< ciso
brief />
Tag Banner

All news with #aws tag

2919 articles

Unplanned Paths Into Cybersecurity Careers

🔎 Shannon Brazil shares candid interviews with AWS security professionals about their unconventional routes into cybersecurity. She profiles individuals who transitioned from retail, marketing, and troubled youth into roles like bug bounty, OSINT, and technical risk, highlighting curiosity and persistence as common drivers. The piece introduces a four-part series for Cybersecurity Awareness Month that will explore varied roles and advice for newcomers.
read more →

AWS Config expands coverage with 77 new types

🆕 AWS Config now supports 77 additional AWS resource types across services including Amazon EC2, Amazon S3 Files, and Amazon Q Business, expanding visibility and governance. If you have enabled recording for all resource types, these additions are tracked automatically and are available for use in Config rules and Config aggregators. The new resource types can be monitored in all AWS Regions where the resources are available, enabling more comprehensive discovery, assessment, audit, and remediation.
read more →

Claude Haiku 5.5 arrives on AWS for cost‑sensitive AI

🚀 Claude Haiku 5.5 is now available on AWS, offering the fastest and most efficient model in the Haiku 5.5 family designed for subagents and high‑volume, cost‑sensitive workloads. Anthropic reports Haiku 5.5 costs about 75% less than Haiku 4.5 for many tasks while improving performance across coding, tool use, agents, and classification. Customers can access Haiku 5.5 via Amazon Bedrock for AWS‑resident deployments or via the Claude Platform on AWS for the native Anthropic experience integrated with AWS billing and authentication.
read more →

Claude Haiku 5.5 Now Available in AWS GovCloud

🔒 AWS GovCloud (US) now offers Claude Haiku 5.5, Anthropic’s fastest and most efficient Haiku model, optimized for subagents and high-volume, cost-sensitive workloads. According to Anthropic, it reduces costs by about 75% compared to Haiku 4.5 for many tasks. Haiku 5.5 introduces effort controls for tuning cost versus intelligence and is suited for real-time experiences and large-scale classification, summarization, and extraction jobs. Amazon Bedrock provides access while keeping data within AWS regional infrastructure and offers AWS-managed features like Guardrails and Knowledge Bases.
read more →

Improving SPIRE Security and Resiliency on AWS

🔒 This post explains how to strengthen SPIRE (the SPIFFE Runtime Environment) deployments by offloading core functions to AWS managed services. It outlines replacing default SPIRE components with AWS KMS, AWS Private CA, Amazon Aurora, Amazon S3, AWS Secrets Manager, and Amazon Verified Permissions to improve security, scalability, and operational resiliency. A GitHub repository provides deployment templates and configuration examples to follow along.
read more →

AWS Batch publishes job metrics to CloudWatch

📊 AWS Batch now publishes job lifecycle metrics natively to Amazon CloudWatch, improving observability for batch workloads. Metrics include state transitions (submitted, running, succeeded, failed) and duration metrics (time between states and total execution time) under the AWS/Batch namespace with a JobQueueName dimension. These metrics are viewable in the AWS Batch console, CloudWatch console, AWS CLI, and SDKs, and are available in all Regions where AWS Batch runs.
read more →

ACM Adds PrivateLink for ACME Certificate Issuance

🔒 AWS Certificate Manager (ACM) now supports AWS PrivateLink for ACME public certificate issuance, enabling requests and renewals over a private network path within the AWS network. You can create a VPC interface endpoint to the ACM ACME service and route issuance traffic from any ACMEv2-compatible client through your VPC. Existing ACME clients require no configuration changes because Private DNS resolves the same ACME directory URL to the interface endpoint internally. Issuance operations and monitoring remain available via the ACM console, AWS CloudTrail, and Amazon CloudWatch.
read more →

Amazon Redshift adds Iceberg materialized views

🚀 Amazon Redshift now supports creating and refreshing Apache Iceberg materialized views that store precomputed joins and aggregations as Iceberg tables in Amazon S3 and register them in the AWS Glue Data Catalog. Materialized views are created with SQL using CREATE MATERIALIZED VIEW ... USING ICEBERG and are queryable by Iceberg-compatible engines such as Amazon Athena, Apache Spark on Amazon EMR, AWS Glue, and third-party engines like Trino or Snowflake. Redshift provides manual incremental refreshes to recompute only changed data, and the resulting Iceberg tables are discoverable and governed through the Glue Data Catalog.
read more →

AWS Continuum Raises Bar for Autonomous Code Security

🔒 AWS reports that Continuum for code vulnerabilities achieved an 89.0% end-to-end pass rate on the CyberGym-E2E benchmark, passing 819 of 920 tasks within a 90-minute limit. The multi-agent system improved on prior public results across all measured stages (discovery, validation, remediation) and reached 93.7% when allowed to run longer. The evaluation was conducted under network-isolation and submission-review rules to ensure results came from analysis rather than retrieval.
read more →

AWS Identity Store adds network access controls

🔒 IAM Identity Center now supports network access controls for the Identity Store and SCIM APIs, letting you restrict API requests by VPC endpoints, source VPCs, or IP ranges. You can apply different restrictions per API and exempt AWS service requests; controls are optional and disabled by default. Configuration is done via the Identity Store API using AWS SDKs or AWS CLI and is available in all Regions where IAM Identity Center is offered.
read more →

AWS Control Tower AFT adds plan-only customization

🛠️ AFT now supports plan-only customization runs that let administrators preview Terraform changes without applying them. This update enables safe pre-rollout validation, drift detection, and integration with CI/CD review workflows across all AFT-supported Terraform distributions. The feature is available in all Regions where AWS Control Tower Account Factory for Terraform is supported; see the AFT documentation and 1.22.0 release notes for setup details.
read more →

AWS Continuum Adds CI/CD Integrated Pentesting

🛠️ AWS Continuum for Penetration Testing (formerly AWS Security Agent) now offers public preview CI/CD integration that makes penetration testing a deploy-time event. The service delivers findings—including severity, affected endpoints, and remediation guidance—directly in pipeline output while avoiding meaningful delays for non-security changes. Teams can paste an auto-generated pipeline snippet into existing workflows and complete setup in under five minutes, with application context bootstrapped automatically on first run.
read more →

AWS Builder Center adds availability and filtering

🔔 AWS announces feature-level availability notifications and enhanced filters in AWS Builder Center for AWS Capabilities by Region. Builders can subscribe to service- or feature-level notifications and receive in-app alerts and a weekly email digest for selected Regions, including an 'All regions' option that covers future Region launches. New filters let users view API operations and CloudFormation resources by availability status and compare Regions by shared or differing availability across more than 19,000 API operations and 5,000 resource types.
read more →

EC2 AMI Shared Tags Simplify Cross‑Account Metadata

🔖 Amazon EC2 now supports AMI tag sharing, enabling AMI owners to expose selected tags to any AWS account the AMI is shared with. Owners prepend the tag key with ec2:SharedTag/ so the tag is automatically visible to recipient accounts without manual replication. Shared tags are read-only for recipients and count only against the owner's tag quota, and the feature is available in all Regions at no extra cost.
read more →

AWS Client VPN adds device posture assessment

🔒 AWS Client VPN now supports device posture assessment, enabling verification that connecting user devices meet security and compliance requirements before granting access. This integrates with existing posture providers such as CrowdStrike, Jamf, and JumpCloud and uses Cedar policies for fine-grained control. A Test Policy tool helps you author and validate posture rules, and evaluations can be enforced or run in monitoring-only mode. The feature continuously re-evaluates active sessions and is available in all AWS Regions at no extra cost, requiring AWS VPN Client v6.2.0+.
read more →

AWS Batch adds EKS access entry authentication

🛠️ AWS Batch now supports Amazon EKS access entry authentication for compute environments. EKS access entries provide an API-driven way to grant IAM principals access to Kubernetes clusters, complementing the existing aws-auth ConfigMap. To enable, set accessEntry.desiredState to ENABLED via the CreateComputeEnvironment or UpdateComputeEnvironment APIs; AWS Batch creates one access entry per cluster and attaches the AWSBatchClusterPolicy. This feature is available in all Regions where AWS Batch is offered.
read more →

AWS Private CA adds detailed issuance logs

📜 The new AWS Private CA CloudTrail IssueCertificateDetails event records full certificate content, issuing CA data, requester identity, and signing status for every issuance. It captures the complete TBS certificate with X.509 fields and convenience fields like subject, issuer, serial, validity, template, and algorithm. Events include both successful and failed issuances and identify the requester (account/IAM principal or service principal). Delivered automatically as a CloudTrail management event in supported Regions, it can be consumed in real time via EventBridge or queried with Athena at standard CloudTrail cost.
read more →

Amazon Nova 2.5 Sonic released for real-time voice

🎙️ Amazon announces general availability of Nova 2.5 Sonic, a speech-to-speech model optimized for real-time voice agents. The model improves reasoning, instruction following, and tool-calling accuracy while reducing latency for more natural interactions. It supports expressive voices in seven languages, a 256K context window, and integration with Strands Bidi Agents for production voice agents.
read more →

ECS adds VPC Lattice blue/green and canary deploys

🔧 Amazon Elastic Container Service (Amazon ECS) now provides built-in blue/green, linear, and canary deployment strategies for services using Amazon VPC Lattice. Applications using VPC Lattice for cross-VPC and cross-account communication can leverage managed traffic shifting directly from ECS when rolling out updates. Teams can validate new versions with test traffic, use lifecycle hooks for custom validations or manual approvals, and rely on CloudWatch alarms and the ECS deployment circuit breaker to trigger automatic rollbacks.
read more →

AWS Health launches version catalog for lifecycle management

📢 The new AWS Health version catalog centralizes lifecycle information for software versions across AWS services, enabling customers to shift from reactive to proactive upgrade and end-of-support management. Available in the AWS Health Dashboard, customers on Business Support Plus, Enterprise Support, or Unified Operations can also access the data via the AWS Health API to integrate version timelines into operational workflows. The catalog initially covers Amazon RDS, Amazon EKS, and AWS Lambda, is available across all AWS Commercial Regions, and will expand to include additional services over time.
read more →