< ciso
brief />
Tag Banner

All news with #aws tag

2922 articles · page 23 of 147

AWS automates post‑launch actions for migrations

🔧 AWS Transform now automates post-launch actions through the migration workflow, letting teams define actions at the account level and automatically apply them to each source server across target accounts, including multi-account migrations. Actions execute via AWS Systems Manager (SSM) immediately after test or cutover launches, and users can choose predefined actions or supply custom SSM documents. The migration inventory file now includes a new structure for bulk post-launch configurations, and the Transform agent handles end-to-end migration configuration, including replication templates, EC2 launch templates, right-sizing, and post-launch actions. This capability is available in all Regions where AWS Transform is offered.
read more →

AWS Security Agent adds email-based MFA pentesting

🛡️ AWS Security Agent (now part of AWS Continuum) can now automate penetration testing for applications that use email-based multi-factor authentication. The agent generates a unique forwarding address per credential so MFA messages can be routed to it via an email provider rule, allowing the agent to read and submit codes or links during a test without storing email account credentials. This complements existing TOTP support and is available in all Regions where the agent is supported.
read more →

Caching KMS Data Keys to Prevent Cache Stampedes

🔐 This post examines how NICE Actimize reduced AWS KMS costs by 77% for a multi-tenant, event-driven platform by rethinking data key caching. It outlines the cache stampede problem that arises when envelope encryption operates at high concurrency and describes two solutions: the AWS-recommended hierarchical keyring with DynamoDB branch keys and a custom CachedKmsClient using Caffeine caches. The article covers design, trade-offs, and security considerations for both patterns.
read more →

WorkSpaces Applications adds CloudWatch observability metrics

🚀 Amazon WorkSpaces Applications now emits expanded performance and session health metrics to Amazon CloudWatch at no extra cost. These include network indicators (e.g., TCP retransmissions, congestion window), compute and GPU utilization, memory page hard faults, and session lifecycle events like connection failures and duration. Administrators can set CloudWatch alarms, create custom or automatic dashboards, and gain fleet-wide visibility to identify and remediate issues faster. Metrics are available in all Regions where WorkSpaces Applications is supported.
read more →

Amazon WorkSpaces expands CloudWatch performance metrics

📈 Amazon WorkSpaces now publishes expanded performance and session health metrics to Amazon CloudWatch, covering network, compute, storage, and session lifecycle events at no additional cost. These metrics let administrators detect and troubleshoot issues—such as TCP retransmissions, GPU usage, CPU queue length, disk I/O queue lengths, and memory page hard faults—by setting alarms and building dashboards. The metrics are available in all Regions where Amazon WorkSpaces is supported and can be viewed via the CloudWatch console or integrated into WorkSpaces dashboards.
read more →

AWS Marketplace adds configurable net payment terms

💡AWS Marketplace now allows sellers to configure net payment terms on private offers, choosing Net 30, Net 45, Net 60, or Net 90. Buyers view these terms on the procurement page before accepting an offer, and the terms apply to all charges within that private offer, including upfront, scheduled, and usage-based fees. For Channel Partner Private Offers (CPPO), ISVs set a maximum term and channel partners may offer equal or shorter terms. This feature is generally available in all commercial AWS Regions and requires no additional onboarding; default AWS payment terms remain unchanged if none are set.
read more →

Amazon MSK adds Authorizer Log Delivery for clusters

🔒 Amazon Managed Streaming for Apache Kafka (MSK) now supports Authorizer Log Delivery for Provisioned clusters, including Standard and Express brokers, at no additional cost. This feature captures denied authorization requests with client IP and attempted API, helping identify client authorization issues and satisfy security requirements. Logs can be delivered to Amazon CloudWatch Logs, Amazon S3, or Amazon Data Firehose, and can be enabled via the MSK console or AWS CLI. Authorizer Log Delivery is available for new and existing Provisioned clusters in all supported Regions except the AWS European Sovereign Cloud (eusc-de-east-1).
read more →

AWS Backup adds direct S3 access to backups

🛈 AWS Backup for Amazon S3 now supports creating S3 Access Points to provide immediate read-only access to backup data using standard S3 APIs without performing a restore. You can create an access point for an S3 recovery point and read data with operations like GetObject, HeadObject, and ListObjectsV2. Access points apply to snapshot and continuous recovery points, work with vaults (including logically air-gapped vaults), and support shared recovery points across accounts. While an access point exists the recovery point is protected from deletion. This capability is available in select AWS Regions and can be managed via the AWS Backup console, API, or CLI.
read more →

AWS, Google and Vercel Patch Agent Tool-Call Flaws

🛡️ Security advisories from Amazon Web Services, Google, and Vercel detail vulnerabilities in agent harnesses that allowed caller-supplied or forged tool-call data to reach execution without a verifying model turn. AWS patched its managed Bedrock AgentCore service, Google fixed ADK for Python in v2.5.0, and Vercel released fixes for its Codex and OpenCode harness packages. Each vendor's path differed in attack surface and required conditions, and mitigations focus on validating and binding tool invocations to authenticated model events.
read more →

AWS Backup adds Neptune air-gapped vaults in regions

🔒 AWS Backup now supports logically air-gapped vaults for Amazon Neptune in three additional Regions: Asia Pacific (Melbourne), Europe (Spain), and Europe (Zurich). These vaults are immutable, locked by default, and encrypted with AWS-owned or customer-managed keys. You can copy backups across accounts and Regions, share vaults for recovery using AWS RAM, and require multi-party approval to protect access during account compromise.
read more →

Amazon SES flags automated open and click events

📣 Amazon Simple Email Service (SES) now marks Open and Click event notifications with an isBotEvent field to indicate whether interactions were likely triggered by automated systems or human recipients. Values are Likely or Unlikely, and the field is automatically included for customers publishing Open or Click events via configuration set event destinations. This capability is available in all AWS Regions where SES operates and requires no additional configuration for existing publishers.
read more →

Amazon Quick adds multi-dataset topic modeling

📊 Amazon Quick now supports multi-dataset topics, allowing users to model relationships across multiple datasets within a single topic and use that model for dashboards and natural-language Q&A. Previously, cross-dataset questions required pre-joining data into a single dataset, consuming SPICE capacity and manual JOIN logic. The new feature performs runtime joins, reuses dataset permissions, and preserves row- and column-level security, providing a governed semantic model as a single source of truth.
read more →

Amazon EC2 M8g instances expand to new regions

🚀 Amazon EC2 M8g instances are now available in AWS Asia Pacific (Taipei) and AWS Mexico (Central). Powered by AWS Graviton4 processors, they deliver up to 30% better performance than Graviton3-based instances and are suited for general-purpose workloads like application servers, microservices, gaming servers, midsize data stores, and caching fleets. Built on the AWS Nitro System, M8g instances offer improved performance and security.
read more →

AWS Lambda adds scalable network bandwidth for functions

🚀 AWS Lambda now supports scalable network bandwidth for functions outside a VPC with 2 GB+ memory, enabling throughput to scale from 625 Mbps at 2 GB up to 3,000 Mbps at 10 GB. This reduces transfer times for latency-sensitive and high-volume data-processing workloads, helping lower execution time and per-invocation cost. Enable the feature via AWS Service Quotas under the Network bandwidth per execution environment quota; it is available at no additional charge in all commercial Regions.
read more →

AWS integrates Continuum into developer code workflows

🔒 AWS announced integrations that extend AWS Continuum into developer coding environments by partnering with Anthropic and OpenAI. The Preview of Continuum for code vulnerabilities delivers on-demand vulnerability discovery, contextual prioritization, sandbox validation, and remediation directly within coding assistants like Claude Code, Codex, and Kiro. Continuum orchestrates multiple models and tool integrations as a harness to select the best model per task and return prioritized, contextual fixes to developers, collapsing multi-team workflows into a single outcome.
read more →

Amazon Keyspaces expands to Canada West (Calgary)

🟦 Amazon Keyspaces (for Apache Cassandra) is now available in the Canada West (Calgary) Region (ca-west-1), enabling customers to build Cassandra-compatible applications with lower latency and keep data within the Region to satisfy residency requirements. Amazon Keyspaces is a scalable, highly available, managed Apache Cassandra–compatible service that is serverless and billed based on usage. This expansion helps organizations in Canada deploy low-latency, high-throughput applications using CQL without managing Cassandra clusters.
read more →

AWS Glue Data Quality adds smarter anomaly detection

🛠️ AWS Glue Data Quality introduces a new observation mode that reduces false positives and better handles irregular data arrival intervals for notebook and exploratory workflows. The mode uses a constant baseline instead of linear trend extrapolation to avoid over-alerting, improving accuracy and reducing noise. Additionally, anomaly detection for Glue ETL jobs is now offered at no extra charge across all AWS commercial and GovCloud (US) regions.
read more →

Amazon Cognito adds self-service provisioned limits

🔒 Today Amazon Cognito launches provisioned limits in the console to let teams self-service authentication rate adjustments in minutes. The feature separates an account-level maximum (managed via Service Quotas) from a provisioned limit you pay for and control in the Amazon Cognito console, enabling rapid scaling for events like Black Friday. It supports granular RPS adjustments, programmatic APIs, and cost optimization by billing only for provisioned capacity above defaults.
read more →

AWS Marketplace adds AI Insights for pricing clarity

🔍 AI Insights in AWS Marketplace explains product pricing directly on listings, showing what pricing units map to, how costs scale with usage, and how multiple pricing dimensions combine. It cites sources drawn from the seller's Marketplace listing and public website so buyers can verify explanations. The feature is live in most listings across commercial AWS Regions and sellers can request edits via the Contact Us link.
read more →

Amazon DynamoDB adds native vector search

🆕 Amazon Web Services announces general availability of native vector search for Amazon DynamoDB. The feature enables indexing and approximate nearest neighbor searches over embeddings with single-digit millisecond latency and 99%+ recall at any scale, including trillions of vectors. You can store embeddings alongside other attributes, choose a model to generate vectors (including Amazon Bedrock models), create vector indexes, and apply attribute filters. DynamoDB vector search preserves serverless benefits—no infrastructure management, zero downtime, and pay-as-you-go—supporting use cases such as agent memory retrieval, semantic search, recommendations, and personalized advertising.
read more →