< ciso
brief />
Vendor and Hyperscaler Watch Banner

All news in category “Vendor and Hyperscaler Watch”

5920 articles · page 34 of 296

Amazon RDS for PostgreSQL adds latest minor versions

🔔 Amazon RDS for PostgreSQL now supports minor releases 18.6, 17.11, 16.15, 15.19, and 14.24. We recommend upgrading to these versions to address prior CVEs and to benefit from community bug fixes and improvements. You can apply upgrades during scheduled maintenance with automatic minor version upgrades, and orchestrate phased rollouts using AWS Organizations Upgrade Rollout Policy. Use Blue/Green deployments to minimize downtime for upgrades.
read more →

The patch window is collapsing: a new control plane

🔒 Modern vulnerability timelines are compressing as disclosures, exploit research, and AI-assisted workflows accelerate attacks while enterprise remediation remains slow due to operational constraints. Visibility and prioritization improve awareness but don’t reduce exposure quickly enough. Network-enforced, context-aware controls can provide rapid, targeted protections to limit exploitability during the interval between disclosure and patching.
read more →

Amazon Connect Cases adds flexible customer profile support

🛠️ Amazon Connect Customer now lets agents change or assign a customer profile on a case after it has been opened. This update helps correct mislinked cases and allows profiles to be added later when customer identity is unknown at creation, such as shared numbers or pending verification. Amazon Connect Cases is available in multiple AWS regions including US, Canada, Europe, Asia Pacific, and Africa, with documentation and getting started resources provided by AWS.
read more →

gVisor sandboxes integrated into Ray clusters

🧰 Google and Anyscale introduce an experimental Ray library that integrates gVisor sandboxes into distributed Ray clusters to provide secure, high-performance isolation for agentic and reinforcement learning workloads. The design maps sandboxes to Ray Actors so schedulers can place, resource, and manage them like other Ray-managed resources. The sandbox API supports OCI images, resource limits, file operations, command execution, and lifecycle controls, while SandboxRuntime offers lower-level access and OCI spec modification.
read more →

How to Spot Suspicious and Risky Websites

🔎 This article explains how many websites fall into a gray area between legitimate services and outright scams, outlining common deceptive practices and how they harm users. It describes schemes such as hidden subscription traps, counterfeit or non-delivered goods, fraudulent crypto and investment platforms, and fake middlemen charging inflated fees. The piece also highlights dangerous fake browser extensions and recommends using Kaspersky security solutions, including the Kaspersky Protection browser extension and Kaspersky Premium, to detect, block, and warn about sites with uncertain trust.
read more →

PowerToys adds app-only window switching feature

🔧 Microsoft released PowerToys 0.101.2362.0, introducing a new utility called Window Hopper that lets users cycle through windows of the currently focused app using a configurable Alt + backtick shortcut. The update also brings a compact Command Palette mode, PowerDisplay linked control support for shortcuts, DemoMirror for ZoomIt, and a Mouse Highlighter ripple mode. PowerToys remains open source on GitHub with a detailed changelog.
read more →

WhatsApp adds multiple passkeys and stronger 2FA

🔐 Meta announced new WhatsApp security features, including support for multiple passkeys per account to enable phishing-resistant sign-ins across iOS and Android. The company reported over 1 billion users now sign in with passkeys and added a full password option for two-step verification, replacing the previous six-digit PIN. Android users will also receive added call context for unknown callers, such as origin and shared groups. Settings for passkey management are available under Settings > Account > Passkeys.
read more →

IAM Roles Anywhere Java SDK v2 plugin available

🛠️ The AWS Identity and Access Management (IAM) Roles Anywhere plugin for the AWS SDK for Java v2 lets applications running outside AWS obtain temporary credentials directly inside the Java process. The JVM-hosted plugin removes the need for a separate credential helper or credential_process configuration and integrates with client builders to auto-resolve and refresh credentials. It supports RSA, EC, and ML-DSA keys, requires Java 8+, and is available across all AWS Regions at no extra charge.
read more →

WhatsApp strengthens account security with passkeys

🔐 WhatsApp is rolling out several account security improvements, including support for multiple passkeys and an upgraded two-step verification option. Users can now create separate passkeys per platform (Android and iOS) and replace the previous six-digit PIN with a longer alphanumeric password. The update also adds more context on call screens for unknown callers to help users spot potential scams.
read more →

AWS Lambda launches managed runtimes in public preview

🔔 AWS Lambda has opened public preview for managed runtimes starting with Node.js 26 and Python 3.15. This preview lets customers, partners, and language communities test upcoming runtimes and provide feedback before general availability. Preview runtimes may change and are not covered by the Lambda SLA or AWS support plans, so they should not be used for production. The preview uses the same runtime identifiers as GA, enabling automatic graduation when released.
read more →

AWS launches EC2 M8i and M8i‑flex in Canada West

🚀 Starting today, Amazon EC2 M8i and M8i‑flex instances are available in Canada West (Calgary). Powered by custom Intel Xeon 6 processors exclusive to AWS, they deliver higher performance and memory bandwidth, offering up to 15% better price-performance and significant workload-specific boosts versus previous generations. M8i‑flex targets common general-purpose sizes, while M8i supports larger, SAP‑certified sizes including a new 96xlarge.
read more →

Nucleus expands AI to detect exposures earlier

🛡️ Nucleus Security is rolling out Nucleus Helix, an AI Agent for natural-language interaction with security data and workflows, plus Nucleus Discover and expanded Nucleus Insights to accelerate early exposure detection and vulnerability intelligence. The company says these capabilities aim to shorten the gap between disclosure and scanner coverage by using environment context, prior scan data and real-time threat intelligence to identify likely affected systems before scanner plugins are available. Nucleus positions Helix as a reasoning assistant while deterministic automation executes approved workflows, and plans to release Helix and Discover in September with Insights available now.
read more →

Gemini Enterprise for Legal: Secure AI for Firms

🔒 Gemini Enterprise for Legal is a purpose-built, governed AI environment designed for law firms and corporate legal teams. It combines reusable skills, secure MCP connectors to existing systems, and agentic workflows to execute tasks like contract review, DSAR fulfillment, and regulatory horizon scanning. The platform preserves document-level permissions, integrates with Google Workspace and Microsoft 365, and supports partner-built agents while enforcing compliance and private data isolation.
read more →

Gemini Enterprise for Financial Services Launch

🔒 Gemini Enterprise for Financial Services integrates Google’s agentic AI into capital markets and corporate banking workflows with secure, auditable connectors and purpose-built financial skills. It ships with a Google-managed Financial Research agent, MCP connectors to licensed market and enterprise data, and an ecosystem of partner agents and integrators. A governed control plane enforces policies, private data isolation, and verifiable citations for outputs.
read more →

Black Hat roundup: Security vendors and AI trends

🔍 Andy Ellis reviews the vendor landscape at Black Hat, highlighting pervasive AI influence across booths and product messaging. He notes that while many vendors emphasize AI in Identity, SaaS, AppSec, and Data, nearly half did not explicitly reference agents or AI in their taglines. Ellis also identifies a market trichotomy: tools that report risk, tools that stop adversaries, and tools that prevent incidents, with diagnostic tools arguably overrepresented.
read more →

Amazon RDS Adds Support for SQL Server 2025 CU6

🔔 Amazon RDS for SQL Server now supports the latest Microsoft cumulative update: SQL Server 2025 CU6 (KB5093421) as RDS version 17.00.4055.5.v1. This update brings the fixes and improvements detailed in Microsoft's KB5093421. AWS recommends upgrading RDS instances using the Amazon RDS Management Console, AWS SDK, or CLI. Refer to the Amazon RDS SQL Server User Guide for detailed upgrade instructions.
read more →

Amazon RDS for Oracle July 2026 Release Update

🛈 Amazon RDS for Oracle now supports the Oracle July 2026 Release Update (RU) for Oracle Database versions 19c, 21c, and 26ai. The update includes security fixes and a revised naming format for 19c RUs: 19.0.0.0.ru-2026-07.mrp-2026-07.r1. You can apply the RU via the RDS console, AWS SDK/CLI, or enable Automatic Minor Version Upgrade. AWS Organizations upgrade rollout policy can stagger and validate upgrades across environments.
read more →

Secrets Manager Adds Cisco and Netskope Rotations

🔒 AWS Secrets Manager now supports managed external secrets for Cisco Security Platform API keys and Netskope API tokens, allowing automated rotation directly from the AWS console without custom rotation code. Cisco rotations refresh the API key's refresh token on a schedule so applications continue to obtain short-lived access tokens. Netskope rotations update RBACv3 service-account tokens via SCIM and validate the new token before completion. These self-authenticating integrations require no separate administrator credential and are available in all Regions where managed external secrets are supported.
read more →

AWS Lambda adds full IAM resource-based policy support

🔒 AWS Lambda functions now support full Identity and Access Management (IAM) resource-based policies, enabling platform and security teams to define granular permissions for multiple principals and actions within a single policy. This replaces the previous per-principal permission model and permits the use of the full range of IAM condition keys, such as source IP or principal tag restrictions. Policies can be managed via the Lambda console JSON editor, AWS CLI, SDKs, CloudFormation, and SAM. The feature is available in all AWS commercial Regions at no extra cost.
read more →

Amazon GameLift Servers Adds Enhanced DDoS Protection

🛡️ Amazon GameLift Servers now includes Enhanced DDoS Protection, automatically active when you run game servers with no configuration required. The feature provides gaming-optimized traffic shaping to mitigate common network and transport layer attacks such as UDP reflection and SYN floods. It complements AWS Shield Standard and integrates with the Player Gateway relay option for higher-risk games.
read more →