< ciso
brief />
Tag Banner

All news with #aws tag

2926 articles · page 73 of 147

AWS Integrates Blu Insights into Transform for Mainframe

🛠️ AWS has integrated Blu Insights into AWS Transform, enabling customers to launch mainframe refactoring projects directly from the AWS Transform console. The release unifies the three modernization patterns—refactor, replatform, and reimagine—and replaces the lines-of-code pricing model with free code transformation. A prior mandatory three-level certification to access the Transformation Center has been removed to reduce friction; self-paced training remains available. The refactor capability is available in 18 AWS Regions, with access via the AWS Mainframe Modernization console where Transform is not yet offered.
read more →

Amazon MSK Express Brokers Arrive in Cape Town and Taipei

🚀 You can now create provisioned Amazon MSK clusters with Express brokers in Africa (Cape Town) and Asia Pacific (Taipei). Express brokers deliver up to 3× more throughput per broker, scale up to 20× faster, and reduce recovery time by 90% compared to standard Apache Kafka brokers. They are pre-configured with Kafka best practices, support all Kafka APIs, and preserve low-latency behavior so existing client applications require no changes. To get started, create a new cluster with Express brokers via the Amazon MSK console or the AWS CLI and consult the Amazon MSK Developer Guide for details.
read more →

Amazon RDS Enhancements for SQL Server Developer Edition

📢 Amazon RDS for SQL Server Developer Edition now supports Additional Storage Volumes, Resource Governor, and SQL Server 2019 (CU32 GDR - 15.0.4455.2). Additional Storage Volumes raise capacity up to 256 TiB—4× more storage—while Resource Governor enables definition of resource pools and workload groups to control CPU and memory for more realistic performance testing. The Developer Edition includes Enterprise functionality and is free for development and test systems (not production). For region availability and pricing, consult AWS documentation and Amazon RDS for SQL Server pricing.
read more →

AWS Glue Data Catalog: IAM Permissions for S3 Tables

🔐 AWS announced IAM-based authorization in the AWS Glue Data Catalog for Amazon S3 Tables and Apache Iceberg materialized views. The change allows administrators to consolidate storage, catalog, and query engine permissions into a single IAM policy, simplifying access management for analytics services. Customers can still opt into AWS Lake Formation for fine-grained controls and manage access via Console, CLI, API, or CloudFormation.
read more →

Amazon Bedrock Launches in Asia Pacific (New Zealand) Region

🚀 Amazon Web Services has launched Amazon Bedrock in the Asia Pacific (New Zealand) Region, enabling customers to build and scale generative AI applications using a single API and a choice of foundation models. The managed service emphasizes built-in security, privacy, and responsible AI capabilities to support enterprise deployments. Models now available in New Zealand include Anthropic (Sonnet 4.5, 4.6; Opus 4.5, 4.6; Haiku 4.5) and Amazon’s Nova 2 Lite with cross-region inference support.
read more →

CloudWatch Org Enablement for EC2 Detailed Metrics

📈 Amazon CloudWatch now supports organization-wide automatic enablement of EC2 detailed monitoring. With CloudWatch Ingestion enablement rules, administrators can automatically enable EC2 detailed monitoring at 1-minute intervals for existing and newly launched instances across an entire AWS Organization, specific accounts, or tag-based resource scopes. The capability ensures consistent telemetry collection to help Auto Scaling and operational alarms react more quickly, is available in all AWS commercial regions, and will be billed according to CloudWatch pricing.
read more →

Amazon CloudWatch Adds HTTP Log Collector Endpoints

📥 Amazon CloudWatch Logs now supports HTTP-based ingestion via a new HTTP Log Collector (HLC) and dedicated endpoints for ND-JSON, Structured JSON, and OpenTelemetry formats. This enables customers to send logs where AWS SDK integration isn't feasible, such as third-party or packaged software. Generate API keys in CloudWatch Settings—AWS creates the service-specific IAM user and credentials—and configure API key expirations (1, 5, 30, 90, or 365 days). To prevent unintended ingestion, enable bearer token authentication on each log group and consider service control policies to block creation of service-specific credentials.
read more →

SageMaker HyperPod Adds Idle Compute Resource Sharing

⚙️Amazon SageMaker HyperPod task governance now supports dynamic idle resource sharing, letting teams borrow unallocated compute capacity beyond their guaranteed quotas. Administrators can set both percentage-based and absolute borrow limits for resource types such as accelerators, vCPU, and memory to ensure fair distribution. HyperPod automatically recalculates borrowable resources as instances and quota policies change, and eligible ready, schedulable instances—including partitioned GPU configurations—contribute to the borrowable pool. This capability is available for EKS-based HyperPod clusters across multiple AWS Regions.
read more →

Amazon Neptune adds openCypher read-from-S3 capability

🔗 Amazon Neptune now supports reading S3 data directly from openCypher via the new neptune.read() procedure. This lets users federate S3-resident datasets into queries without preloading them into the graph. The feature handles standard and Neptune-specific formats (geometry, datetime), uses the caller's IAM credentials for access, and is available in all regions where Neptune runs.
read more →

Amazon Timestream for InfluxDB: Expanded Multi-Node Clusters

🚀 Amazon Timestream for InfluxDB 3 Enterprise now supports expanded multi-node clusters up to 15 nodes, enabling 1–4 combined writer/reader nodes, 0–13 dedicated reader-only nodes, plus a dedicated compactor node for long-term storage. Multi-node deployments distribute nodes across Availability Zones for improved fault tolerance and availability. You can add and remove nodes on Enterprise clusters, upgrade from Core to Enterprise, and configure custom topologies via the console, AWS CLI, or SDKs.
read more →

AWS Partner Central Agents: AI Co-sell Tools Now GA

🤖 AWS announces general availability of AWS Partner Central agents, AI-powered agentic capabilities built on Amazon Bedrock AgentCore to accelerate partner co-selling. Agents provide pipeline insights, tailored sales plays, and next-step recommendations, and can populate CRM fields from transcripts, notes, and emails. They also identify funding eligibility, pre-fill funding requests, and are available in all commercial AWS Regions.
read more →

Amazon SimpleDB adds domain export capability to S3

📤 Amazon SimpleDB now supports exporting domain data directly to Amazon S3 in standard JSON format. Exports run in the background with no impact on database performance and support cross-region and cross-account targets, multiple encryption options, and flexible S3 bucket configuration. The capability is available in all SimpleDB regions and is accessed via three new APIs — StartDomainExport, GetExport, and ListExports — with built-in rate limits; there is no additional charge for the tool, though standard data transfer fees apply.
read more →

Amazon Connect Lets Agents Forward Email Contacts Externally

📧 Amazon Connect now lets agents forward email contacts to external email addresses and distribution lists directly from the Agent workspace and Contact Center Panel. When forwarded, agents retain ownership and the complete communication trail of the original contact, keeping a single point of contact for customers. This streamlines collaboration with back-office teams, subject matter experts, partners, and stakeholders. Email forwarding is available in multiple AWS regions.
read more →

DNS-Based Data Exfiltration via AWS Bedrock Code Interpreter

⚠️ Phantom Labs Research demonstrated a DNS-based exfiltration technique targeting the AWS Bedrock AgentCore Code Interpreter that bypasses expected Sandbox Mode network restrictions. Maliciously crafted files (for example, CSVs) can influence generated Python code to use DNS queries as a covert command-and-control channel. In tests, researchers executed commands, enumerated and retrieved S3 content and secrets while the environment still reported network access disabled. AWS says this is intended behavior and updated documentation; organisations should inventory AgentCore instances, tighten IAM roles and move sensitive workloads to VPC mode.
read more →

Deploy AWS Applications and Access Accounts Across Regions

🔁 AWS now supports IAM Identity Center multi-Region replication, enabling workforce access and supported AWS managed applications to operate from additional Regions for improved resiliency and lower latency. Administrators create a multi-Region customer-managed KMS key, replicate it to target Regions, and add those Regions in the Identity Center console. External IdP configurations (for example, Okta or Microsoft Entra ID) must be updated with new ACS and access portal URLs so both service-provider and IdP-initiated flows work. Instance-level management remains centralized in the primary Region while additional Regions provide read-only replicated configuration and local application access.
read more →

AWS Security Agent Adds Service Quotas for Pentests

🔒 AWS Security Agent now integrates with AWS Service Quotas, giving teams a centralized view of applied limits and utilization for security workloads. Users can request quota increases through the Service Quotas console, and eligible requests are automatically approved to reduce manual intervention. The update explicitly covers pentesting limits, including action hours and concurrent pentest jobs, helping security and development teams scale testing without unexpected constraints.
read more →

Amazon CloudWatch Application Signals Adds SLO Tools

📈 Amazon CloudWatch Application Signals now includes three console-based SLO capabilities: SLO Recommendations, Service-Level SLOs, and SLO Performance Report. The features analyze 30 days of service metrics (P99 latency and error rates) to suggest validated, data-driven SLO targets and allow customers to approve recommendations before rollout. Service-Level SLOs provide a holistic view of service reliability across operations, while SLO Performance Report delivers calendar-aligned historical analysis for daily, weekly, and monthly intervals. These updates aim to reduce misconfigured thresholds and alert fatigue and are available in all Regions where Application Signals runs; pricing is usage-based with per-SLO charges.
read more →

Amazon MSK Adds M7g Graviton3 Brokers in Cape Town

🚀Amazon MSK now supports Standard brokers on AWS Graviton3-based M7g instances in the Africa (Cape Town) region. M7g brokers deliver up to 24% compute cost savings and up to 29% higher write and read throughput versus comparable M5-based MSK clusters. You can create new clusters with M7g brokers or upgrade existing M5 clusters via the Amazon MSK console or AWS CLI; consult the Amazon MSK Developer Guide for implementation details.
read more →

AWS Network Firewall Now in European Sovereign Cloud

🔐 Starting today, AWS Network Firewall is available in the AWS European Sovereign Cloud, enabling European customers — especially highly regulated industries, government agencies, and organizations with strict data sovereignty requirements — to deploy managed firewall protections while keeping data and operations within EU borders. The service delivers the same capabilities offered in other AWS Regions and automatically scales with VPC traffic to provide high-availability protections without customers needing to maintain underlying infrastructure. Refer to the AWS Region Table and service documentation for availability and configuration guidance.
read more →

OpenSearch UI Adds Cross-Account Domain Data Access

🔗 Amazon OpenSearch Service now supports cross-account data access, allowing users to query OpenSearch domains hosted in different AWS accounts from a single OpenSearch UI application within the same region. The capability works for domains in both public and VPC configurations and removes the need to switch endpoints or replicate data. It supports authentication via IAM (including SAML through IAM federation) and IAM Identity Center, enabling centralized observability and analytics while keeping data in place and preserving account-level access controls.
read more →