Invent 2021 at markn.ca/2021/reinvent
At AWS re:Invent 2021, a re-vamped Amazon Inspector was launched. In this video, I take a first look at the service.
We see how to set it up, how to ensure that your EC2 instances and ECR registries are being inspected, and how to handle a vulnerability finding.
Vulnerability management is a critical information security process and one that'll help shut the door on hackers and cybercriminals. This service is strong addition to your cybersecurity toolkit.
Follow Mark on Twitter at twitter.com/marknca
Learn more about what happened at AWS re:Invent 2021 at markn.ca/2021/reinvent




![Have You Been Bugged by an Apple Device? #shorts
Is someone using an Apple device to track your whereabouts? Not usually the realm of hackers, more likely a relationship turned dark or an operational security issue, an upcoming iOS feature looks to put a stop to this.
Learn more about it in this short...
Index:
- The question [0:00]
- Item Safety Alert [0:06]
- Find My [0:29]
#shorts Have You Been Bugged by an Apple Device? #shorts](https://i.ytimg.com/vi/YpzMi3sN6bc/mqdefault.jpg)
![What AWS re:Inforce 2021 Means for Cloud Security…and Cybersecurity in General
AWS re:Inforce is AWS major security focused event. The 2021 edition was entirely virtual and the shortened program focused on five main areas. Across those sessions and in the keynote, the team was painting a bigger picture.
They were showing—again—how AWS treats security internally. Its a fascinating look, not at the technical aspects of security, but at how a security practice should be setup organizationally and the tenets that drive it.
This is not only how cloud security practices should be setup, but ALL security practices.
Index:
- [00:00] Traditional security teams
- [00:32] AWS re:Inforce 2021
- [01:37] Since 2017...
- [02:36] Distributed knowledge
- [03:45] One simple truth
- [04:18] Some centralization
- [05:14] A practice explained What AWS re:Inforce 2021 Means for Cloud Security…and Cybersecurity in General](https://i.ytimg.com/vi/Z2zO-goGqUI/mqdefault.jpg)



![Microsoft Windows PrinterNightmare Patch Highlight “Unperfect” Security Decisions #shorts
The PrinterNightmare vulnerability was patched out-of-band (on an emergency basis) but the patch doesnt completely address the issue.
Hackers can still easily use this to run their code on your systems if youre using a feature called Point and Print (and a lot of people are). Where does that leave defenders?
More in this short...
References:
- Brian Krebs has a post on the out-of-band patch; Microsoft Issues Emergency Patch for Windows Flaw, https://krebsonsecurity.com/2021/07/microsoft-issues-emergency-patch-for-windows-flaw/
- From BleepingComputer, Microsofts incomplete PrintNightmare patch fails to fix vulnerability, https://www.bleepingcomputer.com/news/microsoft/microsofts-incomplete-printnightmare-patch-fails-to-fix-vulnerability/
- Security Update Guide from the Microsoft Security Response Center, https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-34527
- Introduction to Point and Print - Windows drivers from the Microsoft docs, https://docs.microsoft.com/en-us/windows-hardware/drivers/print/introduction-to-point-and-print
Index:
- [0:00] The vulnerability
- [0:17] Point and Print
- [0:29] Make a choice
#shorts Microsoft Windows PrinterNightmare Patch Highlight “Unperfect” Security Decisions #shorts](https://i.ytimg.com/vi/ZmmoIMYMlVQ/mqdefault.jpg)
![Nation State Hackers Are Targeting Email Servers, Is It Time To Panic? #shorts
Microsoft warned that a nation state actor called HAFNIUM is actively targeting users of its Microsoft Exchange email server. Thankfully there are patches out for the four issues involved.
Problem solved, right?
Maybe not. We explore in this short...
Index;
- The question [0:00]
- Microsoft Exchange issue [0:05]
- Just patch [0:16]
#shorts Nation State Hackers Are Targeting Email Servers, Is It Time To Panic? #shorts](https://i.ytimg.com/vi/_jlM33jHwdY/mqdefault.jpg)