< ciso
brief />
Vendor and Hyperscaler Watch Banner

All news in category “Vendor and Hyperscaler Watch”

5909 articles · page 13 of 296

Microsoft adds integrated SOC features to Defender

🔒 Microsoft now offers Integrated Security Operations Center (ISOC) capabilities inside Microsoft Defender for Microsoft 365 E5 and E7 customers at no extra license cost during public preview. ISOC combines SIEM-like functions with Defender XDR, threat intelligence, automation and AI in a single portal, and ingests Microsoft product logs without charges. From Oct. 1, third-party data ingestion will be metered at $2.40 per GB, and more advanced features require an ISOC workspace and Azure subscription.
read more →

AWS launches Network Security Manager in US East

🔒 Today AWS announces the general availability of AWS Network Security Manager, a centralized network security management solution that simplifies policy deployment and enforcement at scale. It supports AWS WAF and AWS Shield Advanced today, with AWS Network Firewall support coming soon. The service enables consistent enforcement of firewall and DDoS protections across an AWS organization and is available in US East (N. Virginia).
read more →

AlloyDB Introduces PostgreSQL for Agentic Workloads

🚀 AlloyDB now offers PostgreSQL for agents (preview), enabling sandboxed, serverless PostgreSQL instances that provide up-to-the-second read-only access to production data while isolating agent workloads. These instances spin up in seconds, leverage Colossus-backed unified storage for sub-millisecond I/O and massive scan throughput, and scale down to zero to control costs. The engine remains fully PostgreSQL-compatible with vector, full-text, and spatial search plus strong Google Cloud security integrations.
read more →

AlloyDB Agentic Database Architecture Explained

🧭 This post outlines AlloyDB’s new agentic database architecture designed for autonomous agent workloads, arguing that traditional and emerging architectures trade off scale, latency, or isolation. It defines three tenets—Isolation, Latency, and Scale—and explains how AlloyDB, built on Google’s Colossus storage and microVM-based ephemeral compute, satisfies all three simultaneously. The article contrasts existing paradigms and presents test results showing shared-storage approaches fail under agentic load.
read more →

Hardening Code Pipelines and CI/CD Infrastructure

🔒 This blog outlines practical guidance for protecting the software supply chain by hardening CI/CD pipelines, developer workstations, repositories, and artifact registries. It describes modern attacker techniques—compromising developer tools, IDE extensions, and pipeline tokens—and recommends concrete controls like EDR/UEM integration, fine‑grained short‑lived credentials, strict dependency pinning, sandboxed developer environments, and centralized artifact proxies. The post emphasizes defense‑in‑depth across five SDLC pillars with actionable steps for continuous verification, provenance, and automated policy enforcement.
read more →

Controlling AI Agents Before They Become Privileged Insiders

🔒 AI agents are evolving into autonomous enterprise workers that do more than generate content: they read email, access SaaS, call APIs, modify records and execute workflows. This shift introduces insider-like risk because agents can act with high autonomy and broad access. Leaders must move beyond traditional IAM to enforce action-level and runtime controls, assign human owners, and apply lifecycle governance to ensure agents are discovered, monitored, and constrained.
read more →

How Google Cloud networking supports fluid AI compute

🔍 This article explains how Google Cloud networking accommodates fluid compute for AI workloads, with guidance for choosing GPUs or TPUs and their distinct backend networking needs. It outlines resource obtainment options—such as Flex-start VMs, calendar reservations, future and flex reservations, ComputeClasses, and Spot VMs—and describes four networking configurations: standard networking, accelerated GPU networking (TCPX/TCPXO and RoCEv2), TPU networking, and Cloud Run. The blog highlights deployment blueprints, GKE DRANET automation, and zonal profiles for RDMA, illustrating trade-offs for multi-node training and inference.
read more →

Microsoft fixes File History backup issue in September patch

🛠️ Microsoft addressed a known issue that caused the built-in File History backup to fail after installing September 2026 security updates. Affected systems experienced FileHistory.exe crashes, "Reconnect your drive" alerts despite attached drives, and missing previous file versions. The vendor says the fix is included in the September preview update for Windows 11, with broader availability on Patch Tuesday (October 13) for users who defer optional updates. Microsoft previously also issued out-of-band fixes for other September update regressions.
read more →

SageMaker HyperPod Inference Gateway Launch

🚀 Amazon SageMaker HyperPod Inference Gateway is a Kubernetes-native, GPU-aware routing add-on for EKS that integrates with existing SageMaker HyperPod infrastructure without application changes. It replaces round-robin balancing with real-time inference-signal-driven routing to reduce first-token latency by up to 82% and p99 TTFT by 97–98% in mixed-hardware and burst scenarios. The Gateway comprises an Envoy Endpoint, a Body-Based Router that reads model names from requests, and an Endpoint Picker that scores pods across six inference-level signals to select the optimal target. It supports OpenAI-compatible model servers like vLLM and SGLang, is available per-cluster in supported Regions, and will soon add cross-cluster, cross-region routing and centralized traffic controls.
read more →

Amazon GameLift Servers expands to more regions

🎮 Amazon GameLift Servers, a managed service for deploying and scaling dedicated multiplayer game servers, is expanding to 5 new AWS Regions and 8 AWS Local Zones worldwide. This expansion reduces player latency by enabling developers to deploy fleets closer to users across Latin America, Southeast Asia, Europe, the Middle East, and South Asia. The new Regions include il-central-1, mx-central-1, eu-south-2, ap-south-2, and ap-southeast-3, while Local Zones add major city locations in the US and Latin America. Developers can now target these additional locations to improve gameplay responsiveness and player experience.
read more →

EMR on EKS adds interactive Spark Connect sessions

🔥 Amazon EMR on EKS now supports interactive Apache Spark sessions via Spark Connect, enabling data engineers and scientists to develop and debug Spark applications from managed notebooks in Amazon SageMaker Unified Studio or their own IDEs like Jupyter and VS Code. An interactive session provides a persistent Spark context that spans cells and scripts, blending local Python execution with remote Spark operations on EKS. Sessions run as pods on virtual clusters secured by IAM execution roles and tagged by project and user, and Spark Connect is available in EMR release 7.14 (Spark 3.5) and emr-spark-8.1.0 (Spark 4.1) across AWS Commercial Regions.
read more →

ElastiCache Global Datastore adds tagging and TBAC

🔖 Amazon ElastiCache now supports resource tagging and tag-based access control (TBAC) for Global Datastore. You can use AddTagsToResource, RemoveTagsFromResource, and ListTagsForResource on Global Datastore and reference tags in IAM policies and SCPs. Tag changes propagate automatically across all Regions the Global Datastore spans, keeping access control and cost allocation consistent. There is no additional cost and no change to Global Datastore creation or management.
read more →

RDS SQL Server Developer Edition adds Multi‑AZ support

🔔 Amazon RDS for SQL Server now enables Multi‑AZ deployments using Always On Availability Groups for SQL Server Developer Edition. This provides a synchronous standby replica in a separate Availability Zone and automatic failover to support testing of high availability in non‑production environments. The capability mirrors Enterprise Edition functionality at no license cost and is available for SQL Server 2019, 2022, and 2025 Enterprise Developer Edition; SQL Server 2025 Standard Developer Edition is not supported.
read more →

AWS August 2026 Security Update Digest

🔒 August’s AWS Security digest highlights new service capabilities, compliance updates, and hands-on resources across identity, data protection, AI security, detection, and governance. It summarizes 20+ blog posts, security bulletins, and 17 code samples focused on agent governance, credential protection, and automated compliance. The update emphasizes prompt patching and practical deployment guidance for enterprise security teams.
read more →

Kinesis adds service‑managed partition keys for on‑demand

🔔 Amazon Kinesis Data Streams now offers service-managed partition keys for On-Demand Standard and On-Demand Advantage streams, automatically distributing records across shards so customers don’t need to supply partition keys when ordering isn’t required. This simplifies ingestion for use cases such as log aggregation, metrics, and IoT telemetry, eliminating hot keys and reducing time to production. The feature is available today in all AWS commercial regions at no extra cost; customers can adopt it by upgrading to the latest AWS SDK or Kinesis Producer Library.
read more →

Amazon Bedrock adds Salesforce and Zendesk connectors

🔗 AWS announced native Salesforce and Zendesk data source connectors for Amazon Bedrock Managed Knowledge Base, enabling direct synchronization of Salesforce knowledge articles and Zendesk help center articles and community posts. The connectors remove the need for custom ingestion pipelines by handling crawling, metadata extraction, and incremental sync using instance credentials. This streamlines building RAG-based AI agents and assistants grounded in up-to-date support and product knowledge.
read more →

Architecture Diagrams Aren’t Proof of Resilience

🔍 This article, based on a conversation with Mark Russinovich, explains why an architecture diagram is only an intent and not evidence of resilience. It highlights how drift, human and machine authorship, and AI model dependencies introduce new failure modes. The post argues for continuous validation, deterministic checks where possible, and automated, measurable practices to keep resilience real over time.
read more →

Amazon Connect adds routing step data to data lake

📊 Amazon Connect Customer now delivers routing step data into its analytics data lake, enabling easier insight generation from routing decisions. Using the data lake, customers can use Amazon Athena and Amazon Quick to analyze trends like contacts queued and contacts joined at each routing step without building complex pipelines. Analysts can report on contact progression, pinpoint where agent matching criteria were relaxed, and measure routing impacts on wait times and agent utilization.
read more →

GKE Adds Native Scale-to-Zero Capabilities

🚀 GKE 1.37 introduces native scale-to-zero so workloads can fully scale down to zero replicas and stop consuming compute while idle. The feature uses HPA with the new AutoscalingMetric CRD and KEP-2021 support for minReplicas: 0 to wake workloads based on external signals such as Pub/Sub or Cloud Monitoring. Capacity buffers provide pooled warm capacity to eliminate cold-start latency and balance cost with instant responsiveness.
read more →

GKE Adds Native Prometheus Metrics for Autoscaling

🔔 Google Cloud announced built-in Prometheus metrics processing for GKE, enabling HPA to use PromQL queries directly via Google Managed Service for Prometheus. This removes the need for third-party adapters, reduces latency, and simplifies autoscaling configuration. The controller runs in the control plane and only deploys pods on nodes when PromQL metrics are actively requested, minimizing resource use. The feature is in preview with plans to add self-hosted Prometheus support before GA.
read more →