< ciso
brief />
Vendor and Hyperscaler Watch Banner

All news in category “Vendor and Hyperscaler Watch”

5908 articles

Three-Layer AI Vulnerability Harness for Scanners

🔍 This post explains a three-layer pipeline that filters raw scanner findings into a prioritized, evidence-backed set of vulnerabilities for engineers to act on. It emphasizes a tool-agnostic architecture combining multi-scanner agreement, AST-based structural verification, and deployment-context checks (IaC) to reduce noise and increase confidence. The article describes context scoping for AI reasoning and notes a companion post that covers the steering file controlling model behavior.
read more →

Cloudflare’s Agentic Security Operations for Alerts

🔒 Cloudflare introduces an agentic security operations harness that uses multiple AI agents and deterministic reconnaissance to reduce analyst workload and speed alert triage. The Managed Defense AI harness aggregates evidence, employs Clef for decision scoring, and leverages approved OpenAI Daybreak and Anthropic models for deeper analysis. Specialist agents run in parallel with constrained scopes to avoid hallucinations, while application code enforces data collection, provenance, and reproducibility. The system produces advisory reports, preserves evidence and gaps, and keeps analysts responsible for final decisions.
read more →

Unplanned Paths Into Cybersecurity Careers

🔎 Shannon Brazil shares candid interviews with AWS security professionals about their unconventional routes into cybersecurity. She profiles individuals who transitioned from retail, marketing, and troubled youth into roles like bug bounty, OSINT, and technical risk, highlighting curiosity and persistence as common drivers. The piece introduces a four-part series for Cybersecurity Awareness Month that will explore varied roles and advice for newcomers.
read more →

Three Lessons from Frontier AI Vulnerability Research

🔍 Microsoft Security’s FORGE Lab advances AI-native vulnerability research across Windows and open-source projects, emphasizing autonomy, defense through offense, and ecosystem-focused outcomes. From May to September 2026, FORGE reported 140 Windows CVEs and 155 validated reports across 23 open-source projects, including the Linux kernel. The post argues that discovery scale shifts the bottleneck from model intelligence to reproducible validation, remediation, and integration with engineering and servicing workflows.
read more →

Google Cloud ULL with U4 Machines for Trading

⚡ The Ultra Low Latency (ULL) Solution and new U4 machine family are now GA, delivering deterministic, low-jitter compute and hardware-accelerated multicast networking for high-frequency trading workflows in Google Cloud. The solution combines bare metal and VM options, precision timing, 24/7 packet capture, and isolated multicast fabrics to match co-location performance while providing cloud elasticity and observability. Available in select private regions, it targets exchanges, market participants, and trading service providers.
read more →

Microsoft Outlook to Block .msix and .msixbundle Files

🛡️ Microsoft will add .msix and .msixbundle attachments to the default blocked file types in Outlook on the web and the new Outlook for Windows, starting with a rollout to Exchange Online in early November and GA by mid-November. These package formats are modern Windows installers and bundles used for multiple architectures. Once policies update, users will not be able to send, receive, open, or download these attachments by default, though admins can whitelist them if required. The change is part of ongoing efforts to reduce exploitation of Office and Windows features that attackers abuse.
read more →

AI-driven infrastructure across lifecycle stages

🤖 Microsoft describes how AI is being applied across the full hardware lifecycle—from design and supply chain to deployment and fleet operations—to accelerate learning and improve decision making. The company emphasizes a “Lean before AI” approach that simplifies processes, builds a governed data foundation, and preserves human judgment. Early results include dramatic reductions in planning cycle time, decreased manual effort, and fewer VM interruptions from disk failures.
read more →

AWS Config expands coverage with 77 new types

🆕 AWS Config now supports 77 additional AWS resource types across services including Amazon EC2, Amazon S3 Files, and Amazon Q Business, expanding visibility and governance. If you have enabled recording for all resource types, these additions are tracked automatically and are available for use in Config rules and Config aggregators. The new resource types can be monitored in all AWS Regions where the resources are available, enabling more comprehensive discovery, assessment, audit, and remediation.
read more →

Anthropic expands tiered AI access for vetted security teams

🛡️ Anthropic has expanded its Cyber Verification Program to give vetted security teams tiered access to advanced AI models with reduced safeguards. The program now includes Defense, Red Team, and Specialized Access tiers for progressively broader cybersecurity testing and defensive work. Anthropic tested tiers using CyScenarioBench and says results demonstrate why authorization, scope, and external controls matter.
read more →

One Evidence Graph Instead of Multiple BOM Programs

🔍 In this analysis, the author argues that enterprises should avoid running separate bill-of-materials (BOM) programs for software, cryptography, AI models, authorization and runtime artifacts. Instead, organizations need a federated evidence graph that links domain-specific records via a common envelope and relationship semantics so incident responders can answer cross-cutting questions about affected products, exposure and remediation. The piece details standards, pilot steps and governance to ensure accuracy, trust and least-disclosure practices.
read more →

Microsoft named Leader in 2026 Industrial AIoT MQ

🔔 Microsoft has been named a Leader in the 2026 Gartner® Magic Quadrant™ for Global Industrial AIoT Platforms. The post describes how Azure’s adaptive cloud — including Azure IoT, Azure Arc, Microsoft Fabric, and Microsoft Foundry — connects cloud and edge to turn operational data into actionable intelligence. It emphasizes Industrial and Physical AI to create learning operations that improve productivity, resilience, and safety.
read more →

MCP Toolbox Java SDK v1.0 for enterprise Java

🛠️ This announcement details the release of the MCP Toolbox Java SDK v1.0, bringing type-safe, enterprise-grade agent orchestration to Java ecosystems. The post outlines new features including a transport abstraction, decoupled authentication, default parameter support, parameter pruning, session tracking, and credential exposure warnings. It illustrates a sample use case (Cymbal Transit) integrating AlloyDB with Spring Boot and LangChain4j to demonstrate conversational state, type-safe tools, and secure production deployment patterns.
read more →

Improving SPIRE Security and Resiliency on AWS

🔒 This post explains how to strengthen SPIRE (the SPIFFE Runtime Environment) deployments by offloading core functions to AWS managed services. It outlines replacing default SPIRE components with AWS KMS, AWS Private CA, Amazon Aurora, Amazon S3, AWS Secrets Manager, and Amazon Verified Permissions to improve security, scalability, and operational resiliency. A GitHub repository provides deployment templates and configuration examples to follow along.
read more →

AWS Batch publishes job metrics to CloudWatch

📊 AWS Batch now publishes job lifecycle metrics natively to Amazon CloudWatch, improving observability for batch workloads. Metrics include state transitions (submitted, running, succeeded, failed) and duration metrics (time between states and total execution time) under the AWS/Batch namespace with a JobQueueName dimension. These metrics are viewable in the AWS Batch console, CloudWatch console, AWS CLI, and SDKs, and are available in all Regions where AWS Batch runs.
read more →

Identity-aware AI data agents with AWS Lake Formation

🔒 This post describes a deployable pattern for propagating user identity through AI data agents built on Amazon Bedrock AgentCore so that AWS Lake Formation evaluates per-user grants. It explains the HTTP header-based token transport (access_token in Authorization and id_token in a custom header) and the three AgentCore features that keep the token out of the model context. The flow ends with a Lambda exchange that assumes a TIP role, runs Athena under the user’s identity, and preserves CloudTrail auditability without changing existing Lake Formation policies.
read more →

CISO Views: Managing Vulnerability Risks in AI Age

🔐 This article outlines how frontier AI is changing vulnerability management by producing vastly greater volumes of findings and shifting the CISO challenge from speed to scale and accuracy. It describes Microsoft’s use of AI-powered scanning, harness layers like MDASH, and Red Teaming to find and mitigate flaws, while urging defense-in-depth and Secure by Default controls such as Microsoft Baseline Security Mode (BSM). The post emphasizes coordinated open-source scanning, risk-based decision making, and rolling out secure defaults to reduce exploitation risk.
read more →

AlloyDB AI simplifies hybrid search with RRF

🔍 This article explains how AlloyDB AI streamlines hybrid search for modern AI and RAG applications by combining vector search and full-text search into a single SQL function using Reciprocal Rank Fusion (RRF). It highlights new FTS capabilities including the RUM extension for positional indexing and the BM25 index for industry-standard ranking. The post also describes an external search Foreign Data Wrapper (FDW) to integrate Elasticsearch, OpenSearch, and Solr while maintaining a unified SQL interface.
read more →

Lakehouse runtime catalog powered by Spanner

🚀 The Lakehouse runtime catalog is a fully serverless, Spanner-backed implementation of the Apache Iceberg REST catalog designed to provide high availability, strong consistency, and horizontal scale for metadata management. It decouples metadata discovery from compute engines to enable multi-engine interoperability and supports credential vending, governance integration, and bi-directional federation. The catalog aims to reduce operational overhead and support agent-scale workloads with enterprise-grade features.
read more →

CISA Endorses Cyber Decoys; FortiDeceptor 6.3

🛡️ CISA published guidance on Using Cyber Decoys to Strengthen Detection and Response, urging an assume-breach posture and use of honeypots, honeytokens, breadcrumbs, and tripwires. FortiDeceptor implements these concepts with decoy VMs, centralized lure management, and integration with the Fortinet Security Fabric. Version 6.3 expands decoy coverage to GitLab, IoT printers, and cloud connectors for S3, GitHub, and SharePoint, and supports automated response workflows.
read more →

ACM Adds PrivateLink for ACME Certificate Issuance

🔒 AWS Certificate Manager (ACM) now supports AWS PrivateLink for ACME public certificate issuance, enabling requests and renewals over a private network path within the AWS network. You can create a VPC interface endpoint to the ACM ACME service and route issuance traffic from any ACMEv2-compatible client through your VPC. Existing ACME clients require no configuration changes because Private DNS resolves the same ACME directory URL to the interface endpoint internally. Issuance operations and monitoring remain available via the ACM console, AWS CloudTrail, and Amazon CloudWatch.
read more →