< ciso
brief />
Tag Banner

All news with #aws tag

2919 articles · page 7 of 146

AWS RTB Fabric adds configurable AZ affinity

🛠️ AWS RTB Fabric now supports configurable Availability Zone affinity for responder gateways, letting partners connect either within their own AZ or to any AZ the gateway spans. This option helps AdTech companies optimize infrastructure use and avoid underutilized capacity without additional RTB Fabric charges. Configurable AZ affinity is available in all Regions where RTB Fabric is offered; check the AWS RTB Fabric User Guide for fleet requirements before enabling.
read more →

Amazon SNS increases message payload limit to 1 MiB

📣 Amazon Simple Notification Service (Amazon SNS) now supports message payloads up to 1 MiB, a 4x increase from the prior 256 KiB limit. This change lets you publish larger messages to both Standard and FIFO topics by configuring the new MaximumMessageSize topic attribute. Topics with sizes above 256 KiB are compatible with Amazon SQS, Amazon Data Firehose, and AWS Lambda subscriptions, supporting up to 100 subscriptions per topic. The feature is available today in all Regions where Amazon SNS operates.
read more →

Securing AWS AgentCore Harness Credentials

🔒 Unit 42 researchers found that default AWS AgentCore Harness configurations can enable prompt-injection attacks that cause the harness to exfiltrate plaintext credentials from AgentCore Identity. The harness ships built-in tools, including a root-running shell enabled by default, which can access credentials when they are resolved to memory. AWS closed the report as informative under the shared responsibility model; operators should scope allowedTools, apply least privilege to identity vault accounts, and monitor egress from harness containers. Unit 42 offers cloud assessments and incident response support.
read more →

AWS PrivateLink adds tunnel VPC endpoint

🔒 AWS PrivateLink now supports a new VPC tunnel endpoint that lets customers privately and securely access network segments in another VPC or account. Instead of sharing individual resources, owners can create a Resource Configuration for a CIDR range and share it via AWS Resource Access Manager (RAM). Vendors create a tunnel endpoint and use GENEVE encapsulation to access the specified CIDR range. Pricing includes an hourly tunnel endpoint fee plus per-GB data charges.
read more →

Run open-weight models on AWS Bedrock in EU sovereign cloud

🔒 Amazon Web Services now supports running open-weight generative AI models on Amazon Bedrock within the AWS European Sovereign Cloud, keeping data and operations inside the EU. The first available family, Gemma 4, is offered under the Apache 2.0 license and served via the bedrock-mantle inference engine with OpenAI-compatible APIs. The service enforces zero operator access and in-Region inference (eusc-de-east-1), preserves data residency and provides IAM-based access controls and CloudTrail auditing.
read more →

AWS Transfer Family preserves SFTP client source IPs

🔒 AWS Transfer Family now preserves client source IPs using Proxy Protocol v2 (PPv2) when you place a Network Load Balancer (NLB) in front of a VPC-hosted SFTP endpoint. Previously, the NLB's private IP replaced the client's address in logs and during authentication, preventing IP-based auditing and access control. You can enable source IP preservation per server through the console, CLI, or API, and the feature is available in all Regions where AWS Transfer Family is offered.
read more →

AWS HealthOmics adds IAM session policy support

🔐 AWS HealthOmics now supports IAM session policies, allowing you to restrict permissions for individual runs without creating and managing multiple IAM roles. An IAM session policy is an inline policy that limits the maximum permissions of a run by intersecting with the underlying identity-based policy. This enables per-run scoping—such as restricting access to a tenant's S3 buckets or specific S3 objects—without provisioning separate roles. Support is available in all Regions where HealthOmics is offered.
read more →

AWS Batch adds bulk job cancellation and termination

🛠️ AWS Batch now supports bulk cancellation and termination of up to 50 jobs via new APIs, simplifying management of large-scale batch workloads. The new CancelJobs, TerminateJobs, and TerminateServiceJobs APIs return per-job results in a single response and work with individual and array jobs. ListJobs and ListServiceJobs now expose lifecycle flags isCancelled and isTerminated to help track job state across regions.
read more →

AWS launches low-cost EC2 T8i burstable instances

🔔 AWS announced general availability of the new low-cost burstable Amazon EC2 T8i instances powered by custom sixth-generation Intel Xeon 6 processors and built on sixth-generation AWS Nitro cards. T8i offers four sizes (nano, micro, small, medium) and delivers up to 30% better price performance versus T3, targeting low-to-moderate CPU workloads like small databases, CI/CD, microservices, and low-traffic websites. The instances provide higher compute, network, and EBS bandwidth, retain the T3 CPU credit model, and are available in multiple global regions with On-Demand and Spot purchase options.
read more →

Elastic Beanstalk adds Cluster Mode for pooled apps

🚀 AWS Elastic Beanstalk introduces Cluster Mode, a deployment option that runs multiple applications on shared, EKS-powered infrastructure. Provide source code, a Dockerfile, or an Amazon ECR image and Elastic Beanstalk handles containerization, provisioning, and lifecycle operations via the console, CLI, APIs, or a new GitHub Action. Cluster Mode supports autoscaling, OpenTelemetry observability, AWS Secrets Manager, and HTTPS via AWS Certificate Manager, and is available in all commercial AWS Regions where Elastic Beanstalk is offered.
read more →

Amazon S3 Express One Zone expands to seven regions

🚀 Amazon S3 Express One Zone is now available in seven additional AWS Regions: Singapore, São Paulo, N. California, Canada (Central), Paris, Sydney, and Seoul. This single-Availability Zone storage class is engineered for consistent single-digit millisecond access and is optimized for latency-sensitive workloads. S3 Express One Zone offers up to 10x faster data access and up to 80% lower request costs versus S3 Standard. The expansion brings the storage class to 15 AWS Regions overall.
read more →

AWS Builder Center launches mobile app globally

📱AWS has expanded the AWS Builder Center to mobile, releasing apps for iOS and Android that mirror the desktop experience. The app lets builders browse trending articles, access 600+ AWS Skill Builder courses, join hands-on workshops with free sandbox environments, and follow community leaders. It also supports push notifications, the Wishlist product-feedback feature, and sync via AWS Builder ID for seamless sign-in across sessions.
read more →

Amazon SES adds tenant-level deliverability insights

📊 Amazon Simple Email Service (SES) now provides tenant-level deliverability insights in Virtual Deliverability Manager (VDM). The VDM dashboard adds a Tenants view with per-tenant metrics and a detail page that breaks metrics down by mailbox provider, identities, and configuration sets. Customers can search and export tenant sent messages and query metrics via the BatchGetMetricData API using the new TENANT_NAME dimension. VDM is available in all Regions where Amazon SES is offered.
read more →

Amazon Quick adds AI sheet and image-based analysis

🛠️ Amazon Quick expands Generate Analysis with two new features that speed dashboard creation. With Generate Sheet, users describe a sheet in natural language and Quick inserts it into an existing analysis with visuals, filters, and common calculated fields. With the new image-driven generator, users attach a dashboard image and Quick recreates an editable analysis from supported elements.
read more →

Amazon Corretto 27 Feature Release Now Available

🟢 Amazon Corretto 27, a Feature Release (FR) of the no-cost, production-ready OpenJDK distribution, is now available for Linux, Windows, and macOS. Corretto 27 will be supported through April 2027 and introduces G1 as the default garbage collector, post-quantum hybrid key exchange for TLS 1.3, compact object headers, and JFR in-process data redaction. Several preview and incubator features are continued, including enhanced pattern matching, structured concurrency, lazy constants, and the Vector API.
read more →

Amazon ECS adds consolidated Managed Daemon deployment view

🟦 Amazon Elastic Container Service (Amazon ECS) introduces a console-only consolidated deployment view for Managed Daemons that centralizes rollout progress, failures, and potential blockers. The view provides a lifecycle timeline with timestamps and duration, per-capacity-provider progress bars, and a monitoring panel showing circuit breaker, alarms, and health checks with live CloudWatch details. Failed daemon tasks show stop reasons with links to task logs and troubleshooting guidance, and the console displays target/source revisions, instance counts, drain percentages, and bake time. This enhancement is available at no additional cost in all AWS Commercial Regions.
read more →

Architecting a Secure Landing Zone in EUSC

🔒 This post explains how to design a secure, scalable landing zone for the AWS European Sovereign Cloud (aws-eusc), a partitioned AWS environment operated within the EU. It covers account structure and governance, identity as IaC, centralized logging to a SIEM, data protection, perimeter and network design, CI/CD and artifact distribution, and incident response. The guidance maps to the AWS Security Reference Architecture and the AWS Well-Architected Framework, and highlights which behaviors are partition boundaries versus configurable choices.
read more →

AWS Client VPN Adds macOS 27 Golden Gate Support

🖥️ AWS Client VPN now supports macOS 27 Golden Gate with client versions 6.0 and later. The AWS-supplied desktop VPN client can be run on the latest macOS releases and remains available free of charge. Client VPN is a managed service that securely connects remote users to AWS and on-premises networks and supports macOS, Windows (x64 and Arm64) and Ubuntu Linux clients.
read more →

AWS launches simplified Builder experience

🔧 Builders can now sign up for a simplified experience that speeds turning ideas into running code on AWS. The new flow reduces setup effort by auto-configuring an initial project with sensible defaults and supports sign-in via Google, GitHub, Apple, or Amazon credentials. New customers may receive up to $200 in free credits and no credit card is required for most signups. Projects include automated IAM role management, team invites, per-project spend limits, and easy upgrades to advanced features without downtime.
read more →

Amazon WorkSpaces adds NVIDIA Blackwell G7 bundles

🚀 Amazon WorkSpaces Personal and Core now offer Graphics G7 bundles powered by NVIDIA RTX PRO 4500 Blackwell Server Edition GPUs and Intel Xeon 6 processors. These bundles deliver up to 2.1x better graphics performance versus Graphics G6 and come in four sizes from 8 vCPUs/32 GB/1 GPU to 48 vCPUs/192 GB/2 GPUs. Graphics G7 supports demanding professional workloads, Windows licensing options, AlwaysOn and AutoStop modes, and is initially available in three US Regions with broader rollout planned.
read more →