IAM is great, but debugging policies is sometimes a little bit cumbersome, or time consuming, waiting for Cloudtrail to report the missing details... Here's a great update from AWS!

Many parts of this great article are not specific to serverless and could also help you approach your security in the cloud.

If you are concerned about your secret management and haven't yet been able to use Vault or similar, this is really a required read, not so long, a very good and comprehensive landscape view of secrets management options available.

In web application security, identifying hackers early in the attack process is key to keep applications secure. This article explains the attack surface concept and how developers can protect themselves

