< ciso
brief />
Tag Banner

All news with #aws tag

2921 articles · page 18 of 147

Aurora DSQL adds CloudWatch Database Insights

🔍 Amazon Aurora DSQL introduces a CloudWatch Database Insights metric that provides per-statement, cluster-level performance monitoring. The feature captures sampled wait states and normalized SQL statements for active sessions, helping diagnose performance issues and identify resource-heavy queries. Metrics are collected at 1-minute intervals, available by default at no additional cost, and usable with CloudWatch Database Insights, CloudWatch PromQL, and the Aurora DSQL system diagnostics AI skill.
read more →

AWS Direct Connect adds inbound prefix controls

⚙️ AWS Direct Connect announced inbound prefix controls that let customers allocate and manage inbound route-prefix allocations for private and transit virtual interfaces (VIFs) based on workload needs. You can now assign up to 1,000 prefixes each for IPv4 and IPv6 on dedicated and hosted connections, up from a 100-prefix limit. New prefix capacity pools exist at the dedicated connection and Direct Connect gateway (DXGW) levels, and allocations are configurable via the console or CLI/API. This feature is available at no extra cost in all commercial AWS Regions, AWS GovCloud, and the China Regions operated by Sinnet and NWCD.
read more →

Redshift adds long-term system table retention

📌 Amazon Redshift now supports long-term retention of system table data through native integration with Amazon S3 Tables in Apache Iceberg format. This eliminates the prior 7-day limit and removes the need for custom ETL pipelines by automatically writing, partitioning, compacting, and retaining system table data in S3. The stored data can be queried via Redshift, Athena, or any Iceberg-compatible engine for cross-warehouse observability and auditing.
read more →

AWS Marketplace adds category-based partner notifications

📣 Partners can now configure category-based notifications and multi-channel delivery for AWS Marketplace through AWS User Notifications. Previously, notifications went only to the AWS account root email or custom aliases, without category routing. Partners can now assign contacts and delivery channels for four categories: Product listings, Offers and agreements, Payments and disbursements, and Account management. Notifications can be delivered by email, the AWS Console Mobile App, or chat via Amazon Q Developer in Slack and Microsoft Teams.
read more →

Amazon Bedrock expands Web Search with external access

🔎 Today AWS expanded Amazon Bedrock's Web Search to support an external_web_access parameter, allowing models to fetch live public web content while preserving control over data egress. Grant the bedrock-websearch:ExternalWebAccess IAM permission to enable live fetches; leaving the parameter false restricts results to Amazon's in-AWS index. The capability is available in US East (N. Virginia), US East (Ohio), and US West (Oregon).
read more →

EC2 AMI Creation with Local Outpost Snapshots

🔔 Amazon EC2 now allows creation of Amazon Machine Images (AMIs) using local snapshots from instances running on AWS Outposts. Customers may store snapshots on the Outpost or in the parent AWS Region, helping meet data residency needs. EC2 auto-selects the target Outpost based on the instance location, eliminating the need to specify an Outpost ARN. This feature integrates with existing backup and lifecycle workflows and is available where Outposts supports local snapshot storage.
read more →

CloudWatch Centralization Adds Tag Propagation

🔔 Amazon CloudWatch Centralization now copies log group tags from source accounts to destination log groups created by centralization rules. Tag propagation preserves cost, ownership, and compliance tags so teams can scope access and report spend centrally. The feature syncs tags based on propagation behavior chosen in the centralization rule and is available in all Regions where CloudWatch Centralization is offered.
read more →

Sakura Internet breach exposes up to 1.36M accounts

🔒 Japanese cloud provider Sakura Internet disclosed unauthorized access to its sales management system storing customer contract and membership data. The company said the incident was discovered during a separate investigation into a smaller breach at its Sakura Rental Server service and that up to 1,360,563 accounts may have been affected. Sakura reported no confirmed data exfiltration, noted stored passwords are hashed and no credit card data is kept in the compromised system, and is notifying affected customers and authorities.
read more →

SageMaker notebooks add trusted identity propagation

🧭 Amazon SageMaker Notebooks now support Trusted Identity Propagation (TIP) with Amazon Athena, Amazon Redshift, and Amazon EMR Serverless, enabling per-user access control for data analytics. When connected to a TIP-enabled compute in a TIP-enabled Project, each notebook user's IAM Identity Center identity flows through to AWS Lake Formation, ensuring they see only the tables, columns, and rows their permissions allow. TIP provides per-user data boundaries, full audit attribution with CloudTrail, and reduces admin friction by automatically propagating identity through existing compute connections without extra logins or role management. The feature is available in all Regions where Amazon SageMaker Unified Studio is available.
read more →

CloudWatch adds GeoIP, RDS and XML log parsers

🔧 Amazon CloudWatch pipelines now includes three new processors: an Amazon RDS log parser, an XML parser, and a GeoIP enrichment processor. These processors parse and enrich logs as they are ingested, turning RDS Aurora audit and error logs into structured fields, converting XML strings into JSON, and adding geographic context to IP addresses. They are available at no extra charge where CloudWatch pipelines is GA; standard ingestion and storage rates still apply.
read more →

CareCloud data breach impacts 3.7M patients

🩺 CareCloud, a U.S. healthcare IT provider, disclosed a March breach that disrupted services and exposed patient data. The company said an unauthorized third party accessed an AWS environment between March 10 and March 16, 2026, and claimed to have exfiltrated database contents. Notifications began July 25, and impacted individuals are offered identity protection via IDX. No group has claimed responsibility and investigations continue.
read more →

AWS Security Agent adds cost controls and revalidation

🔒 AWS Security Agent (part of AWS Continuum) now offers two capabilities for its on-demand AI-driven penetration testing service: a configurable maximum task-hours limit and selective revalidation of findings. Teams can set preset or custom hour caps so tests stop gracefully when the limit is reached while preserving discovered findings and keeping billing tied to actual task-hours used. Individual findings from completed runs can be re-tested against the live application to confirm an Active or Resolved status, with full revalidation history linked to the original finding.
read more →

MediaConnect Router Adds Configurable Latency Modes

🔧 AWS Elemental MediaConnect Router now lets customers set internal recovery latency per output. Customers can choose between balanced mode (default behavior) and low-latency mode to optimize recovery time for latency-sensitive workflows. The setting is configurable via the MediaConnect API, AWS Management Console, or AWS CLI, and a new CloudWatch metric, RouteFabricRecoveryLatency, exposes recovery latency per route. This feature is available in all regions where MediaConnect Router is deployed.
read more →

AWS Cost Anomaly Detection Adds Bedrock Third-Party Model Coverage

🔍 AWS Cost Anomaly Detection now monitors spend for third-party foundation models on Amazon Bedrock, including provider-hosted models like Anthropic Claude. The service uses machine learning to detect and alert on unusual spend, and this update extends automatic anomaly detection to Bedrock model usage. Alerts include a ranked root-cause breakdown by dollar impact across service, account, Region, and usage type, and the feature is available in all commercial AWS Regions except GovCloud and China.
read more →

Amazon OpenSearch Ingestion now in GovCloud regions

🔔 Starting today, Amazon OpenSearch Ingestion is available in AWS GovCloud (US-East) and AWS GovCloud (US-West), enabling secure ingestion into Amazon OpenSearch Service managed clusters and serverless collections. OpenSearch Ingestion is a fully managed data ingestion tier that offers a no-code experience to filter, transform, redact, and route data. It automatically provisions and scales resources to handle variable workloads and is now generally available across 19 AWS regions.
read more →

AWS Marketplace AMIs Now Launchable on Lightsail

🛠️ Customers can now deploy eligible AWS Marketplace AMIs directly on Amazon Lightsail. Lightsail offers simple, predictable pricing with instance bundles that include compute, storage, and data transfer at a fixed monthly rate. When subscribing to supported products — such as Microsoft Windows Server, Microsoft SQL Server Express, Ubuntu, cPanel & WHM, and Plesk — users may choose Amazon Lightsail in addition to Amazon EC2. The "Launch on Lightsail" option opens the Lightsail console with the AMI and region pre-configured for fast deployment.
read more →

AWS Adds Fourth Availability Zone in London

🟦 AWS has added a fourth Availability Zone (eu-west-2d) to the Europe (London) Region, expanding capacity for AI, ML, and general-purpose compute. The new zone provides next-generation accelerated instances such as Trn3 and P6, enabling local model training and inference. Customers can distribute workloads across four zones for improved fault tolerance, accessible via the Console, APIs, and existing workflows at standard regional pricing.
read more →

AWS adds fourth Availability Zone in London region

🚀 AWS has added a fourth Availability Zone to the Europe (London) Region (eu-west-2), increasing capacity for cloud compute and AI/ML workloads. The new zone provides next-generation accelerated instances such as Trn3 and P6, plus general-purpose EC2, enabling customers to run training and inference locally within the London region. It improves fault isolation for resilient, highly available architectures and is accessible via the AWS Console, APIs, and existing workflows at standard regional pricing.
read more →

AWS Lambda MicroVMs Expand to Five More Regions

🚀 AWS Lambda MicroVMs are now available in five additional Regions: Asia Pacific (Mumbai), Asia Pacific (Singapore), Asia Pacific (Sydney), Europe (Frankfurt), and Europe (Stockholm), bringing availability to 10 Regions in total. Lambda MicroVMs deliver VM-level isolation, near-instant launch and resume speeds, and state preservation so developers can run isolated, stateful workloads without managing virtualization. Developers create a MicroVM image from a Dockerfile and launch per-user or per-job MicroVMs with dedicated HTTPS URLs supporting HTTP/2, gRPC, and WebSockets via the Lambda console, CloudFormation, CDK, or Agent Toolkit for AWS.
read more →

Amazon Quick introduces deny-by-default governance

🔒 Amazon Quick now offers a deny by default governance setting for custom permissions, automatically blocking new AI capabilities until administrators explicitly allow them. Previously, new capabilities were enabled for all users on release, requiring reactive controls. Administrators can apply the restriction per custom permissions profile for users, roles, or the entire account via the Amazon Quick console or AWS CLI. The setting is available in all Regions where Amazon Quick is offered and also restricts existing capabilities within a restricted category.
read more →