< ciso
brief />
Tag Banner

All news with #aws security hub tag

36 articles

AWS Security Hub Extended Adds Supply Chain Security

πŸ”’ AWS Security Hub Extended has added Supply Chain Security as its tenth curated category, expanding the program to 23 partners. The launch features Chainguard and Socket as integrated partners, offering rebuilt, provenance-backed open source packages and behavioral package analysis respectively. Both offerings are available via pay-as-you-go pricing or Private Offers for committed terms, and findings flow into Security Hub in OCSF to correlate supply chain risk with other security signals. The move aims to reduce activation friction and enable cross-partner correlation across endpoint, identity, cloud, and more.
read more β†’

Route Bedrock Guardrails Interventions to Security Lake

πŸ”’ This post shows how to route Amazon Bedrock Guardrails intervention events into Amazon Security Lake by transforming model invocation logs into OCSF-compliant Detection Finding records. It outlines an automated pipeline using CloudWatch Logs subscription filters, an AWS Lambda transformer, Parquet output, and Security Lake partitions so analysts can query guardrail events alongside identity, network, and application telemetry. The solution maps guardrail fields to OCSF attributes, supports multi-account deployment, and offers scaling guidance and an alternative CloudWatch-only approach.
read more β†’

AWS Security Hub Extended adds supply chain security

πŸ”’ The AWS Security Hub Extended plan now adds Supply Chain Security as its 10th category, integrating curated partners Chainguard and Socket. This enables detection and blocking of malicious dependencies before they reach builds and maintains streamlined activation with pay-as-you-go pricing. The Extended plan now includes 23 curated partner solutions, all billed on a single AWS invoice with no long-term commitments.
read more β†’

AWS Security Hub MCP App preview announced

πŸ›‘οΈ The AWS Security Hub MCP App preview introduces a local Model Context Protocol (MCP) server that brings Security Hub exposure findings into Claude Desktop to streamline investigations. The app enables natural-language investigation of top findings, attack and network paths, correlated findings, affected resource configurations, and remediation suggestions. The MCP server runs locally using existing AWS credentials and is read-only. This preview is available at no additional cost in all commercial Regions that support Security Hub.
read more β†’

Security Hub expands to AI protections and Azure

πŸ”’ Security Hub now adds native AI workload protection and Microsoft Azure monitoring to centralize enterprise security across clouds. It discovers Azure resources, evaluates posture against CIS benchmarks, and prioritizes findings alongside AWS signals using the same formats and workflows. New GuardDuty AI Protection detects anomalous model invocations and cost-harvesting, while AI-powered investigations accelerate triage. A continuous AI inventory catalogs models and agents across accounts, and Security Hub Extended integrates 21 curated partners to broaden coverage.
read more β†’

AWS Security Hub adds AI inventory for visibility

πŸ›‘οΈ AWS Security Hub now offers an AI inventory that gives central security teams a continuously updated, organization-wide view of AI assets and their security posture. It automatically discovers AI workloads via managed-service integration, SBOM analysis for self-hosted workloads, and GuardDuty DNS telemetry for external API endpoints. Discovered assets are mapped to underlying infrastructure and correlated with security findings to help prioritize remediation. The feature is included with Security Hub Essentials at no additional cost and is available in all commercial AWS Regions where Security Hub is offered.
read more β†’

AWS Security Hub adds internet Network Scanning

πŸ” AWS Security Hub now includes Network Scanning to identify resources that are actually reachable from the public internet. The feature probes public IPs, VMs, and load balancers across AWS and Azure, detects reachable ports, and identifies services running behind them. Findings are created per reachable port and correlated by Security Hub Exposures to assess broader risk. Existing customers can enable the feature per account, region, or organization; it is enabled by default for new customers and included with Security Hub Essentials at no extra cost in supported commercial Regions.
read more β†’

AWS Security Hub adds impact analysis for exposures

πŸ” Today, AWS Security Hub introduces impact analysis for exposure findings, enabling security teams to see the downstream resources an attacker could reach if an exposure is exploited. The feature maps privilege escalation paths by analyzing effective IAM permissions and displays potential attack paths in a graph. A new Impact Assessment tab prioritizes chains of compromise and shows the permissions at each step, while severity scores are adjusted to reflect downstream reach.
read more β†’

AWS Security Hub Adds Microsoft Azure Monitoring

πŸ”’ AWS Security Hub now monitors Microsoft Azure resources, extending risk analytics, cloud security posture management, vulnerability management, and security response across both clouds. The service auto-discovers Azure VMs, ACR images, Function Apps, and identities, evaluating misconfigurations, internet exposure, and software vulnerabilities. Findings from AWS and Azure appear in a single prioritized view with consistent formats and automation workflows, and a 30-day free trial for Azure monitoring is available.
read more β†’

Palo Alto DNS Security Preview for Route 53 Resolver

πŸ›‘οΈ Amazon Web Services announces a preview integration of Palo Alto Networks Advanced DNS Security with Route 53 Resolver DNS Firewall. Security teams can now subscribe to PANW protections directly from the DNS Firewall console and apply categories like Command and Control, Malware, and Phishing without deploying separate firewalls. The integration supports hybrid traffic, AWS multi-account management, centralized visibility via AWS Security Hub, and preview availability across multiple regions.
read more β†’

Operationalizing AWS security: a maturity roadmap

πŸ”’ This post outlines a practical, phased maturity roadmap for organizations that have enabled AWS Security Hub and Amazon GuardDuty. It emphasizes moving from enabled tooling to operational security practices by assessing current state, tuning signal quality, routing findings, automating safe remediations, and establishing a recurring operational cadence. Each phase includes goals, timelines, deliverables, and decision criteria to measure progress and reduce alert fatigue.
read more β†’

AWS Config adds internal service linked rules support

πŸ”’ AWS Config now supports internal service linked rules, allowing AWS services to evaluate resource configurations using AWS Config managed rules. These rules let AWS services like AWS Security Hub CSPM deploy and manage service-specific evaluations, with results sent directly to the deploying service. Evaluations occur at no charge from AWS Config and run independently of customer-managed recorders and rules, preserving existing inventory and compliance workflows. The feature is available in commercial, GovCloud, and China Regions.
read more β†’

AWS Security Hub Adds Unused Identity Access Detection

πŸ” AWS Security Hub now brings identity risk into the same unified console where central security teams manage threats, exposures, and posture findings. It detects unused IAM permissions, roles, and credentials across an AWS organization and correlates those identity findings with exposure context. When enabled, Security Hub automatically creates a service‑linked IAM Access Analyzer in each member account and evaluates 90 days of actual access activity. It also offers on‑demand recommended least‑privilege policies and is included in Security Hub Essentials at no additional cost.
read more β†’

AWS Security Hub Extended Expands Curated Partner Set

πŸ”’ AWS Security Hub Extended adds 21 curated partner solutions across nine security categories, including SentinelOne, CyberArk, Sublime, Varonis, LayerX, Native Security, and Zenity. The plan centralizes procurement, billing, and support with pay-as-you-go pricing, a single AWS bill, automatic Enterprise Discount Program eligibility, unified Level 1 support for Enterprise customers, and no long-term commitments. Findings from participating solutions are emitted in the OCSF schema and aggregated in AWS Security Hub to accelerate cross-domain detection and response.
read more β†’

Security Hub Extended: A New Product-Led Adoption Model

πŸ”’Security Hub Extended expands AWS Security Hub to include curated partner solutions in a single, unified console. Customers can discover, evaluate, and deploy vendor products with one click and pay-as-you-go pricing on their AWS bill, avoiding lengthy procurement and multi-year commitments. Integrated onboarding, OCSF-normalized findings, and AWS-native correlation surface combined attack paths and risk scoring. The offering launched in February 2026 with an expanding partner ecosystem.
read more β†’

Technical Walkthrough: AWS Security Hub Extended, Multicloud

πŸ”’ AWS Security Hub Extended consolidates AWS and curated partner security services into a unified, pay-as-you-go offering for multicloud full-stack protection. It centralizes procurement, billing, and operations across endpoint, identity, email, network, data, browser, cloud, and AI protections while integrating findings in OCSF format. Customers can onboard via the AWS Console, assign delegated administrator accounts for centralized management, and route normalized findings to tools such as Splunk and 7AI for coordinated response.
read more β†’

Amazon CloudWatch Ingests AWS Security Hub Findings

πŸ”” Amazon CloudWatch now ingests AWS Security Hub CSPM findings into CloudWatch Logs, supporting both ASFF and OCSF schemas via CloudWatch Pipelines. Customers can query findings with CloudWatch Logs Insights, create metric filters for monitoring, and use Amazon S3 Tables for advanced analytics and reporting. Organization-level enablement rules allow automatic delivery to all accounts or selected groups, standardizing monitoring coverage. Findings delivery is available in all AWS commercial regions and is charged under tiered CloudWatch pricing.
read more β†’

AWS Security Hub Now Available in GovCloud US Regions

πŸ”’ AWS Security Hub is now available in the AWS GovCloud (US-East) and AWS GovCloud (US-West) Regions. Security Hub offers a unified cloud security posture by correlating and enriching signals from Amazon GuardDuty, Amazon Inspector, and Security Hub CSPM to prioritize active risks. The service delivers near‑real‑time risk analytics, exposure findings, automated response workflows, attack path visualization, and centralized organization-wide deployment with streamlined pricing for improved cost predictability.
read more β†’

Managing the AMI Lifecycle with AMI Lineage on AWS

πŸ›‘οΈ This post presents the AMI Lineage solution to help organizations track and govern Amazon Machine Images (AMIs) across AWS. It explains how AWS lineage metadata (announced at the end of 2024) can be combined with a centralized Amazon Neptune graph, EventBridge, Lambda, API Gateway, and Security Hub to validate image origins, enforce SCPs, and assess CVE impact. The architecture uses a three-account model (management, security tooling, member) to centralize sensitive processing, automate compliance checks, and provide queryable lineage and remediation workflows for security teams.
read more β†’

AWS Security Hub Expands to Unify Multicloud Operations

πŸ”’ AWS announced a major expansion of AWS Security Hub, repositioning it as a unified security operations solution that aggregates signals from across the stack and across clouds. The service now consolidates findings from services such as Amazon GuardDuty, Amazon Inspector, Security Hub CSPM, and Amazon Macie into a single pane for prioritized risk analytics. An Extended plan simplifies procurement and partner integrations, with AWS as seller of record and pay-as-you-go billing. AWS says forthcoming multicloud capabilities will add a common data layer, unified policies, expanded vulnerability scanning, and external network exposure checks.
read more β†’