< ciso
brief />
Vendor and Hyperscaler Watch Banner

All news in category “Vendor and Hyperscaler Watch”

5914 articles · page 16 of 296

Cloudflare reclaims 100 TB RAM with hashing fix

🔎 This post describes how Cloudflare reduced memory usage in its Pingora Backend Router by optimizing consistent hashing. The team identified excessive memory in the pingora-ketama structures and analyzed how hash counts, weights, and collisions affect load distribution. A Rust-level storage change and mathematical analysis allowed them to safely shrink per-server hash counts and reclaim significant RAM without disrupting cache routing.
read more →

CISA ends weekly vulnerability bulletin amid shift

🔒 CISA will discontinue its weekly vulnerability bulletin effective September 28, citing the new Binding Operational Directive (BOD 26-04) that requires prioritizing patches based on real-world exploitation rather than severity scores. The agency points to rising AI-driven threats and urges CISOs to rely more on vendors' security bulletins and updates. CISA will continue other channels like KEV, Cybersecurity Alerts and CVE catalogs to share critical information.
read more →

AWS Resilience Hub adds EKS labels, insights, sharing

🔧 AWS Resilience Hub introduces three capabilities: EKS labels as service input sources, generative AI-powered dependency insights, and resilience policy sharing via AWS Organizations. EKS labels let teams scope discovery using Kubernetes labeling conventions. Dependency insights analyze discovered dependencies to surface new links, cross-Region dependencies, and unusual patterns. Policy sharing enables centralized policy distribution and organization-wide observability.
read more →

Native BM25 search in AlloyDB and Cloud SQL

📰 This post introduces native BM25 full-text search in AlloyDB and Cloud SQL for PostgreSQL 17+ via the open-source pg_textsearch extension from TigerData. The change eliminates the need for separate full-text backends, reducing data duplication and sync complexity while delivering industry-standard BM25 ranking directly in the database. AlloyDB further offers accelerated vector search (ScaNN, HNSW) and an out-of-the-box hybrid search UDF to merge vector and keyword results; Cloud SQL supports hybrid results via CTEs and coalesced RRF scoring.
read more →

AI-native agents for continuous code security

🔒 Google describes AI-native, agent-driven methods that embed high-precision vulnerability scanning and automated patching into the software development lifecycle. By evolving the open-source Mantis multi-agent harness and using localized threat models plus call-graph analysis, pre-submit scans detect issues in near real-time with low false-positive rates. A two-step validation (fast triage agent then nightly post-submit testing) and an automated bug-fix agent streamline detection-to-resolution while preserving developer productivity.
read more →

Amazon EC2 I7ie instances arrive in Israel

🚀 Amazon Web Services has launched Amazon EC2 I7ie instances in the AWS Israel (Tel Aviv) region. These high-density, storage-optimized instances use 5th Gen Intel Xeon processors and 3rd generation AWS Nitro SSDs to boost compute, storage throughput, and latency consistency versus prior I3en instances. I7ie offers up to 120TB local NVMe, higher vCPU and memory counts, and up to 100Gbps network and 60Gbps EBS bandwidth across nine sizes. They are aimed at large, I/O-intensive workloads that need fast, low-latency local storage.
read more →

Borderless Lakehouse adds cross-cloud caching

🔒 Today Google Cloud announced enhancements to the borderless Lakehouse to let data engineers, analysts, and AI agents query governed data in place across clouds. The update introduces preview cross-cloud caching for BigQuery to reduce remote data transfer by caching columnar blocks locally and preview cross-cloud connections to query non-Iceberg data. The features use the Apache Iceberg REST catalog spec, Partner Cross-Cloud Interconnect, and default encryption to improve performance, security, and TCO for multi-cloud analytics.
read more →

AWS RTB Fabric adds configurable AZ affinity

🛠️ AWS RTB Fabric now supports configurable Availability Zone affinity for responder gateways, letting partners connect either within their own AZ or to any AZ the gateway spans. This option helps AdTech companies optimize infrastructure use and avoid underutilized capacity without additional RTB Fabric charges. Configurable AZ affinity is available in all Regions where RTB Fabric is offered; check the AWS RTB Fabric User Guide for fleet requirements before enabling.
read more →

Moonshot AI Kimi K3 Now on Amazon Bedrock

🚀 Moonshot AI's Kimi K3 is now generally available on Amazon Bedrock, delivering an open-weight model with native vision and a 1-million-token context window. The model, claimed to have 2.8 trillion parameters and improved scaling efficiency over Kimi K2, targets long-running coding sessions, multi-document analysis, and extended agent workflows. On Bedrock it runs within the same security boundary as proprietary models and supports explicit prompt caching to reduce latency and input costs.
read more →

Amazon SNS increases message payload limit to 1 MiB

📣 Amazon Simple Notification Service (Amazon SNS) now supports message payloads up to 1 MiB, a 4x increase from the prior 256 KiB limit. This change lets you publish larger messages to both Standard and FIFO topics by configuring the new MaximumMessageSize topic attribute. Topics with sizes above 256 KiB are compatible with Amazon SQS, Amazon Data Firehose, and AWS Lambda subscriptions, supporting up to 100 subscriptions per topic. The feature is available today in all Regions where Amazon SNS operates.
read more →

Microsoft Teams to allow custom blocked file types

🛡️ Microsoft Teams will let administrators customize the list of file extensions blocked by the built-in Weaponizable File Protection feature to align with organizational security policies. The capability is in development and slated to begin rolling out in November 2026 across Android, desktop, iOS, macOS, and web for standard multi-tenant cloud environments. Previously, admins could only rely on Microsoft’s default blocked file list. The change gives organizations greater flexibility to tailor file protection while preserving secure collaboration.
read more →

AWS Announces Generational Update to AgentCore Runtime

🚀 The new AgentCore Runtime for Amazon Bedrock AgentCore is now generally available, introducing elastic memory management that reclaims unused memory and consistent cold start times regardless of container image size. It preserves serverless benefits—no pre-provisioning, scale-to-zero, hardware-enforced isolation, and pay-for-use—while lowering costs and speeding startup. Sessions begin with a compact memory profile and expand on demand; idle memory is reclaimed. Snapshot-based cold start restoration delivers P75 cold starts of ~1.9–2.0s across 200 MB–2 GB images in tests. The runtime is available in select regions and can be enabled by setting platformVersion to V2 when creating or updating a runtime.
read more →

Webinar: Prioritizing Google Workspace Security Controls

🛡️ BleepingComputer will host a live webinar on September 23, 2026, titled "Breach autopsy: How fast-growing companies are breached through Google Workspace" with Material Security. Speakers Rajan Kapoor (VP of Security, Material Security) and Rick Fitzgerald (President, Fireside Consulting LLC) will analyze real documented Google Workspace breaches to show which controls matter most. The session focuses on practical prioritization for lean security teams, covering social engineering, malicious OAuth attacks, response actions in the first hours after a breach, and quick improvements ranked by effort and impact.
read more →

Conversational Policy Management for Workforce AI

🛡️ Check Point’s Workforce AI Security lets organizations control employee interactions with AI across apps, conversations, and agent activity. Through Manage Interactions, teams can define allowed AI applications, data handling for prompts and uploads, and govern the Model Context Protocol (MCP) servers and tools available to agents. The Workforce AI MCP enables natural-language access to policy information, investigation, and management, making complex analysis and changes more direct and efficient.
read more →

Microsoft fixes false Defender Antivirus alerts

🔔 Microsoft resolved a bug that produced incorrect notifications stating Microsoft Defender Antivirus is turned off after recent updates. The fix was rolled out in the Microsoft Defender Antivirus update (version 4.18.26080.4) on September 17 and addresses alerts affecting supported Windows client and server releases. The erroneous messages appeared in the Windows Security app despite the antivirus functioning normally, and Microsoft has previously asked users to ignore similar false alerts from other updates.
read more →

CISA launches VINCE-NT to modernize vulnerability reporting

🛡️ The US Cybersecurity and Infrastructure Security Agency (CISA) has upgraded its vulnerability reporting and coordination platform to VINCE-NT, a modernized, CISA-managed version of Carnegie Mellon’s VINCE. The change, announced on September 17, shifts ownership to CISA’s Coordinated Vulnerability Disclosure (CVD) team and introduces automation, built-in collaboration tools, and a revamped interface to simplify reporting and improve triage. Active cases will be migrated over the coming weeks while inactive cases remain on the original VINCE; organizations are advised to update internal reporting procedures to submit vulnerabilities via VINCE-NT.
read more →

Microsoft fixes Excel copy-and-paste bug for 2016

🛠️ Microsoft released a targeted update to address a code regression in KB5002914 that caused silent copy-and-paste, autofill, and formula dragging failures in Excel. The fix, KB5002655, applies only to the Microsoft Installer (.msi) edition of Office 2016, not Click-to-Run or Office 365 editions. Affected users can use Paste Special or uninstall the security update as temporary workarounds, though uninstalling removes important security patches.
read more →

AWS PrivateLink adds tunnel VPC endpoint

🔒 AWS PrivateLink now supports a new VPC tunnel endpoint that lets customers privately and securely access network segments in another VPC or account. Instead of sharing individual resources, owners can create a Resource Configuration for a CIDR range and share it via AWS Resource Access Manager (RAM). Vendors create a tunnel endpoint and use GENEVE encapsulation to access the specified CIDR range. Pricing includes an hourly tunnel endpoint fee plus per-GB data charges.
read more →

Palo Alto Networks Named Market Shaper in AI Security

🚀 Palo Alto Networks announces recognition as a ‘Market Shaper’ in Gartner’s September 2026 Emerging Market Quadrant for AI Application Security – Established Vendors. The company highlights its unified AI security platform, Prisma AIRS, which consolidates discovery, risk assessment, runtime protection, identity and access control, and governance for AI coding, enterprise AI apps, and autonomous agents. The post emphasizes avoiding fragmented point solutions and enabling secure AI adoption across organizations.
read more →

Run open-weight models on AWS Bedrock in EU sovereign cloud

🔒 Amazon Web Services now supports running open-weight generative AI models on Amazon Bedrock within the AWS European Sovereign Cloud, keeping data and operations inside the EU. The first available family, Gemma 4, is offered under the Apache 2.0 license and served via the bedrock-mantle inference engine with OpenAI-compatible APIs. The service enforces zero operator access and in-Region inference (eusc-de-east-1), preserves data residency and provides IAM-based access controls and CloudTrail auditing.
read more →