< ciso
brief />
Vendor and Hyperscaler Watch Banner

All news in category “Vendor and Hyperscaler Watch”

5908 articles · page 2 of 296

PromptGuardX: Extending AI Security into Files

🛡️ PromptGuardX inspects PDFs before their content reaches an LLM or AI agent, detecting hidden instructions and obfuscation techniques that can enable prompt injection. Integrated into Check Point Threat Emulation, it extracts and normalizes text, locates suspicious instruction regions, analyzes context with fine-tuned classifiers, and returns explainable verdicts and confidence scores. This upstream file-layer protection complements runtime monitoring, access controls and prompt inspection.
read more →

Red Hat's Lightwell Remediates 400+ Java Vulnerabilities

🔒 Red Hat's open-source security initiative Lightwell has remediated over 400 novel vulnerabilities across core Java libraries since launching in June. The company announced the general availability of the Lightwell Clearinghouse after a pilot phase, aiming to validate AI-generated reports and reduce noise for maintainers. Backed by IBM and supported by major financial institutions, Lightwell offers continuous signed binaries, SBOMs and a premium clearinghouse for targeted backports to production systems.
read more →

Google pauses OSS product bug bounty rewards

🛡️ Google has suspended product vulnerability submissions to its Open Source Software Vulnerability Reward Program (OSS VRP) effective October 1, citing a significant rise in automated, largely invalid reports. Reports filed before October 1 and supply chain compromise reports remain accepted, and the company says the pause is temporary while it reworks the program with an update promised in Q1 2027. The pause removed listed product vulnerability payouts for flagship and important projects, though supply chain and other issue rewards remain in place.
read more →

Why SMBs Seek Advanced Security Without Complexity

🔒 SMBs face escalating threats from state-backed and financially motivated actors, compounded by AI-driven attack techniques and a growing AI attack surface. They want robust protection that is simple to operate, with 24/7 monitoring, clear guidance, and expert help. Managed detection and response (MDR) can reduce operational burden, but cost, onboarding complexity, and integration challenges remain barriers for many smaller organizations.
read more →

Gartner’s ISOC: A New Layer for Security Ops

🔒 Gartner introduced the Integrated Security Operations Center (ISOC) category to address the limits of traditional SIEMs by unifying detection, investigation, case management and response. ISOC emphasizes native detection and response, centralized data ownership, persistent incident case objects and cross-domain correlation to reduce latency and operational friction. The aim is streamlined workflows and lower costs for lean security teams confronting AI-accelerated threats.
read more →

Amazon Redshift adds Iceberg materialized views

🚀 Amazon Redshift now supports creating and refreshing Apache Iceberg materialized views that store precomputed joins and aggregations as Iceberg tables in Amazon S3 and register them in the AWS Glue Data Catalog. Materialized views are created with SQL using CREATE MATERIALIZED VIEW ... USING ICEBERG and are queryable by Iceberg-compatible engines such as Amazon Athena, Apache Spark on Amazon EMR, AWS Glue, and third-party engines like Trino or Snowflake. Redshift provides manual incremental refreshes to recompute only changed data, and the resulting Iceberg tables are discoverable and governed through the Glue Data Catalog.
read more →

Amazon Bedrock adds GLM 5.3 support for enterprise

🛠️ Amazon Bedrock now supports GLM 5.3 from Z.ai, enabling agentic coding and long-horizon software engineering workloads with AWS security and compliance. GLM 5.3 is a mixture-of-experts model with 753B parameters and a 1-million-token context window, offering selectable reasoning effort levels and up to 128K output tokens. Bedrock provides prompt caching for system prompts and messages to lower latency and input costs. The model is available to eligible enterprise customers via the Bedrock console and APIs in US and Global cross-Region inference profiles.
read more →

AWS Continuum Raises Bar for Autonomous Code Security

🔒 AWS reports that Continuum for code vulnerabilities achieved an 89.0% end-to-end pass rate on the CyberGym-E2E benchmark, passing 819 of 920 tasks within a 90-minute limit. The multi-agent system improved on prior public results across all measured stages (discovery, validation, remediation) and reached 93.7% when allowed to run longer. The evaluation was conducted under network-isolation and submission-review rules to ensure results came from analysis rather than retrieval.
read more →

AWS Identity Store adds network access controls

🔒 IAM Identity Center now supports network access controls for the Identity Store and SCIM APIs, letting you restrict API requests by VPC endpoints, source VPCs, or IP ranges. You can apply different restrictions per API and exempt AWS service requests; controls are optional and disabled by default. Configuration is done via the Identity Store API using AWS SDKs or AWS CLI and is available in all Regions where IAM Identity Center is offered.
read more →

Amazon EC2 Hpc8a Now in Asia Pacific (Singapore)

⚙️ Hpc8a instances, powered by 5th Gen AMD EPYC (Turin) processors, are now available in the Asia Pacific (Singapore) region. These instances deliver up to 40% higher performance and up to 25% better price performance versus Hpc7a, with up to 42% higher memory bandwidth. Built on sixth-generation AWS Nitro Cards, Hpc8a targets tightly coupled, latency-sensitive HPC workloads like CFD, weather forecasting, and FEA.
read more →

AWS Control Tower AFT adds plan-only customization

🛠️ AFT now supports plan-only customization runs that let administrators preview Terraform changes without applying them. This update enables safe pre-rollout validation, drift detection, and integration with CI/CD review workflows across all AFT-supported Terraform distributions. The feature is available in all Regions where AWS Control Tower Account Factory for Terraform is supported; see the AFT documentation and 1.22.0 release notes for setup details.
read more →

AWS Continuum Adds CI/CD Integrated Pentesting

🛠️ AWS Continuum for Penetration Testing (formerly AWS Security Agent) now offers public preview CI/CD integration that makes penetration testing a deploy-time event. The service delivers findings—including severity, affected endpoints, and remediation guidance—directly in pipeline output while avoiding meaningful delays for non-security changes. Teams can paste an auto-generated pipeline snippet into existing workflows and complete setup in under five minutes, with application context bootstrapped automatically on first run.
read more →

AWS Builder Center adds availability and filtering

🔔 AWS announces feature-level availability notifications and enhanced filters in AWS Builder Center for AWS Capabilities by Region. Builders can subscribe to service- or feature-level notifications and receive in-app alerts and a weekly email digest for selected Regions, including an 'All regions' option that covers future Region launches. New filters let users view API operations and CloudFormation resources by availability status and compare Regions by shared or differing availability across more than 19,000 API operations and 5,000 resource types.
read more →

EC2 AMI Shared Tags Simplify Cross‑Account Metadata

🔖 Amazon EC2 now supports AMI tag sharing, enabling AMI owners to expose selected tags to any AWS account the AMI is shared with. Owners prepend the tag key with ec2:SharedTag/ so the tag is automatically visible to recipient accounts without manual replication. Shared tags are read-only for recipients and count only against the owner's tag quota, and the feature is available in all Regions at no extra cost.
read more →

AWS Client VPN adds device posture assessment

🔒 AWS Client VPN now supports device posture assessment, enabling verification that connecting user devices meet security and compliance requirements before granting access. This integrates with existing posture providers such as CrowdStrike, Jamf, and JumpCloud and uses Cedar policies for fine-grained control. A Test Policy tool helps you author and validate posture rules, and evaluations can be enforced or run in monitoring-only mode. The feature continuously re-evaluates active sessions and is available in all AWS Regions at no extra cost, requiring AWS VPN Client v6.2.0+.
read more →

AWS releases advanced Ruby driver wrapper for RDS/Aurora

🚀 The AWS Advanced Ruby Driver Wrapper is now generally available for Amazon RDS and Amazon Aurora PostgreSQL and MySQL-compatible databases. It reduces RDS Blue/Green switchover, Aurora Global database switchover and failover times to improve application availability and supports authentication via AWS Secrets Manager and token-based AWS IAM. Built on the community pg and mysql2 drivers, it integrates with Aurora/RDS to detect cluster status and reconnect to promoted writers, and provides aws_postgresql and aws_mysql2 ActiveRecord adapters so applications require no code changes.
read more →

Google Cloud Modernize: AI-Driven Enterprise Transformation

🚀 Google Cloud announces Google Cloud Modernize, an end-to-end portfolio that consolidates migration and modernization tools to accelerate enterprise transformation with AI. The offering centers on Modernization Hub, an in-console experience for analyzing code and mapping dependencies for Java, .NET, and mainframe apps. New Gemini-powered capabilities in Migration Center provide rapid TCO estimates and interactive cost modeling. Purpose-built compute, VMware support, and agentic migration tools (EKS-to-GKE) help organizations modernize infrastructure and application estates with enterprise-grade controls.
read more →

AWS Batch adds EKS access entry authentication

🛠️ AWS Batch now supports Amazon EKS access entry authentication for compute environments. EKS access entries provide an API-driven way to grant IAM principals access to Kubernetes clusters, complementing the existing aws-auth ConfigMap. To enable, set accessEntry.desiredState to ENABLED via the CreateComputeEnvironment or UpdateComputeEnvironment APIs; AWS Batch creates one access entry per cluster and attaches the AWSBatchClusterPolicy. This feature is available in all Regions where AWS Batch is offered.
read more →

Cloudflare Birthday Week 2026: Platform and Security

🎉 Cloudflare recapped its 16th Birthday Week, detailing 46 announcements spanning open source, application security, developer tools, monetization, data platforms, and observability. Highlights include a new cf CLI and Forge pipeline, EmDash CMS, post-quantum cryptography efforts, plans to become a certificate authority, Monetization Gateway and Pay Per Use, and GA launches for Basin and K2. The company emphasized support for agents, developer ecosystems, intern contributions, and commitments to open tools and civic programs.
read more →

Expanding Credential Layer: Visibility and Risk

🔒 GitGuardian outlines why the credential layer deserves immediate attention and how detection is the first essential step. The article explains that credential sprawl spans repositories, endpoints, collaboration tools, and AI agents, increasing attack surfaces and making discovery urgent. It highlights research showing rising hardcoded secrets and explains the need for context — validity, ownership, permissions, and dependencies — to prioritize remediation. The piece argues security teams must connect multiple discovery sources to measure coverage and reduce exposure.
read more →