< ciso
brief />
Vendor and Hyperscaler Watch Banner

All news in category “Vendor and Hyperscaler Watch”

5908 articles · page 3 of 296

Apple to Tighten macOS Full Disk Access Controls

🔒 Apple is moving to strengthen controls around the macOS Full Disk Access (FDA) setting after concerns that AI agents and some apps may misuse it to access sensitive data. The company said FDA can expose files, mail, messages, browsing history and backups, and plans updates to require explicit user actions before granting such deep access. The change appears prompted by incidents involving agentic tools like Meta's Muse and proof-of-concept exploits that demonstrated token theft and broader privilege amplification risks. Apple did not announce a rollout date but emphasized clearer user consent and heightened safeguards.
read more →

Google pauses OSS bug bounty until 2027

🛑 Google has paused its Open Source Vulnerability Rewards Program (OSS VRP) until 2027 after a surge of automated, largely invalid submissions. Launched in August 2022, the OSS VRP rewards researchers for finding flaws in Google-hosted open-source projects and related repository configurations. The pause excludes supply-chain reports and already filed submissions, while Google says it will reformat the program and provide an update in Q1 2027. Researchers are urged to use other Google VRPs or the Patch Rewards Program in the interim.
read more →

AWS Private CA adds detailed issuance logs

📜 The new AWS Private CA CloudTrail IssueCertificateDetails event records full certificate content, issuing CA data, requester identity, and signing status for every issuance. It captures the complete TBS certificate with X.509 fields and convenience fields like subject, issuer, serial, validity, template, and algorithm. Events include both successful and failed issuances and identify the requester (account/IAM principal or service principal). Delivered automatically as a CloudTrail management event in supported Regions, it can be consumed in real time via EventBridge or queried with Athena at standard CloudTrail cost.
read more →

Google pauses OSS bug bounty amid AI report surge

🔒 Google has temporarily suspended submissions to its Open Source Software Vulnerability Rewards Program (OSS VRP) after a flood of largely invalid AI-generated reports. The pause doesn't affect supply chain reports or previously submitted product vulnerabilities, and researchers can still use the Patch Rewards Program or Cloud VRP. Google plans to rework the OSS VRP to address automated submission issues and will provide an update in Q1 2027.
read more →

Should the CISO role be split in two?

🔒 The CISO role has expanded from technical oversight to strategic business leadership, encompassing risk reporting, governance, privacy, AI oversight, and resilience. Many CISOs now carry executive authority, but two-thirds still report into IT, creating perception and resource gaps. Experts argue against creating two CISOs, favoring one strategic CISO supported by deputies or distinct functional leads for operations and governance.
read more →

The State of Cybersecurity in 2026: Key Trends

🔎 This vendor-focused overview summarizes how cloud expansion, AI, distributed systems, and complex digital environments are reshaping security. It highlights shifts toward continuous visibility, least-privilege identity controls, telemetry management, AI-native SOCs, and exposure reduction. The piece profiles vendors addressing identity, telemetry, endpoint, human risk, exposure, email, device, AI, and cloud security.
read more →

ECS adds VPC Lattice blue/green and canary deploys

🔧 Amazon Elastic Container Service (Amazon ECS) now provides built-in blue/green, linear, and canary deployment strategies for services using Amazon VPC Lattice. Applications using VPC Lattice for cross-VPC and cross-account communication can leverage managed traffic shifting directly from ECS when rolling out updates. Teams can validate new versions with test traffic, use lifecycle hooks for custom validations or manual approvals, and rely on CloudWatch alarms and the ECS deployment circuit breaker to trigger automatic rollbacks.
read more →

AI21 Accelerates Model Training with AI Hypercomputer

🔧 AI21 Labs adopted Google Cloud AI Hypercomputer and Kueue on GKE to run foundation models like the Jamba family at scale. They pooled thousands of A3 and A3 Ultra GPU instances into a shared GKE cluster to maximize utilization and replaced manual capacity negotiation in Slack with automated scheduling. The change reduced high-priority job wait times from 72 hours to 12, cut manual scheduling interventions from 20 per week to zero, and lowered fragmentation.
read more →

AWS Health launches version catalog for lifecycle management

📢 The new AWS Health version catalog centralizes lifecycle information for software versions across AWS services, enabling customers to shift from reactive to proactive upgrade and end-of-support management. Available in the AWS Health Dashboard, customers on Business Support Plus, Enterprise Support, or Unified Operations can also access the data via the AWS Health API to integrate version timelines into operational workflows. The catalog initially covers Amazon RDS, Amazon EKS, and AWS Lambda, is available across all AWS Commercial Regions, and will expand to include additional services over time.
read more →

Amazon EKS Distro Adds Kubernetes 1.37 Support

🚀 Amazon EKS and EKS Distro now support Kubernetes version 1.37. This release lets you create new clusters or upgrade existing ones via the EKS console, eksctl, or infrastructure-as-code tools. Kubernetes 1.37 promotes the Metrics API to GA, graduates Dynamic Resource Allocation device taints and tolerations to GA, and enables HPA scale-to-zero by default. EKS 1.37 is available in all Regions where EKS operates, with EKS Distro images published to ECR Public Gallery and GitHub.
read more →

Aurora DSQL Adds Partial Index Support

🔍 Amazon Aurora DSQL now supports partial indexes, enabling indexes over a subset of table rows defined by a WHERE clause. This reduces index storage and improves query performance for common working sets, such as active orders amid large historical data. Aurora DSQL will use a partial index when a query's filter is covered by the index condition. The feature is available in all AWS Regions where Aurora DSQL is offered.
read more →

AWS launches Brazil 2P software license distribution

🛈 AWS Brazil introduces the AWS Brazil 2P Distribution Program to automate distribution of SaaS product licenses for eligible non-Brazilian ISVs. AWS Brazil becomes the seller of record, invoicing customers in BRL, calculating and withholding applicable Brazilian taxes, and handling disbursements. ISVs create distribution authorizations via AWS Partner Central or APIs and monitor transactions and payments through the Seller Insights dashboard.
read more →

Streamline: Cloudflare’s Developer Video Pipeline

🎥 Cloudflare released Streamline, a developer playground demonstrating how to build custom video processing pipelines on its Developer Platform. The system pairs long-running Containers for media processing with Workers and Durable Objects for orchestration, control, and preview. Streamline supports RTMPS, HLS, webcam ingestion, live overlays, burned-in subtitles, and WebSocket preview delivery. The design emphasizes modularity, local development parity, and security for credentials and session control.
read more →

Cloudflare launches Web Search API for AI Gateway

🔎 Cloudflare announced integration of a Web Search API into its AI Gateway, partnering with providers like Ceramic.ai, Exa, and Linkup. The feature supplies live, structured web snippets to agents and models, addressing stale knowledge and reducing inefficient URL guessing. Partners commit to Cloudflare's verified bot standards, transparency, and respect for robots.txt. The API is accessible via REST, Workers, and AI Gateway with observability, BYOK, and optional Zero Data Retention.
read more →

Cloudflare Account Abuse Protection Dashboard Launch

🔍 Cloudflare introduces an Account Abuse Protection dashboard that builds stateful, privacy-preserving account overviews from login and signup activity. Using a Hashed User ID, the system aggregates network and device signals to reveal behavioral baselines and surface deviations for investigation. Early Access customers can use the workspace to move from population-level trends to individual account investigations and apply role-based access controls for PII.
read more →

Cloudflare Now Fastest in 74% of Top Networks

🚀 Cloudflare reports it is the fastest provider in 74% of the 1,000 largest networks worldwide, up from 60% in April 2026. The update summarizes measurement methods, introduces a new approach using Cloudflare Challenge Pages, and explains how expanded data collection improved geographic and network coverage. The post highlights connection time and the trimean metric as core evaluation methods and describes plans to scale measurements while preserving user experience and privacy.
read more →

Protected Quick Tunnels: Email-Restricted Local URLs

🔒 Cloudflare introduces email-based access controls for Quick Tunnels so developers and agents can publish local services securely. Add the --allowed-mail flag to cloudflared to restrict access to specific email addresses or domains; visitors verify ownership with a one-time PIN via Cloudflare Access. The design keeps authorization rules on the developer's machine while using a stateless authentication broker to validate emails, ensuring guest lists never leave the host.
read more →

Cloudflare Traces: Expanded Open Beta Tracing

🛰️ Cloudflare Traces enters open beta, extending automatic distributed tracing beyond Workers to cover the entire request path. The feature records supported security rules, transformations, caching, routing, Worker execution, and origin interactions as OpenTelemetry spans, which can be exported via OTLP to compatible backends. Tracing is enabled per domain with baseline sampling and flexible Trace Rules to capture targeted, full-trace investigations without instrumenting code.
read more →

Cloudflare supports civil society automation with AI

🚀 Cloudflare Impact is funding civil society groups with over $7.5M in developer credits to help non-profits build secure, scalable AI tools. Project Galileo continues to protect thousands of public-interest domains while lightweight serverless services and Workers AI reduce infrastructure cost and complexity. The company launched a nonprofit startup cohort and provides engineering support to help organizations automate sensitive workflows safely.
read more →

Cloudflare expands enterprise features to all users

📣 Cloudflare announced that many features previously restricted to Enterprise customers are now available to Free, Pro, and Business users. The company is making advanced capabilities like Logpush, Transformers, Custom Dashboards, and expanded RBAC broadly accessible with pay-as-you-go or free tiers where possible. They also introduced self-serve multi-account creation, Organizations for unified management, resource tagging, and improved Terraform support.
read more →