< ciso
brief />
Vendor and Hyperscaler Watch Banner

All news in category “Vendor and Hyperscaler Watch”

5924 articles · page 56 of 297

Enterprise resilience and toolchain security insights

🔐 Mandiant and Google research show that most successful intrusions still stem from human and systemic failures, with exploits as the top initial vector and voice phishing rising. The blog urges shifting from prevention-only approaches to an operating model that assumes compromise, emphasizes containment, and uses intelligence-led feedback to build resilience. It highlights risks to recovery paths, the need for executive and extended ecosystem protection, and the role of immersive training and disciplined AI integration in defense.
read more →

Microsoft Databases: Reliability and AI Readiness

🟦 Customer feedback and PeerSpot recognitions highlight five priorities for Microsoft Databases: reliability, scalability, operational simplicity, developer productivity, and AI readiness. Reviews from SQL Server, Azure SQL Database, Azure Cosmos DB, and Azure Database for PostgreSQL users emphasize uptime, ease of migration, performance, and integration with Azure services. These insights guide Microsoft’s investments to help customers modernize and build AI-powered applications while maintaining security and governance.
read more →

NOAA and Google Cloud Modernize Weather Supercomputing

🌤️ NOAA has selected Google Cloud as the primary provider of high-performance computing for the Weather and Climate Operational Supercomputing System (WCOSS). This move marks a shift toward cloud-first infrastructure, using H4D VMs powered by fifth-generation AMD EPYC™ processors to support compute-intensive numerical weather prediction. The collaboration builds on years of joint projects in data sharing, wildfire tracking, and advanced modeling, aiming to improve forecast accuracy and public safety.
read more →

The branding and attribution behind cybercrime

🔍 Threat actor names like LockBit or Fancy Bear often suggest a single, clear identity, but naming is more complex. Some names are chosen by attackers as public brands; others are labels assigned by researchers, vendors, or databases to track activity clusters. Confusing branding with attribution risks overstating certainty, missing links between aliases, or focusing on names rather than observed behavior. Exposure management helps translate those insights into prioritized action.
read more →

Cloudflare open sources a privacy proxy CLI

🔒 Cloudflare has open sourced pvcli, a command-line tool designed to simplify debugging and testing of privacy-preserving protocols such as Oblivious HTTP (OHTTP). The tool automates binary HTTP encoding, key parsing, encryption steps, and protocol flows across relay, gateway, and origin, replacing fragile, script-heavy workflows. Released under the Apache-2.0 License, pvcli supports curl-like arguments, detailed logs, headers forwarding, and mTLS, and will expand to include MASQUE and other privacy protocols.
read more →

Open Secure AI Alliance launches without OpenAI

🔒 The Open Secure AI Alliance, spearheaded by Nvidia and backed by more than 30 major AI vendors and users, aims to promote open-source defensive AI tools after an incident revealed limitations of closed commercial models. Hugging Face’s forensic work was blocked by safety guardrails on hosted models, forcing it to use an open-weight model on its own infrastructure. The alliance emphasizes that open models and harnesses democratize defense, increase transparency, and allow localized control. OpenAI has not commented on whether it will join the initiative.
read more →

Cognyte Sells Mobile Cell Surveillance Van

🚨Made by Israeli surveillance company Cognyte, the device simulates a mobile phone tower, forcing nearby phones to connect and allowing law enforcement to monitor all devices in the area. The system, called FalcoNet, can be hidden inside vehicles, carried in a backpack for foot operations, or mounted on helicopters. Cognyte’s contract with Texas reveals its deployment options and links the technology to earlier cell-site simulators like the Stingray made by L3Harris.
read more →

GitHub adds three-day Dependabot cooldown default

🔒 GitHub introduced a three-day cooldown in Dependabot that delays version-update pull requests for at least 72 hours after a release by default, while security updates continue to be issued immediately. The cooldown is configurable via dependabot.yml, letting teams set a different interval to suit their workflows. GitHub framed the change as a mitigation against short-lived poisoned package releases that spread quickly before removal, and recommended it be used alongside other defenses such as lockfiles and scoped tokens.
read more →

CISOs Rising to Lead Business Resilience

🔒 CISOs are increasingly acting as de facto chief resilience officers, expanding from prevention to incident response and recovery. Experts recommend framing resilience in business terms — uptime, data protection, and financial impact — to secure board-level buy-in and funding. Practical steps include defining minimum viable operations, rehearsing recovery through a "ResOps" approach, and partnering with GRC, finance, and operations to share responsibility.
read more →

RDS for SQL Server Adds TDE Restore to Multi‑AZ

🔒 Amazon RDS for SQL Server now supports restoring Transparent Data Encryption (TDE)-enabled databases to Multi-AZ instances and instances with a same-region read replica using native backup and restore. Previously, TDE restore was limited to Single-AZ, requiring disabling TDE or migrating to Single-AZ before restore. Back up your TDE certificate to Amazon S3, restore it to the RDS instance with the TDE option enabled, then restore the database backup from S3. This capability is available in all Regions where RDS for SQL Server is supported.
read more →

GitHub and PyPI add time-based supply chain controls

🛡️ GitHub and PyPI have implemented time-based defenses to reduce supply chain attack risk. GitHub’s Dependabot now defaults to a 72-hour cooldown before applying package updates, while PyPI blocks adding new files to releases older than 14 days. These measures aim to limit the impact of token or workflow compromises and complement other best practices such as lockfiles and restricted tokens.
read more →

OpenAI confirms ChatGPT outage affecting users globally

🔴 OpenAI has confirmed a widespread ChatGPT outage that began around 5 AM ET, preventing users worldwide from loading chats or accessing previous conversations. Affected users report the interface getting stuck on loading animations and an inability to interact with the AI. OpenAI acknowledged the issue on its status page and stated it is investigating. The situation is ongoing and being monitored.
read more →

Amazon Connect adds audio optimization for Azure VDI

🎧 Agents using Azure Virtual Desktop (AVD) or Windows 365 Cloud PC can now take Amazon Connect calls directly from their virtual desktop with audio optimization enabled. IT administrators perform a one-time setup to redirect media from the virtual desktop to the agent's local device, improving call audio quality. Agents access calls via the Amazon Connect Customer agent workspace or custom interfaces built with the Amazon Connect Customer open-source JavaScript libraries. This capability complements existing support for Amazon WorkSpaces, Citrix, and Omnissa cloud desktops and is available in all AWS Regions offering Amazon Connect Customer except AWS GovCloud (US-West).
read more →

Amazon MWAA adds support for Apache Airflow 2.11.2

🛠️ Amazon Managed Workflows for Apache Airflow (MWAA) now supports Apache Airflow 2.11.2, a maintenance release with security improvements, bug fixes, and dependency upgrades. The update enhances webserver stability, task execution, and task lifecycle handling, and improves secrets masking and UI behavior. You can create new 2.11.2 environments or upgrade existing ones in all available MWAA regions via the AWS Management Console.
read more →

AWS HealthLake adds FHIR resource matching

🔍 AWS HealthLake now offers automatic resource matching to identify and link duplicate FHIR records across seven resource types, enabling more accurate longitudinal patient records and population health datasets. The feature recognizes high-confidence identifiers (SSN, MRN, NPI), filters placeholders to reduce false matches, and connects matches via FHIR Linkage resources without modifying original records. Available in gated preview across multiple AWS Regions; interested customers can request allowlist access.
read more →

EC2 Dedicated Hosts add flexible Host Resource Groups

🛡️ Starting today, Amazon EC2 Dedicated Hosts support creating Host Resource Groups (HRGs) without requiring Self-Managed Licenses (SMLs). This change benefits customers who use Dedicated Hosts for hardware-level isolation or EC2 Mac Instances, while customers with BYOL needs can still opt to create HRGs with SMLs to restrict AMIs and track license consumption. To create an HRG without an SML, uncheck the "Restrict to AMIs associated with self-managed license" option in the EC2 Console or set instance-launch-option to license-configuration-required via the AWS CLI. The feature is available in all Regions that support Host Resource Groups.
read more →

Accelerating Network Firewall Troubleshooting with DevOps Agent

🛡️ This post shows how AWS DevOps Agent accelerates root-cause analysis for AWS Network Firewall issues by correlating CloudWatch alarms, firewall logs, route tables, and CloudTrail events. It walks through three reproducible failure scenarios—domain deny list, stateless rule priority inversion, and asymmetric cross-AZ routing—deployed via an AWS CDK app. The CDK stack includes a sample workload, test endpoint, status page, and a webhook pipeline so alarms trigger investigations and the agent returns mitigation plans for operator review.
read more →

Kinesis adds on-demand warm throughput scale-down

🔧 Amazon Kinesis Data Streams now lets you scale down on-demand warm throughput for streams running in On-demand Advantage mode. By setting a lower warm throughput value, streams adjust to the requested capacity or to the peak ingest usage from the last hour, whichever is higher, ensuring sufficient capacity while releasing unneeded throughput. The capability incurs no additional cost and is available in all Regions that support On-demand Advantage; documentation and pricing guidance are provided in the Developer Guide and console instructions.
read more →

AWS Lambda Managed Instances now publishes logs

📣 AWS Lambda now sends logs for Lambda Managed Instances (LMI) capacity providers to Amazon CloudWatch Logs, providing visibility into scaling activity and instance lifecycle operations. LMI lets you run Lambda functions on Amazon EC2 instances while keeping serverless operational simplicity. Capacity provider logs capture structured JSON lifecycle events like launches, terminations, and health checks to help monitor, troubleshoot, and optimize managed EC2 resources. Logs are enabled by default across supported AWS Commercial Regions and incur standard CloudWatch Logs charges.
read more →

Amazon SES simplifies SMTP setup with Mail Manager

📧 Amazon Simple Email Service (SES) now provides a guided console setup for sending email over SMTP using Mail Manager. The new workflow automatically creates and configures required resources and delivers a working SMTP endpoint with downloadable credentials. This lets developers plug SMTP credentials into any application or framework quickly, streamlining transactional and notification email workflows. The feature is available in all AWS Regions where SES is offered.
read more →