< ciso
brief />
Tag Banner

All news with #aws s3 tag

185 articles

AWS Security Hub adds S3 CSV and JSON exports

πŸ“ AWS Security Hub now supports exporting findings directly to Amazon S3 in either CSV or JSON (OCSF) formats. This feature lets security teams export from any findings page β€” including Threats, Exposure, Vulnerabilities, Posture Management, Sensitive Data, and All Findings β€” without building custom extraction pipelines. Exports can be started on demand and delivered to an S3 bucket in your account. The JSON option aligns with the Open Cybersecurity Schema Framework (OCSF).
read more β†’

Amazon S3 Vectors adds metadata pre-filtering in GovCloud

🟦 Amazon S3 Vectors metadata pre-filtering is now available in the AWS GovCloud (US-East) and AWS GovCloud (US-West) Regions. Pre-filtering evaluates metadata filters before running similarity search, returning up to 5x more matching vectors for selective filters. S3 Vectors also introduces a $startsWith prefix operator for filtering values like paths and URLs. New vector buckets in GovCloud use pre-filtering by default; existing indexes can be updated in place via the UpdateIndexMode API.
read more β†’

Amazon Redshift adds Iceberg materialized views

πŸš€ Amazon Redshift now supports creating and refreshing Apache Iceberg materialized views that store precomputed joins and aggregations as Iceberg tables in Amazon S3 and register them in the AWS Glue Data Catalog. Materialized views are created with SQL using CREATE MATERIALIZED VIEW ... USING ICEBERG and are queryable by Iceberg-compatible engines such as Amazon Athena, Apache Spark on Amazon EMR, AWS Glue, and third-party engines like Trino or Snowflake. Redshift provides manual incremental refreshes to recompute only changed data, and the resulting Iceberg tables are discoverable and governed through the Glue Data Catalog.
read more β†’

Redshift Cross‑Region S3 Data Lake Query Support

πŸš€ Amazon Redshift now lets customers query Amazon S3 data lake tables in a different AWS Region while keeping query traffic within their VPC using enhanced VPC routing. The integrated data lake query engine runs on RG provisioned and Serverless cluster compute, avoiding public networks and supporting compliance needs. Cross‑Region queries remove the need to copy or replicate data, simplify global analytics, and incur standard data transfer charges.
read more β†’

Amazon DynamoDB adds filtered export to S3

πŸ” Amazon DynamoDB now supports filtered export to Amazon S3, letting you export only the items and attributes you specify. Using a key condition expression, filter expression, and projection expression, you can produce datasets tailored for granular recovery, cross-account transfers, analytics, or compliance. Filtered export works with both full and incremental exports and is available in all AWS Regions except AWS GovCloud (US). See the DynamoDB developer guide to get started.
read more β†’

S3 Object Lock Variable Retention in GovCloud

πŸ”’ Amazon S3 Object Lock variable retention with event holds is now available in AWS GovCloud (US-East) and AWS GovCloud (US-West). This feature lets you place an event hold with a retention duration so objects receive WORM protection starting from a future event, such as a contract close or audit completion. Unlike legal holds, event holds enforce retention for the specified period after release, helping meet event-based regulatory requirements without over-retention. Cohasset Associates has assessed this capability for SEC, FINRA, and CFTC compliance contexts.
read more β†’

Amazon S3 Tables raise table bucket quota to 100

πŸ”” Amazon S3 Tables now support up to 100 table buckets per AWS Region in an AWS account, increased from 10, allowing up to 1 million tables per Region. The higher default quota applies to all accounts at no additional cost and is available in all Regions where S3 Tables are offered. With more buckets you can separate datasets, workloads, or teams and apply bucket-level settings such as encryption, access policies, and replication. If you need more than the default, request a quota increase through AWS Support.
read more β†’

AWS introduces system-managed Iceberg materialized views

πŸ›ˆ AWS announces system-managed materialized views for Apache Iceberg that lock write access to view data and definitions to AWS Glue. These views let you precompute expensive queries and store results as standard Iceberg tables in Amazon S3 while preventing other writers from altering the computed outcome. You define the view with SQL and an optional refresh schedule; AWS Glue computes and maintains the results in the Glue Data Catalog. The feature is available in all supported regions, providing governed, consistent datasets readable by Iceberg-compatible engines.
read more β†’

AWS introduces system-managed Iceberg materialized views

πŸ”” AWS announces system-managed materialized views for Apache Iceberg in AWS Glue. These views precompute queries and store results as standard Iceberg tables in Amazon S3 while preventing any writer other than AWS Glue from modifying the data or view definition. You define the view with SQL and an optional refresh schedule; AWS Glue computes, stores, and maintains the result so any Iceberg-compatible engine can read it reliably. The feature is available in regions that support Iceberg materialized views.
read more β†’

Amazon S3 Vectors adds metadata pre-filtering option

πŸ”Ž Amazon S3 Vectors now supports metadata pre-filtering to evaluate filters before similarity search, returning up to 5x more matching vectors when filters are selective. It also introduces a $startsWith prefix-match operator for filtering on paths and URLs. New indexes in vector buckets enable pre-filtering by default; existing indexes can be updated with the UpdateIndexMode API. The feature is available at no extra cost across commercial and China AWS Regions and will be deployed in the coming days.
read more β†’

Aurora PostgreSQL adds direct Iceberg and Parquet query

πŸš€ Starting today, Aurora PostgreSQL can directly query operational data alongside data stored in data lakes in Apache Iceberg and Parquet formats using your existing PostgreSQL applications and tools. You can create PostgreSQL foreign tables that reference data in Amazon S3, Amazon S3 Tables, or AWS Glue Data Catalog, and queries against those foreign tables use DuckDB’s high-performance engine embedded in PostgreSQL. The capability supports external Iceberg REST Catalog–compatible catalogs federated via AWS Glue Data Catalog, and data can be materialized into native Aurora tables for low-latency workloads. It is generally available on Aurora PostgreSQL versions 17.11, 18.6 and higher across AWS commercial and GovCloud (US) Regions at no extra charge.
read more β†’

Amazon S3 Express One Zone expands to seven regions

πŸš€ Amazon S3 Express One Zone is now available in seven additional AWS Regions: Singapore, SΓ£o Paulo, N. California, Canada (Central), Paris, Sydney, and Seoul. This single-Availability Zone storage class is engineered for consistent single-digit millisecond access and is optimized for latency-sensitive workloads. S3 Express One Zone offers up to 10x faster data access and up to 80% lower request costs versus S3 Standard. The expansion brings the storage class to 15 AWS Regions overall.
read more β†’

Amazon ECS adds S3 Files support for EC2 tasks

πŸ“ Amazon Elastic Container Service (Amazon ECS) now supports Amazon S3 Files for tasks using the Amazon EC2 launch type, allowing containerized applications to access S3 data as a shared file system. This extension enables file-based applications, AI agents, and data processing workloads to use standard file system semantics without code changes or data duplication. S3 Files was already available for ECS on AWS Fargate and ECS Managed Instances and now provides consistent access across all three ECS launch types.
read more β†’

Lambda adds direct read control for S3 Files

πŸ“’ AWS Lambda now supports configurable direct reads for Amazon S3 Files, letting you choose whether functions read from S3 Files high-performance storage or directly from your S3 bucket. This setting enables optimizing throughput and latency per application by routing large reads (β‰₯1 MB) directly from the bucket for maximum throughput when enabled, or serving all reads from high-performance storage for lowest latency when disabled. The feature is available across most AWS commercial and GovCloud regions and can be configured via Console, CLI, SDKs, or CloudFormation with no additional charge beyond standard pricing.
read more β†’

Storage Gateway adds FIPS PrivateLink for S3

πŸ”’ AWS Storage Gateway now supports FIPS 140-3 validated endpoints over AWS PrivateLink for Amazon S3 File Gateway, enabling private, FIPS-compliant traffic on the AWS network. Previously, FIPS endpoints were reachable only via the public internet. File Gateway and S3 can now be accessed through FIPS interface VPC endpoints, and gateways must run software version 2.1.10 or later to activate a FIPS PrivateLink endpoint.
read more β†’

Amazon S3 Object Lock Adds Variable Retention

πŸ”’ Amazon S3 Object Lock now supports variable retention via event holds that start on a future triggering event, enabling WORM protection that begins when a contract closing, audit completion, or similar event occurs. You can apply event holds to individual objects, set them as a bucket default, or scale them with S3 Batch Operations, while new IAM and bucket policy condition keys let you control who can set or release holds and enforce duration limits. CloudTrail logs hold operations and S3 Inventory reports hold status; the feature is available in all AWS Regions at no extra charge and has relevant regulatory assessments.
read more β†’

Amazon S3 Adds PrivateLink for FIPS Endpoints

πŸ”’ Amazon S3 now supports AWS PrivateLink for endpoints validated under the FIPS 140-3 program, enabling customers to use FIPS-validated cryptographic modules while keeping traffic inside their VPC. To enable, create or edit an interface VPC endpoint for S3 and select the FIPS S3 endpoint. This feature is available at no additional cost in several AWS Regions, including US East, US West, Canada, and AWS GovCloud (US).
read more β†’

AWS Backup Expands S3 Bucket Protection Limit

πŸ”’ AWS Backup now supports protecting and restoring more than 1,000 Amazon S3 buckets per account, aligning with the Amazon S3 bucket quota set for each account. Previously limited to 1,000 buckets, this update enables protection of all general-purpose buckets without requiring changes to existing backup plans when using default AWS Backup managed policies. The feature is available across all AWS commercial and AWS GovCloud (US) Regions; consult AWS Backup documentation for custom policy permissions.
read more β†’

CloudFront OAC Adds Native Support for S3 MRAP

πŸ”’ Starting today, CloudFront can use Origin Access Control (OAC) to restrict access to Amazon S3 Multi-Region Access Points (MRAP), allowing only designated CloudFront distributions to reach MRAP origins. This native integration removes the need for customers to compute and forward SigV4a Authorization headers via custom Lambda@Edge functions. CloudFront now signs requests to S3 MRAP origins, improving cache-miss fill performance from the nearest replicated region and enforcing OAC-secured access. The feature is available globally except in the CloudFront China region and can be enabled via Console, SDK, CLI, or CloudFormation with no additional fees.
read more β†’

Redshift adds long-term system table retention

πŸ“Œ Amazon Redshift now supports long-term retention of system table data through native integration with Amazon S3 Tables in Apache Iceberg format. This eliminates the prior 7-day limit and removes the need for custom ETL pipelines by automatically writing, partitioning, compacting, and retaining system table data in S3. The stored data can be queried via Redshift, Athena, or any Iceberg-compatible engine for cross-warehouse observability and auditing.
read more β†’