< ciso
brief />
Vendor and Hyperscaler Watch Banner

All news in category “Vendor and Hyperscaler Watch

5221 articles · page 7 of 262

ACM lets you switch validation from email to DNS

🔐 AWS Certificate Manager now allows changing domain validation on existing public TLS certificates from e-mail to DNS without reissuing or changing the ARN. ACM will phase out email validation through 2027 per CA/B Forum mandates; it will stop issuing email-validated certs on March 31, 2027 and stop renewing them on September 30, 2027. Use the console or UpdateCertificateOptions API to switch and add provided CNAME records within 72 hours.
read more →

Cloudflare reduces noise in CT monitoring alerts

🛡️ Certificate Transparency Monitoring, launched in public beta in 2019, now filters out certificates Cloudflare issues on customers' behalf before sending alerts. This change addresses noisy notifications caused by routine Universal SSL renewals and other Cloudflare-managed certificates. The service is generally available and will only notify customers about certificates issued outside Cloudflare's automated systems. Settings remain available in the Cloudflare dashboard.
read more →

AWS Clean Rooms adds minimum aggregation for custom queries

🔒 AWS Clean Rooms now supports minimum aggregation thresholds for the Custom analysis rule type, preventing queries from returning results about individuals or small groups. Data providers can enforce a minimum identity count (for example, user IDs) per output row and set higher thresholds for specific columns. The update removes the need for pre-approved templates and manual code reviews, allowing ad-hoc custom SQL while specifying which columns may be filtered or joined to protect privacy.
read more →

WhatsApp launches on-device scam alert beta

🔔 WhatsApp has started a limited beta for an optional Scam Alert that runs an on-device machine learning model to warn users of likely scam messages. The feature analyzes linguistic signals and conversational structure for messages from non-contacts, displaying a chat warning that suggests blocking, reporting, or continuing. No message content or the model leaves the device; users can mark chats as trusted or opt to share recent messages to improve accuracy. Scam Alert complements existing security updates aimed at preventing account takeover and spyware attacks.
read more →

Amazon Quick introduces approval policies for sharing

🔒 Administrators can now enforce approval policies in Amazon Quick to govern how assets are shared across their organization. Policies can be scoped to asset types such as knowledge bases, spaces, and custom chat agents, routing share requests to designated approver groups. Approvers can inspect assets (including full dependency packages for custom agents) and approve or deny requests, while all actions are logged to AWS CloudTrail for auditability. The capability is available on Professional and Enterprise plans in Regions that support Amazon Quick agentic features.
read more →

Amazon Quick adds per-user resource limits

🔒 Amazon Quick now lets administrators set per-user limits on index storage and agent hours to control subscription costs. With limits management, admins can create limit profiles that cap individual consumption and assign them at the user, role, or account level with a priority hierarchy. When a user reaches their limit, new consumption is blocked but existing content is preserved. The feature is available for Professional and Enterprise plans in supported AWS Regions.
read more →

AWS IAM Role Manager simplifies role provisioning

🔒 IAM Role Manager automates the creation and attachment of IAM roles as you build resources in supported AWS service consoles. When enabled, AWS provisions roles from managed templates or reuses suitable ones, letting you start services quickly while maintaining full visibility and control. Roles are ordinary IAM roles you can review, edit, or delete, and IAM Access Analyzer can later recommend least-privilege policies.
read more →

AWS Global View adds interactive map view

🗺️ AWS has added an interactive map view to AWS Global View in the AWS Management Console, enabling users to visualize AWS Regions and AWS Local Zones on a single map. Users can toggle between the new map view and the existing list view to see enabled locations and all available AWS locations at a glance. The feature is available in all public AWS Regions and can be accessed via the Regions and Zones page in the AWS Global View console.
read more →

Amazon EKS adds control plane configuration options

🔧 Amazon Elastic Kubernetes Service (Amazon EKS) now lets administrators configure control plane parameters for the scheduler, controller manager, and API server. This capability enables tuning of pod placement strategies, horizontal pod autoscaler responsiveness, and resource lifecycle settings such as event retention. Cluster operators can choose different scheduler fit strategies (for example, MostAllocated or LeastAllocated) to prioritize density or headroom. These control plane configuration options are available in any AWS Region where Amazon EKS is offered.
read more →

AWS IAM Role Manager Now Generally Available

🛡️ Today AWS announces the general availability of Role Manager, a capability in AWS Identity and Access Management (IAM) that automatically creates or reuses IAM roles required by supported AWS service consoles. Role Manager can be enabled or disabled at any time and exposes the AWS-managed templates it deploys. At launch it supports six service consoles, including AWS Lambda and Amazon EventBridge, and is available in all Regions except AWS GovCloud (US) and China Regions.
read more →

Amazon Connect adds agent-first callback self-assignment

🔔 Amazon Connect Customer now allows agents to view and self-assign queued agent-first callbacks alongside emails, tasks, and chats. This capability lets agents prioritize follow-ups or take ownership when they already have context, reducing handoffs and accelerating resolution. The feature is available in all AWS Regions where Amazon Connect Customer is offered, with guidance in the product documentation and Worklist app setup materials.
read more →

Deadline Cloud adds EBS persistent volume cost tracking

🗂️ AWS Deadline Cloud now reports costs for Amazon EBS persistent volumes in the Usage Explorer within the Deadline Cloud Monitor app. This feature tracks EBS volume costs from creation to deletion independent of jobs or sessions and surfaces them as a new persistent volume usage type in the Usage Explorer and statistics APIs. Costs are attributed to the owning fleet to allow aggregation by fleet, farm, or time period, helping customers identify idle volumes and adjust time-to-live settings. Cost tracking is enabled automatically across all AWS Regions where Deadline Cloud is available and introduces no additional charges.
read more →

Managing AI Spend with Agent Optimization

🧭 This post introduces a four-part series, The Economics of Agent Optimization, explaining how organizations can run AI as a managed investment system using Microsoft Foundry. It argues that cost discipline—not just model choice—determines whether pilots scale, and outlines the need for visibility, controls, and workflow optimization to manage token-driven spend. The piece positions Foundry and Microsoft Agent 365 as integrated solutions for cost attribution, runtime optimization, and continuous governance.
read more →

Amazon Nova Multimodal Embeddings Now in GovCloud

🔔 Amazon announced general availability of Amazon Nova Multimodal Embeddings in AWS GovCloud (US-West). The unified embedding model supports text, documents, images, video, and audio through a single model to enable cross-modal retrieval and agentic RAG. It accepts up to 8K tokens and video/audio segments up to 30 seconds, with synchronous and asynchronous API options for latency-sensitive and bulk workloads.
read more →

Unit 42 expands Frontier AI exposure analysis

🔍 Unit 42 is deploying advanced frontier AI cyber models in customer environments to find, validate, and help remediate meaningful attack paths. Through a partnership with OpenAI, Palo Alto Networks is integrating models like GPT-5.6 Daybreak into its Frontier AI Exposure Analysis to test exploitability, chain weaknesses, and prioritize fixes. Unit 42 combines model output with its offensive expertise and telemetry to validate findings and guide defenders.
read more →

Signal adds automatic key verification feature

🔐 Signal introduced Automatic Key Verification, a new feature within a key transparency system that uses Cloudflare and Trail of Bits as independent auditors to confirm the integrity of encrypted chats. The feature enables users to verify contacts’ public keys automatically via Settings > Privacy > Advanced or by selecting "Verify Automatically" on the safety number screen, showing a green checkmark when successful. Users may disable it and continue with manual safety number checks if they prefer. Signal says this complements existing safety numbers and helps prevent undetected key swaps and man-in-the-middle attacks.
read more →

Chrome reduces Android notification abuse by billions

🔔 Google reports that Chrome's anti-abuse systems blocked over 7 billion unwanted Android notifications per day in Q1 2026. The company says notification abuse has become a vector for scams, malware, phishing, and fraudulent payment requests, prompting a layered "Swiss cheese" defense model. Chrome now auto-revokes notification permissions from inactive or repeatedly abusive sites and allows users to review and restore access via Safety Hub. The browser also limits message rates for disruptive sites and adjusted permission prompts to be less intrusive on Android.
read more →

Amazon Quick agentic AI now in AWS GovCloud

🛡️ Amazon Quick's agentic AI is now available in AWS GovCloud (US-West), bringing an AI teammate into an isolated, FedRAMP Class D (formerly High) authorized environment for government and regulated-industry teams. The service enables custom chat agents for mission workflows—such as procurement, ATO compliance, and grants management—while keeping data hosted and processed within the GovCloud region. Spaces enforce least-privilege access and Quick integrates with existing tools like Microsoft 365, SharePoint, and OneDrive via GCC High connectors.
read more →

Amazon EC2 R8a instances now in Canada Central

🚀 Amazon EC2 R8a instances are now available in Canada (Central). These instances use 5th Gen AMD EPYC processors with up to 4.5 GHz and deliver up to 30% higher performance and up to 19% better price-performance versus R7a. Built on the AWS Nitro System with sixth generation Nitro Cards, R8a offers 12 sizes (including 2 bare metal) and is SAP-certified.
read more →

Landing Zone Accelerator C5:2020 Assessment Report Now Available

🔒 Landing Zone Accelerator now has an independent assessment report for C5:2020 available on AWS Artifact, evaluating how LZA's baseline implements nearly 200 native security controls. The report, prepared by AWS partner Schellman, maps LZA's Universal Configuration and security control baseline to C5:2020 technical criteria and describes architecture, best practices, and scoping considerations. LZA supports standard multi-account and container deployments in the AWS European Sovereign Cloud and is accompanied by a Compliance Workbook to help customers accelerate evidence collection and assessment preparation.
read more →