< ciso
brief />
Vendor and Hyperscaler Watch Banner

All news in category “Vendor and Hyperscaler Watch”

5908 articles · page 4 of 296

Cloudflare Traces: Expanded Open Beta Tracing

🛰️ Cloudflare Traces enters open beta, extending automatic distributed tracing beyond Workers to cover the entire request path. The feature records supported security rules, transformations, caching, routing, Worker execution, and origin interactions as OpenTelemetry spans, which can be exported via OTLP to compatible backends. Tracing is enabled per domain with baseline sampling and flexible Trace Rules to capture targeted, full-trace investigations without instrumenting code.
read more →

Cloudflare expands enterprise features to all users

📣 Cloudflare announced that many features previously restricted to Enterprise customers are now available to Free, Pro, and Business users. The company is making advanced capabilities like Logpush, Transformers, Custom Dashboards, and expanded RBAC broadly accessible with pay-as-you-go or free tiers where possible. They also introduced self-serve multi-account creation, Organizations for unified management, resource tagging, and improved Terraform support.
read more →

Why CISOs Struggle to Answer Boards on Risk

🔒 Boards routinely ask three simple questions—How secure are we, what is our financial exposure, and are we improving? Traditional reports focus on activity counts from discrete tools (vulnerabilities, patches, alerts) and lack cross-tool context. The gaps between identity, cloud, SaaS, endpoint and vulnerability data hide real attack paths. A board-ready approach maps crown jewels, correlates signals into attack paths, prioritizes by blast radius and translates exposure into financial terms to show trend and risk reduction.
read more →

Android 17 locks Accessibility API under Advanced Protection

🔒 Google announced that Android 17 will restrict access to the AccessibilityService API to verified apps labeled as Accessibility Tools when Advanced Protection is enabled. The change aims to close a frequent attack vector abused by banking trojans and spyware while preserving assistive capabilities. Android 17 also introduces features like Intrusion Logging, USB Protection, Disabled WebGPU, Failed Authentication Lock, and visibility into apps checking Advanced Protection status.
read more →

AWS MCP Server expands to six additional regions

🚀 The AWS MCP Server, part of the Agent Toolkit for AWS, is now available in six additional Regions: Asia Pacific (Singapore), Asia Pacific (Sydney), Asia Pacific (Tokyo), Europe (Ireland), Europe (London), and US West (Oregon). The managed Model Context Protocol server provides a single interface for AI coding agents to discover and call AWS services without per-service integrations. Running the server closer to developers reduces latency and helps meet regional data residency requirements. It can access services across all commercial AWS Regions while operating in the listed Regions.
read more →

AgentCore Gateway adds private TLS for VPC endpoints

🔒 Amazon Bedrock AgentCore Gateway now accepts TLS certificates signed by private certificate authorities for MCP, OpenAPI, and HTTP proxy targets, enabling secure native connections to private endpoints in your VPC without an intermediate Application Load Balancer. You can register PEM-encoded CA certificates stored in Amazon S3 or AWS Secrets Manager, which the gateway uses as a trust anchor for outbound TLS. This support is available in all Regions where AgentCore Gateway and Amazon VPC Lattice are offered. See the AgentCore Developer Guide for details.
read more →

GKE CPU Startup Boost for Faster Pod Starts

🚀 GKE introduces CPU startup boost in preview, integrated into the Vertical Pod Autoscaler (VPA), to temporarily elevate CPU allocation during container initialization and then in-place scale it back to steady-state levels without restarting containers. The feature leverages Kubernetes In-place Pod Resize (IPPR) and operates across admission, startup, and unboosting phases. It targets CPU-intensive startup workloads—such as Java JVMs, Node.js, and Python/AI microservices—so teams can avoid overprovisioning while reducing cold starts and costs. Available on GKE 1.36.0-gke.4447000+ for Standard and Autopilot clusters.
read more →

Two-Tier AI Agent Memory with AlloyDB and Memorystore

🧠 This article outlines a two-tier memory architecture for enterprise AI agents that pairs Memorystore for Valkey as a short-term session buffer with AlloyDB AI for long-term persistent memory. It explains how the design reduces token consumption, improves latency, and preserves transactional integrity while supporting hybrid retrieval, in-database embeddings, and generative functions. The post includes benchmark results showing significant token and latency savings and summarizes implementation patterns and SQL functions used to build the system.
read more →

ElastiCache Valkey: OpenTelemetry Metrics and Monitoring

📈 Amazon ElastiCache for Valkey now exports OpenTelemetry metrics to Amazon CloudWatch for node-based clusters, with each metric carrying attributes usable in PromQL expressions. Two monitoring modes are available: Standard monitoring (60s) which now includes a core OpenTelemetry set, and Detailed monitoring (15s) which exposes the full metric set for finer diagnostics. Detailed monitoring supports detection of short-lived events and feeds ElastiCache Insights dashboards; CloudWatch OpenTelemetry pricing applies.
read more →

Spanner Queues Bring Native Transactional Messaging

🚀 Spanner queues are now generally available, embedding native transactional messaging directly within Spanner to support reliable agentic execution. Creating a message is a single write within the same ACID transaction that updates an agent's state, enabling atomic decide-and-act semantics, scheduled deliveries, streaming SQL pulls, and exactly-once processing guarantees. The feature simplifies multi-agent orchestration, timeouts, human approvals, and observability using standard GoogleSQL.
read more →

AWS Security Hub Adds GuardDuty Runtime Monitoring

🔔 AWS has integrated Amazon GuardDuty Runtime Monitoring into the AWS Security Hub Threat Analytics plan. This runtime capability inspects OS, network, and file activity to detect threats like container escapes, privilege escalation, and cryptomining across Amazon EC2, Amazon EKS, and Amazon ECS on AWS Fargate. Billing for Runtime Monitoring is now consolidated under Security Hub as a single usage type, eliminating separate GuardDuty Runtime Monitoring charges for accounts and regions with Security Hub enabled. Detection behavior, finding types, and GuardDuty agents remain unchanged, and no reconfiguration is required; free-trial terms for Threat Analytics and Security Hub Essentials remain separate.
read more →

AWS debuts Well‑Architected Agent preview

🔍 AWS announced a preview of the AWS Well‑Architected Agent, an AI‑driven evolution of Trusted Advisor and the Well‑Architected Tool. The agent analyzes AWS infrastructure across cost, security, performance, and reliability to produce contextualized, prioritized recommendations aligned to business goals. It correlates metrics, application topology, and IaC templates (Terraform, CDK, CloudFormation) and can deliver automation‑ready fixes such as SSM runbooks and CLI scripts.
read more →

Redshift Cross‑Region S3 Data Lake Query Support

🚀 Amazon Redshift now lets customers query Amazon S3 data lake tables in a different AWS Region while keeping query traffic within their VPC using enhanced VPC routing. The integrated data lake query engine runs on RG provisioned and Serverless cluster compute, avoiding public networks and supporting compliance needs. Cross‑Region queries remove the need to copy or replicate data, simplify global analytics, and incur standard data transfer charges.
read more →

Amazon Q Developer adds richer console visualizations

🛠️ Amazon Q Developer in the AWS Management Console now provides enhanced visualizations that reason across hundreds of AWS APIs to deliver comprehensive answers about an account. The update adds health dashboards with status indicators, interactive time-series charts with trend and anomaly detection, troubleshooting diagnostics, and detailed resource views. Responses are faster and more actionable, replacing multi-step text replies with immediate visual summaries. The features are available in all Regions where Amazon Q Developer is supported.
read more →

Amazon DynamoDB adds filtered export to S3

🔍 Amazon DynamoDB now supports filtered export to Amazon S3, letting you export only the items and attributes you specify. Using a key condition expression, filter expression, and projection expression, you can produce datasets tailored for granular recovery, cross-account transfers, analytics, or compliance. Filtered export works with both full and incremental exports and is available in all AWS Regions except AWS GovCloud (US). See the DynamoDB developer guide to get started.
read more →

Why scanners alone can’t secure modern infrastructure

🔍 Kaspersky’s analysis shows a sharp rise in detected vulnerabilities and a shrinking window between disclosure and exploitation, fueled in part by AI. Relying solely on periodic scanners creates gaps: findings pile up, prioritization is often manual and inconsistent, patches are delayed or incompletely applied, and assets can remain untracked. The article advocates four core processes—asset inventory, contextualized vulnerability analysis, risk-based prioritization, configuration hygiene, and post-patch verification—and highlights the Kaspersky Vulnerability Management module as a solution to centralize and operationalize these steps.
read more →

DynamoDB Accelerator (DAX) expands to 17 regions

🚀 AWS has announced that Amazon DynamoDB Accelerator (DAX) is now available in 17 additional Regions, including new Asia Pacific, Canadian, European, Israel, Mexico, and AWS GovCloud locations. DAX is a fully managed, in-memory cache for DynamoDB that delivers up to 10x performance improvements—lowering latencies from milliseconds to microseconds—while supporting millions of requests per second. The expansion helps customers meet local data residency and low-latency requirements and simplifies cache management with automated patching, failover, and scaling.
read more →

GuardDuty organization enablement policies now available

🔒 Amazon GuardDuty now supports AWS Organizations declarative policies to centrally enable threat detection across all accounts and Regions. Using a centrally managed organization policy, you can apply a consistent GuardDuty enablement configuration that automatically extends to existing accounts and to new accounts as they join. The policy allows a default baseline across all Regions where GuardDuty is available, with optional per-Region overrides, and prevents overrides through the GuardDuty console or API. This feature is available in all AWS commercial Regions and AWS GovCloud (US) Regions.
read more →

PayPal modernizes analytics with managed Apache Spark

🔍 PayPal migrated its legacy, on-premise Hadoop analytics platform to Google’s Managed Service for Apache Spark to streamline operations and accelerate insights. The move delivered rapid provisioning, elastic scaling, and native integration with Google Cloud Storage and BigQuery, reducing operational overhead and data silos. Results included 25% faster processing, 30% better SLA adherence, lower costs, and more engineering time for innovation.
read more →

End-to-End Checksums Now Default in Cloud Storage SDKs

🔒 Google Cloud now enables end-to-end checksumming by default across all Cloud Storage SDKs to strengthen data integrity. The SDKs compute and pass checksums during uploads if the application does not, and verify checksums on downloads and range reads via gRPC. Cloud Storage maintains checksums at multiple internal layers—chunks, shards, blocks—ensuring a continuous chain-of-custody from application to disk. Users are advised to update to the latest SDK versions to benefit from these protections.
read more →