< ciso
brief />
Vendor and Hyperscaler Watch Banner

All news in category “Vendor and Hyperscaler Watch”

5914 articles · page 17 of 296

AWS Transfer Family preserves SFTP client source IPs

🔒 AWS Transfer Family now preserves client source IPs using Proxy Protocol v2 (PPv2) when you place a Network Load Balancer (NLB) in front of a VPC-hosted SFTP endpoint. Previously, the NLB's private IP replaced the client's address in logs and during authentication, preventing IP-based auditing and access control. You can enable source IP preservation per server through the console, CLI, or API, and the feature is available in all Regions where AWS Transfer Family is offered.
read more →

AWS HealthOmics adds IAM session policy support

🔐 AWS HealthOmics now supports IAM session policies, allowing you to restrict permissions for individual runs without creating and managing multiple IAM roles. An IAM session policy is an inline policy that limits the maximum permissions of a run by intersecting with the underlying identity-based policy. This enables per-run scoping—such as restricting access to a tenant's S3 buckets or specific S3 objects—without provisioning separate roles. Support is available in all Regions where HealthOmics is offered.
read more →

AWS Batch adds bulk job cancellation and termination

🛠️ AWS Batch now supports bulk cancellation and termination of up to 50 jobs via new APIs, simplifying management of large-scale batch workloads. The new CancelJobs, TerminateJobs, and TerminateServiceJobs APIs return per-job results in a single response and work with individual and array jobs. ListJobs and ListServiceJobs now expose lifecycle flags isCancelled and isTerminated to help track job state across regions.
read more →

Security Fundamentals to Reduce AI-era Cyber Risk

🔒 This post outlines Microsoft's Secure Now initiative within Microsoft Security Exposure Management, introduced May 2026, to help organizations prioritize foundational controls as AI accelerates threat complexity. It summarizes recent agentic and campaign-based incidents that show how familiar weaknesses—excessive permissions, unprotected authentication, unpatched systems—can chain rapidly into broader compromises. The blog maps practical mitigations, guided by Zero Trust, and highlights resources like FastTrack to operationalize continuous exposure reduction.
read more →

Google named a leader in external threat intelligence

🛡️ Google has been named a Leader in The Forrester Wave™: External Threat Intelligence Service Providers, Q3 2026, receiving top scores across multiple criteria. The announcement highlights Google Threat Intelligence’s integration of Mandiant, VirusTotal, and Google-scale telemetry, plus AI-enabled agents powered by Gemini for rapid, autonomous investigations and malware analysis. The recognition emphasizes deep and dark web monitoring, authoritative attribution, and an open partner-centric strategy.
read more →

Pine59’s migration to Airflow 3 on Google Cloud

🚀 Pine59 modernized its data orchestration by moving to Managed Service for Apache Airflow (Gen 3) running Airflow 3 on Google Cloud to support massive location-intelligence pipelines. The company observed immediate gains in processing speed, reduced queue latency, and improved stability, enabling faster runs for heavy jobs like Daily Foot Traffic. Engineers also built custom UI plugins and a compatibility shim to streamline developer workflows and operator migration.
read more →

Solo founder runs global tender platform on AlloyDB

🔎 Lucius AI, a tender-intelligence startup covering five continents, consolidated its relational catalog, audit logs, and vector embeddings into AlloyDB for PostgreSQL and automated routine operations via the Model Context Protocol (MCP). By migrating semantic search to a ScaNN index, query latency fell from 1.14s to 24ms, a 47x improvement. The platform ingests notices from multiple procurement sources and runs across two production regions with strict least-privilege controls.
read more →

Microsoft Defender email security benchmarking updates

📈 This post summarizes Microsoft's latest quarterly email security benchmark covering May–July 2026 and highlights how continuous measurement improves prevention, detection, and adaptation. It reports Defender missed 221 high-severity threats per 1,000 users—55.4% fewer than the next closest SEG vendor—and notes Defender's 92% average post-delivery malicious catch. The report emphasizes evolving threat dynamics driven by AI and outlines Defender investments informed by telemetry and customer feedback.
read more →

AWS launches low-cost EC2 T8i burstable instances

🔔 AWS announced general availability of the new low-cost burstable Amazon EC2 T8i instances powered by custom sixth-generation Intel Xeon 6 processors and built on sixth-generation AWS Nitro cards. T8i offers four sizes (nano, micro, small, medium) and delivers up to 30% better price performance versus T3, targeting low-to-moderate CPU workloads like small databases, CI/CD, microservices, and low-traffic websites. The instances provide higher compute, network, and EBS bandwidth, retain the T3 CPU credit model, and are available in multiple global regions with On-Demand and Spot purchase options.
read more →

Windows 11 24H2 Home and Pro reach end of support

🛡️ Microsoft warned this week that Windows 11, version 24H2 Home and Pro editions will stop receiving security and preview updates on October 13, 2026. Under the company's lifecycle policy, Windows 11 24H2 Enterprise and Education editions remain supported until October 2027. Customers are advised to upgrade to Windows 11 25H2, which started rolling out via an enablement package in September 2024. Devices not managed by IT will be auto-upgraded but users can delay restarts.
read more →

16 Tools for Governing and Securing Enterprise AI

🛡️ This article surveys 16 vendors offering governance, guardrails, and security platforms for production LLMs and agent fleets. It outlines each vendor’s primary capabilities, standout features, pricing model, and the types of organizations best suited to their offerings. The piece emphasizes themes such as data protection, automated red teaming, compliance with regulations like the EU AI Act and GDPR, and integrations with cloud or data ecosystems. Readers get a comparative, vendor-focused guide to building control planes for AI risk management.
read more →

Elastic Beanstalk adds Cluster Mode for pooled apps

🚀 AWS Elastic Beanstalk introduces Cluster Mode, a deployment option that runs multiple applications on shared, EKS-powered infrastructure. Provide source code, a Dockerfile, or an Amazon ECR image and Elastic Beanstalk handles containerization, provisioning, and lifecycle operations via the console, CLI, APIs, or a new GitHub Action. Cluster Mode supports autoscaling, OpenTelemetry observability, AWS Secrets Manager, and HTTPS via AWS Certificate Manager, and is available in all commercial AWS Regions where Elastic Beanstalk is offered.
read more →

Amazon S3 Express One Zone expands to seven regions

🚀 Amazon S3 Express One Zone is now available in seven additional AWS Regions: Singapore, São Paulo, N. California, Canada (Central), Paris, Sydney, and Seoul. This single-Availability Zone storage class is engineered for consistent single-digit millisecond access and is optimized for latency-sensitive workloads. S3 Express One Zone offers up to 10x faster data access and up to 80% lower request costs versus S3 Standard. The expansion brings the storage class to 15 AWS Regions overall.
read more →

AWS Builder Center launches mobile app globally

📱AWS has expanded the AWS Builder Center to mobile, releasing apps for iOS and Android that mirror the desktop experience. The app lets builders browse trending articles, access 600+ AWS Skill Builder courses, join hands-on workshops with free sandbox environments, and follow community leaders. It also supports push notifications, the Wishlist product-feedback feature, and sync via AWS Builder ID for seamless sign-in across sessions.
read more →

Amazon SES adds tenant-level deliverability insights

📊 Amazon Simple Email Service (SES) now provides tenant-level deliverability insights in Virtual Deliverability Manager (VDM). The VDM dashboard adds a Tenants view with per-tenant metrics and a detail page that breaks metrics down by mailbox provider, identities, and configuration sets. Customers can search and export tenant sent messages and query metrics via the BatchGetMetricData API using the new TENANT_NAME dimension. VDM is available in all Regions where Amazon SES is offered.
read more →

Amazon Quick adds AI sheet and image-based analysis

🛠️ Amazon Quick expands Generate Analysis with two new features that speed dashboard creation. With Generate Sheet, users describe a sheet in natural language and Quick inserts it into an existing analysis with visuals, filters, and common calculated fields. With the new image-driven generator, users attach a dashboard image and Quick recreates an editable analysis from supported elements.
read more →

Amazon Corretto 27 Feature Release Now Available

🟢 Amazon Corretto 27, a Feature Release (FR) of the no-cost, production-ready OpenJDK distribution, is now available for Linux, Windows, and macOS. Corretto 27 will be supported through April 2027 and introduces G1 as the default garbage collector, post-quantum hybrid key exchange for TLS 1.3, compact object headers, and JFR in-process data redaction. Several preview and incubator features are continued, including enhanced pattern matching, structured concurrency, lazy constants, and the Vector API.
read more →

SageMaker Adds Serverless Fine‑Tuning for Nemotron 3.5

🔧 Amazon SageMaker AI now supports serverless model customization for the NVIDIA Nemotron 3.5 Lightning model, enabling supervised fine‑tuning (SFT), Direct Preference Optimization (DPO), and reinforcement fine‑tuning (RFT). The hybrid Mixture‑of‑Experts model has 3B active parameters and 30B total parameters. SageMaker handles infrastructure and orchestration so teams can focus on data and evaluation. Serverless customization is available in US East, US West, Asia Pacific (Tokyo), and Europe (Ireland).
read more →

Amazon ECS adds consolidated Managed Daemon deployment view

🟦 Amazon Elastic Container Service (Amazon ECS) introduces a console-only consolidated deployment view for Managed Daemons that centralizes rollout progress, failures, and potential blockers. The view provides a lifecycle timeline with timestamps and duration, per-capacity-provider progress bars, and a monitoring panel showing circuit breaker, alarms, and health checks with live CloudWatch details. Failed daemon tasks show stop reasons with links to task logs and troubleshooting guidance, and the console displays target/source revisions, instance counts, drain percentages, and bake time. This enhancement is available at no additional cost in all AWS Commercial Regions.
read more →

Architecting a Secure Landing Zone in EUSC

🔒 This post explains how to design a secure, scalable landing zone for the AWS European Sovereign Cloud (aws-eusc), a partitioned AWS environment operated within the EU. It covers account structure and governance, identity as IaC, centralized logging to a SIEM, data protection, perimeter and network design, CI/CD and artifact distribution, and incident response. The guidance maps to the AWS Security Reference Architecture and the AWS Well-Architected Framework, and highlights which behaviors are partition boundaries versus configurable choices.
read more →