< ciso
brief />
Tag Banner

All news with #aws tag

2919 articles · page 8 of 146

Amazon Connect Customer adds tag-based access control

🔐 Amazon Connect Customer now supports tag-based access control for custom metrics, enabling administrators to govern who can view, create, or modify each metric. This lets teams tag metrics and assign permissions so they retain full control over their own metrics, have view-only access to other teams’ metrics, or are prevented from seeing restricted metrics. Search results respect these access controls. The feature is available in all Regions where Amazon Connect Customer is offered.
read more →

Amazon Connect imports evaluation form PDFs with AI

🤖 Amazon Connect Customer now supports importing evaluation form PDFs from third-party quality management applications and uses AI to recreate them within Connect. The service extracts sections, questions, answer options, and scoring into a draft form after you choose percentage or points-based scoring. You can provide natural language instructions to refine the import, reducing manual edits before activation. This feature is available in multiple AWS Regions including N. Virginia, Oregon, Singapore, Sydney, Tokyo, Frankfurt, and Canada (Central).
read more →

MediaTailor adds new monetization function hooks

🔔 AWS Elemental MediaTailor now supports two additional monetization function lifecycle hooks: post ADS response and pre manifest insertion. These hooks let customers run custom logic after ADS responses are parsed and just before ad pods are returned to viewers, enabling secondary ad sourcing, policy-based ad removal, house ads, and final checks including personalized slates. Pre-built recipes are available and both hooks are fail-open to avoid playback disruption.
read more →

Amazon Connect Customer adds APIs for custom metrics

📈 Amazon Connect Customer now supports programmatic creation, management, and search of custom metrics through seven new API operations. These include CreateMetric, DeleteMetric, DescribeMetric, ListMetrics, SearchMetrics, UpdateMetricContent, and UpdateMetricMetadata. Changes are logged in AWS CloudTrail and the feature is available in all Regions where Amazon Connect Customer is offered.
read more →

Amazon Keyspaces expands availability to 11 Regions

🚀 Amazon Keyspaces (for Apache Cassandra) is now generally available in 11 additional AWS Regions, enabling customers to run Cassandra-compatible applications with lower latency and meet regional data residency requirements. Amazon Keyspaces is a managed, serverless, and highly available Cassandra-compatible database service that scales for high throughput and storage demands. Customers pay only for resources used and can serve thousands of requests per second with virtually unlimited capacity. New Region availability details are provided in AWS region capability listings.
read more →

Amazon Connect Talent: AI hiring at scale

🤖 Amazon Connect Talent is now generally available as an AI-powered hiring solution for talent acquisition leaders. Informed by Amazon's hiring science, it uses AI agents to conduct structured voice interviews, administer evidence-based competency assessments, and consistently score candidates. The service supports 24/7 interviews from any device, provides transcripts and detailed evaluations, and includes a brand-customizable candidate portal and admin tools for scaling hiring operations.
read more →

AWS STS enforces unified 4,096-byte session limit

🔒 AWS Security Token Service (STS) now enforces a single 4,096-byte size limit for session tokens, replacing separate limits for tokens and passed-in parameters. This change lets you combine larger session policies and session tags more flexibly. STS also returns token size and percentage utilization in responses, logs those values to AWS CloudTrail, and publishes metrics to Amazon CloudWatch. An optional API parameter lets you request larger tokens for testing, and the features are available in all commercial, GovCloud (US), and European Sovereign Cloud Regions.
read more →

AWS STS simplifies token limits and adds monitoring

🔒 AWS Security Token Service (STS) now enforces a single assembled session token size limit of 4,096 bytes, replacing the previous packed policy and token size limits. STS returns session token size and utilization in API responses, CloudWatch metrics, and CloudTrail events, and preserves PackedPolicySize for backward compatibility. A new MinimumSessionTokenSize parameter lets you generate larger tokens to test infrastructure limits; error handling remains unchanged with PackedPolicyTooLargeException used for over-limit tokens.
read more →

AWS BCM adds Detected Anomalies widget to Dashboards

🧾 AWS Billing and Cost Management now includes a Detected Anomalies widget in BCM Dashboards, letting teams view cost anomalies alongside budgets, usage, and Savings Plans or Reserved Instance reports. The widget shows anomaly counts, cost impact relative to month-to-date spend, root cause, duration, and supports 30/60/90-day look-backs. Filters for severity, service, account, and region and direct links to the Cost Anomaly Detection console facilitate investigation. The widget is available in all commercial AWS Regions at no additional charge and supports exports, scheduled email reports, CSV/PDF downloads, and cross-account dashboard sharing.
read more →

Architecting resilient authentication with Cognito MRR

🔒 Amazon Cognito now supports multi-Region replication (MRR) to automatically replicate user pools across AWS Regions with near-real-time synchronization, built-in failover, and interoperable JWT sessions. Replica user pools support sign-in and token operations but are read-only for configuration and attribute writes, which must be performed in the primary Region. To use MRR you must configure a symmetric multi-Region AWS KMS customer managed key and consider adopting the updated multi-Region OIDC issuer to ensure consistent discovery and JWKS endpoints. Cognito supports automatic domain and OAuth failover via Route 53 health checks and recommends using infrastructure-as-code and JWKS caching strategies for smooth migration and operational continuity.
read more →

AWS Direct Connect introduces flat-rate 10G/100G pricing

🔔 AWS Direct Connect now offers flat-rate monthly pricing for 10 Gbps and 100 Gbps dedicated connections, eliminating per-gigabyte data transfer out (DTO) charges within the chosen pricing tier. The model provides five geographic tiers from same-metro to global coverage and introduces an optional port-pair concept that provisions two redundant connections sharing the same bandwidth at no extra charge. Flat-rate pricing is available at all commercial AWS Direct Connect locations (excluding China Regions) and can be applied or changed per connection.
read more →

AWS Billing Conductor adds custom rates and tiers

🛠️ AWS Billing Conductor now supports defining custom rate pricing and usage tiers for AWS services, enabling customers and partners to model negotiated commercial agreements more accurately. Using SKU-scoped pricing rules, users can enter exact rates and configure tier thresholds rather than applying percentage markups or markdowns to public on-demand rates. This feature is available in all commercial AWS Regions except the two China regions operated by Sinnet and NWCD. It simplifies pro forma billing configuration by providing precise control over pricing and tier breaks.
read more →

AWS Step Functions adds automatic service integrations

🛠️ AWS Step Functions now automatically adds AWS SDK integrations for newly released AWS services and capabilities within weeks, starting with AWS Lambda MicroVMs and AWS Lambda Core. This lets you orchestrate the latest AWS services from workflows without waiting for manual updates. The integrations are generally available in all Regions where Step Functions is offered, though specific APIs depend on regional service availability. Continuous updates mean AWS will no longer publish What's New posts for these SDK integration updates.
read more →

SageMaker adds instance preference lists for jobs

🆕 Amazon SageMaker now supports instance preference lists for training and processing jobs, letting you submit prioritized sets of instance types and counts so SageMaker can pick the first available configuration. This reduces wait times and removes the need for complex retry logic or multiple concurrent submissions during high-demand GPU periods. You can include on-demand sources or reserved SageMaker Flexible Training Plans, and the feature is available today in all AWS Regions via CLIs, APIs, SDKs, and the Console.
read more →

CloudTrail now integrates with Amazon Q Console

🔍 AWS CloudTrail now integrates with Amazon Q Console to let you investigate account activity using natural language queries. You can ask about CloudTrail configuration, search logged events for security investigations, and troubleshoot operational issues without writing queries. The integration queries CloudTrail trails, CloudWatch log groups, and event data stores to provide answers grounded in your account activity. It is available in all AWS commercial regions where Amazon Q Console is supported.
read more →

Amazon Connect adds agent shift bidding capability

🔔 Amazon Connect Customer now lets contact center agents bid on preferred shifts, giving them greater control over schedules. Schedulers establish agent rankings via CSV upload or randomized generation, and Connect Customer uses forecasted demand and shift profiles to create available shifts for agents to rank. After the bidding window closes, the service assigns agents to their highest-ranked available shift, using rankings as tiebreakers to resolve conflicts. This feature aims to improve agent satisfaction and reduce manual scheduling effort.
read more →

Automating IAM least-privilege remediation via CI/CD

🔒 This post describes an automated workflow that turns AWS IAM Access Analyzer findings into actionable remediation artifacts. It classifies roles by origin—IaC-managed, manually created, or unused—and produces either a production-ready CDK pull request, a migration issue with recommended policies, or a soft-disable decommission plan. The automation integrates Access Analyzer, CloudTrail, Amazon Bedrock, and your CI/CD pipeline to create reviewable, deployable changes instead of accumulating tickets.
read more →

Exposed Vite servers probed for cloud credentials

🔎 Attackers have begun probing exposed Vite development servers for sensitive data, including AWS and Azure credentials, environment files, and infrastructure state. F5 Labs observed over 32,000 scan attempts in August exploiting a file-access bypass (CVE-2026-39364) that defeats Vite's deny-list protections when specific query parameters are used. F5 urges patching Vite, rotating secrets, and ensuring development servers are not bound to external interfaces.
read more →

AWS Glue adds archived Salesforce records capture

🔔 AWS Glue zero-ETL integrations for Salesforce now capture archived records and expose their status via the isArchived field, providing a complete replica of Salesforce data for analytics and reporting. This applies automatically to new integrations and is backfilled for existing integrations with no reconfiguration or schema changes. The feature is available in all AWS Commercial and AWS GovCloud (US) Regions where AWS Glue zero-ETL for Salesforce is supported.
read more →

AWS enhances regional resiliency for root sign-ins

🔒 AWS now serves root user sign-in across US East (N. Virginia), US East (Ohio), and US West (Oregon), distributing traffic across these Regions to reduce dependency on a single Region and improve resiliency during disruptions. Sign-in routing is automatic and requires no action from customers. CloudTrail records ConsoleLogin events in the Region that processed the sign-in; update monitoring and alerts to include all three Regions. This change is available now for all AWS accounts.
read more →