< ciso
brief />
Vendor and Hyperscaler Watch Banner

All news in category “Vendor and Hyperscaler Watch”

5932 articles · page 79 of 297

AWS HealthOmics Adds Nextflow Profile Support

🧬 AWS HealthOmics now supports Nextflow profiles, letting users activate predefined execution settings at run time. This allows separation of platform-specific configuration from core workflow logic and enables switching between development and production settings without editing workflow source code. The feature reduces errors, improves portability, and supports nf-core built-in and institutional profiles. It is available in all AWS HealthOmics Regions listed.
read more →

AWS launches Lambda MicroVMs for isolated serverless

🚀 AWS announces Lambda MicroVMs, a new serverless compute primitive delivering VM-level isolation, near-instant launch and resume speeds, and up to 8 hours of state preservation. Built on Firecracker, MicroVMs let developers provide each user or job a dedicated, secure execution environment without managing virtualization infrastructure. MicroVM images are created from Dockerfiles and support HTTP/2, gRPC, and WebSockets, with regional availability and pay-for-use pricing.
read more →

Defending AI Memory: Microsoft’s Multi‑Layer Strategy

🔒 Microsoft outlines a defense-in-depth approach to protect AI memory across storage, retrieval, model interaction, and user control. The post explains how memory transforms AI from stateless tool to learning collaborator, increasing attack surface and enabling staged attacks that persist beyond initial prompts. It summarizes protections in M365 Copilot including prompt-injection classifiers, Task Adherence checks, tenant policy controls, unified compliance, and audit logging integrated with Defender and Sentinel.
read more →

Race condition in hyper caused truncated image responses

🛠️ Cloudflare’s Images service, built in Rust on Workers, encountered intermittent truncation of larger transformed images after a 2025 rearchitecture that connected Workers to Images via a local binding. The failure returned HTTP 200 with a shortened body and no logged errors, appearing only under production concurrency and reproducible as a timing-dependent race in the hyper HTTP library. Instrumentation, strace, and controlled reproductions identified premature shutdown calls from the Images service that left most response bytes in hyper’s internal buffer; a four-line change ultimately fixed the issue.
read more →

Microsoft confirms Windows 11 version 26H2 release

📰 Microsoft confirmed Windows 11 version 26H2 as the next feature update and has begun testing with Windows Insiders in the Dev Channel. The company says devices running Windows 11 24H2 and 25H2 can upgrade via a small 174 KB enablement package, while systems on 23H2 or older will need the full 6.5 GB update. Microsoft also published a whitepaper explaining the shared servicing model for these releases.
read more →

AWS Transform expands migration target regions

🔁 AWS Transform for migrations now supports deployment to all AWS commercial regions as migration targets, enabling customers to select where migrated resources are provisioned, including landing zones and network infrastructure. The announcement lists newly supported regions such as US East (N. California), Africa (Cape Town), multiple Asia Pacific and European locations, Canada (Calgary), Mexico (Querétaro), and Middle East (Tel Aviv). Target region selection is integrated into the AWS Transform for migrations workflow and documentation lists the current supported target regions.
read more →

Check Point Integrates OpenAI Frontier Cyber Models

🤖 Check Point is embedding OpenAI frontier cyber models into its security products through the Daybreak Cyber Partner Program to deliver sharper prevention, faster remediation, and stronger security operations. The partnership emphasizes built-in guardrails, misuse monitoring, and task-focused outputs. Initial explorations target agentic network security orchestration and CTEM Agentic Exposure Validation to improve policy translation, configuration validation, exposure summarization, prioritization, and remediation drafting.
read more →

BigQuery Managed Python UDFs Now Generally Available

🐍 BigQuery now supports fully managed Python User-Defined Functions (UDFs) in GA, enabling data teams to run custom Python code securely inside BigQuery using SQL or BigQuery DataFrames. The service runs on BigQuery-managed serverless infrastructure that auto-scales and removes the need to manage containers. It provides access to popular Python libraries, vectorized PyArrow processing, configurable container resources, concurrency controls, and streaming logs for observability. Billing is integrated with BigQuery SKUs and supports spend commitments and cost monitoring.
read more →

AWS Network Firewall changes default stateful action

🚨 AWS Network Firewall now sets the default stateful action for newly created firewall policies to Application drop established (server-directed only), replacing the previous Application drop established (bidirectional). This safer default prevents silent drops of legitimate server-to-client TCP packets (for example, window updates, keep-alives, and resets) that caused intermittent connection issues. No action is required for new policies; existing environments that rely on bidirectional behavior for post-quantum cryptography (PQC) fragmented TLS handshakes should consult the documentation for guidance on switching or adding the to_server flag to TCP drop rules.
read more →

AWS Continuum aims to streamline code security

🔒 AWS has introduced Continuum, a service to continuously discover, investigate, and remediate vulnerabilities across first-party and third-party codebases. The platform uses AI to validate exploitability, generate remediation recommendations, and propose fixes that integrate with existing development workflows. New capabilities include automatic threat modeling in STRIDE format, while more established features derive from the Security Agent product. Continuum supports graduated trust from human-in-the-loop review to an "enforce mode" for autonomous remediation.
read more →

AWS Batch adds ordered instance allocation strategies

🚀 AWS Batch introduces two new allocation strategies—Best Fit Progressive Ordered (BFPO) and Spot Capacity Optimized Prioritized (SCOP)—allowing customers to specify ordered instance type preferences for on‑demand and Spot compute environments. Use BEST_FIT_PROGRESSIVE_ORDERED for on‑demand and SPOT_CAPACITY_OPTIMIZED_PRIORITIZED for Spot environments, supplying an ordered list of instance types or families. These options are configurable via the AWS Batch API (CreateComputeEnvironment or UpdateComputeEnvironment) or the AWS Management Console and are available in all Regions where AWS Batch is offered.
read more →

IAM Identity Center adds separate account and app quotas

🔔 AWS IAM Identity Center now supports separate quotas for AWS accounts and applications. By default, administrators can configure up to 7,000 AWS accounts and 7,000 applications independently, so use of one does not reduce capacity for the other. Existing customers with higher limits retain those limits automatically. Quota increases remain available via the AWS Service Quotas console.
read more →

Implementing Egress Controls to Prevent Data Exfiltration

🔒 This post outlines an architecture and controls for preventing data exfiltration from AWS environments by combining centralized network inspection, DNS filtering, and data perimeter policies. It explains a hub-and-spoke pattern using Transit Gateway, AWS Network Firewall, and Route 53 Resolver DNS Firewall to inspect and block unauthorized outbound traffic, including scenarios involving compromised workloads and agentic AI. The article details layered preventive, detective, and corrective measures using AWS services such as GuardDuty, Security Hub, IAM Access Analyzer, EventBridge, and Firewall Manager to automate detection and response.
read more →

Amazon MSK Replicator adds mTLS support for Express

🔒 Amazon MSK Replicator now supports mutual TLS (mTLS) authentication for replicating data from external Apache Kafka clusters — including on‑premises, self‑managed on AWS, or other cloud providers — to Amazon MSK Express brokers. This enables migrations, disaster recovery, and hybrid or multi‑cloud data distribution using mTLS‑configured external clusters. MSK Replicator automates replication while preserving topic names and avoiding infinite loops, and also synchronizes consumer group offsets bidirectionally to allow independent movement of producers and consumers.
read more →

Amazon MSK adds AI Agent Skills for operators

🤖 Amazon MSK now offers AI Agent Skills that provide AI coding assistants with expert, up-to-date guidance for operating Amazon MSK. The skills cover common operational tasks including troubleshooting, sizing, configuring, monitoring, and migration from external Kafka clusters. Teams can use these skills to keep clusters healthy, improve performance, and accelerate migration to MSK Express with higher throughput and faster scaling. Setup involves configuring the Agent Toolkit for AWS via the AWS CLI and using supported coding agents like Kiro, Claude Code, or Cursor.
read more →

Google enforces developer verification on Android

🔒 Google will begin enforcing Android developer verification on September 30, 2026, in Brazil, Indonesia, Singapore, and Thailand. Certified devices from major OEMs will block normal installs of apps whose developers have not registered an identity with Google, affecting sideloaded and independent apps most. The Android Developer Verifier service rolls out to phones running Android 8+ starting June, with APIs and limited-distribution accounts arriving mid-year.
read more →

AWS Outposts adds self-service lifecycle controls

🛠️ AWS Outposts introduces self-service lifecycle management allowing customers to configure, quote, order, manage subscriptions, renew, and decommission Outposts via the AWS Management Console, CLI, and API. A new configuration and quoting tool provides real-time cost estimates across payment options and term lengths, surfaces account and regional constraints, and converts quotes to orders for new deployments or capacity additions. Subscription details and term information are exposed programmatically, and guided workflows support renewal or decommissioning with resource cleanup. These capabilities are available in all commercial AWS Regions that support AWS Outposts.
read more →

Google AI Studio Starter Tier: Quick prototyping

🧩 Google Cloud's Starter Tier for Google AI Studio provisions a managed, limited stack (Cloud Run, Firestore, Cloud SQL for PostgreSQL, Firebase Auth) so individual Google Accounts can publish prototypes without a billing account. The environment is fully managed by Google, with region, APIs, and security policies preselected. It supports two active apps, a simplified console, and automatic agent-driven provisioning and code generation. Quotas, locked APIs, ephemeral storage, and upgrade paths to paid projects are explained.
read more →

Zero Trust as the AI control plane for Southeast Asia

🔒 At Zscaler’s Zenith Live 2026 in Vienna, the vendor argued that AI agents are rapidly becoming digital workers while regulators tighten data residency and supply‑chain threats move closer to core operations. Zscaler proposes extending its Zero Trust Exchange and SASE platform to govern AI agents, unmanaged devices, multi‑cloud workloads, and B2B partners, positioning zero trust as the control plane for secure AI adoption in regulated, highly connected markets like Southeast Asia. The company emphasised an AI Broker, endpoint AI security, and an AI Access Graph to map and protect AI assets and data flows.
read more →

Analysis of Reported Credential Compromise of FortiGate

🔐 Fortinet has observed malicious actors harvesting FortiGate credentials in an activity labeled "FortiBleed." Their initial analysis indicates attackers are reusing credentials from prior incidents and leveraging brute-force techniques against devices lacking strong passwords and multi-factor authentication. This is not a new Fortinet vulnerability and is unrelated to recent advisories. Fortinet is investigating, notifying impacted customers, and recommending immediate defensive actions and hardening.
read more →