< ciso
brief />
Vendor and Hyperscaler Watch Banner

All news in category “Vendor and Hyperscaler Watch”

5910 articles · page 15 of 296

Security Hub AI Inventory Adds Azure Self‑Hosted Support

🔐 AWS Security Hub AI Inventory now discovers and catalogs AI assets on self‑hosted Microsoft Azure instances, extending visibility beyond AWS. It uses enhanced Amazon Inspector SBOM analysis to identify inference endpoints, models, and AI agents on Azure VMs, including frameworks like Ollama, vLLM, and Hugging Face TGI. Discovered assets are mapped to underlying infrastructure and correlated with security findings for filtering and querying across AWS and Azure. This capability is included with Security Hub Essentials at no extra cost and is available in all commercial Regions where Security Hub is offered.
read more →

Amazon RDS Custom Adds Support for SQL Server CU26

🔔 Amazon RDS Custom for Microsoft SQL Server now supports the latest Cumulative Update, SQL Server 2022 CU26 (KB5093420) on RDS version 16.00.4265.3.v1. The update brings the fixes and improvements documented by Microsoft. You can apply the CU through the Amazon RDS Management Console or programmatically via the AWS SDK or AWS CLI. Refer to the Amazon RDS Custom User Guide for upgrade procedures.
read more →

Amazon Connect Customer adds agent-to-agent A2A support

🤝 Amazon Connect Customer now enables agent-to-agent collaboration, allowing enterprises to bring specialized AI agents into live interactions to resolve customer requests. Connect Customer supports collaboration over the open agent-to-agent (A2A) protocol via text and bidirectional voice, letting AI agents delegate tasks and maintain session continuity. Administrators receive a unified contact record with observability, guardrails, and escalation controls captured for analytics and quality management.
read more →

Amazon ECS adds real-time deployment observability

🛠️ Amazon Elastic Container Service (Amazon ECS) now offers real-time service deployment observability in the Amazon ECS Console for native Linear, Canary, and Blue/Green deployment strategies. The console provides a live deployment timeline showing phases, service events, and task launch/termination progress, along with traffic shift distribution and lifecycle stage visibility. Deployment health signals—circuit breaker status, alarms, container and load-balancer checks, and lifecycle hooks—appear alongside the timeline, and failed tasks surface with diagnostic context and deep links for rapid troubleshooting.
read more →

Amazon EVS Achieves FedRAMP Class C Authorization

🛈 Amazon Elastic VMware Service (EVS) is now in scope for FedRAMP Class C across all US Regions. FedRAMP provides a standardized security assessment and continuous monitoring process for cloud services used by US federal agencies. Amazon EVS runs VMware Cloud Foundation directly in an Amazon VPC on EC2 bare-metal instances, enabling rapid VCF environment deployment and workload migration. This helps organizations reduce legacy infrastructure risks and meet data center exit timelines.
read more →

Microsoft to retire Microsoft 365 companion apps

📰 Microsoft announced that it will retire the Calendar, People, and Files Microsoft 365 companion apps on December 16, 2026, and advised admins to remove them from managed devices. The company previously began auto-installing these taskbar-integrated apps on compatible Windows 11 enterprise devices with the Microsoft 365 desktop client. Admins could opt out via Device Configuration or users disable auto-launch in app settings. Microsoft has stopped installing the apps via Microsoft 365 Apps updates and asked unmanaged users to uninstall them.
read more →

Maximize Apache Spark availability with flexible VMs

🔧 This article explains how Google’s Managed Service for Apache Spark uses flexible VMs to mitigate capacity stockouts that can disrupt Spark pipelines. Flexible VMs let teams specify ordered machine-family preferences for masters and workers, enabling multi-family blending, mixed storage support, and comprehensive cluster coverage. The post gives tiered machine-family and storage recommendations for common shapes (n2d, n1) and highlights the role of Hyperdisk Balanced. It also covers quota, CUDs, testing, and complementary strategies like AutoZone, autoscaling, smaller shapes, and regional fallbacks.
read more →

GKE Pod Snapshots: Faster Startup for AI Workloads

🚀 GKE Pod snapshots let you capture and restore a running Pod’s full state, including CPU and GPU memory, to dramatically reduce cold-start times for AI inference and sandboxed agent workloads. By persisting snapshots to high-throughput Cloud Storage, new replicas restore directly from a warmed state, cutting startup latency by up to 89% in benchmarks. This enables aggressive autoscaling, lowers idle GPU costs, and replaces complex custom caching solutions with a simple declarative CRD-driven workflow.
read more →

Google Cloud enhances Secure Source Manager for CI/CD

🔒 Google Cloud announced two generally available Secure Source Manager (SSM) features to harden CI/CD pipelines: enhanced blocking of unauthorized access across version control, build, and deployment systems, and a new Code Owners system for granular per-file and per-branch approver controls. The Code Owners feature supports nested ownership, branch-specific governance, glob-style path rules, and independent approval sections, while Developer Connect and Private Network Integrations let SSM connect CI/CD and runtimes across private networks with VPC Service Controls and Private Service Connect.
read more →

Transform Bedrock Guardrails Events into OCSF

🛡️ This post shows how to capture AWS Bedrock Guardrails intervention events from model invocation logs, transform them into OCSF Detection Finding records, and ingest them into the CloudWatch unified data store for centralized analysis. It explains why guardrail interventions are security-relevant, the limitations of ingestion-time processors, and the need for a dedicated transform step to split and normalize assessments. The end-to-end pipeline uses an AWS Lambda to map fields, assigns severity based on policy type, and writes results to a log group associated with AWS S3 Tables so analysts can query with Athena or CloudWatch Logs Insights.
read more →

Microsoft fixes Excel copy-and-paste bug for users

🛠️ Microsoft has issued fixes for an Excel paste failure introduced by September 2026 security updates that caused copy-and-paste, autofill, and formula dragging to fail silently in multiple Excel versions and Excel Online. Affected users must manually install specific updates for Excel 2016 and Office LTSC 2019, 2021, and 2024 to resolve the issue. Microsoft noted paste may still fail when workbooks contain conditional formatting and recommended using the Paste Special workaround (Ctrl+Alt+V) until a broader fix is available.
read more →

Microsoft urges Entra ID migration to passkeys

🔐 Microsoft reminded administrators to migrate Entra ID users to phishing-resistant authentication methods, such as passkeys, ahead of the retirement of SMS first-factor sign-ins in February 2027. Admins can also use QR code authentication, FIDO2 security keys, or other Entra ID-supported methods. The retirement affects workforce tenant authentication and not Azure AD B2C or Entra External ID scenarios. Microsoft provided guidance and tools, including a PowerShell scanner, to help identify impacted users.
read more →

Cloudflare Announces General Availability of Python Workers

🐍 Cloudflare has made Python Workers generally available, offering first-class, fully supported Python on the Cloudflare Developer Platform. The announcement highlights native bindings to platform services (R2, D1, Hyperdrive, Durable Objects, Queues, Workflows, and Workers AI) and support for frameworks like FastAPI, Django, and Flask via built-in ASGI/WSGI connectors. It explains how Pyodide and a WebAssembly-based socket bridge enable database drivers and HTTP clients, and describes ecosystem improvements such as PEP 783 (PyEmscripten) and tooling updates to expand package compatibility.
read more →

Amazon EC2 X8i Instances Now in São Paulo

🚀 Amazon EC2 X8i instances are now available in the South America (São Paulo) Region. These instances use custom Intel Xeon 6 processors unique to AWS and are SAP-certified, offering up to 43% higher performance, 1.5x more memory capacity (up to 6TB), and 3.3x more memory bandwidth versus X2i. They target memory-intensive workloads such as SAP HANA, large databases, data analytics, and EDA, and are offered in 14 sizes including bare metal options.
read more →

AWS Continuum adds pre-test credential discovery

🔒 AWS Continuum for penetration testing introduces a frontier agent that performs on-demand, customized penetration tests with real exploitability checks. The new capability authenticates using provided login credentials before a full test, capturing and suggesting all accessible domains reached during login to help define accurate network scope. Accessible domains are surfaced whether credential attempts succeed, fail, or time out, reducing misconfiguration and wasted test cycles.
read more →

Amazon ECS Express Mode Adds ARM64 Support

🐧 Amazon Elastic Container Service Express Mode now supports specifying ARM64 as the CPU architecture for services, enabling deployment of ARM-based container images on AWS Graviton-powered compute with up to 40% better price-performance versus x86. ECS Express Mode orchestrates networking, load balancing, autoscaling and deployments, providing an auto-generated URL while simplifying launches of web apps and APIs. Users can set the CPU architecture for new and existing services via the AWS Console, CLI, SDKs, or IaC tools, and the feature is available in all AWS commercial Regions and AWS GovCloud (US).
read more →

Cloudflare reclaims 100 TB RAM with hashing fix

🔎 This post describes how Cloudflare reduced memory usage in its Pingora Backend Router by optimizing consistent hashing. The team identified excessive memory in the pingora-ketama structures and analyzed how hash counts, weights, and collisions affect load distribution. A Rust-level storage change and mathematical analysis allowed them to safely shrink per-server hash counts and reclaim significant RAM without disrupting cache routing.
read more →

CISA ends weekly vulnerability bulletin amid shift

🔒 CISA will discontinue its weekly vulnerability bulletin effective September 28, citing the new Binding Operational Directive (BOD 26-04) that requires prioritizing patches based on real-world exploitation rather than severity scores. The agency points to rising AI-driven threats and urges CISOs to rely more on vendors' security bulletins and updates. CISA will continue other channels like KEV, Cybersecurity Alerts and CVE catalogs to share critical information.
read more →

AWS Resilience Hub adds EKS labels, insights, sharing

🔧 AWS Resilience Hub introduces three capabilities: EKS labels as service input sources, generative AI-powered dependency insights, and resilience policy sharing via AWS Organizations. EKS labels let teams scope discovery using Kubernetes labeling conventions. Dependency insights analyze discovered dependencies to surface new links, cross-Region dependencies, and unusual patterns. Policy sharing enables centralized policy distribution and organization-wide observability.
read more →

Native BM25 search in AlloyDB and Cloud SQL

📰 This post introduces native BM25 full-text search in AlloyDB and Cloud SQL for PostgreSQL 17+ via the open-source pg_textsearch extension from TigerData. The change eliminates the need for separate full-text backends, reducing data duplication and sync complexity while delivering industry-standard BM25 ranking directly in the database. AlloyDB further offers accelerated vector search (ScaNN, HNSW) and an out-of-the-box hybrid search UDF to merge vector and keyword results; Cloud SQL supports hybrid results via CTEs and coalesced RRF scoring.
read more →