< ciso
brief />
Vendor and Hyperscaler Watch Banner

All news in category “Vendor and Hyperscaler Watch”

5908 articles · page 9 of 296

Amazon RDS for PostgreSQL extended support announced

🛈 Amazon RDS for PostgreSQL announces Extended Support minor versions 13.23-rds.20260514, 12.22-rds.20260514, and 11.22-rds.20260514. This Extended Support provides up to three additional years of fixes for critical CVEs and bugs beyond a major version's end of standard support date. You can upgrade via Blue/Green Deployments, in-place upgrade, or restore from a snapshot. Use the Amazon RDS Management Console or AWS CLI to create or update managed PostgreSQL instances.
read more →

Amazon Aurora PostgreSQL adds multiple minor updates

🔔 Amazon Aurora PostgreSQL-Compatible Edition now supports PostgreSQL versions 18.6, 17.11, 16.15, 15.19, and 14.24, delivering community bug fixes and Aurora-specific enhancements. We recommend enabling automatic minor version upgrades to receive these fixes and address known CVEs. Use scheduled maintenance windows or the AWS Organizations Upgrade Rollout Policy to orchestrate phased upgrades across environments. Aurora continues to offer high performance, global resilience, serverless options, and security-focused features.
read more →

Graph Workflows in ADK: Patterns and Practices

🔎 This post explains how the Agent Development Kit (ADK) turns graph engineering into executable workflows using a refund example. It covers fan-out and fan-in, deterministic and agent routers, human-in-the-loop pauses, parallel workers, and dynamic orchestration. The article contrasts static graphs against Python-driven scheduling and shows when to use each approach.
read more →

Anthropic Claude models expand in Asia regions

🚀 Amazon Bedrock now offers Anthropic's Claude Opus 5, Claude Sonnet 5, and Claude Haiku 4.5 in India, Claude Opus 5 and Claude Sonnet 5 in South Korea, and Claude Sonnet 5 in Singapore. These deployments enable customers in regulated industries to keep inference and data processing within-country using in-region or geographic cross-Region inference. In India, endpoints run across Mumbai and Hyderabad Regions; South Korea and Singapore support in-region bedrock-runtime endpoints.
read more →

AWS Transform adds MSK migration assessment

🤖 AWS Transform now provides agentic migration assessments to evaluate migrating on-premises Apache Kafka clusters to Amazon MSK. The agent analyzes workloads, performs compatibility checks, recommends right-sized MSK Express brokers, and projects costs to produce a TCO business case and actionable next steps in minutes. Users can upload a Kafka inventory file or describe clusters in chat and create what-if scenarios to compare Regions, retention, and configurations. Assessments are available in all Regions offering AWS Transform.
read more →

Defending at machine speed for public sector

🔒 Over the last three decades, cybersecurity has evolved rapidly and today’s landscape is defined by AI-driven attackers operating at machine speed. Reactive, manual security reviews no longer suffice, so resilience requires proactive defenses with continuous posture validation and autonomous remediation built into workloads from day one. Google AI Threat Defense integrates Gemini, Wiz, CodeMender, and Mandiant to provide unified, continuous protection across code and cloud, enabling agencies to monitor and neutralize threats and protect mission-critical services.
read more →

Cloudflare’s Framework for Application Security in AI Era

🛡️ Cloudflare outlines an integrated security framework to address AI-driven attacks, connecting discovery, governance, runtime protection, and iterative investigation. The post summarizes recent AI-agent compromises, explains why isolated controls fail, and introduces new capabilities such as LLM-powered pentesting, Adaptive Security, Botbase registration, Precursor session signals, Application Profiles, and expanded threat intelligence. The approach emphasizes continuous validation, overlapping controls, and using global telemetry to turn investigations into protections.
read more →

Cloudflare adds TLS post-quantum visibility tools

🔒 Cloudflare has added post-quantum (PQ) cryptography visibility into its Application Security and Logs products, enabling customers to inspect TLS key exchange algorithms in Logpush, Log Explorer, and HTTP Traffic Analytics. The update surfaces the negotiated key exchange per incoming request so teams can audit PQ adoption, assess compliance, and identify cryptographic gaps across domains. Cloudflare highlights X25519MLKEM768 as the primary TLS 1.3 PQ key-exchange and provides guidance for enabling TLS 1.3 and collecting PQ telemetry.
read more →

Cloudflare announces PQ-capable CA using MTCs

🔐 Cloudflare outlines its plan to operate a post‑quantum capable Certificate Authority (CA) that supports Merkle Tree Certificates (MTCs) to enable scalable, efficient PQ authentication. The post explains how MTCs integrate issuance and transparency, reducing the cost of PQ signatures and improving auditability with cosigners and mirrors. Cloudflare will offer MTC issuance for free, build ACME tooling, and target Chrome inclusion in early 2027.
read more →

Adaptive AI-driven WAF testing and lessons

🛡️ Cloudflare evaluated how frontier LLMs can act as adaptive attackers against a WAF by building a tester that iterates payload encodings and delivery methods, observing HTTP responses to guide next moves. The tests ran against an authorized staging environment across 45 scenarios and six attack categories, producing 1,107 attempts that were human-triaged into 49 actionable findings and 558 blocked requests. Findings led to rule and normalization changes in the Managed Ruleset and produced practical deployment guidance to strengthen layered defenses.
read more →

Cloudflare Application Profiles for Positive Security

🔒 Cloudflare is launching Application Profiles to enforce positive security by learning the expected structure and format of HTTP requests and flagging deviations. The feature extends existing API Schema Learning to web applications, creating per-operation profiles that validate paths, query parameters, headers, cookies, and request bodies. Profiles are learned from observed traffic, updated weekly, and produce metadata (cf.schema_validation.learned.violated) that teams can use in Security Rules to monitor or enforce blocking. A closed beta is available to invited Enterprise customers and those with API Security already have access.
read more →

Cloudflare’s AI-Driven Cryptography Discovery Effort

🔍 Cloudflare describes its internal effort to achieve full post-quantum (PQ) readiness by 2029, focusing on discovering and classifying cryptographic uses across its centralized codebase. The company developed an AI-assisted tool, CryptoLabe, to map repositories, identify cryptography in source, configs, and docs, and generate actionable reports for product and engineering teams. CryptoLabe runs two-stage scans—discovery and analysis—assigning cautious classifications and surfacing prerequisites when ecosystem support is lacking. The system runs on Cloudflare Workers, Durable Objects, Workflows, and an AI Gateway to manage model requests and resource limits.
read more →

Cloudflare launches scalable Threat Signals

🛡️ Threat Signals converts open-source reporting into actionable intelligence by using agentic AI skills to summarize research, extract and normalize indicators, and apply tags into a private, account-scoped dataset. Feeds (RSS/Atom/RDF) are ingested into Workflows that fetch content, clean it, run IOC extraction and Cloudforce One skills, and store results as Threat Events tied to the original report. Outputs are searchable, tagged, and can be used to create WAF rules; Threat Events Platform access is expanded to all Cloudflare accounts with tiered enhancements for enterprise customers.
read more →

Cloudflare announces intent to become a public CA

🔒 Cloudflare today announced its intent to become a public certificate authority (CA), detailing milestones including applications to major root programs and an agreement to acquire a trusted root from GlobalSign. The company plans ACME-first automation, support for post-quantum and Merkle Tree Certificates, and transparency through reproducible builds and public dashboards. Cloudflare emphasizes reliability, redundancy, and gradual adoption while continuing partnerships with existing CAs.
read more →

Cloudflare adds IPsec downgrade protection extension

🔒 Cloudflare and the IETF developed and implemented a mitigation for downgrade attacks against IPsec to guard against quantum-capable adversaries. The company has rolled out beta support across IPsec products including Cloudflare WAN and Magic Transit, enabling customers to request an ipsec_downgrade_protection flag. The upgrade helps ensure post-quantum key agreement is not bypassed by active attackers during protocol negotiation.
read more →

AWS Systems Manager adds org-wide document sharing

📢 AWS Systems Manager now supports sharing Systems Manager Documents (SSM Documents) with an entire AWS organization or specific OUs using AWS Resource Access Manager (AWS RAM). Previously limited to public or per-account sharing, this update lets you create an AWS RAM resource share, select SSM Documents and target organizations or OUs, and have access automatically kept in sync as accounts change. Sharing uses standard AWS authorization and resource-based policies, and external accounts receive an invitation they must accept. The feature is available in the console, AWS CLI, and SDKs across all Regions where Systems Manager is offered, with no additional charge.
read more →

CloudWatch Logs Introduces Automatic Field Indexing

🛰️ Amazon CloudWatch Logs now automatically indexes frequently queried fields, removing the need for manual selection and setup. It detects fields used with = and IN filters and indexes them to speed up CloudWatch Logs Insights queries while reducing scanned data. Automatically indexed fields are retained for 30 days and don't count toward the 20-field-per-log-group limit; you can promote fields to a permanent index via console or API. Auto-indexing is available in supported AWS Regions at no extra cost.
read more →

AWS DataSync adds support for shared VPCs

🔒 AWS DataSync now supports shared Virtual Private Clouds (VPCs) enabling agents and transfer tasks to use subnets shared across AWS accounts with AWS Resource Access Manager (RAM). This lets you transfer data privately over a centrally managed subnet and VPC endpoint instead of provisioning one per account. Shared VPC support reduces IP address consumption and operational overhead and works for both Enhanced and Basic agent modes. The feature is available in all AWS Regions offering DataSync except Secret Regions.
read more →

CloudWatch Logs Insights estimates bytes scanned

🔎 Amazon CloudWatch Logs Insights now provides an estimate of the number of bytes a query would scan across selected log groups and a specified time range, without executing the query. The estimate appears automatically in the CloudWatch console when you change log group selection, time range, or query text, and can be requested via the AWS CLI or API by appending the estimate command. Queries using the estimate command do not incur CloudWatch Logs Insights query charges, and the feature is available in all AWS commercial regions.
read more →

AWS Transfer Family adds multi-file and folder downloads

🗂️ AWS Transfer Family web apps now allow users to select and download multiple files and folders in a single action. The selection is packaged as a zip archive that preserves folder structure and shows real-time progress and per-file status. This feature works in Google Chrome, Mozilla Firefox, and Chromium-based browsers (including Edge) but is not yet supported in Safari. It is available in all Regions where Transfer Family Web Apps are offered.
read more →