< ciso
brief />
Vendor and Hyperscaler Watch Banner

All news in category “Vendor and Hyperscaler Watch”

5930 articles · page 77 of 297

FedRAMP 20x and the rise of GRC engineering

🔍 The author argues that much of traditional compliance has become theatrical—focused on curated, point-in-time evidence rather than continuous operational truth. FedRAMP 20x and the broader GRC engineering movement push assurance toward automation, machine-readable evidence and continuous telemetry, shifting audits from static snapshots to ongoing validation. The writer recounts their organization’s FedRAMP 20x pilot, describing early setbacks as iterative learning rather than failure.
read more →

Amazon RDS Custom adds latest Microsoft SQL Server updates

🛈 Amazon RDS Custom for SQL Server now supports the latest Cumulative Updates (CU) and General Distribution Release (GDR) updates for Microsoft SQL Server, including SQL Server 2019 CU32+GDR (KB5090407) and SQL Server 2022 CU25 (KB5081477). These GDR updates address vulnerabilities described in CVE-2026-40370. You can apply the updates via the Amazon RDS Management Console, AWS SDK, or AWS CLI, and guidance is available in the Amazon RDS Custom User Guide.
read more →

Amazon RDS Adds Latest Microsoft SQL Server GDRs

🔄 Amazon RDS for SQL Server now supports the latest General Distribution Release (GDR) updates across SQL Server 2016 SP3, 2017, 2019, and 2022, corresponding to specific RDS engine versions. These GDRs address vulnerabilities identified as CVE-2026-32167 and CVE-2026-32176. AWS recommends upgrading instances via the Amazon RDS Management Console, AWS SDK, or CLI and refers users to the RDS SQL Server User Guide for upgrade instructions.
read more →

Amazon OpenSearch Ingestion now in Paris region

🚀 Amazon OpenSearch Ingestion is now available in the Europe (Paris) Region (eu-west-3). This fully managed ingestion tier enables no-code filtering, transformation, redaction, and routing of data into Amazon OpenSearch Service managed clusters or serverless collections, automatically provisioning and scaling resources to match workload demands. The service is now generally available in 17 AWS regions worldwide, expanding customers' options for regional data ingestion and processing.
read more →

Google expands privacy controls for Search and Play

🔒 Google announced new privacy controls that separate saved history and personalization for Search services and Google Play, rolling out in users' Google Accounts in the coming days. The update creates distinct Search Services History and Personalized Recommendations settings, and similarly splits Play History and Personalization in Play. If Web & App Activity is on, the new Search Services History and its Save Media subsetting will be enabled after transition, but users can disable or delete saved media later.
read more →

Restrict AWS Console Access Using Sign-In Policies

🔒 This post explains how AWS Sign-In now supports resource-based policies and resource control policies (RCPs) to restrict AWS Management Console and AWS CLI sign-in to expected networks such as corporate IP ranges, on-premises data center networks, and Amazon VPCs. It walks through a financial services use case that enforces console sign-in from a corporate network, shows how to create and enable a sign-in resource permission statement, and describes verification via AWS CloudTrail. The article also contrasts single-account resource-based policies with organization-wide RCPs and explains integration with AWS Management Console Private Access and the broader data perimeter framework.
read more →

EC2 AMI Watermarks for Provenance and Governance

🔒 Amazon EC2 now supports AMI watermarks that embed custom identifiers into private AMIs and persist through copies and derived AMIs. Watermarks include metadata such as AMI ID, owner ID, region, and timestamps to support provenance and tracking. You can apply watermarks via the AWS Management Console, AWS CLI, SDKs, or EC2 Image Builder. Watermarks integrate with Allowed AMIs and Declarative Policies to enforce AMI usage across organizations.
read more →

Amazon EMR Serverless enables live config updates

🔧 Amazon EMR Serverless now permits live updates to key application configurations, such as maximum capacity and custom image settings, without stopping or restarting the application. New workloads submitted after a configuration change automatically use the updated settings while existing jobs continue under their original configuration. This removes the previous need to coordinate maintenance windows and restart applications when adjusting scaling boundaries or deploying updated custom images.
read more →

AWS releases IoT Device SDK for Swift across platforms

🔒 The AWS IoT Device SDK for Swift is now generally available, enabling Swift developers to build secure, scalable IoT applications natively on Apple platforms (macOS, iOS, tvOS) and Linux. The SDK fills a prior gap in native Swift support for AWS IoT services and provides production-ready APIs for teams managing device fleets and cross-platform Apple ecosystem solutions. It integrates service clients for AWS IoT Device Shadow, Jobs, and Fleet Provisioning and includes built-in TLS 1.3 support on Apple platforms. Install via Swift Package Manager and consult the documentation and GitHub samples to get started.
read more →

CNAPP evolution: Microsoft aligns with cloud risk platforms

🔍 Cloud security is shifting from mere visibility to context-aware risk reduction across multicloud, Kubernetes, APIs, and AI workloads. The Frost & Sullivan 2026 Frost Radar positions CNAPP as an operational cloud risk platform that correlates posture, workload, identity, data, and runtime signals. Microsoft Defender for Cloud is highlighted among leading vendors for connecting findings into prioritized, actionable attack paths and enabling continuous risk validation across the application lifecycle.
read more →

Google Cloud adds cross-region backups for DR

🔒 Google Cloud announces general availability of cross-region backups for its Backup and DR Service. This release decouples backup destinations from source regions, enabling backups to be stored in distinct geographic regions to improve resilience and meet data residency requirements. The capability is available now for Compute Engine instances, Disks, and Filestore, with Cloud SQL and AlloyDB support coming soon.
read more →

Route 53 Global Resolver adds DNS view sharing

🔒 Amazon Route 53 Global Resolver now allows sharing DNS views across AWS accounts via AWS Resource Access Manager (AWS RAM). Consumer accounts can associate their private hosted zones with a shared DNS view to make records resolvable through the owner's global resolver in all Regions where it runs, while retaining hosted zone ownership. Access is controlled with predefined AWS RAM permissions—association-only, lifecycle management, or full access—or with custom permissions. This feature is available at no additional cost in supported Regions.
read more →

Amazon Neptune adds CloudFormation for global DBs

📣 Amazon Neptune now supports AWS CloudFormation for provisioning and managing Neptune global databases using the new AWS::Neptune::GlobalCluster resource type. You can define multi-region graph database topology as code, automate deployments, store configurations in source control, and integrate with CI/CD pipelines. Neptune global databases offer a single read-write primary and up to five read-only secondaries across Regions for low-latency reads, disaster recovery, and data residency. This capability is available in all Regions where Neptune global databases are supported.
read more →

Amazon CloudWatch adds tagging for dashboards

🔖 Amazon CloudWatch now supports tagging for dashboards, enabling organizations to organize, categorize, and control access using key-value tags. The PutDashboard API accepts an optional Tags parameter for up to 50 tags on new dashboards, while TagResource, UntagResource, and ListTagsForResource now support dashboard ARNs to manage tags on existing dashboards. Dashboard tags can also be handled through AWS CloudFormation, and tags can be used to scope IAM permissions, group dashboards by team or project, and filter dashboards in AWS Resource Explorer. This capability is available at no additional cost in all Regions where CloudWatch is offered.
read more →

AI-SPM Buyers Guide: Comparing AI Security Tools

🔒 This article examines the rising need for AI security posture management (AI-SPM) as enterprises adopt AI across workflows. It outlines how AI maturity stages — from AI-assisted to AI-native — change security requirements and why agents and model services expand the attack surface. The piece surveys vendor approaches, key features, and integrations, and provides guidance for selecting AI-SPM solutions to avoid coverage gaps.
read more →

Cloudflare Opens Self‑Managed OAuth to All Customers

🔐 Cloudflare announced self-managed OAuth, allowing any customer to create and manage OAuth clients for delegated access to the Cloudflare API. The company upgraded its underlying OAuth engine (Hydra) through staged 1.X and 2.X migrations, implemented blue‑green cutovers, and used queues to preserve revocations during the transition. Post‑upgrade improvements reduced latency and resource usage and enabled broader, safer integration patterns for developers.
read more →

AWS launches EC2 U7in-24TB in Seoul region

🚀 Amazon EC2 High Memory U7in-24TB instances (u7in-24tb.224xlarge) are now available in the AWS Asia Pacific (Seoul) region. These 7th-generation U7i instances use custom Intel Sapphire Rapids CPUs and provide 24 TiB of DDR5 memory, 896 vCPUs, up to 200 Gbps network, and 100 Gbps EBS bandwidth to accelerate in-memory workloads. U7i offers up to 45% better price performance over prior U-1 instances and is suited for mission-critical databases like SAP HANA, Oracle, and SQL Server.
read more →

Amazon CloudWatch adds managed syslog ingestion

📥 Amazon CloudWatch Logs now offers managed syslog ingestion, allowing firewalls, routers, switches, and Linux servers to send syslog messages directly to CloudWatch without agents. It accepts TCP, TCP+TLS, and UDP to a VPC endpoint and supports RFC 5424, RFC 3164, and Cisco FTD/ASA formats. CloudWatch automatically parses messages to extract fields like facility, severity, hostname, and application, enabling immediate querying via Logs Analytics. The feature is available in all commercial AWS Regions except UAE, Bahrain, and Israel.
read more →

AI-powered investigations preview for Amazon GuardDuty

🛡️ AWS previewed AI-powered investigations in Amazon GuardDuty to automate analysis of findings and reduce manual investigation time. The capability uses knowledge graphs and threat intelligence to examine 90 days of related activity, affected resources, and indicators, delivering disposition assessments with confidence scores, MITRE ATT&CK classifications, evidence, and remediation recommendations. Available in preview in 10 regions and accessible via the GuardDuty console, CLI, API, or AWS' MCP Server.
read more →

AWS SageMaker Notebook Instances Add G6e GPUs

🚀 Amazon EC2 G6e instances are now generally available for SageMaker notebook instances, offering up to 8 NVIDIA L40s GPUs and third-generation AMD EPYC processors. G6e delivers up to 2.5x better performance versus G5 and supports interactive model testing and training, including generative AI fine-tuning and LLMs up to 13B parameters. G6e is available in multiple US, Europe, Asia-Pacific and Middle East regions.
read more →