< ciso
brief />
Vendor and Hyperscaler Watch Banner

All news in category “Vendor and Hyperscaler Watch”

5918 articles · page 24 of 296

AWS Systems Manager expands EC2 diagnosis reach

🔍 AWS Systems Manager now diagnoses six additional root causes preventing Amazon EC2 instances and hybrid-activated nodes from becoming managed. The expanded checks include IAM permissions, SSM Agent version, instance status checks, operating system configuration, Default Host Management Configuration, and hybrid activation, in addition to prior network connectivity diagnostics. The console reports specific issues with step-by-step guidance and can run Automation runbooks to remediate some problems directly.
read more →

Amazon Connect Customer Profiles: Segment Events

🔔 Amazon Connect Customer Profiles now emits segment membership events to notify when customer profiles enter or exit segments such as high-value or low-satisfaction cohorts. This removes the prior need to export full segments and run differential scripts, which caused delays and errors. Events stream to Amazon Kinesis Data Streams and include profile ID, segment name, operation type, and whether the change was real-time or from a scheduled snapshot. Real-time detection applies to standard-condition segments, while enhanced segments (Spark SQL) use configurable periodic snapshots.
read more →

AWS Private CA connectors arrive in GovCloud

🔒 AWS Private Certificate Authority (AWS Private CA) now offers the AWS Private CA Connector for Kubernetes as a managed Amazon EKS add-on and the AWS Private CA Connector for Active Directory in AWS GovCloud (US-East) and (US-West). These additions simplify certificate automation for government workloads, integrating with cert-manager to provision and renew TLS certificates in Kubernetes and enabling AD-based automatic issuance for domain-joined objects. The service secures private keys using FIPS 140-3 Level 3 HSMs.
read more →

Timestream for InfluxDB adds custom Python plugins

🛠️ Amazon Timestream for InfluxDB now supports running custom Python plugins on managed InfluxDB 3 Core and Enterprise editions. You store plugin code in public or private repositories you control, and the processing engine fetches and executes it in response to supported triggers, enabling in-database data transformation, alerting, aggregation, and service integrations. Plugins run in a managed Python environment with the standard library and Amazon-vetted packages; private repos are authenticated via tokens in AWS Secrets Manager. To enable a plugin, configure a plugin repository in a DB parameter group, apply it to your cluster, and create triggers referencing the plugin via the influxdb3 CLI or HTTP API; the feature is available in all Regions where the service is offered.
read more →

SageMaker Feature Store adds feature-level writes

🔧 Amazon SageMaker Feature Store now supports feature-level writes, enabling updates to individual features within a record without rewriting the entire record. This reduces write latency and cost by allowing pipelines to replace read-modify-write patterns with single update calls. Multiple pipelines can independently update different features in the same feature group, simplifying ingestion logic for streaming and batch jobs. The feature is available in all Regions where SageMaker Feature Store is offered.
read more →

AWS Transform arrives in GovCloud (US-West)

🔒 AWS Transform is now available in the AWS GovCloud (US-West) Region, enabling government agencies and regulated organizations to plan and execute large-scale migrations to AWS. The service automates server migrations within an isolated environment for sensitive data and supports migrating servers to both AWS GovCloud (US-East) and GovCloud (US-West) target Regions. Supported sources include VMware, bare metal, Hyper-V, and databases; however, modernization, custom transformation, and assessment features remain available only in commercial Regions.
read more →

Amazon API Gateway adds mutual TLS for backends

🔐 You can now configure Amazon API Gateway REST APIs to present an AWS Certificate Manager (ACM) certificate to your backend during the TLS handshake, enabling mutual TLS (mTLS). Previously API Gateway only offered a self-signed certificate; now you may use certificates from your trusted certificate authority or issue/manage them via AWS Private Certificate Authority. Certificate updates in ACM propagate automatically with no redeployments.
read more →

Data Agent Kit: Agentic Analytics in IDEs

🧭 The Data Agent Kit streamlines exploratory data investigations by enabling agents inside IDEs to query multiple systems—data warehouses, operational databases, and object stores—via the open Model Context Protocol (MCP) and modular skills. It integrates with popular IDEs and plugins so developers can run queries, inspect execution trails, and grant scoped permissions without switching tools. The kit can convert ad-hoc analysis into reproducible dbt projects and iteratively fix issues, though human oversight and data quality checks remain important.
read more →

Amazon RDS Adds Latest Community MariaDB Minors

🆕 Amazon RDS for MariaDB now supports community minor versions 10.6.28, 10.11.19, 11.4.13, 11.8.9, and 12.3.3, which include operational improvements and post-quantum TLS (PQ-TLS) key exchange support for in-transit encryption. AWS recommends upgrading to gain CVE fixes, bug fixes, performance improvements, and new features. You can upgrade via Blue/Green deployments, in-place upgrades, or snapshot restores, and automate rollouts with automatic minor upgrades and the AWS Organizations Upgrade Rollout Policy. Migration from external MariaDB sources is supported via AWS Database Migration Service.
read more →

AWS HealthOmics adds resource fallback for WDL

🔬 Today, AWS HealthOmics introduces the resource fallback directive, allowing users to specify an ordered list of preferred accelerator types — including a final CPU fallback — for tasks in Workflow Description Language (WDL) workflows. This feature reduces time spent diagnosing and resubmitting runs when accelerators are constrained and helps keep production workflows running. HealthOmics is HIPAA-eligible and available in multiple AWS Regions to support bioinformatics at scale.
read more →

KDDI Optimizes RAG Performance with ADK

📘 KDDI developed Buffmee, a consumer-facing Retrieval-Augmented Generation (RAG) app, to provide grounded, trustworthy AI-assisted learning across books, magazines, and web media. Facing latency and hallucination challenges, KDDI worked with KDDI iret and Google Cloud teams to implement automated evaluation using Gemini Enterprise, BigQuery Agent Analytics, and the Agent Development Kit (ADK). These optimizations reduced response latency by 38% and improved TTFT by nearly 18%, while boosting groundedness by 25% through systematic testing and prompt modularization. The result is a faster, more reliable experience that preserves content trust and compliance.
read more →

Amazon Bedrock AgentCore Memory supports direct ingestion

🔔 Amazon Bedrock AgentCore Memory now offers the IngestData API to submit content directly for long-term memory extraction without first creating a short-term memory event. The API accepts conversational and JSON payloads along with optional metadata, fans content out to configured long-term strategies, and makes resulting records available via existing retrieval operations. Developers can verify and manage extraction results with ListMemoryRecords, RetrieveMemoryRecords, Kinesis streaming for notifications, and ListMemoryExtractionJobs for redrives.
read more →

US Military Disables Ad Tracking on Government Phones

🔒 Branches of the US military have disabled advertising IDs on government-issued phones and computers after concerns that commercially available location data was being used to target American forces. Senator Ron Wyden and Representative Pat Harrigan pushed the Pentagon for action and sought an inspector general investigation into how location data risks were handled. The move follows warnings about adversary exploitation of commercial location data and broader guidance urging personnel to limit personal device sharing and clean up social media.
read more →

AWS adds smart cropping and optimization to DIT

🖼️ Today, AWS announced four new features for Dynamic Image Transformation for Amazon CloudFront (DIT), enhancing smart cropping with custom label detection and advanced composition controls to preserve products, text, logos, and custom objects. The update also adds enhanced automatic image optimization across devices using CloudFront's multi‑tier device detection, an interactive transformation playground for testing, and full feature parity between ECS and Lambda architectures. DIT is available in all commercial regions and four opt‑in regions.
read more →

Cloudflare Enables Automatic Key Exchange for Origins

🔐 Cloudflare introduces Automatic Key Exchange, extending Automatic SSL/TLS to probe origin servers and choose the optimal TLS 1.3 key agreement on the first ClientHello. This measurement-driven approach replaces a static X25519 guess, dramatically reducing HelloRetryRequests and lowering handshake latency while enabling broader post-quantum hybrid key usage. The feature is active by default and includes compliance filters for operators who need to restrict allowable algorithms.
read more →

How Chainguard Scaled to One Billion Build Manifests

🔧 Over six months Chainguard doubled its output from 500 million to over 1 billion container build manifests, surpassing 3,000 images and 675,000 versions. The article explains what a build manifest represents and how Chainguard OS and Chainguard Factory produce continuous, reproducible artifacts with SLSA Level 3 provenance, Sigstore signatures, and SBOMs. It describes the transition from an event-driven Factory to Factory 2.0 (DriftlessAF), which uses continuous reconciliation, redundant work queues, and targeted AI to remove toil and accelerate rebuild velocity. The piece argues that faster rebuilds are essential to staying ahead of AI-enabled attackers and outlines future expansion and open sourcing of DriftlessAF.
read more →

AWS Builder ID adds recovery and third‑party MFA

🔐 AWS Builder ID now supports adding a recovery email and new self-service account recovery options to help users regain access without contacting support. You can reset forgotten passwords via primary or recovery email and restore access if an MFA device is lost by verifying both emails. Third-party sign-ins from Google, Apple, GitHub, or Amazon can now register MFA devices directly in AWS Builder ID, and users may permanently switch to an email/password sign-in if they lose a third-party account.
read more →

Nx Plugin for AWS: Scaffolding Full‑Stack Apps

🚀 Version 1.0 of the Nx Plugin for AWS is now available as an open source toolkit to scaffold full-stack applications on AWS. The plugin extends Nx with generators that create AI agents, Model Context Protocol servers on Amazon Bedrock AgentCore, APIs, websites, and databases using TypeScript and Python. Generated code includes infrastructure defined as AWS CDK constructs or Terraform modules and applies recommended practices like AWS WAF protection, CloudWatch logging, and AWS X-Ray tracing. The output is reproducible, type-safe, and yours to own with no runtime dependency on the plugin.
read more →

AWS extends EMR support to ease customer migrations

🔔 Amazon EMR will provide additional support at no extra cost for customers actively migrating from older releases. Eligible releases will receive critical security fixes and extended Standard Support on a best-effort basis through specified dates in 2027; customers must contact AWS Support with a migration plan to receive the extension. The policy covers all EMR deployment models (EMR on EC2, EMR on EKS, and EMR Serverless) across AWS Regions and recommends using the Apache Spark Upgrade Agent to move applications to current releases.
read more →

Amazon S3 Object Lock Adds Variable Retention

🔒 Amazon S3 Object Lock now supports variable retention via event holds that start on a future triggering event, enabling WORM protection that begins when a contract closing, audit completion, or similar event occurs. You can apply event holds to individual objects, set them as a bucket default, or scale them with S3 Batch Operations, while new IAM and bucket policy condition keys let you control who can set or release holds and enforce duration limits. CloudTrail logs hold operations and S3 Inventory reports hold status; the feature is available in all AWS Regions at no extra charge and has relevant regulatory assessments.
read more →