< ciso
brief />
Vendor and Hyperscaler Watch Banner

All news in category “Vendor and Hyperscaler Watch”

5915 articles · page 19 of 296

Windows Server 2022 to leave mainstream support

🔔 Microsoft confirmed that Windows Server 2022 will reach end of mainstream support on October 13, 2026, and then transition into extended support through October 14, 2031. The October 2026 security update will be the last release under mainstream support. Hotpatching for Datacenter: Azure Edition is extended until October 2027. Administrators are advised to plan upgrades to Windows Server 2025 to remain fully supported.
read more →

SE Labs launches PIVOT test for vendor defences

🛡️ SE Labs has launched a six-month testing program called PIVOT to evaluate how effectively cybersecurity vendors defend against major nation-state and criminal threat groups. The program runs real-world attack chains from July through October in SE Labs’ London test lab and will publish verified results in January 2027. Participants include Broadcom (Symantec, Carbon Black), CrowdStrike, Fortinet, Palo Alto Networks and Sophos. Gartner and Forrester analysts will independently verify the findings before publication.
read more →

SMBs Must Accelerate Cyber Readiness Amid AI Risks

🔒 AI is accelerating both the scale and speed of cyberthreats, expanding attack surfaces as businesses rush to adopt the technology. SMBs need security that is simple to operate, combines AI-driven automation with human oversight, and aligns with business outcomes. Effective partnerships and prevention-centric, as-a-service models help smaller teams detect, contain and recover from incidents while minimizing operational disruption.
read more →

AWS STS enforces unified 4,096-byte session limit

🔒 AWS Security Token Service (STS) now enforces a single 4,096-byte size limit for session tokens, replacing separate limits for tokens and passed-in parameters. This change lets you combine larger session policies and session tags more flexibly. STS also returns token size and percentage utilization in responses, logs those values to AWS CloudTrail, and publishes metrics to Amazon CloudWatch. An optional API parameter lets you request larger tokens for testing, and the features are available in all commercial, GovCloud (US), and European Sovereign Cloud Regions.
read more →

AWS STS simplifies token limits and adds monitoring

🔒 AWS Security Token Service (STS) now enforces a single assembled session token size limit of 4,096 bytes, replacing the previous packed policy and token size limits. STS returns session token size and utilization in API responses, CloudWatch metrics, and CloudTrail events, and preserves PackedPolicySize for backward compatibility. A new MinimumSessionTokenSize parameter lets you generate larger tokens to test infrastructure limits; error handling remains unchanged with PackedPolicyTooLargeException used for over-limit tokens.
read more →

AWS BCM adds Detected Anomalies widget to Dashboards

🧾 AWS Billing and Cost Management now includes a Detected Anomalies widget in BCM Dashboards, letting teams view cost anomalies alongside budgets, usage, and Savings Plans or Reserved Instance reports. The widget shows anomaly counts, cost impact relative to month-to-date spend, root cause, duration, and supports 30/60/90-day look-backs. Filters for severity, service, account, and region and direct links to the Cost Anomaly Detection console facilitate investigation. The widget is available in all commercial AWS Regions at no additional charge and supports exports, scheduled email reports, CSV/PDF downloads, and cross-account dashboard sharing.
read more →

Architecting resilient authentication with Cognito MRR

🔒 Amazon Cognito now supports multi-Region replication (MRR) to automatically replicate user pools across AWS Regions with near-real-time synchronization, built-in failover, and interoperable JWT sessions. Replica user pools support sign-in and token operations but are read-only for configuration and attribute writes, which must be performed in the primary Region. To use MRR you must configure a symmetric multi-Region AWS KMS customer managed key and consider adopting the updated multi-Region OIDC issuer to ensure consistent discovery and JWKS endpoints. Cognito supports automatic domain and OAuth failover via Route 53 health checks and recommends using infrastructure-as-code and JWKS caching strategies for smooth migration and operational continuity.
read more →

AWS Direct Connect introduces flat-rate 10G/100G pricing

🔔 AWS Direct Connect now offers flat-rate monthly pricing for 10 Gbps and 100 Gbps dedicated connections, eliminating per-gigabyte data transfer out (DTO) charges within the chosen pricing tier. The model provides five geographic tiers from same-metro to global coverage and introduces an optional port-pair concept that provisions two redundant connections sharing the same bandwidth at no extra charge. Flat-rate pricing is available at all commercial AWS Direct Connect locations (excluding China Regions) and can be applied or changed per connection.
read more →

AWS Billing Conductor adds custom rates and tiers

🛠️ AWS Billing Conductor now supports defining custom rate pricing and usage tiers for AWS services, enabling customers and partners to model negotiated commercial agreements more accurately. Using SKU-scoped pricing rules, users can enter exact rates and configure tier thresholds rather than applying percentage markups or markdowns to public on-demand rates. This feature is available in all commercial AWS Regions except the two China regions operated by Sinnet and NWCD. It simplifies pro forma billing configuration by providing precise control over pricing and tier breaks.
read more →

AWS Step Functions adds automatic service integrations

🛠️ AWS Step Functions now automatically adds AWS SDK integrations for newly released AWS services and capabilities within weeks, starting with AWS Lambda MicroVMs and AWS Lambda Core. This lets you orchestrate the latest AWS services from workflows without waiting for manual updates. The integrations are generally available in all Regions where Step Functions is offered, though specific APIs depend on regional service availability. Continuous updates mean AWS will no longer publish What's New posts for these SDK integration updates.
read more →

SageMaker adds instance preference lists for jobs

🆕 Amazon SageMaker now supports instance preference lists for training and processing jobs, letting you submit prioritized sets of instance types and counts so SageMaker can pick the first available configuration. This reduces wait times and removes the need for complex retry logic or multiple concurrent submissions during high-demand GPU periods. You can include on-demand sources or reserved SageMaker Flexible Training Plans, and the feature is available today in all AWS Regions via CLIs, APIs, SDKs, and the Console.
read more →

Google Cloud introduces granular session controls

🔐 Google Cloud has rolled out a 16-hour default session length and expanded session management into a granular, Context-Aware Access (CAA) feature. Administrators can now configure session controls via Terraform, gcloud, and REST APIs for DevSecOps workflows. Policies can target Google Groups and specific applications like the Cloud Console, gcloud, and OAuth apps, and policy management is being integrated into the Google Cloud Console preview. These updates aim to reduce credential theft and account takeover risk while preserving developer productivity.
read more →

CloudTrail now integrates with Amazon Q Console

🔍 AWS CloudTrail now integrates with Amazon Q Console to let you investigate account activity using natural language queries. You can ask about CloudTrail configuration, search logged events for security investigations, and troubleshoot operational issues without writing queries. The integration queries CloudTrail trails, CloudWatch log groups, and event data stores to provide answers grounded in your account activity. It is available in all AWS commercial regions where Amazon Q Console is supported.
read more →

Amazon Connect adds agent shift bidding capability

🔔 Amazon Connect Customer now lets contact center agents bid on preferred shifts, giving them greater control over schedules. Schedulers establish agent rankings via CSV upload or randomized generation, and Connect Customer uses forecasted demand and shift profiles to create available shifts for agents to rank. After the bidding window closes, the service assigns agents to their highest-ranked available shift, using rankings as tiebreakers to resolve conflicts. This feature aims to improve agent satisfaction and reduce manual scheduling effort.
read more →

Filestore agent volumes for scalable agent storage

🚀 Filestore agent volumes deliver fully managed, high-performance elastic file storage tailored for large-scale agent fleets on Google Cloud. Integrated with Agent Substrate and GKE Agent Sandbox, volumes attach in milliseconds to provide isolated persistent workspaces with RWX support, POSIX semantics, and granular access controls. The feature targets non-production workloads now, with GA production access via allowlist.
read more →

Agent Substrate now available on GKE clusters

🛡️ Agent Substrate is now available on Google Kubernetes Engine (GKE). This open-source agent execution runtime is engineered for high-density sandboxing, delivering sub-500ms resume times and hundreds of suspend/resume activations per second with native kernel and network isolation. Optimized for GKE but portable to any Kubernetes cluster, it supports hardware-isolated microVMs or gVisor sandboxes and integrates with existing agent frameworks like Hermes, Claude Code, and OpenClaw.
read more →

Cloud reliability incident handling best practices

🔧 This blog summarizes Google Cloud’s recommended “Verify→Investigate→Report→Resolve→Review” workflow for handling reliability incidents and advises preparing in advance by designing for failure, ensuring observability data, maintaining playbooks, and running drills. It distinguishes how to detect incidents via Personalized Service Health, Cloud Service Health, and observability tools, and provides guidance on scoping blast radius, diagnosing causes, and when to open and escalate support cases. It also covers mitigation steps while waiting for resolution and emphasizes blameless post-mortems to improve future response.
read more →

Distributed GraphFlow: Scalable GNNs for Telco Networks

🚀 Google Cloud introduces Distributed GraphFlow (DGF), an open-source Python library and framework designed to train and deploy Graph Neural Networks (GNNs) at scale for telecommunications. The post outlines an Autonomous Network Operations architecture built around a real-time network digital twin hosted in Spanner Graph, and explains how DGF integrates with that twin to enable anomaly detection, root cause analysis, predictive maintenance, and what-if simulations. DGF offers composable primitives and a high-level API to simplify GNN lifecycle management and production inference via Gemini Enterprise endpoints.
read more →

Automating IAM least-privilege remediation via CI/CD

🔒 This post describes an automated workflow that turns AWS IAM Access Analyzer findings into actionable remediation artifacts. It classifies roles by origin—IaC-managed, manually created, or unused—and produces either a production-ready CDK pull request, a migration issue with recommended policies, or a soft-disable decommission plan. The automation integrates Access Analyzer, CloudTrail, Amazon Bedrock, and your CI/CD pipeline to create reviewable, deployable changes instead of accumulating tickets.
read more →

Exaforce Expands AI Agent Monitoring Across Providers

🛡️ Exaforce now helps security teams discover and monitor AI agents by correlating data they already collect from endpoints, cloud, SaaS and model providers, avoiding additional sensors. The product builds on the Claude Compliance API integration and extends coverage to OpenAI, Gemini, Microsoft Copilot and OAuth-connected apps, mapping each agent to people, devices and permissions. It can detect suspicious behavior and, where needed, trigger actions via existing EDR, identity and model-provider controls to contain threats. Analysts note this agentless approach reduces friction but may be weaker for runtime blocking without dedicated agent identities and tighter enforcement.
read more →