< ciso
brief />
Tag Banner

All news with #aws tag

2926 articles · page 78 of 147

EC2 Image Builder: wildcard lifecycle policies, IAM defaults

🔧 EC2 Image Builder now supports wildcard patterns in lifecycle policies so teams can apply retention and cleanup rules across multiple image recipes with a single policy. The console also simplifies IAM role creation by pre-populating required default permissions for lifecycle management. These enhancements reduce manual configuration, lower the risk of misconfiguration, and make it easier to scale image lifecycle operations as new recipes are added. Lifecycle Policies are available in all commercial AWS regions.
read more →

Amazon ARC Region Switch adds post-recovery and RDS blocks

🔁 Amazon Application Recovery Controller (ARC) Region switch now includes post-recovery workflows, native Amazon RDS execution blocks, and support in the AWS provider for Terraform. The update automates failover and the subsequent recovery preparation steps to reduce manual coordination and lower error risk. Post-recovery workflows support Lambda actions, RDS read-replica creation, nested ARC plans, and manual approvals, and can be triggered for active/passive deployments. Terraform support enables DR plans as Infrastructure-as-Code for CI/CD integration.
read more →

AWS Network Firewall Adds EventBridge State Notifications

🔔 AWS Network Firewall now emits real-time state change and configuration notifications via Amazon EventBridge. This integration reports updates across AWS Managed Rules, Partner Managed Rules, and firewall configurations so security and ops teams can centralize monitoring. With EventBridge you can route events to Amazon SNS, ITSM ticketing, or third‑party SIEMs to automate alerts and accelerate response.
read more →

Amazon Bedrock Batch Inference Adds Converse API Support

🔁 Amazon Bedrock batch inference now accepts the Converse API as a model invocation type, letting you submit batch inputs in a consistent, model-agnostic Converse request format and receive outputs in the Converse response format. This unifies real-time and batch request formats, simplifying prompt management and reducing the effort of switching between models. You can configure the Converse invocation type through the Bedrock console or API, and the capability is available in all Regions that support Bedrock batch inference.
read more →

CloudWatch log centralization supports custom groups

🔧 Amazon CloudWatch now lets administrators customize destination log group names when creating log centralization rules, using attributes such as account ID, region, log group name, organization ID, organizational unit ID, root ID, or the full organizational path. Patterns like ${source.accountId}/${source.region}/${source.logGroup} produce readable hierarchies (for example, 123456789012/us-east-1/cloudtrail/managementevent). The feature is available in all centralization rules supported regions. One centralized copy is ingested for free; additional copies (including backup-region copies) are charged at $0.05/GB and storage fees apply.
read more →

AWS RAM supports retaining shares when accounts move

🔒 AWS Resource Access Manager (RAM) now provides a resource share configuration that preserves shared access when accounts move between AWS Organizations. The new RetainSharingOnAccountLeaveOrganization parameter and the ram:RetainSharingOnAccountLeaveOrganization condition key allow administrators to retain access to resources such as Route53 Resolver Rules, Transit Gateways, and IPAM pools when accounts leave an organization. Security teams can enforce the setting using Service Control Policies (SCPs). RAM will treat moved accounts as external principals, requiring explicit invitation acceptance to maintain access. This capability is available in all AWS commercial Regions at no additional cost.
read more →

AWS Adds Bacs Direct Debit Payment Option for UK Customers

💳 AWS now lets UK customers pay via Bacs Direct Debit, enabling automated GBP-based bank payments for AWS services. Customers can connect personal or business accounts that support the Bacs standard and authenticate through their bank’s mobile app or online banking to verify ownership. New customers select Bacs Direct Debit during sign-up; existing customers add it in the Billing console’s Payment Preferences. The option is available in UK regions at no additional cost.
read more →

Amazon OpenSearch Adds Insights to Improve Cluster Stability

🔍 AWS has enhanced Amazon OpenSearch Service Cluster Insights with two new detections: Cluster Overload and Suboptimal Sharding Strategy. The updates surface shard imbalances and elevated resource utilization (CPU, memory, disk I/O, throughput, and disk utilization), identify affected resources, and provide clear mitigation and scale-up recommendations. These insights are available at no additional cost for OpenSearch 2.17+ in Regions where the OpenSearch UI is offered.
read more →

Oracle Database@AWS Launches in Dublin (EU-West-1) Region

🚀 Oracle Database@AWS is now available in the EU‑West‑1 (Dublin) AWS Region, initially deployed in a single Availability Zone. The service provides access to OCI managed Oracle Exadata systems hosted within AWS data centers and supports like‑for‑like migrations of on‑premises Exadata and Oracle RAC workloads. Integrations include AWS Key Management Service for encryption and AWS CloudWatch for monitoring, helping address regional data residency requirements.
read more →

Ransomware Shift: Stealthy, Long-Term Access Tactics

🔒 Picus Security's annual red-teaming report finds ransomware operators shifting from noisy encryption to stealthy, long-term access, favoring persistence, defense evasion and data exfiltration. The firm reports a 38% drop in encryption as attackers prioritize double-extortion and silent leaks, often routing C2 traffic through trusted services like OpenAI and AWS. Experts urge stronger identity controls, monitoring of third-party integrations, and detections tuned to persistence and exfiltration.
read more →

AWS IAM Identity Center Adds IPv6 in Taipei and GovCloud

🌐 AWS IAM Identity Center now supports IPv6 through dual‑stack endpoints in the AWS Asia Pacific (Taipei) and AWS GovCloud (US) Regions, completing global availability wherever IAM Identity Center is offered. Clients and browsers will resolve either IPv4 or IPv6 addresses based on network and client protocol. Administrators can find the dual-stack portal URL in the IAM Identity Center console under Settings and share it with their workforce; GovCloud deployments should consult region-specific documentation.
read more →

Amazon Bedrock Adds OpenAI-Compatible Projects API

🚀 Amazon Bedrock now offers an OpenAI-compatible Projects API within the Mantle inference engine, enabling customers to create isolated projects for separate applications, environments, or teams. Each project supports distinct IAM-based access controls and tagging to improve security boundaries and cost visibility. The feature is available for OpenAI-compatible APIs, the Responses API, and Chat Completions through Mantle. There is no additional charge beyond model inference consumption.
read more →

Amazon SageMaker HyperPod: API-driven Slurm Management

🔧 Amazon SageMaker HyperPod now supports API-driven Slurm configuration, enabling you to define Slurm topology, instance group to partition mappings, and FSx filesystem mounts directly in the cluster CreateCluster and UpdateCluster APIs or via the AWS Console. The update lets you specify node roles such as Controller, Login, and Compute per instance group and mount FSx for Lustre or FSx for OpenZFS filesystems. A new SlurmConfigStrategy (Managed, Overwrite, Merge) detects partition-node drift and controls whether updates are paused, overwritten, or merged to preserve manual customizations.
read more →

AWS Completes First ISO/IEC 42001:2023 Surveillance Audit

🔒 In November 2025, AWS completed its first surveillance audit for ISO/IEC 42001:2023 — the Artificial Intelligence Management System standard — with no findings. This follows AWS’s November 2024 announcement that several AI services, including Amazon Bedrock, Amazon Q Business, Amazon Textract, and Amazon Transcribe, were accredited under the standard. The successful no-findings outcome provides independent validation of AWS’s ongoing commitment to responsible AI practices and gives customers added assurance when building and operating AI applications on AWS.
read more →

AWS Security Agent: Multi-Agent Penetration Testing

🔒 AWS describes a multi-agent penetration testing capability in AWS Security Agent that pairs LLM-driven reasoning with specialized scanners and browser-based sign-in to automate complex assessments. The design combines baseline scanning, managed static tests, and a guided explorer that dynamically generates contextual attack tasks. A swarm of risk-focused worker agents executes tests and submits structured findings, which are then validated via deterministic checks and LLM-assisted exploit attempts and scored with CVSS to produce actionable remediation reports.
read more →

ECS Managed Instances Now Support EC2 Capacity Reservations

🔔 Amazon Elastic Container Service (ECS) Managed Instances now integrate with Amazon EC2 Capacity Reservations, letting you apply reserved capacity to managed EC2 compute while ECS handles infrastructure. Configure capacity providers with capacityOptionType=reserved and choose reservation preferences — reservations-only, reservations-first, or reservations-excluded — to balance predictability and cost. Available in all regions and configurable via Console, CLI, CloudFormation, or SDKs.
read more →

AWS Marketplace Adds Concurrent Agreements for SaaS

🔁 AWS Marketplace now supports Concurrent Agreements for SaaS and Professional Services products, enabling multiple active purchases of the same product within a single AWS account. The change removes the prior one-agreement-per-product limitation and lets different business units procure independently with separate terms and pricing. Buyers gain flexibility for mid-term expansions and repeat purchases, while sellers can close multi-unit deals immediately and avoid operational workarounds.
read more →

Amazon Connect adds dynamic dialing mode switching

🔁 AWS announced general availability of dynamic dialing mode switching for Amazon Connect Outbound Campaigns, allowing administrators to change between preview and non-preview dialing modes while a campaign is running. Previously, campaigns were locked to their initial dialing mode and required stopping and restarting to change strategy. The new capability lets contact centers adapt dialing behavior in real time to improve agent productivity and campaign efficiency without interruptions. It is available at no additional cost in all supported AWS Regions.
read more →

CloudWatch Database Insights: PostgreSQL Lock Diagnostics

🔒 Amazon CloudWatch Database Insights now provides lock contention diagnostics for Amazon RDS for PostgreSQL instances when operating in Advanced mode. The feature visualizes blocking and waiting sessions to highlight the dominant sessions, queries, or objects causing contention and preserves historical locking data for up to 15 months. You can enable diagnostics on PostgreSQL clusters via the RDS console, AWS APIs, or the AWS SDK. CloudWatch Database Insights is available in all public AWS Regions and uses vCPU-based pricing.
read more →

AWS Security Hub Extended: Unified Pay-as-You-Go Plan

🔒 AWS Security Hub Extended is now generally available, offering a single-vendor plan that combines AWS detection services with curated partner security solutions on a pay-as-you-go or flat-rate basis. The plan consolidates procurement and billing—AWS serves as seller of record and Enterprise Support customers receive unified Level 1 support. It centralizes findings in a standard format for cross-tool visibility, reduces manual integration work, and lets organizations add or remove categories such as endpoint, identity, email, network, data, browser, cloud, AI, and security operations without long-term commitments.
read more →