< ciso
brief />
Tag Banner

All news with #aws tag

2922 articles · page 22 of 147

AWS CyberVadis 2026 Report Eases Supplier Due Diligence

🔒 Amazon Web Services (AWS) completed the 2026 CyberVadis assessment and achieved the highest score (Mature) across all evaluated areas, demonstrating commitment to elevated cloud-security expectations. The report and scorecard are now available to help customers reduce third-party due-diligence burdens and map AWS controls to common industry frameworks. Customers can download the full assessment via the CyberVadis portal or AWS Artifact and contact their AWS account team with questions.
read more →

Amazon MSK adds in-place ZooKeeper to KRaft migration

🚀 Amazon Managed Streaming for Apache Kafka (Amazon MSK) now supports in-place migration from Apache ZooKeeper to KRaft, letting customers convert existing clusters without provisioning new infrastructure or reconfiguring clients. KRaft moves metadata management into Kafka controllers, improving metadata propagation, scalability, and simplifying architecture. The migration requires Kafka 3.9.x as an intermediate step and enables upgrades to Kafka 4.x, and is available today in all MSK provisioned regions except the European Sovereign Cloud (Germany).
read more →

Amazon OpenSearch Serverless raises collection limits

🔔 The next generation of Amazon OpenSearch Serverless now supports up to 10,000 collections within a single collection group, increased from the previous limit of 1,500. Collection groups let multiple collections share OpenSearch Compute Units (OCUs) even when encrypted with different AWS KMS keys. This change enables greater consolidation, improved compute utilization, and reduced per-collection costs for multi-tenant workloads. The higher limit applies automatically to new and existing nextgen collection groups in all available AWS Regions.
read more →

AWS DRS preserves UEFI boot mode for Linux servers

🔧 AWS Elastic Disaster Recovery now preserves UEFI boot mode when recovering Linux source servers that boot with UEFI firmware. Previously, recovered Linux instances launched in legacy BIOS mode and could require extra post-recovery configuration. Recovered instances now launch with the same UEFI boot mode as the source, ensuring applications that depend on UEFI behavior function without additional steps. This automatic capability is available in all Regions where AWS DRS is offered at no extra cost.
read more →

A decade of AWS Managed Microsoft AD evolution

🔒 Over ten years, AWS Managed Microsoft AD evolved from a basic managed Microsoft Active Directory offering into a foundational enterprise identity service integrated across more than 20 AWS services. The service reduced operational overhead by handling domain controllers, HA, backups, patching, and replication while adding features like schema extensions, gMSA, multi-Region replication, and CRUD APIs. Recent additions include Hybrid Edition, self-service edition upgrades, and integrations for database, file, and remote-access authentication.
read more →

Timestream for InfluxDB adds backup and restore

🔒 Amazon Timestream for InfluxDB now supports customer-driven backups and restores for InfluxDB 2 and 3 engines. You can trigger one-time on-demand backups, schedule up to four recurring backup configurations per resource with custom frequency and retention, and restore either to a new resource or overwrite an existing one via the Console, CLI, or API. The first backup is full and subsequent backups are incremental, and KMS-managed keys are preserved for encrypted resources.
read more →

Amazon Cognito added to Agent Toolkit skills

🔧 The Amazon Cognito (aws-auth) skill is now included in the Agent Toolkit for AWS, enabling AI coding agents to set up, configure, secure, and troubleshoot Amazon Cognito using best-practice workflows. The skill supports user pools, app clients, OAuth 2.0 flows, token and JWT authorizer management, passkey/WebAuthn enrollment, threat protection, Lambda triggers, and identity pools. When used with the AWS MCP Server, commands run with IAM guardrails and CloudTrail audit logging; it also works standalone via the AWS CLI.
read more →

VPC IPAM adds BGP route protection and delegated RPKI

🛡️ Amazon VPC IPAM now supports BGP route protection monitoring and delegated RPKI management for BYOIP prefixes, enabling centralized monitoring of RPKI validity, ROA strength, and route overlap across accounts and regions. Administrators can detect invalid or missing ROAs, identify potential hijacks via overlap detection, and differentiate strict versus permissive ROA configurations. With Delegated RPKI, after a one-time setup with ARIN, RIPE, APNIC, or LACNIC, IPAM automates ROA creation, renewal, and management for both BYOIP and on-premises prefixes. The capability is available in all commercial AWS Regions except AWS GovCloud (US) and the China regions.
read more →

AgentCore adds memory, policy and harness in GovCloud

🛡️ Amazon Bedrock AgentCore is now available in AWS GovCloud (US-West), enabling regulated organizations to build context-aware agents with controls for production scale. AgentCore memory provides short-term conversational context and long-term persistent insights without complex infrastructure. Policy features let teams author natural-language policies that convert to Cedar and enforce tool access at an AgentCore gateway. The managed harness simplifies deployment by declaring models, tools, and instructions via configuration and running agents with a few API calls.
read more →

GameLift adds 21 EC2 instance types support

⚙️ Amazon GameLift Servers now supports 21 additional EC2 instance types for managed EC2 and container fleets. The expansion covers compute-optimized C-series (C8a, C8i, C9g) and general-purpose M-series (M8a, M8i, M9g), offering x86 and Arm architectures. Customers can choose processors including 5th-gen AMD EPYC, custom Intel Xeon 6, or AWS Graviton5 to balance performance, cost, and engine compatibility.
read more →

CloudWatch adds wall clock alarm evaluation windows

🕒 Amazon CloudWatch now supports wall clock evaluation windows for metric alarms, letting customers align evaluations to fixed calendar boundaries such as the top of the hour, midnight, or start of the week. This complements existing sliding window behavior and helps reduce false alerts for scheduled or business-aligned workloads. Time zone support and automatic handling of daylight saving transitions are included, and the feature is available in all Regions except UAE and Bahrain.
read more →

Amazon OpenSearch Service extends upgrade runway

🔔 Amazon OpenSearch Service is extending security and OS patch coverage for several legacy Elasticsearch and OpenSearch engine versions through November 7, 2027, with an updated Extended Support surcharge schedule. Coverage includes Elasticsearch 1.5–7.8 (excluding 5.6 which remains covered through 2028), OpenSearch 1.0–1.2, and OpenSearch 2.3–2.9; domains on these versions will remain operational. New Standard and Extended Support windows and pricing for additional versions (Elasticsearch 6.8, 7.9, 7.10; OpenSearch 1.3, 2.11–2.19) are announced, with an Extended Support charge of $0.0065 per NIH in US East (N. Virginia). AWS recommends upgrading to the latest OpenSearch release for performance and security improvements.
read more →

AWS PCS expands security and compliance coverage

🔒 AWS Parallel Computing Service (PCS) has broadened its compliance posture to support regulated workloads. PCS is now in scope for FedRAMP Class C in US East (Ohio), US East (N. Virginia), and US West (Oregon), and FedRAMP Class D in AWS GovCloud (US). PCS is included in SOC 1/2/3 reports, ISO certifications, CSA STAR (CCM 4.0), PCI attestations, and is HIPAA eligible, enabling sensitive HPC workloads on AWS.
read more →

Amazon Connect adds agent schedule adherence metrics

📊 Amazon Connect Customer now shows historical agent schedule adherence metrics on dashboards, giving supervisors visibility into scheduled time, adherent time, non-adherent time, and adherence percentage. The metrics can be grouped by shift activity to reveal patterns across work, break, or training periods. Supervisors can use these insights for targeted coaching, such as addressing consistent late returns from lunch.
read more →

ACM Adds ACME Support to Automate TLS Certificates

🔒 This post announces ACME protocol support in AWS Certificate Manager (ACM), enabling customers to use familiar ACME clients like certbot and cert-manager to automate public certificate issuance and renewal. It explains the new ACME endpoint resource, domain validation scopes, EAB credentials, and IAM controls for isolating environments. The article outlines setup steps, operational best practices, and monitoring recommendations to help scale certificate automation securely.
read more →

Amazon EC2 G7 instances now available in Spain

🚀 Amazon EC2 G7 instances powered by NVIDIA RTX PRO 4500 Blackwell Server Edition GPUs are now available in the Europe (Spain) Region. G7 delivers up to 4.6x AI inference and up to 2.1x graphics performance versus G6, with faster GPU-accelerated analytics. Instances offer up to 8 GPUs (32 GB each), custom Intel Xeon 6 CPUs, up to 192 vCPUs, 768 GiB memory, 700 Gbps EFA, and 7.6 TB NVMe local storage. G7s are available as On-Demand, Spot, and Savings Plans in four regions today.
read more →

Amazon ElastiCache adds Graviton4 M8g/R8g/C8gn nodes

🚀 Amazon ElastiCache now supports Graviton4-based M8g, R8g, and C8gn node families for Valkey and Memcached. These nodes deliver up to 47% higher throughput, up to 43% lower P99 latency, and up to 31% better price-performance for on-demand pricing compared with Graviton3 equivalents, varying by family, size, and workload. Graviton4 instances also provide more memory per node and enhanced networking, with C8gn offering up to 200 Gbps. The new sizes are available from large to 16xlarge across 30+ AWS Regions, including AWS GovCloud and China Regions; use the Console, SDK, or CLI to create or modify clusters.
read more →

AWS Glue Schema Registry expands to 10 regions

📢 The AWS Glue Schema Registry is now available in ten additional regions, including New Zealand, Thailand, Hyderabad, Osaka, Malaysia, Melbourne, Mexico (Central), Israel (Tel Aviv), Taipei, and Canada West (Calgary). The serverless, free registry supports Apache Avro, JSON, and Protobuf formats to validate and manage streaming data evolution. It serves as a centralized repository that reduces validation logic and cross-team coordination, improving data quality and lowering downstream failures. The registry integrates with C# and Java apps for Apache Kafka/MSK, Amazon Kinesis Data Streams, Apache Flink/Managed Flink, and AWS Lambda.
read more →

OpenSearch UI adds network access controls

🔒 Amazon OpenSearch Service now supports network access controls for OpenSearch UI applications, enabling administrators to restrict access to approved networks using IAM condition keys like aws:SourceVpce, aws:SourceVpc, and aws:SourceIp. You can enforce restrictions via identity-based policies, VPC endpoint policies, and organization-wide resource control policies (RCPs), which can block off-network users before authentication. This feature is available in all Regions where OpenSearch UI is offered.
read more →

Amazon Connect adds one-click drill-down metrics

📊 Amazon Connect Customer dashboards now support one-click drill-down into real-time queue and routing profile performance. Supervisors can jump from a summary view into pre-filtered routing profile, queue, agent, or routing step widgets to investigate spikes or bottlenecks. This enables rapid identification of agent activity and reassignment to reduce wait times. The feature is available in all AWS commercial and AWS GovCloud (US-West) regions where Amazon Connect Customer is offered.
read more →