< ciso
brief />
Tag Banner

All news with #aws tag

2920 articles · page 12 of 146

Transfer Family SFTP connectors support credential rotation

🔒 AWS Transfer Family SFTP Connectors now continue file transfers while you rotate authentication credentials, eliminating the need to repoint connectors to new secret versions. Connectors can retrieve credentials from an ordered list of AWS Secrets Manager version stages (for example, current and previous) and will try each version in sequence until authentication succeeds. This behavior is configured when creating or updating a connector, requires storing credentials in AWS Secrets Manager, and is available in all Regions where Transfer Family SFTP Connectors are supported.
read more →

CloudTrail incident response: multi‑Region Bedrock attack

🔍 This post examines a multi‑stage attack that begins with a web application SSRF vulnerability on an EC2 instance, leads to IMDSv1 credential harvesting for an attached webdev role, and culminates in unauthorized access to Amazon Bedrock across Regions. It walks through four CloudTrail events—failed CreateUser, console sign‑in without MFA, ListFoundationModels in another Region, and a Converse call invoking Amazon Nova Pro—and shows which log fields reveal attribution, intent, and cross‑Region pivots. The article also provides containment, remediation, and hardening recommendations.
read more →

Incident response guide for AWS CloudTrail

🔍 This guide from the AWS Security Incident Response Team explains how to analyze AWS CloudTrail events to investigate cross-account unauthorized access, cryptocurrency mining deployments, and AI service abuse. It walks through real-world scenarios showing which CloudTrail fields matter, how to interpret session metadata, and investigative techniques for reconstructing activity timelines and assessing blast radius. The guide emphasizes practical steps to prioritize containment, identify misconfigurations such as overbroad cross-account roles or missing MFA, and extract evidentiary details from CloudTrail and related logs.
read more →

CloudFront flat-rate pricing plans now programmable

🚀 Customers can now subscribe and manage CloudFront flat-rate pricing plans programmatically via the AWS CLI, SDKs, CloudFormation, CDK, or the PricingPlanManager API. Flat-rate plans cover global content delivery, WAF, DDoS, DNS, logging, and edge compute under one monthly fee without usage overages. Paid plans offer a two-phase activation (create then approve) for controlled billing, while free plans activate immediately. There are no extra fees for using the API.
read more →

Amazon Quick Max: Higher-capacity plan for power users

🚀 Amazon Quick introduces Quick Max, a new plan aimed at power users, offering 5x the usage and 5x the storage of the Plus tier. The plan supports large, concurrent workloads throughout the month and provides greater value at higher usage levels. Quick Max is available with monthly and annual billing; existing Plus users can upgrade via the product navigation. New users can sign up free, and plan comparisons are available on the pricing page.
read more →

Amazon WorkSpaces adds NVIDIA Blackwell G7 GPUs

🖥️ Amazon WorkSpaces Applications now supports Graphics G7 instances powered by NVIDIA RTX PRO 4500 Blackwell Server Edition GPUs and Intel Xeon Scalable (6th Gen) processors. G7 delivers up to 2.1× better performance for graphics workloads versus G6 and offers 32 GB of GDDR7 per GPU with 2.67× faster memory bandwidth. Six sizes are available (1–8 GPUs, 8–192 vCPUs, 32–768 GB RAM) and G7 is initially available in three US regions.
read more →

AWS Gateway Load Balancer adds TCP Reset support

🔧 AWS Gateway Load Balancer (GWLB) now supports sending TCP Reset packets to accelerate failure recovery for client and server connections. Previously, GWLB exhibited fail-open behavior where traffic continued to be forwarded to unhealthy targets, causing prolonged interruptions due to TCP retries and back-off. TCP Reset can be enabled per target group via the Console, CLI, or API and responds to three independent triggers: target unhealthy, target deregistration after connection draining, and TCP idle timeout expiry. This capability is available in all GWLB regions at no additional cost and is off by default for backward compatibility.
read more →

Amazon Redshift RG.large Adds Single‑Node Option

🔷 Amazon Redshift now supports single-node clusters for rg.large instances on P204 or later patches, enabling cost-effective testing and proof-of-concept deployments without high-availability requirements. RG instances, powered by AWS Graviton processors, offer up to 2.4x faster performance than prior RA3 generations and a ~30% lower price per vCPU. The RG family includes Redshift’s custom vectorized engine for SQL analytics over Apache Iceberg and Parquet data, and these instances are available across numerous global AWS Regions.
read more →

Amazon Aurora MySQL 8.4.8: PQ‑TLS and replication

🔒 Amazon Aurora MySQL-Compatible Edition 8.4 now supports MySQL 8.4.8, introducing security enhancements and bug fixes plus features such as post-quantum TLS (PQ-TLS) key exchange, transaction timeout, multi-source replication, and delayed replication. These additions strengthen in-transit encryption options and improve operational resilience by preventing long-running transaction impacts and enabling consolidated or lagged replicas for recovery and reporting. Upgrades are available via automatic minor version upgrades during scheduled maintenance and supported across all AWS Regions where Aurora MySQL is offered.
read more →

Aurora MySQL adds multi-source and delayed replication

📢 Amazon Aurora MySQL now supports multi-source replication and delayed replication, enabling consolidation of multiple MySQL sources into a single Aurora cluster and intentional replica lag for protection against human error and logical corruption. Multi-source replication simplifies merging shards or aggregating regional and departmental databases into a central cluster for reporting and backups. Delayed replication allows a binlog replica to intentionally lag, letting you stop replication and promote the replica to recover quickly from harmful changes without a full restore. These features are available on Aurora MySQL 8.4.8+ in all Regions where Aurora MySQL is offered.
read more →

Amazon MWAA adds integrated CloudWatch monitoring

🛠️ Amazon Managed Workflows for Apache Airflow (MWAA) now includes a built-in monitoring experience on the environment detail page in the AWS Management Console. A new metrics dashboard consolidates key Amazon CloudWatch metrics with optional toggles to overlay suggested warning ranges to highlight potential issues. The page also lists associated CloudWatch alarms and offers a one-click Create Recommended Alarms action to provision alarms from an AWS-managed template. This capability is available for MWAA Provisioned environments in all supported regions; standard CloudWatch pricing applies.
read more →

SageMaker Workflows adds Python and Bash operators

🐍 Amazon SageMaker Unified Studio Workflows now includes PythonOperator and BashOperator, allowing you to run custom Python functions and shell commands inside serverless workflows without provisioning separate compute. Configure operators by adding your script files in workflow settings and pointing each operator to the function or command. This feature is available in all Regions where SageMaker Unified Studio runs.
read more →

Investigation of Amazon Bedrock LLMjacking Incident

🛡️ FortiGuard Labs examines an AWS incident where a long-lived IAM access key with Administrator privileges was abused to create identities, subscribe to foundation models on AWS Marketplace, and invoke those models for profit. The report outlines the concept of LLMjacking, the steps observed in the compromise, and why valid cloud credentials make detection challenging. It also lists FortiCNAPP (Lacework) detections and recommended posture changes to reduce risk.
read more →

Amazon Linux 2027 public preview announced

🛡️ Amazon Web Services has launched the public preview of Amazon Linux 2027 (AL2027), a cloud-native OS built on AL2023 for web, database, container, and AI/ML workloads. AL2027 uses kernel 7.1+, enables SELinux enforcing by default, and boosts crypto performance with AWS-LC. Preview AMIs and container images are available across commercial regions for x86-64 and ARM, with feedback accepted via the AL2027 GitHub repository.
read more →

Amazon SES Adds S/MIME Email Signing Support

🔒 Amazon Simple Email Service (SES) now supports S/MIME signing, enabling recipients to verify that messages are authentic and unaltered. Previously, senders had to pre-sign messages before submitting them to SES, adding operational complexity. Now you can store your signing certificate in AWS Certificate Manager and enable S/MIME for your sender identity so SES signs outbound mail automatically. Recipients without S/MIME-capable clients can still read messages normally, and the feature is available in all Regions where SES operates.
read more →

Amazon S3 Adds PrivateLink for FIPS Endpoints

🔒 Amazon S3 now supports AWS PrivateLink for endpoints validated under the FIPS 140-3 program, enabling customers to use FIPS-validated cryptographic modules while keeping traffic inside their VPC. To enable, create or edit an interface VPC endpoint for S3 and select the FIPS S3 endpoint. This feature is available at no additional cost in several AWS Regions, including US East, US West, Canada, and AWS GovCloud (US).
read more →

AWS Transform Adds FSx for NetApp ONTAP Support

🚀 AWS Transform now supports Amazon FSx for NetApp ONTAP as a general available target for block storage migrations. This enables customers to migrate block workloads directly to FSx for ONTAP alongside compute and network migrations, removing the need for intermediate storage platforms or separate migration tools. Workloads maintain existing data access patterns and operational processes while running on a managed, production-ready shared storage service that combines ONTAP enterprise features with AWS scalability and resiliency. The capability is available in all Regions supported by AWS Transform and FSx for ONTAP.
read more →

Managing Identity Source Transitions for IAM Identity Center

🔐 This AWS blog explains how to plan and execute an identity source transition in AWS IAM Identity Center, focusing on migrations such as Active Directory to Okta. It outlines destructive and non‑destructive transition scenarios, a five‑step migration runbook, and prerequisites including backup, validation, SCIM configuration, and restore processes. The post also references sample scripts and a migration tool on GitHub to automate prechecks, cutover, validation, and cleanup.
read more →

Agentic Security: Detection and Response at Machine Speed

🔒 AWS outlines how the rise of autonomous AI agents demands a shift in security posture from event-driven to continuous, machine-speed detection and response. The post summarizes a collaborative chapter with the SANS Institute in the 2026 Cloud Security Exchange eBook, emphasizing that existing security principles—identity governance, least privilege, and defense in depth—must be adapted for probabilistic, autonomous workloads. AWS highlights built-in platform services like Amazon GuardDuty, Amazon Inspector, and AWS Security Hub as components to extend trusted controls for agentic AI adoption.
read more →

Amazon Bedrock Web Search now in AWS GovCloud

🔎 Amazon Bedrock's Web Search tool is now available in AWS GovCloud (US-West), enabling grounded web results with citations for supported OpenAI GPT models. Web Search keeps request data inside the AWS boundary by default and is governed by IAM so administrators can control access at account, organization, and Region levels. At launch it supports GPT-5.4, GPT-5.6 Terra, and Luna models and joins other US Regions where the capability is already available.
read more →