< ciso
brief />
Tag Banner

All news with #aws security hub tag

41 articles

AWS Security Hub Adds GuardDuty Runtime Monitoring

🔔 AWS has integrated Amazon GuardDuty Runtime Monitoring into the AWS Security Hub Threat Analytics plan. This runtime capability inspects OS, network, and file activity to detect threats like container escapes, privilege escalation, and cryptomining across Amazon EC2, Amazon EKS, and Amazon ECS on AWS Fargate. Billing for Runtime Monitoring is now consolidated under Security Hub as a single usage type, eliminating separate GuardDuty Runtime Monitoring charges for accounts and regions with Security Hub enabled. Detection behavior, finding types, and GuardDuty agents remain unchanged, and no reconfiguration is required; free-trial terms for Threat Analytics and Security Hub Essentials remain separate.
read more →

AWS Security Hub adds remediation plans to prioritize fixes

🔒 AWS Security Hub now groups related exposure findings into remediation plans that target shared root causes. Each plan provides prioritization (Critical, High, Medium, Low), impact assessment, and step-by-step remediation instructions with examples for AWS CLI, Terraform, CloudFormation, Python, and CDK. Security Hub automatically ranks plans by potential risk reduction so teams can focus on the most impactful fixes, and AI agents can consume the plans via API to automate remediation. Remediation plans are available in all Regions where Security Hub is offered and included at no extra cost under the AWS Security Hub Essentials plan.
read more →

Security Hub AI Inventory Adds Azure Self‑Hosted Support

🔐 AWS Security Hub AI Inventory now discovers and catalogs AI assets on self‑hosted Microsoft Azure instances, extending visibility beyond AWS. It uses enhanced Amazon Inspector SBOM analysis to identify inference endpoints, models, and AI agents on Azure VMs, including frameworks like Ollama, vLLM, and Hugging Face TGI. Discovered assets are mapped to underlying infrastructure and correlated with security findings for filtering and querying across AWS and Azure. This capability is included with Security Hub Essentials at no extra cost and is available in all commercial Regions where Security Hub is offered.
read more →

Agentic Security: Detection and Response at Machine Speed

🔒 AWS outlines how the rise of autonomous AI agents demands a shift in security posture from event-driven to continuous, machine-speed detection and response. The post summarizes a collaborative chapter with the SANS Institute in the 2026 Cloud Security Exchange eBook, emphasizing that existing security principles—identity governance, least privilege, and defense in depth—must be adapted for probabilistic, autonomous workloads. AWS highlights built-in platform services like Amazon GuardDuty, Amazon Inspector, and AWS Security Hub as components to extend trusted controls for agentic AI adoption.
read more →

AWS partners with Upwind to extend Security Hub

🔒 AWS invited Upwind to join Security Hub Extended after customers repeatedly cited Upwind as a complementary solution. Upwind integrated deeply, offering runtime-first protection, pay-as-you-go pricing, and aligned go-to-market efforts that have driven strong joint deal activity. The integration enables unified findings in OCSF across build-to-runtime tools, simplified procurement on one AWS bill, and no custom integrations for customers.
read more →

AWS Security Hub Extended Adds Supply Chain Security

🔒 AWS Security Hub Extended has added Supply Chain Security as its tenth curated category, expanding the program to 23 partners. The launch features Chainguard and Socket as integrated partners, offering rebuilt, provenance-backed open source packages and behavioral package analysis respectively. Both offerings are available via pay-as-you-go pricing or Private Offers for committed terms, and findings flow into Security Hub in OCSF to correlate supply chain risk with other security signals. The move aims to reduce activation friction and enable cross-partner correlation across endpoint, identity, cloud, and more.
read more →

Route Bedrock Guardrails Interventions to Security Lake

🔒 This post shows how to route Amazon Bedrock Guardrails intervention events into Amazon Security Lake by transforming model invocation logs into OCSF-compliant Detection Finding records. It outlines an automated pipeline using CloudWatch Logs subscription filters, an AWS Lambda transformer, Parquet output, and Security Lake partitions so analysts can query guardrail events alongside identity, network, and application telemetry. The solution maps guardrail fields to OCSF attributes, supports multi-account deployment, and offers scaling guidance and an alternative CloudWatch-only approach.
read more →

AWS Security Hub Extended adds supply chain security

🔒 The AWS Security Hub Extended plan now adds Supply Chain Security as its 10th category, integrating curated partners Chainguard and Socket. This enables detection and blocking of malicious dependencies before they reach builds and maintains streamlined activation with pay-as-you-go pricing. The Extended plan now includes 23 curated partner solutions, all billed on a single AWS invoice with no long-term commitments.
read more →

AWS Security Hub MCP App preview announced

🛡️ The AWS Security Hub MCP App preview introduces a local Model Context Protocol (MCP) server that brings Security Hub exposure findings into Claude Desktop to streamline investigations. The app enables natural-language investigation of top findings, attack and network paths, correlated findings, affected resource configurations, and remediation suggestions. The MCP server runs locally using existing AWS credentials and is read-only. This preview is available at no additional cost in all commercial Regions that support Security Hub.
read more →

Security Hub expands to AI protections and Azure

🔒 Security Hub now adds native AI workload protection and Microsoft Azure monitoring to centralize enterprise security across clouds. It discovers Azure resources, evaluates posture against CIS benchmarks, and prioritizes findings alongside AWS signals using the same formats and workflows. New GuardDuty AI Protection detects anomalous model invocations and cost-harvesting, while AI-powered investigations accelerate triage. A continuous AI inventory catalogs models and agents across accounts, and Security Hub Extended integrates 21 curated partners to broaden coverage.
read more →

AWS Security Hub adds AI inventory for visibility

🛡️ AWS Security Hub now offers an AI inventory that gives central security teams a continuously updated, organization-wide view of AI assets and their security posture. It automatically discovers AI workloads via managed-service integration, SBOM analysis for self-hosted workloads, and GuardDuty DNS telemetry for external API endpoints. Discovered assets are mapped to underlying infrastructure and correlated with security findings to help prioritize remediation. The feature is included with Security Hub Essentials at no additional cost and is available in all commercial AWS Regions where Security Hub is offered.
read more →

AWS Security Hub adds internet Network Scanning

🔍 AWS Security Hub now includes Network Scanning to identify resources that are actually reachable from the public internet. The feature probes public IPs, VMs, and load balancers across AWS and Azure, detects reachable ports, and identifies services running behind them. Findings are created per reachable port and correlated by Security Hub Exposures to assess broader risk. Existing customers can enable the feature per account, region, or organization; it is enabled by default for new customers and included with Security Hub Essentials at no extra cost in supported commercial Regions.
read more →

AWS Security Hub adds impact analysis for exposures

🔍 Today, AWS Security Hub introduces impact analysis for exposure findings, enabling security teams to see the downstream resources an attacker could reach if an exposure is exploited. The feature maps privilege escalation paths by analyzing effective IAM permissions and displays potential attack paths in a graph. A new Impact Assessment tab prioritizes chains of compromise and shows the permissions at each step, while severity scores are adjusted to reflect downstream reach.
read more →

AWS Security Hub Adds Microsoft Azure Monitoring

🔒 AWS Security Hub now monitors Microsoft Azure resources, extending risk analytics, cloud security posture management, vulnerability management, and security response across both clouds. The service auto-discovers Azure VMs, ACR images, Function Apps, and identities, evaluating misconfigurations, internet exposure, and software vulnerabilities. Findings from AWS and Azure appear in a single prioritized view with consistent formats and automation workflows, and a 30-day free trial for Azure monitoring is available.
read more →

Palo Alto DNS Security Preview for Route 53 Resolver

🛡️ Amazon Web Services announces a preview integration of Palo Alto Networks Advanced DNS Security with Route 53 Resolver DNS Firewall. Security teams can now subscribe to PANW protections directly from the DNS Firewall console and apply categories like Command and Control, Malware, and Phishing without deploying separate firewalls. The integration supports hybrid traffic, AWS multi-account management, centralized visibility via AWS Security Hub, and preview availability across multiple regions.
read more →

Operationalizing AWS security: a maturity roadmap

🔒 This post outlines a practical, phased maturity roadmap for organizations that have enabled AWS Security Hub and Amazon GuardDuty. It emphasizes moving from enabled tooling to operational security practices by assessing current state, tuning signal quality, routing findings, automating safe remediations, and establishing a recurring operational cadence. Each phase includes goals, timelines, deliverables, and decision criteria to measure progress and reduce alert fatigue.
read more →

AWS Config adds internal service linked rules support

🔒 AWS Config now supports internal service linked rules, allowing AWS services to evaluate resource configurations using AWS Config managed rules. These rules let AWS services like AWS Security Hub CSPM deploy and manage service-specific evaluations, with results sent directly to the deploying service. Evaluations occur at no charge from AWS Config and run independently of customer-managed recorders and rules, preserving existing inventory and compliance workflows. The feature is available in commercial, GovCloud, and China Regions.
read more →

AWS Security Hub Adds Unused Identity Access Detection

🔐 AWS Security Hub now brings identity risk into the same unified console where central security teams manage threats, exposures, and posture findings. It detects unused IAM permissions, roles, and credentials across an AWS organization and correlates those identity findings with exposure context. When enabled, Security Hub automatically creates a service‑linked IAM Access Analyzer in each member account and evaluates 90 days of actual access activity. It also offers on‑demand recommended least‑privilege policies and is included in Security Hub Essentials at no additional cost.
read more →

AWS Security Hub Extended Expands Curated Partner Set

🔒 AWS Security Hub Extended adds 21 curated partner solutions across nine security categories, including SentinelOne, CyberArk, Sublime, Varonis, LayerX, Native Security, and Zenity. The plan centralizes procurement, billing, and support with pay-as-you-go pricing, a single AWS bill, automatic Enterprise Discount Program eligibility, unified Level 1 support for Enterprise customers, and no long-term commitments. Findings from participating solutions are emitted in the OCSF schema and aggregated in AWS Security Hub to accelerate cross-domain detection and response.
read more →

Security Hub Extended: A New Product-Led Adoption Model

🔒Security Hub Extended expands AWS Security Hub to include curated partner solutions in a single, unified console. Customers can discover, evaluate, and deploy vendor products with one click and pay-as-you-go pricing on their AWS bill, avoiding lengthy procurement and multi-year commitments. Integrated onboarding, OCSF-normalized findings, and AWS-native correlation surface combined attack paths and risk scoring. The offering launched in February 2026 with an expanding partner ecosystem.
read more →