
Cloud Security Updates, AI Infrastructure Gains, and Active Threats
Coverage: 20 Aug 2026 (UTC)
< view all daily briefs >Cloud providers delivered a dense set of security and infrastructure updates, with new controls for certificate management, origin protection, network routing, and disaster recovery. AI infrastructure also expanded, including higher-performance GPUs, inference tuning, and vector search scale, while enterprise tooling gained stronger key management. In parallel, agencies and researchers flagged active exploitation of software used in AI pipelines and perimeter devices, tracked targeted credential-theft operations, and reported a high-profile outage affecting a major AI service.
Managed Security and Resilience Across Cloud Platforms
Amazon EKS now supports automated certificate authority (CA) rotation to help clusters replace expiring CAs without service disruption. EKS manages the rotation lifecycle across AWS-managed components, provides advance expiration notifications, appends a successor CA if one is not created, can activate rotation on a vendor schedule if required, and offers rollback. Operators remain responsible for replacing worker nodes and updating external clients to trust the successor CA; EKS Auto Mode instances and AWS Fargate nodes are updated automatically. The capability is available in all commercial Regions at no extra charge and can be used via the console, CLI, APIs, or CloudFormation. In a complementary operational enhancement, Network Firewall adds rule hit counts to identify which stateful rules match traffic. Hit counts increment on alert logs (alert, drop, reject), with metadata linking matches to specific rule groups or policies. Logs stream to CloudWatch Logs or Amazon S3 and can be queried via CloudWatch Logs Insights or Athena; the console’s Top Rule Hits dashboard surfaces aggregated metrics. The feature is enabled by default and carries no additional Network Firewall charges beyond standard logging and storage costs.
CloudFront OAC now natively supports Amazon S3 Multi-Region Access Points, eliminating the need for custom Lambda@Edge logic to compute and forward SigV4a signatures. This simplifies configuration and tightens origin protection by restricting MRAP endpoints to specified CloudFront distributions, while improving cache-miss behavior by fetching from the nearest replicated S3 bucket. The capability is available worldwide except in the CloudFront China region and does not incur additional fees. At the network edge, Direct Connect introduces inbound prefix controls that increase per-VIF inbound route capacity from 100 to up to 1,000 prefixes (IPv4 and IPv6) across dedicated and hosted connections. New capacity pools at the connection and Direct Connect gateway levels support granular allocations per virtual interface, scaling with connection speed and LAG membership; the feature is available across commercial Regions, AWS GovCloud, and China Regions at no additional cost.
To streamline database failover in multi-Region architectures, the ARC Region Switch adds an Amazon RDS Switchover Read Replica execution block. For RDS instances using Oracle Data Guard, it automates planned switchovers with zero data loss by reversing roles between primary and read replica, and can promote a read replica during unplanned failovers. Integrated into Region switch plans with cross-account orchestration, the block reduces manual steps, shortens recovery time objectives, and standardizes failover procedures.
Scaling AI Infrastructure and Model Operations
EC2 P6-B300 instances are now available in the Asia Pacific (Seoul) Region, extending the latest GPU-accelerated class. Each instance provides 8 NVIDIA Blackwell Ultra GPUs with 2.1 TB of high-bandwidth GPU memory, 4 TB of system memory, 6.4 Tbps EFA networking, and 300 Gbps dedicated ENA throughput. Compared to the P6-B200 generation, P6-B300 offers roughly 2x networking bandwidth, 1.5x GPU memory, and 1.5x GPU TFLOPS at FP4 (without sparsity), targeting training and deployment of very large foundation and language models requiring substantial memory and interconnect performance. For faster production tuning, SageMaker AI Studio introduces Generative AI Inference Recommendations. The low-code workflow benchmarks instance types, serving containers, and optimizations using NVIDIA AIPerf, aligns techniques to goals (e.g., speculative decoding for throughput), and returns ranked, production-ready configurations with measured latency, throughput, and cost metrics. Recommendations can be generated from models in JumpStart, S3, the Model Registry, or existing SageMaker models and deployed directly to real-time endpoints; there is no extra charge for generating recommendations, though standard compute costs apply.
AlloyDB ScaNN adds a four-level tree architecture (preview) to scale vector search toward 10 billion+ vectors. The hierarchical design narrows search paths, reduces vectors scanned per query, and improves build and traversal efficiency, with internal tests reporting p95 latency ≤ 51 ms at 95% recall. Memory efficiency gains come from balanced tree construction and sampling optimizations, including smaller targeted samples under constraints. Separately, Google Antigravity expands for enterprise via Gemini Enterprise app subscriptions, adding admin controls, spend management, pooled token quotas, optional overage handling, and centralized metrics. Developers get multiple surfaces (desktop app, CLI, and IDE extensions in preview for several environments) with native Workforce Identity Federation and Application Default Credentials to reduce setup overhead.
At the edge and in data management, the new AWS Local Zone in Las Vegas is generally available, bringing supported EC2 instances, multiple EBS volume types, managed containers via Amazon ECS and Amazon EKS, Application Load Balancer, and connectivity with AWS Direct Connect closer to users for single-digit millisecond latency and data residency needs. For time series databases, Timestream CMKs add support for AWS KMS customer managed keys to encrypt data at rest for InfluxDB 2 instances, read replicas, and InfluxDB 3 clusters. Customers select an immutable symmetric KMS key in the same account and Region during resource creation; there is no additional Timestream-specific charge, though standard KMS fees apply.
Exploited Vulnerabilities and Emergency Mitigations
CISA warning highlights active exploitation of CVE-2026-64849 in MLflow, a DNS-rebinding SSRF bypass in outbound webhook delivery that exposes a synchronous unauthenticated test endpoint. In default Tracking Server configurations, the webhooks API may be reachable without authentication and return upstream response status and body, enabling forced requests to internal loopback and cloud-metadata endpoints. Impact can include theft of cloud credentials, internal admin access, and internal scanning. The vulnerability was added to the KEV catalog, with U.S. federal civilian agencies directed to secure exposed instances under a binding operational directive. All organizations are advised to assess internet exposure and prioritize updating to version 3.15.0 or apply mitigations immediately.
Citrix updates address two vulnerabilities in customer-managed NetScaler ADC and NetScaler Gateway: CVE-2026-19490 (authentication bypass, CVSS 9.3) and CVE-2026-19489 (memory overflow, CVSS 8.8). Supported on-premises builds are affected, including certain FIPS and NDcPP images and SecurAccess ZTNA Hybrid deployments; Citrix-managed cloud services and Adaptive Authentication were already updated. Cloud marketplace images may lack fixes and should be replaced from Citrix downloads where necessary. Guidance urges immediate patching, credential rotation, session termination, and compromise hunting, given prior rapid weaponization of NetScaler flaws. The overflow requires SIP ALG enabled on a Large Scale NAT group and can cause instability or DoS.
U.S. agencies issued a joint ICS advisory on an active campaign using AI-generated exploit scripts targeting Siemens S7 PLCs across sectors including Critical Manufacturing, Energy, and Water and Wastewater. Actors use public internet scanners to find exposed or weakly protected devices and deploy Python tools leveraging open-source libraries like snap7.dll and python-snap7 to read/write PLC memory and configuration, sometimes masquerading as legitimate utilities. Recommended actions include applying the latest firmware and patches, removing or isolating PLCs from the internet, enforcing strong access controls and segmentation, and deploying OT/ICS monitoring tuned to anomalous activity.
Targeted Threat Activity and Service Disruption
A Google report tracks three suspected Russian cyber espionage clusters—UNC6293, UNC7005, and UNC5976—targeting individuals in academia, aerospace and defense, governments, and think tanks in Europe and the U.S. The campaigns persistently abuse legitimate authentication workflows, including app passwords, OAuth consent prompts, Microsoft device codes, and WhatsApp device linking, to gain access without overt credential theft. Techniques include attacker-controlled event pages, system fingerprinting, analysis-evasion scripts, and malicious JavaScript capable of recording audio/video and exfiltrating data. Lures are tailored to relevant themes, and templates are quickly changed when detected, raising the risk of stealthy account compromise.
The Manic malware family blends banking fraud with mobile spyware and targets a broad range of apps, with primary effects observed against services in Ukraine and additional targeting across Russia and Europe. Delivery occurs via phishing domains and dropper apps; capabilities include Accessibility and notification abuse, overlay-based PIN harvesting, UI keylogging, WebRTC remote sessions, screenshots, contact and SMS exfiltration, SMS sending, and disabling Google Play Protect via UI automation. A novel store-and-forward exfiltration enables staging on offline devices and relay over Wi‑Fi Direct, Bluetooth RFCOMM, or BLE GATT via nearby infected peers in up to four hops, allowing data leakage even without direct internet connectivity.
An OpenAI outage disrupted ChatGPT logins, signups, and access to prior conversations, with users encountering persistent loading and “too many concurrent requests” errors. The incident extended to multiple OpenAI API endpoints, affecting third-party integrations. OpenAI acknowledged the issue, marked it as identified, and said it was implementing a mitigation while monitoring and testing.