< ciso
brief />
Tag Banner

All news with #aws tag

2592 articles

ToxicPanda Android malware adds VPN and ADB abuse

πŸ›‘οΈ ToxicPanda 2.0 now requests VPN service permissions to create a local interface that can block Google Play and Google Play Services, enabling it to interfere with app verifications, updates, and Play Protect checks. After establishing the VPN, the malware extracts and installs payloads, requests Accessibility Service permissions, and automates Wireless ADB to gain shell-level access. Zimperium reports distribution via AWS-hosted buckets and notes support for 167 remote commands and overlays targeting 349 financial apps across 16 countries.
read more β†’

Amazon Connect Customer adds conversational analytics

πŸ€– Managers can now query Amazon Connect Customer in plain language to get answers, evidence, and recommended fixes in seconds. The feature searches over 150 metrics across self-service, agent, and queue performance to identify what matters and explain why. Users can start with broad questions and drill downβ€”receiving prioritized actions with confidence scores and projected impact. Available in all Regions that support Amazon Connect Customer AI Agents.
read more β†’

AWS Deadline Cloud adds automatic download status

πŸ–₯️ The Deadline Cloud Monitor desktop app now displays download progress, status, and health for automatic job file downloads to your destination drive. The monitor provides visibility into render environments, jobs, resources, and costs, and the new Download status column appears at both job and task levels to confirm when outputs are available. An indicator shows how current the status is and the app provides guidance when files are unavailable.
read more β†’

AWS Glue 6.0: Lower Cost and Iceberg v3 Support

πŸš€ AWS Glue 6.0 is now generally available with a 30% price reduction and upgraded runtimes including Apache Spark 4.1, Python 3.13, and Scala 2.13. It adds full support for Apache Iceberg v3, newer Apache Hudi and Delta Lake versions, and productivity features such as Spark Declarative Pipelines, Real-Time Mode streaming, and Arrow-native Python UDFs. Glue 6.0 is available across AWS Commercial, GovCloud (US), and China regions.
read more β†’

Amazon SES adds per-request open and click tracking override

πŸ“£ Amazon Simple Email Service (SES) now supports per-request open and click tracking override parameters in the SendEmail and SendBulkEmail APIs. This lets senders enable or disable open and click tracking on individual API calls instead of managing multiple configuration sets. The override takes precedence over the associated configuration set and helps honor recipient-level consent requirements like GDPR and CNIL guidance. The feature is available in all AWS Regions where Amazon SES is offered and has no additional cost.
read more β†’

AWS Local Zone in Las Vegas Now Generally Available

πŸš€ The AWS Local Zone in Las Vegas, Nevada is now generally available. This Local Zone supports Amazon EC2 instances (C7i, M7i, R7i, C8gn), Amazon EBS volume types (gp3, gp2, io1, sc1, st1), Amazon ECS, Amazon EKS, Application Load Balancer, and AWS Direct Connect. AWS Local Zones extend AWS infrastructure closer to metropolitan areas to enable single-digit millisecond latency, address data residency, and support AI/ML inference and migration of legacy applications. Enable the Las Vegas Local Zone (us-west-2-las-2a) from the AWS Global View or use the ModifyAvailabilityZoneGroup API.
read more β†’

AWS expands Graviton4 EC2 instances with local NVMe

πŸš€ Amazon EC2 C8gd, M8gd, and R8gd instances with up to 11.4 TB of local NVMe SSD are now available in more regions. Powered by AWS Graviton4, they deliver up to 30% better performance than Graviton3 and improved I/O and query speeds for demanding workloads. Instances offer up to 50 Gbps network, EBS bandwidth controls, Elastic Fabric Adapter on larger sizes, and 12 sizes per family to suit diverse compute, balanced, and memory-intensive use cases.
read more β†’

Timestream for InfluxDB adds customer managed KMS

πŸ” Amazon Timestream for InfluxDB now supports AWS KMS customer managed keys to encrypt data at rest for InfluxDB 2 databases, InfluxDB 2 Read Replicas, and InfluxDB 3 clusters. Customers choose a symmetric AWS KMS key during resource creation; the key must reside in the same AWS account and Region and cannot be changed later. The capability is available via the AWS Console, AWS CLI, and the Timestream for InfluxDB API across all supported Regions, with standard AWS KMS charges applying.
read more β†’

AWS Network Firewall adds rule hit count visibility

πŸ”’ This post announces a new AWS Network Firewall capabilityβ€”rule hit countβ€”that provides visibility into how often stateful rules match network traffic across custom and managed rule groups. Rule hit counts increment when matches produce alert logs (alert, drop, reject), and pass rules can be tracked by adding the alert keyword. Alert logs include aws_metadata with resource ARN and signature ID, are delivered to CloudWatch Logs or S3, and drive the Top Rule Hits dashboard for monitoring and compliance validation.
read more β†’

Amazon EC2 P6‑B300 instances reach Seoul region

πŸš€ Amazon EC2 P6-B300 instances are now available in the Asia Pacific (Seoul) Region. These instances offer 8x NVIDIA Blackwell Ultra GPUs with 2.1 TB high-bandwidth GPU memory, 6.4 Tbps EFA networking, 300 Gbps dedicated ENA throughput, and 4 TB of system memory. The P6-B300 delivers 2x networking bandwidth, 1.5x GPU memory, and 1.5x GPU TFLOPS (FP4) versus P6-B200, targeting large trillion-parameter FMs and LLM training and deployment. The p6-b300.48xlarge size is available in Seoul, US West (Oregon), AWS GovCloud (US-East), and US East (N. Virginia).
read more β†’

Automated RDS Switchover for ARC Region Switch

βš™οΈ Amazon launches the RDS Switchover Read Replica execution block for ARC Region switch to automate recovery orchestration for Amazon RDS databases using Oracle Data Guard in multi-Region workloads. The feature automates role reversal or promotion between primary and read replica to enable zero data loss in planned failovers and rapid recovery in unplanned events. It includes native cross-account support for centralized recovery management.
read more β†’

Aurora DSQL adds CloudWatch Database Insights

πŸ” Amazon Aurora DSQL introduces a CloudWatch Database Insights metric that provides per-statement, cluster-level performance monitoring. The feature captures sampled wait states and normalized SQL statements for active sessions, helping diagnose performance issues and identify resource-heavy queries. Metrics are collected at 1-minute intervals, available by default at no additional cost, and usable with CloudWatch Database Insights, CloudWatch PromQL, and the Aurora DSQL system diagnostics AI skill.
read more β†’

Redshift adds long-term system table retention

πŸ“Œ Amazon Redshift now supports long-term retention of system table data through native integration with Amazon S3 Tables in Apache Iceberg format. This eliminates the prior 7-day limit and removes the need for custom ETL pipelines by automatically writing, partitioning, compacting, and retaining system table data in S3. The stored data can be queried via Redshift, Athena, or any Iceberg-compatible engine for cross-warehouse observability and auditing.
read more β†’

AWS Direct Connect adds inbound prefix controls

βš™οΈ AWS Direct Connect announced inbound prefix controls that let customers allocate and manage inbound route-prefix allocations for private and transit virtual interfaces (VIFs) based on workload needs. You can now assign up to 1,000 prefixes each for IPv4 and IPv6 on dedicated and hosted connections, up from a 100-prefix limit. New prefix capacity pools exist at the dedicated connection and Direct Connect gateway (DXGW) levels, and allocations are configurable via the console or CLI/API. This feature is available at no extra cost in all commercial AWS Regions, AWS GovCloud, and the China Regions operated by Sinnet and NWCD.
read more β†’

AWS Marketplace adds category-based partner notifications

πŸ“£ Partners can now configure category-based notifications and multi-channel delivery for AWS Marketplace through AWS User Notifications. Previously, notifications went only to the AWS account root email or custom aliases, without category routing. Partners can now assign contacts and delivery channels for four categories: Product listings, Offers and agreements, Payments and disbursements, and Account management. Notifications can be delivered by email, the AWS Console Mobile App, or chat via Amazon Q Developer in Slack and Microsoft Teams.
read more β†’

Amazon Bedrock expands Web Search with external access

πŸ”Ž Today AWS expanded Amazon Bedrock's Web Search to support an external_web_access parameter, allowing models to fetch live public web content while preserving control over data egress. Grant the bedrock-websearch:ExternalWebAccess IAM permission to enable live fetches; leaving the parameter false restricts results to Amazon's in-AWS index. The capability is available in US East (N. Virginia), US East (Ohio), and US West (Oregon).
read more β†’

EC2 AMI Creation with Local Outpost Snapshots

πŸ”” Amazon EC2 now allows creation of Amazon Machine Images (AMIs) using local snapshots from instances running on AWS Outposts. Customers may store snapshots on the Outpost or in the parent AWS Region, helping meet data residency needs. EC2 auto-selects the target Outpost based on the instance location, eliminating the need to specify an Outpost ARN. This feature integrates with existing backup and lifecycle workflows and is available where Outposts supports local snapshot storage.
read more β†’

CloudWatch Centralization Adds Tag Propagation

πŸ”” Amazon CloudWatch Centralization now copies log group tags from source accounts to destination log groups created by centralization rules. Tag propagation preserves cost, ownership, and compliance tags so teams can scope access and report spend centrally. The feature syncs tags based on propagation behavior chosen in the centralization rule and is available in all Regions where CloudWatch Centralization is offered.
read more β†’

Sakura Internet breach exposes up to 1.36M accounts

πŸ”’ Japanese cloud provider Sakura Internet disclosed unauthorized access to its sales management system storing customer contract and membership data. The company said the incident was discovered during a separate investigation into a smaller breach at its Sakura Rental Server service and that up to 1,360,563 accounts may have been affected. Sakura reported no confirmed data exfiltration, noted stored passwords are hashed and no credit card data is kept in the compromised system, and is notifying affected customers and authorities.
read more β†’

SageMaker notebooks add trusted identity propagation

🧭 Amazon SageMaker Notebooks now support Trusted Identity Propagation (TIP) with Amazon Athena, Amazon Redshift, and Amazon EMR Serverless, enabling per-user access control for data analytics. When connected to a TIP-enabled compute in a TIP-enabled Project, each notebook user's IAM Identity Center identity flows through to AWS Lake Formation, ensuring they see only the tables, columns, and rows their permissions allow. TIP provides per-user data boundaries, full audit attribution with CloudTrail, and reduces admin friction by automatically propagating identity through existing compute connections without extra logins or role management. The feature is available in all Regions where Amazon SageMaker Unified Studio is available.
read more β†’