
AWS AI, DR, and Data Updates; Next.js RCE; CISA Citrix Order
Coverage: 27 Aug 2026 (UTC)
< view all daily briefs >AWS led a dense slate of platform updates spanning AI agents, data platforms, and resilience, alongside Google’s new serverless option for long-lived agents and Microsoft’s broad security enhancements. Security teams also faced urgent patching for Next.js and Citrix NetScaler, while Boston Scientific disclosed a global IT disruption. Research and disclosures covered GPU memory attacks, an ATF "major incident," and an agentic IDE prompt-injection fix.
AI Agents and Model Platforms Expand
NVIDIA’s Cosmos 3 family is now available through SageMaker JumpStart, bringing Cosmos3-Edge (4B parameters for on-device robot control and real-time visual reasoning), Cosmos3-Nano (16B for physics-aware world generation and multimodal physical reasoning), and Cosmos3-Super (64B for high-fidelity world simulation and synthetic data) to AWS customers. The models support resolutions up to 720p and chain-of-thought reasoning across modalities, and can be launched via the SageMaker console or Python SDK to accelerate robotics, autonomous systems, and simulation workflows.
AWS also added Meta’s Muse-Glimmer-30B and Alibaba’s Qwen 3.8-27B to SageMaker JumpStart. Muse-Glimmer-30B targets autonomous, agentic tasks with a ViT-G/14 vision encoder and 131K+ context; Qwen 3.8-27B is a vision-language model for coding and complex multi-step tasks with a 262K native context (extendable via YaRN). Both offer selectable reasoning levels and are deployable from the JumpStart catalog or programmatically, expanding options for enterprise agents and multimodal applications on AWS.
AgentCore from Amazon Bedrock expanded to US West (N. California) and Asia Pacific (Hyderabad), providing agent runtime, identity and access control, policy management, session persistence, tool connectivity, evaluations, and observability in additional regions. AWS highlights enforcement at the infrastructure layer to prevent agents from bypassing controls, with the expansion intended to reduce latency and ease compliance planning for local deployments.
Google introduced preview Cloud Run instances for long‑lived, stateful workloads such as personal AI agents. Each instance runs as a single dedicated replica (no autoscaling), can run continuously for up to seven days with automatic restarts, exposes a stable HTTPS URL, and uses shared vCPU with burst budgets for predictable pricing. The feature aims to bridge the gap between ephemeral serverless services and always‑on VMs for always‑available agent processes.
Microsoft detailed wide-ranging Microsoft Security enhancements: expanding Defender Experts Threat Intelligence and MDR with third-party data via Sentinel; introducing Entra Tenant Governance to reduce shadow-tenant risk; device-management improvements including Windows Autopilot association and Unattended Support with Remote Sign-In; and scaling Purview auto-labeling to 500,000 SharePoint and OneDrive files daily. New Secure Now guidance focuses on agentic containment, identity governance, and improved visibility.
Backup and Disaster Recovery Strengthen
AWS DRS Recovery Plans automate ordered recovery for multi-server applications. Teams can define startup sequences, insert wait times and approval gates, run non-disruptive drills, and monitor progress in real time, reducing coordination overhead and error risk during disaster scenarios. The capability is available in all AWS Regions where AWS DRS is offered and adds no extra charge beyond standard usage.
FSx for ONTAP now supports copying backups across Regions and accounts, adding an extra protection layer for disaster recovery, isolation, and compliance. In parallel, AWS Backup enables policy-based or on-demand cross-Region and cross-account copies of FSx for NetApp ONTAP backups, centrally managed and automatable via AWS Organizations to simplify governance.
Data Platforms and Compute Updates
Redshift streaming can now ingest Amazon Kinesis Data Streams records up to 10 MiB, a tenfold increase that removes the need to split large producer payloads and broadens high-volume use cases. Separately, Redshift integrated with the Agent Toolkit for AWS, allowing AI agents—via the AWS MCP server and curated Redshift skills—to perform tasks from query generation and metadata exploration to data loading, performance tuning, and migrations on both provisioned and Serverless deployments.
EC2 X8i instances became available in Europe (Milan) and Europe (Spain). Powered by AWS-exclusive Intel Xeon 6 processors and SAP-certified, X8i delivers up to 43% higher performance than X2i, 1.5x larger memory capacity (up to 6TB), and 3.3x greater memory bandwidth, with workload-specific gains such as up to 50% higher SAPS and 46% faster AI inference.
Amazon EVS now supports the i7i.metal-48xl bare-metal instance, offering higher core counts, larger memory, and increased storage versus prior i4i hosts. AWS cites up to 23% improved compute performance and more than 10% better price performance, enabling higher VM consolidation, access to VCF 9.x features such as memory tiering, and new automations like Amazon EVS Deployment Orchestrator.
Patches, Exploits, and Incidents
Vercel issued emergency fixes for unauthenticated RCEs in Next.js, including an AVIF processing flaw tied to libheif and a Windows-only path traversal (CVE-2026-75604, CVSS 9.0). Patches are in 15.5.24 and 16.3.3, with AVIF optimization temporarily disabled pending a corrected dependency. Details are summarized by The Hacker News.
CISA added CVE-2026-8452 for Citrix NetScaler to the KEV catalog and ordered federal agencies to patch by August 29 under BOD 26-04. Researchers demonstrated RCE as root on unpatched appliances, and mass exploitation has included web shell drops; coverage via BleepingComputer notes tens of thousands of exposed instances and a history of NetScaler flaws used by ransomware.
Boston Scientific reported a cyber incident causing a global IT disruption and network outage that limited access to systems and impeded order processing and shipping. The company activated response protocols and engaged third-party experts; recovery timelines remain unknown. See Infosecurity Magazine for details.
University of Toronto researchers disclosed GPUThor, a GPU Rowhammer-style attack on NVIDIA Ampere-class workstation GPUs using GDDR6 that can defeat SECDED ECC and enable host privilege escalation. The work observed high flip rates, detected uncorrectable errors with ECC enabled, and exploited timing windows to achieve root shells; no in-the-wild exploitation or CVE is reported. Coverage via The Hacker News.
The ATF confirmed a "major incident" after the Qilin ransomware group’s breach claims, stating a standalone system was compromised while asserting no evidence of impact to the enterprise network, eForms, or other systems. Investigations are ongoing with the Department of Justice. Read more at BleepingComputer.
Researchers at Mindguard disclosed a prompt-injection issue in Amazon’s agentic IDE Kiro (fixed in 0.8.140) that allowed crafted repository content and steering files to drive sensitive data exfiltration once a workspace was opened and the agent messaged. The flaw reflected a trust boundary failure across model instructions, IDE configuration, and network actions; see The Hacker News for the disclosure.
A ThreatsDay bulletin highlighted diverse activity: an operator-driven phishing framework maintaining live WebSocket sessions, a nearly 296,000-device IoT compromise offering residential proxies, a C++ loader shifting C2 to Polygon smart contracts, and malware controllers integrating LLM analysis. Additional items included an HP ThinPro boot-chain vulnerability and Q2 2026 mobile telemetry showing nearly 2 million blocked attacks. Summary via The Hacker News.