< ciso
brief />
Tag Banner

All news with #aws tag

2926 articles · page 85 of 147

Amazon Connect adds appeals workflow for evaluations

🔁 Amazon Connect introduces an integrated appeals workflow that lets agents contest performance evaluations directly within the Connect UI. Agents can submit reasoning and cite specific examples when they disagree with scores, such as contested active listening ratings. Designated managers receive automated email notifications, can review appeals, and track resolution status across all regions where Amazon Connect is offered.
read more →

Amazon Aurora DSQL Adds Index Support for NUMERIC Type

🧮 Aurora DSQL now supports creating indexes on the NUMERIC data type, allowing NUMERIC columns to be used in primary keys and secondary indexes. This change targets workloads that require high-precision values such as currency amounts, scientific measurements, and statistical datasets. The feature is available in all Regions where Aurora DSQL is offered and is intended to improve query performance for operations that sort, filter, or join on precise numeric values. Customers should test index impact on storage and write performance with representative workloads.
read more →

AWS Console Displays Account Name in Nav Bar Globally

ℹ️ AWS announced general availability of displaying the account name in the AWS Management Console navigation bar across all public Regions. The new account name display lets authorized users visually identify and distinguish accounts at a glance rather than relying solely on numeric account IDs. The capability is available at no additional cost; administrators must enable it by applying the appropriate managed policy before users will see the name in the console.
read more →

Amazon Quick Suite: Resolve Ambiguous Map Locations

🗺️ Authors can now resolve ambiguous locations directly on map visuals in Amazon Quick Suite using Quick Sight. When place names occur in multiple regions—examples include cities like Springfield or Abbeville—authors may disambiguate by adding supporting geospatial fields to create location hierarchies, searching the product’s geographic database, or entering precise latitude/longitude coordinates. The feature presents clear status indicators (Unmatched, Matched, Unused) and resolution actions accessible from map visuals. It is available in all regions that support Quick Sight, and documentation plus a blog post provide guidance on maps and geospatial charts.
read more →

AI-Driven AWS Attack: From Exposed Key to Admin in Minutes

⚠️ Sysdig researchers observed an AI-assisted intrusion in November 2025 that converted exposed AWS credentials in a public S3 bucket into full administrative control in under eight minutes. The attackers exploited an IAM user with Lambda and limited Amazon Bedrock access, injected malicious code into an existing Lambda function, and generated admin keys from the function output. They then moved laterally across multiple principals, invoked multiple foundation models (LLMjacking), disabled model-invocation logging, and attempted to provision costly GPU instances to run ML workloads. Sysdig recommends enforcing least privilege, restricting UpdateFunctionCode and PassRole, protecting S3 buckets, enabling Lambda versioning, and turning on Bedrock logging.
read more →

Oracle Database@AWS Expands to Canada Central and Sydney

📢 Oracle Database@AWS is now available in CA-Central-1 (Canada Central) and AP-Southeast-2 (Sydney), each starting with one Availability Zone. The service provides access to OCI-managed Exadata systems hosted inside AWS data centers, enabling like-for-like migrations of on-premises Oracle Exadata and RAC workloads. Integrations with AWS services such as AWS KMS for encryption and Amazon CloudWatch for monitoring are supported. Customers must request a private offer from Oracle via the AWS Marketplace and use the AWS Management Console to provision and manage databases.
read more →

AWS Adds DeepSeek OCR, MiniMax, and Qwen3 to JumpStart

📢 AWS has added DeepSeek OCR, MiniMax M2.1, and Qwen3-VL-8B-Instruct to SageMaker JumpStart, expanding the set of foundation models available to customers. DeepSeek OCR focuses on visual-text compression and structured extraction from forms, invoices, diagrams, and other dense document layouts. MiniMax M2.1 targets multilingual coding, tool use, instruction following, and long-horizon planning to support autonomous workflows. Qwen3-VL-8B-Instruct enhances vision-language reasoning, spatial and video dynamics comprehension, and extended context handling. Customers can deploy any of these models via the JumpStart catalog or the SageMaker Python SDK to accelerate AI application development on AWS infrastructure.
read more →

NVIDIA NIMs Now Available on Amazon SageMaker JumpStart

🚀 With Amazon SageMaker JumpStart, customers can now deploy four NVIDIA NIMs — ProteinMPNN, Nemotron-3.5B-Instruct, MSA Search NIM, and Cosmos Reason — with one click. These prebuilt, optimized inference microservices are designed for NVIDIA-accelerated infrastructure and target biosciences and physical AI use cases. They enable protein sequence optimization, GPU-accelerated multiple sequence alignment, large-context reasoning and agentic tool calling, and vision-language planning for robotics. Deployments are accessible from the SageMaker JumpStart catalog or via the SageMaker Python SDK.
read more →

Amazon Lightsail Adds Memory-Optimized Instance Bundles

🧠 Amazon Lightsail now offers memory-optimized instance bundles with up to 512 GB of RAM across seven sizes, available for Linux and Windows blueprints and both IPv6-only and dual-stack networking. The bundles include pre-configured OS and application blueprints such as WordPress, cPanel & WHM, Plesk, Drupal, Magento, MEAN, LAMP, Node.js, Ruby on Rails, Amazon Linux, Ubuntu, CentOS, Debian, AlmaLinux, and Windows. These instances target memory-intensive workloads like in-memory databases, real-time analytics, caching systems, HPC, and large enterprise applications. The new bundles are available in all Regions where Lightsail is offered; check Lightsail pricing for regional costs.
read more →

AWS STS Validates Provider Claims for OIDC Roles Now

🔐 AWS Security Token Service (STS) now validates select identity-provider-specific claims from Google, GitHub, CircleCI, and Oracle Cloud Infrastructure for OIDC federation via the AssumeRoleWithWebIdentity API. You can reference these custom claims as condition keys in IAM role trust policies and resource control policies to enforce finer-grained access control and establish data perimeters. This enhancement builds on IAM's OIDC federation capabilities and is available in all AWS Commercial Regions.
read more →

AWS Multi-Party Approval Adds One-Time Password Voting

🔐 AWS announced that AWS Multi-Party Approval now requires approvers to verify voting actions with a one-time password sent to their registered AWS Identity Center email address. The OTP is a six-digit code that must be entered within 10 minutes of receipt, with up to three attempts allowed. Verification occurs when the approver submits their vote, after they have reviewed request details. Administrators cannot bypass this control via credential resets or authentication endpoint changes.
read more →

Amazon RDS for MySQL: New Minor Versions 8.0.45 & 8.4.8

🔒 Amazon RDS for MySQL now supports the MySQL community minor releases 8.0.45 and 8.4.8. AWS recommends upgrading to these minors to remediate known security vulnerabilities present in earlier releases and to benefit from bug fixes, performance improvements, and incremental features. You can enable automatic minor version upgrades to apply eligible updates during scheduled maintenance windows to reduce manual effort. For lower-risk updates and faster cutover, consider Amazon RDS Managed Blue/Green deployments and follow the Amazon RDS User Guide for upgrade instructions, regional availability, and pricing details.
read more →

Amazon CloudFront Adds Mutual TLS Authentication for Origins

🔐 Amazon CloudFront now supports mutual TLS (mTLS) for origins, allowing origin servers to cryptographically verify that incoming requests originate from authorized CloudFront distributions. This certificate-based approach replaces custom solutions like shared-secret headers and IP allow-lists, reducing operational overhead and improving security for public and externally hosted origins. Customers may use client certificates issued by AWS Private Certificate Authority or third-party private CAs imported through AWS Certificate Manager, and can configure origin mTLS via the Console, CLI, SDK, CDK, or CloudFormation. Origin mTLS works with AWS-supported mutual TLS origins such as Application Load Balancer and API Gateway, as well as on-premises and custom origins, and is available at no additional charge.
read more →

AWS Network Firewall Flexible Cost Allocation in GovCloud

💰 AWS Network Firewall now supports flexible cost allocation via AWS Transit Gateway native attachments in AWS GovCloud (US) Regions, enabling centralized inspection charges to be distributed automatically across accounts. Administrators can create metering policies to allocate data processing costs to application teams based on actual usage instead of consolidating expenses in the firewall owner account. The feature is available in GovCloud (US-East) and GovCloud (US-West) and can be enabled through the AWS Management Console, CLI, or SDK. There are no additional fees beyond standard Network Firewall and Transit Gateway pricing.
read more →

Amazon Connect APIs for Simulating Voice Contact Tests

📞 Amazon Connect now provides APIs to configure and run tests that simulate contact center voice interactions. You can programmatically set test parameters such as caller phone number or customer profile, call intent, expected responses, and business conditions like after-hours or full queues. The APIs support parallel execution and CI/CD integration to enable automated regression testing. These capabilities help validate workflows and accelerate safe deployments of new customer experiences.
read more →

AWS HealthImaging Adds JPEG XL Support for DICOM Storage

🏥 AWS HealthImaging now supports storing and retrieving lossy compressed medical images using the JPEG XL DICOM transfer syntax (1.2.840.10008.1.2.4.112). This enables applications such as digital pathology whole slide imaging systems to consume native JPEG XL-encoded frames without on-the-fly transcoding. HealthImaging preserves image fidelity, reduces storage costs, and avoids retrieval latency caused by transcoding. JPEG XL support is available in all Regions where the service is generally available.
read more →

CloudWatch Application Signals Integrates with Kiro Powers

🔍 AWS announced integration of Amazon CloudWatch Application Signals with Kiro Powers to deliver AI agent-assisted troubleshooting workflows directly within the Kiro IDE. The Kiro power packages the Application Signals MCP server with curated steering files and hooks, providing focused observability guidance so agents receive only the context needed for a specific task. Developers can accelerate SLO triage and service isolation from hours to minutes with one-click installation across AWS Regions.
read more →

Scaling AWS Managed Microsoft AD: Monitoring and Options

🔍 This post explains how to scale AWS Managed Microsoft AD by choosing between scale-up (edition upgrade to Enterprise) and scale-out (adding domain controller instances), and shows how to use Amazon CloudWatch dashboards to monitor directory health. It highlights key metrics—CPU, memory, disk, I/O, network, and DNS—recommended thresholds, and alerting guidance to inform scale decisions. The guidance recommends preferring reversible scale-out for capacity issues and reserving scale-up for Enterprise-only features such as multi-Region replication and large object counts.
read more →

Amazon Connect adds improved estimated wait time metrics

⌛ Amazon Connect now provides improved estimated wait time metrics for queues and enqueued contacts, enabling contact centers to set accurate customer expectations and offer options such as callbacks when hold times extend. By integrating with routing criteria and agent proficiency settings, the metric supports smarter cross‑queue routing so customers reach appropriately skilled agents faster. Administrators can use the enhanced visibility for resource planning and workload balancing across multiple queues. This capability is available in all AWS regions where Amazon Connect is offered.
read more →

Amazon SageMaker Unified Studio adds PrivateLink access

🔒 Amazon SageMaker Unified Studio can now be accessed through AWS PrivateLink, enabling customers to route traffic between their VPC and Unified Studio without traversing the public internet. Network administrators can onboard SageMaker service endpoints to a VPC and combine them with IAM policies to enforce that customer data remains on the AWS network. The capability is available in all Regions that support Unified Studio, giving customers a built-in option for stronger network isolation.
read more →