< ciso
brief />
Vendor and Hyperscaler Watch Banner

All news in category “Vendor and Hyperscaler Watch”

5942 articles · page 90 of 298

Alcidion modernizes Miya Precision with AlloyDB

🔍 Alcidion migrated its Miya Precision platform from Microsoft SQL Server to Google Cloud's AlloyDB for PostgreSQL to improve stability, performance, and operational overhead. The move used Database Migration Service and custom synchronization tools to achieve a rapid cutover, reducing transition time to about 15 minutes. The new architecture enabled dramatic speedups in JSON processing and reduced administrative burden for SREs.
read more →

Fortinet Q1 2026 Results and Strategic Momentum

📈 Fortinet reported a strong Q1 2026 driven by broad-based demand across Secure Networking, Unified SASE, and AI-Driven Security Operations. Leadership highlighted 31% billings growth, 20% total revenue growth, record non-GAAP operating margin, and $1.01B free cash flow, attributing performance to platform integration, FortiASIC technology, and FortiOS innovation. Executives noted large AI, OT, and distributed infrastructure wins and raised full-year guidance.
read more →

Amazon Redshift lowers manual snapshot storage costs

📣 Amazon Redshift now charges manual snapshot storage based on unique data blocks stored across snapshots rather than the full size of each snapshot. This change applies to Amazon Redshift Serverless and Amazon Redshift RG instances and reduces costs for customers who keep multiple manual snapshots. The billing model automatically applies to both existing and new manual snapshots in all AWS commercial and AWS GovCloud (US) Regions where these services are available. Customers can take more frequent snapshots to improve RPOs without incurring proportional cost increases.
read more →

Google advisory on evolving global fraud and scams

🛡️ Google outlines recent global scam trends and mitigation efforts, highlighting sophisticated Adversary-in-the-Middle (AITM) phishing, QR-code and calendar-based scams, AI-driven cryptocurrency fraud, mobile extortion apps, and government impersonation campaigns. The advisory describes technical responses, policy enforcement, and legal actions to disrupt abuse, plus practical safety tips for users.
read more →

OpenAI adds Lockdown Mode and session auditing

🔒 OpenAI has rolled out two new security controls for ChatGPT: Lockdown Mode and Active Sessions. Lockdown Mode restricts outbound network access to prevent data exfiltration via prompt injection, at the cost of disabling live connectors and certain features. Active Sessions gives users visibility into and control over signed-in devices, with the ability to end single or all sessions. Both controls target account security and sensitive-data use cases, though SSO accounts and some logins remain unsupported.
read more →

Cloudflare adds realtime threat intel to WAF

🛡️ Cloudflare now exposes live Threat Events signals directly to its WAF engine, enabling security teams to create proactive rules using attacker names, target industries, countries, attack types, and dataset sources. The integration enriches HTTP request metadata in real time without adding noticeable latency, supporting both UI and Infrastructure-as-Code workflows via API and Terraform. Matches are logged in Security Analytics for auditing, and Saved Views can be exported directly into WAF rules for streamlined operations.
read more →

The Hardest Fork: Securing Open Source Supply

🔐 Mythos and emergent AI capabilities are creating a new class of supply-chain threats that chain many low-level findings into high-impact exploits. Washington is watching, but open source is globally distributed and not directly governable, so policy focus must be on consumption and mitigation. The author—an industry veteran who helped create Sigstore and other initiatives—argues for a dual plan: scale coordinated disclosure and provide a neutral, funded maintainer of last resort to manage trusted forks.
read more →

DSIT Rethinks Remediation to Simplify Vulnerability Fixes

🔍 The UK's DSIT manages security for over half a million government domains and is streamlining how vulnerabilities are communicated and fixed. Nick Woodcraft explained at Infosecurity Europe 2026 that DSIT focuses on clear, outcome-oriented guidance so non-experts can prioritise remediations. The department uses SIEM integration and NCSC channels to distribute trusted data and avoids overwhelming organisations by staging issue disclosures. Emphasis remains on basics like patching to mitigate faster-emerging threats.
read more →

AWS Transform Adds RDS for SQL Server Cost Assessment

🔎 Amazon RDS for SQL Server now integrates cost assessment into AWS Transform, enabling customers to estimate migration costs from on-premises SQL Server to RDS for SQL Server. AI-powered agents analyze environments and recommend optimal instance types while supporting BYOM and License Included options. The tool includes what-if cost comparisons, Database Savings Plans guidance, and MAP eligibility to help reduce migration expenses.
read more →

Amazon OpenSearch Serverless Adds Agentic Search

🔍 Amazon OpenSearch Serverless now supports Agentic Search, enabling natural-language queries over users' data. The system interprets intent, plans searches, generates DSL queries, and returns results with transparent reasoning. A built-in QueryPlanningTool powered by LLMs translates requests and orchestrates retrieval; behavior can be customized via APIs or OpenSearch Dashboards. Agentic Search is available in all AWS Commercial Regions where OpenSearch Serverless operates.
read more →

VS Code introduces two‑hour extension update delay

🔒 Microsoft will delay automatic extension updates in Visual Studio Code by two hours to reduce exposure to potentially compromised releases. The feature, available in VS Code 1.123, allows immediate manual updates via the "Update" button and shows reasons and scheduled times for pending updates. Trusted publishers such as Microsoft, GitHub, and OpenAI are exempt and continue to update immediately. The change follows similar cooldown controls added across package managers to curb software supply chain threats.
read more →

Amazon Bedrock AgentCore adds interactive shells

🖥️ Amazon Bedrock AgentCore Runtime introduces the InvokeAgentRuntimeCommandShell API, providing a persistent, PTY-backed terminal over WebSocket into running agent sessions. This complements existing one-shot execution via InvokeAgentRuntimeCommand and delivers a full terminal experience inside an isolated microVM with features like colors, tab completion, Ctrl+C, resize, and automatic reconnect. Developers hosting coding agents (for example, Claude Code, OpenAI Codex, Amazon Kiro) can now authenticate, drop into the agent microVM, inspect files, run ad-hoc commands, and debug while retaining session state across reconnects. Each interactive session uses a runtime session ID and shell ID for resume; up to 10 concurrent shells are supported per runtime.
read more →

Simplified S3 Tables and Iceberg permissions in GovCloud

🔒 AWS Glue Data Catalog now supports IAM-based authorization for Amazon S3 Tables and Apache Iceberg materialized views in AWS GovCloud (US) Regions. This change lets you consolidate required permissions for storage, catalog, and query engines into a single IAM policy. The capability eases integration with analytics services such as Amazon Athena, Amazon EMR, Amazon Redshift, and AWS Glue. You can still opt in to AWS Lake Formation for fine-grained access controls.
read more →

OpenSearch UI arrives in AWS GovCloud regions

🔔 Amazon OpenSearch Service now offers its modernized operational analytics UI in AWS GovCloud (US-East) and AWS GovCloud (US-West), enabling unified access to managed domains and serverless collections from a single endpoint. The release introduces Workspaces for team collaboration and a revamped Discover experience with multi-source data selection, PPL and SQL support, DQL and Lucene compatibility, updated visuals, and query autocomplete. The UI updates are available regardless of the underlying managed cluster or collection version.
read more →

Fine-grained B2C Access Control with Cognito

🔐 This article demonstrates how to implement enterprise-grade authentication and authorization for a Streamlit sample application using Amazon Cognito for identity and Amazon Verified Permissions with Cedar policies for fine-grained access control. It outlines a layered architecture that separates identity verification, authorization evaluation, application logic, and enforcement to reduce blast radius. The post explains Cedar policy anatomy and common patterns—ownership, role-based, hierarchical, and emergency access—plus evaluation precedence where forbid policies take priority. Practical guidance covers required tools, provisioning steps, policy design tips, and testing recommendations to help developers scale secure applications.
read more →

RubyGems adds cooldown to Bundler to curb supply-chain risks

🔒 The RubyGems team added a cooldown option to Bundler to delay installing recently published gems, aiming to reduce exposure to software supply-chain attacks. The feature checks timestamps and ignores gems until they have been published for a configurable number of days, allowing time for malicious modifications to be discovered. Administrators can override the delay when rapid patching is required, balancing security and operational needs.
read more →

AWS adds C8in instances in Asia Pacific and Europe

🚀 Amazon EC2 C8in instances are now available in additional AWS regions including Asia Pacific (Sydney, Singapore, Malaysia) and Europe (Frankfurt). These instances use custom sixth-generation Intel Xeon Scalable processors exclusive to AWS and the latest sixth-generation AWS Nitro cards, offering up to 43% higher performance versus C6in. C8in supports sizes up to 384 vCPUs and 600 Gbps networking, targeting network-intensive distributed compute and large-scale analytics. They are offered via Savings Plans, On-Demand, and Spot.
read more →

AWS Fargate adds 32vCPU tasks for ECS

🖥️ Amazon Elastic Container Service (Amazon ECS) with AWS Fargate now supports 32vCPU compute configurations, offering memory choices of 60 GiB, 120 GiB, or 244 GiB for both x86 and ARM Linux workloads. These larger task sizes enable high-performance computing, large-scale data processing, and AI inference use cases by allowing deployment of bigger containers and scaling beyond previous limits. The sizes are available on Fargate and Fargate Spot across commercial and GovCloud (US) Regions, and integrate with existing Compute Savings Plans. Configure task definitions with 32 vCPU and select a memory option to deploy via console, CLI, or IaC.
read more →

XChat launch raises serious privacy and security doubts

🔒 Elon Musk’s XChat launched on iOS in April 2026 as a purportedly private messaging alternative, but its encryption model and key handling have raised alarm among experts. XChat stores users’ private keys on servers protected by HSMs and uses four-digit PINs to encrypt those keys for multi-device sync, a design that undermines classic end-to-end guarantees. Practical issues — message requests sent without E2EE, confusing PIN prompts, and weak brute-force protection — further complicate user security. The net result: XChat offers convenience at the cost of meaningful privacy assurances.
read more →

Cloudflare AI Gateway Adds Dollar-Based Spend Limits

🛡️ Cloudflare announces spend controls in AI Gateway, plus a closed beta for identity-driven budgets and routing using Cloudflare Access and existing identity providers. The update introduces dollar-denominated budgets, real-time cost tracking, and options to block or route requests when limits are reached. Identity integration enables per-user and per-team attribution and policies to manage who can access which models and how much they may spend.
read more →