< ciso
brief />
Vendor and Hyperscaler Watch Banner

All news in category “Vendor and Hyperscaler Watch

5221 articles · page 6 of 262

Amazon Quick adds Microsoft Purview DLP integration

🔒 Amazon Quick now integrates with Microsoft Purview to enforce data loss prevention (DLP) policies across Quick environments. Administrators can apply existing Purview sensitivity labels to control file handling in Quick features such as chat, spaces, and knowledge bases. Enforcement actions—block, warn, or allow—are configurable per label to provide granular control over sensitive file sharing. The integration is available in all AWS Regions that support Amazon Quick agentic capabilities.
read more →

Amazon Quick adds approval policies for asset sharing

🔒 Amazon Quick introduces approval policies that give administrators governance over how assets are shared within an organization. Administrators can require designated approvers to review and approve share requests before access is granted, ensuring sharing of sensitive assets is deliberate, compliant, and auditable. Policies can be scoped to asset types like knowledge bases, spaces, and custom chat agents, and events are recorded in AWS CloudTrail for auditability.
read more →

Amazon Quick adds deny-by-default for permissions

🛡️ Amazon Quick custom permissions now support a deny-by-default governance setting that blocks new AI capabilities until administrators explicitly allow them. Administrators can restrict an AI capability category within a custom permissions profile and assign that profile to users, roles, or an account, causing Quick to deny any newly released capabilities in that category for those subjects. The restriction also affects existing capabilities in the category and can be configured in Manage account or via the AWS CLI. This feature is available in all Regions where Amazon Quick is offered.
read more →

Practical IAM Compliance: Requirements and Best Practices

🔐 This guide defines IAM compliance as proving that identity and access controls are not only documented but enforced across users, applications, infrastructure, and non-human identities. It explains key obligations from frameworks like SOX, PCI DSS, HIPAA, ISO/IEC 27001, NIST SP 800-53, and GDPR, and highlights evidence gaps between policy intent and runtime execution. The article outlines core controls—least privilege, segregation of duties, MFA, lifecycle management—and urges continuous, application-layer verification rather than periodic reviews.
read more →

Amazon RDS for Oracle Adds APEX 26.1 Support

🔔 Amazon RDS for Oracle now supports Oracle Application Express (APEX) 26.1, a low-code platform for building secure, scalable enterprise applications. This managed database service simplifies setup, operation, and scaling of Oracle Database deployments in the cloud. APEX 26.1 is available in all AWS regions where RDS for Oracle is offered; consult the RDS documentation for details on enabling or modifying APEX options.
read more →

Amazon Quick adds customizable no-data messages

📣 Amazon Quick now lets report authors replace the default "No data to display" text with a tailored message when a visual returns no data. Authors can configure a custom title, subtitle, and hyperlink, and toggle title/subtitle independently. All text fields support parameters so messages can reflect current filters; hyperlinks accept http://, https://, and mailto: schemas. The feature is available now in all AWS Regions offering Amazon Quick.
read more →

Cloudflare One updates for MCP security

🔒 Cloudflare announces new Cloudflare One capabilities to detect and control Model Context Protocol (MCP) traffic. These features let administrators identify which users and servers are generating MCP requests, distinguish Portal-mediated connections from direct ones, and block unauthorized direct connections on managed network paths. The update combines Gateway protocol signals with MCP Server Portals to help teams find shadow MCP servers and enforce Portal-only access to trusted MCP endpoints.
read more →

Oracle launches Database Security Central free trial

🔒 Oracle has introduced Database Security Central, a tool that provides a centralized view of security risk across database environments and will be free through February 2027. It arrives as attackers increasingly target Oracle database flaws and following Oracle’s move to monthly patch releases. The tool assesses posture, detects configuration drift, highlights privileged access risks, monitors sensitive data access, and centralizes policy management and audit evidence collection.
read more →

Protect Workers with Cloudflare Access by Default

🔐 Cloudflare now lets you apply Access directly to a Worker or to all Workers in an account so applications are protected by your company login by default. When enabled, Access enforces authentication before any request reaches Worker code, regardless of domain, route, or preview URL. Policies can be set per hostname, per Worker, or account-wide, with the most specific policy taking priority. Developers can also access authenticated user details through ctx.access.getIdentity() for personalization and logging.
read more →

How CSOs Turn Cybersecurity into Growth Strategy

🔒 Cybersecurity leaders must shift from proving relevance to demonstrating how security enables innovation and growth. CSOs should embed security into business roadmaps, partner early with operational teams, and translate cyber risk into business impact. Emphasizing resilience, user-centered controls, and seamless protections helps security become a catalyst for transformation rather than an obstacle.
read more →

Amazon SES adds custom URL deep linking support

📣 Amazon Simple Email Service (SES) now supports mobile app deep linking via a new ses:custom-path HTML attribute. When added to an <a> tag, SES preserves the path segment in its tracking URL so iOS Universal Links and Android App Links can route users to the app while keeping engagement tracking enabled. The capability is available in all AWS Regions that offer SES and requires a custom redirect domain with an AASA or Digital Asset Links verification file hosted on that domain. Follow the SES Developer Guide sections on custom domains and email metrics for configuration details.
read more →

AWS introduces managed billing and cost dashboards

📊 AWS Billing and Cost Management now provides Managed Dashboards: a set of five preconfigured, read-only dashboards that populate with your account data automatically. They include Cost Overview & Trends, Compute and Database breakdowns, and Reservations and Savings Plans performance views. Dashboards are maintained by AWS, can be duplicated for editing, and support widget export via PDF or CSV.
read more →

AWS to End Email Validation for ACM Certificates

🛡️ AWS Certificate Manager (ACM) will discontinue support for email-validated public certificates by September 30, 2027, aligning with the CA/B Forum’s March 15, 2028 deprecation of email-based domain validation. Customers must migrate to DNS validation; ACM is updating the UpdateCertificateOptions API to allow in-place switching from email to DNS without changing certificate ARNs. ACM provides a CNAME record for DNS validation and offers a 72-hour window to add it; once validated, ACM will handle automatic renewals. AWS provides console and AWS CLI steps, a migration user guide, and support resources to assist customers through the transition.
read more →

AWS Client VPN adds CLI and enterprise controls

🛠️ The rebuilt AWS VPN Client v6.0.x now includes a fully featured command-line interface (CLI), enterprise administrative controls, and faster connection establishment, enabling automation and centralized device management. The CLI matches GUI functionality and supports background operations so VPN connections can be scripted into workflows and infrastructure-as-code. Administration controls let organizations scope and enforce profiles per user or provide global device profiles, removing the need to distribute profiles manually. Built on OpenVPN3, the client preserves backward compatibility with existing AWS Client VPN endpoints and runs concurrently with the GUI; it is available today for Windows, macOS, and Linux with no additional charges beyond standard AWS Client VPN pricing.
read more →

Amazon Redshift adds new RG instance sizes in GovCloud

🔔 Amazon Redshift now supports rg.large and rg.12xlarge RG instances in AWS GovCloud (US-West) and GovCloud (US-East). These RG instances run data warehouse and data lake workloads up to 2.4x faster than previous RA3 instances and offer about 30% lower price per vCPU. New sizes require patch version P202 or later and existing clusters can be resized or upgraded via Elastic Resize, Classic Resize, or Snapshot & Restore. Multiple pricing options are available including On-Demand and 1- and 3-year Reserved Instances.
read more →

Claude Opus 5 Now Available in AWS GovCloud

🛡️ AWS GovCloud (US) now supports Claude Opus 5, the latest Opus model, with zero data retention (ZDR) enabled by default. The model is accessible via the bedrock-runtime endpoint in both GovCloud regions and via bedrock-mantle in GovCloud (US‑West). Claude Opus 5 improves coding, long-running agents, and complex document reasoning while maintaining regional data residency.
read more →

Amazon Quick Microsoft 365 Extensions Now Generally Available

🔔 Amazon Quick has made Microsoft 365 extensions for Excel, PowerPoint, Word, and Outlook generally available. These extensions let Quick operate directly inside users' M365 environments to handle complex local tasks, including document redlining, financial model building, presentation creation, and inbox management. Each extension is tailored: Excel for data analysis and cleaning, PowerPoint for template-driven decks, Word for formatted drafting and track changes, and Outlook for prioritizing, organizing, and drafting emails. The extensions are available in multiple AWS regions globally.
read more →

AWS Adds Local Zones to Spot Placement Score

🔍 AWS now includes Local Zones in Spot placement score, enabling customers to identify where Spot capacity requests are most likely to succeed. The feature evaluates target capacity and compute requirements and returns scores for Regions or Availability Zones. Previously, Local Zone capacity was excluded from zonal and regional scores; inclusion is now optional and expands Spot capacity visibility. Spot placement score is available via the EC2 Spot Console, AWS CLI, and SDK.
read more →

BigQuery Graphs with Measures for Agentic Workloads

🧭 BigQuery Graph introduces measures to unify governed metrics with relationship mapping, enabling agents to reason across complex, multi-hop dependencies without ETL. By mapping tables to an in-place property graph and defining MEASURE in the Property Graph DDL, BigQuery resolves graph paths before computing aggregations using GRAPH_EXPAND and AGG. The release includes a visual graph modeler in BigQuery Studio and native Looker integration to keep business metrics at the data layer.
read more →

OpenAI Daybreak models now on Amazon Bedrock

🔒 Security teams can now access Daybreak Red and Daybreak Blue from OpenAI on Amazon Bedrock. Daybreak Blue supports common defensive workflows like vulnerability discovery, detection engineering, and incident response, while Daybreak Red targets advanced, authorized tasks such as vulnerability research and exploit reproduction with stronger identity verification and monitoring. Both models run on Bedrock's next-generation inference engine with zero-operator access and do not use inference data for model training.
read more →