< ciso
brief />
Vendor and Hyperscaler Watch Banner

All news in category “Vendor and Hyperscaler Watch”

5924 articles · page 45 of 297

A decade of AWS Managed Microsoft AD evolution

🔒 Over ten years, AWS Managed Microsoft AD evolved from a basic managed Microsoft Active Directory offering into a foundational enterprise identity service integrated across more than 20 AWS services. The service reduced operational overhead by handling domain controllers, HA, backups, patching, and replication while adding features like schema extensions, gMSA, multi-Region replication, and CRUD APIs. Recent additions include Hybrid Edition, self-service edition upgrades, and integrations for database, file, and remote-access authentication.
read more →

Timestream for InfluxDB adds backup and restore

🔒 Amazon Timestream for InfluxDB now supports customer-driven backups and restores for InfluxDB 2 and 3 engines. You can trigger one-time on-demand backups, schedule up to four recurring backup configurations per resource with custom frequency and retention, and restore either to a new resource or overwrite an existing one via the Console, CLI, or API. The first backup is full and subsequent backups are incremental, and KMS-managed keys are preserved for encrypted resources.
read more →

Amazon Cognito added to Agent Toolkit skills

🔧 The Amazon Cognito (aws-auth) skill is now included in the Agent Toolkit for AWS, enabling AI coding agents to set up, configure, secure, and troubleshoot Amazon Cognito using best-practice workflows. The skill supports user pools, app clients, OAuth 2.0 flows, token and JWT authorizer management, passkey/WebAuthn enrollment, threat protection, Lambda triggers, and identity pools. When used with the AWS MCP Server, commands run with IAM guardrails and CloudTrail audit logging; it also works standalone via the AWS CLI.
read more →

BigQuery DTS expands integrations and features

🚀 BigQuery Data Transfer Service (DTS) reduces engineering overhead by automating zero-code data ingestion into BigQuery, enabling teams to shift focus from pipeline maintenance to analytics. Recent additions include Open Lakehouse ingestion to Apache Iceberg, a managed Model Context Protocol (MCP) Server, expanded database connectors (PostgreSQL, MySQL, SQL Server), SaaS connectors (Shopify, Klaviyo, HubSpot, Mailchimp), and a Snowflake migration path. DTS emphasizes free ingestion for many first-party sources, low consumption-based pricing for third-party SaaS, integrated Cloud IAM security, and a 99.99% SLA for resilient data pipelines.
read more →

Securing Amazon S3: Identify and Remediate Over‑Permissions

🔒 This post explains how to detect and remediate over‑permissioned Amazon S3 buckets across single‑ or multi‑account AWS environments. It outlines a five‑phase workflow—setup, detection, remediation, continuous monitoring, and cleanup—while recommending AWS Config, Security Hub, EventBridge, IAM Access Analyzer, and Lambda‑based scanning scripts. The guidance focuses on methodology and customization for security engineers, cloud architects, and DevOps teams.
read more →

Prisma AIRS Integrates with OpenAI Codex

🔒 Palo Alto Networks announces native integration of Prisma AIRS Runtime API with OpenAI Codex, enabling centralized, API-level security controls for developer workflows. The integration inspects developer inputs and prevents sensitive data leakage without requiring client-side hooks, preserving developer productivity in Codex. SecOps benefit from consistent policy enforcement, audit-ready logging, and organization-wide visibility through the Codex Enterprise Management UI.
read more →

One-click multi-Region option for IAM Identity Center

🔒 AWS IAM Identity Center now offers a one-click multi-Region option when creating a new organization instance, simplifying what previously required multiple manual steps. The multi-Region instance choice automatically creates a customer managed multi-Region KMS key and replicates the instance to an additional Region to provide resilient access. Customers can also choose single-Region or custom instances, with custom allowing use of existing customer managed KMS keys and fine-grained Region configuration.
read more →

How Google Cloud detects and contains emerging threats

🔒 Google Cloud outlines its proactive, shared-fate approach to detect and contain emerging threats across AI workloads, cryptomining, credential exposure, supply chain attacks, and account takeover. The post describes detection signals, tailored containment actions like granular throttling and localized identity isolation, and escalation paths including targeted suspensions. It highlights integrations such as GitHub Secret Scanning and details observability tools like Cloud Abuse Event Logging, Cloud Audit Logging, and billing alerts.
read more →

VPC IPAM adds BGP route protection and delegated RPKI

🛡️ Amazon VPC IPAM now supports BGP route protection monitoring and delegated RPKI management for BYOIP prefixes, enabling centralized monitoring of RPKI validity, ROA strength, and route overlap across accounts and regions. Administrators can detect invalid or missing ROAs, identify potential hijacks via overlap detection, and differentiate strict versus permissive ROA configurations. With Delegated RPKI, after a one-time setup with ARIN, RIPE, APNIC, or LACNIC, IPAM automates ROA creation, renewal, and management for both BYOIP and on-premises prefixes. The capability is available in all commercial AWS Regions except AWS GovCloud (US) and the China regions.
read more →

AgentCore adds memory, policy and harness in GovCloud

🛡️ Amazon Bedrock AgentCore is now available in AWS GovCloud (US-West), enabling regulated organizations to build context-aware agents with controls for production scale. AgentCore memory provides short-term conversational context and long-term persistent insights without complex infrastructure. Policy features let teams author natural-language policies that convert to Cedar and enforce tool access at an AgentCore gateway. The managed harness simplifies deployment by declaring models, tools, and instructions via configuration and running agents with a few API calls.
read more →

Assessing Good and Bad Agentic Behaviors Online

🔍 Cloudflare outlines how the line between human and automated traffic is blurring and why site owners must evaluate continuous behaviors rather than one-time checks. The post explains the team’s Risk vs. Trust framework, introduces tools like Precursor for continuous client-side behavioral analysis and the BotBase directory for tracking bot reputations, and previews Adaptive Intelligence and advanced mitigations for managing agentic traffic responsibly.
read more →

Top Exposure Management Questions Security Leaders Ask

🔎 This article answers common questions security leaders ask when evaluating Check Point Exposure Management, covering asset discovery, cloud coverage, supplier monitoring, dark web intelligence, leaked credentials, IOC feeds, and integrations. It explains how EASM and CAASM discover external and internal assets, how findings are enriched with vulnerabilities and controls, and how unified visibility supports prioritization and remediation. The piece emphasizes integrations and operational workflows that accelerate response and reduce organizational risk.
read more →

Cloudflare Radar Researcher beta launches

🛰️ Cloudflare launches Radar Researcher in beta, an AI-powered assistant that lets users query Radar’s open Internet datasets in plain language and receive interactive charts. The tool combines screenshots, raw API data, and view parameters to generate precise explanations and visualizations. Built on Cloudflare Workers, Agents SDK, and Workers AI, Researcher runs models with fallbacks, exposes tool traces, and uses Code Mode to query the Radar API dynamically.
read more →

Cloudflare refreshes community and open-source support

🛠️ Cloudflare announced a refreshed community program with two main tracks: Cloudflare Ambassadors and Community Engineers. Ambassadors will receive resources, visibility, and support to run events, teach, and grow local communities, with applications open through September 6. Community Engineers will receive grant funding to support open-source maintainers, backed by a $1M commitment and an additional $1M for Vite-related work. The update also creates a Discord committee to improve community collaboration and reduce moderation burden with new automation.
read more →

Cloudflare unifies Workers AI and AI Gateway

🛠️ Cloudflare is consolidating AI Gateway and Workers AI into a single unified control plane and entrypoint. The unified path provides a shared binding and a single /ai/ REST API endpoint, enabling automatic creation of a default gateway for immediate observability, logging, token tracking, and cost attribution. Users can route to any provider or Workers AI with unified billing and optional elevated rate limits when using AI Gateway credits.
read more →

Open Source Growing Up: Enterprise Trust and Risk

🔍 Open Source's informal era is ending as enterprises and regulators demand accountability, continuity, and demonstrable maintenance. The community will split: projects that adopt enterprise-grade practices—reachable maintainers, disclosure paths, and continuous proof-of-life—and projects that remain community-driven without those guarantees. Vendors and foundations will increasingly provide contracts, long-term support, and retirement pathways to bridge gaps while the free, volunteer-led ecosystem continues alongside.
read more →

GameLift adds 21 EC2 instance types support

⚙️ Amazon GameLift Servers now supports 21 additional EC2 instance types for managed EC2 and container fleets. The expansion covers compute-optimized C-series (C8a, C8i, C9g) and general-purpose M-series (M8a, M8i, M9g), offering x86 and Arm architectures. Customers can choose processors including 5th-gen AMD EPYC, custom Intel Xeon 6, or AWS Graviton5 to balance performance, cost, and engine compatibility.
read more →

CloudWatch adds wall clock alarm evaluation windows

🕒 Amazon CloudWatch now supports wall clock evaluation windows for metric alarms, letting customers align evaluations to fixed calendar boundaries such as the top of the hour, midnight, or start of the week. This complements existing sliding window behavior and helps reduce false alerts for scheduled or business-aligned workloads. Time zone support and automatic handling of daylight saving transitions are included, and the feature is available in all Regions except UAE and Bahrain.
read more →

Amazon OpenSearch Service extends upgrade runway

🔔 Amazon OpenSearch Service is extending security and OS patch coverage for several legacy Elasticsearch and OpenSearch engine versions through November 7, 2027, with an updated Extended Support surcharge schedule. Coverage includes Elasticsearch 1.5–7.8 (excluding 5.6 which remains covered through 2028), OpenSearch 1.0–1.2, and OpenSearch 2.3–2.9; domains on these versions will remain operational. New Standard and Extended Support windows and pricing for additional versions (Elasticsearch 6.8, 7.9, 7.10; OpenSearch 1.3, 2.11–2.19) are announced, with an Extended Support charge of $0.0065 per NIH in US East (N. Virginia). AWS recommends upgrading to the latest OpenSearch release for performance and security improvements.
read more →

AWS PCS expands security and compliance coverage

🔒 AWS Parallel Computing Service (PCS) has broadened its compliance posture to support regulated workloads. PCS is now in scope for FedRAMP Class C in US East (Ohio), US East (N. Virginia), and US West (Oregon), and FedRAMP Class D in AWS GovCloud (US). PCS is included in SOC 1/2/3 reports, ISO certifications, CSA STAR (CCM 4.0), PCI attestations, and is HIPAA eligible, enabling sensitive HPC workloads on AWS.
read more →