< ciso
brief />
Tag Banner

All news with #aws tag

2926 articles · page 95 of 147

Amazon EC2 R8i and R8i-flex Expand to More Regions

🚀 Amazon Web Services has expanded EC2 R8i and R8i-flex instances to Asia Pacific (Seoul), Asia Pacific (Tokyo), and South America (Sao Paulo). These memory-optimized instances run on custom Intel Xeon 6 processors exclusive to AWS, delivering up to 15% better price-performance and 2.5x more memory bandwidth versus prior Intel-based instances. R8i offers 13 sizes including two bare-metal options and a new 96xlarge for the largest workloads, while R8i-flex provides common sizes (large to 16xlarge) for cost-efficient memory-heavy applications. Instances are available via Savings Plans, On-Demand, and Spot.
read more →

ECS: Schedule Weekly Windows for Fargate Task Retirements

🕒 Amazon ECS now lets you define weekly event windows to control when AWS Fargate retires tasks for platform updates. Enable the account setting fargateEventWindows, create EC2 event windows with time ranges, and associate them to ECS tasks using managed tags like aws:ecs:clusterArn, aws:ecs:serviceArn, or aws:ecs:fargateTask. This allows precise timing (for example, weekend-only retirements) to avoid disruption during peak business hours and is available in all commercial AWS Regions.
read more →

AWS Clean Rooms: Change Requests for Collaborations

🔒 AWS Clean Rooms now supports change requests for existing collaborations, enabling participants to propose updates such as adding new members, adjusting member abilities, and modifying auto-approval behavior. All members must approve change requests before updates take effect, and every request is recorded in the collaboration change history for member review. This preserves existing privacy controls while reducing onboarding time and speeding time-to-insight—for example, a publisher can add an advertiser’s marketing agency to receive analysis results directly.
read more →

Amazon SES adds email validation to reduce bounces

📧 Amazon Simple Email Service (SES) introduces email validation to help customers reduce bounce rates and protect sender reputation. The capability offers API-based address checks and detailed validation insights such as syntax verification and DNS record analysis. With Auto Validation enabled, SES can automatically review every outbound address at the account or configuration-set level via simple console toggles, requiring no code changes. This feature is available in all AWS Regions where Amazon SES is offered and integrates with existing email workflows.
read more →

ECS: Weekly Event Windows for Fargate Task Retirements

🔁 Amazon ECS now supports defining weekly event windows to control when Fargate task retirements occur. This capability lets teams schedule infrastructure updates and automatic task replacements during off-peak periods, reducing disruption to mission-critical services. To use it, enable the account setting fargateEventWindows, create EC2 event windows with time ranges, and associate them to tasks using Amazon ECS-managed tags.
read more →

Amazon MSK Express Brokers Add KRaft with Kafka 3.9

🔔 Amazon Managed Streaming for Apache Kafka (MSK) Express Brokers now support Apache Kafka v3.9, introducing KRaft (Kafka Raft) for metadata management. New Express Broker clusters created with Kafka v3.9 will default to KRaft, moving metadata storage and replication into broker-managed topics and removing the dependency on ZooKeeper. The ability to upgrade existing clusters to v3.9 is planned for a future release. Kafka v3.9 for Express Brokers is available in all regions where MSK Express is supported; create a new cluster via the AWS Management Console, CLI, or SDKs to get started.
read more →

AWS Control Tower Adds 176 Security Hub Controls in Catalog

🔒 AWS announces that AWS Control Tower now includes 176 additional AWS Security Hub controls in its Control Catalog. You can search, discover, enable and manage these controls directly from the Control Tower console or via the ListControls, GetControl and EnableControl APIs. The new AWS Config rules are searchable in all Regions where Control Tower is available, including AWS GovCloud (US); check each rule's supported-region list before deployment.
read more →

AWS Control Tower Adds 176 Security Hub Controls in Catalog

🔐 Today, AWS Control Tower adds 176 additional AWS Security Hub controls to the Control Catalog, enabling you to search, discover, enable, and manage them directly from the Control Tower console. You can also call the ListControls, GetControl, and EnableControl APIs to automate governance across multi-account environments. New AWS Config rules are searchable in all Regions where Control Tower is available, including AWS GovCloud (US); check each rule's supported regions before deployment.
read more →

AWS Direct Connect Adds FIS-Based Resilience Testing

🧪 AWS Direct Connect now integrates with AWS Fault Injection Service (FIS) to run controlled resilience tests that deliberately disrupt Border Gateway Protocol (BGP) sessions on Virtual Interfaces. You can simulate BGP session failures to validate that traffic fails over to redundant Virtual Interfaces and that applications remain operational. This capability helps teams proactively verify failover behavior, observability, and recovery procedures and is available in all AWS Commercial Regions where AWS FIS is offered.
read more →

Zeroday Cloud: $320,000 awarded for 11 zero-days in London

🔒 The Zeroday Cloud competition in London, hosted by Wiz Research with support from AWS, Microsoft, and Google Cloud, awarded $320,000 to teams that demonstrated 11 zero-day remote code execution vulnerabilities. Exploits affected critical cloud components including Redis, PostgreSQL, MariaDB, Grafana, and a Linux-kernel container escape that broke tenant isolation. Team Xint Code earned the top prize of $90,000. Attempts against AI tooling such as vLLM and Ollama were made but failed due to time exhaustion.
read more →

Amazon warns of cryptomining campaign abusing AWS IAM

⚠️ Amazon's GuardDuty team is tracking an ongoing cryptomining campaign that uses compromised Identity and Access Management (IAM) credentials to abuse EC2 and ECS resources. The attacker deployed an yenik65958/secret Docker Hub image containing the SBRMiner-MULTI miner and configured large ECS tasks and auto-scaling EC2 groups to maximize mining. The actor also enabled instance termination protection to hinder remediation; Amazon has removed the malicious image, alerted affected customers, and recommends rotating compromised IAM credentials while following GuardDuty mitigation guidance.
read more →

AWS Security Hub Automation Rule Migration: CSPM to OCSF

🔁 This post explains a Python-based solution to migrate automation rules from Security Hub CSPM (ASFF) to the new Security Hub that adopts the open OCSF schema. The toolkit discovers rules across specified Regions, evaluates each rule against predefined ASFF→OCSF field mappings, and converts compatible rules into a CloudFormation template preserving order and Regional context. Actions or criteria without OCSF equivalents are flagged or partially migrated; migrated rules are created in a DISABLED state by default to allow review and testing. The package includes discovery, transformation, and template-generation scripts plus a migration report to guide manual adjustments.
read more →

AWS Databases Available on the Vercel Marketplace Launch

🚀 AWS Databases including Amazon Aurora PostgreSQL, Amazon Aurora DSQL, and Amazon DynamoDB are now generally available on the Vercel Marketplace, allowing developers to create and connect to managed databases directly from Vercel in seconds. You can provision a new AWS account from Vercel that includes access to these databases and $100 USD in credits usable for up to six months, and manage billing and usage via the AWS settings portal in the Vercel dashboard. Serverless options support scale-to-zero economics and are available in multiple Regions including US East, US West, Europe, and Asia Pacific.
read more →

CloudWatch metrics for Amazon WorkSpaces Applications

📊 Administrators and support teams can now monitor the health and performance of Amazon WorkSpaces Applications fleets, sessions, instances, and users through a new set of Amazon CloudWatch metrics. These metrics can be enabled across fleets from the CloudWatch console and dynamically update to reflect current state, simplifying troubleshooting of end-user streaming sessions and performance investigations. To receive the metrics, fleets must use a WorkSpaces Applications image with the agent released on or after December 06, 2025, or be updated via Managed WorkSpaces Applications image updates released on or after December 05, 2025; metrics are available in AWS commercial and AWS GovCloud (US) Regions where the service operates.
read more →

AWS Billing Conductor adds service-specific line items

📄 AWS Billing Conductor now supports service-specific custom line items scoped to a single AWS service or a selected set of services. Customers can control whether these line items appear itemized or consolidated in pro forma billing artifacts such as the Bills Page, Cost Explorer, and Cost and Usage Records. The enhancement enables more precise charge-back and re-billing workflows, including applying discounts to Saving Plans fees or allocating shared support charges. This capability is available now across AWS commercial Regions, excluding China.
read more →

ECR Public adds PrivateLink support in US East (N. Virginia)

🔒 Amazon Elastic Container Registry (ECR) Public now supports PrivateLink for the US East (N. Virginia) SDK endpoint. This enables private, secure connectivity from an Amazon VPC to the ECR Public SDK endpoint, reducing exposure to the public internet. Organizations can maintain network privacy, meet stricter security requirements, and simplify access patterns when creating and managing ECR Public repositories. Use cases include protecting sensitive image pulls and streamlining CI/CD network architecture.
read more →

Amazon OpenSearch Service Adds OI2 Optimized Instances

🚀 Amazon Web Services has introduced OI2 instances for Amazon OpenSearch Service, expanding the OpenSearch Optimized Instance family with sizes from large to 24xlarge and up to 22.5 TB of storage. The OI2 instances use the same architecture as OR2, pairing compute and 3rd-generation AWS Nitro SSDs for caching with remote S3-based managed storage, delivering up to 9% higher indexing throughput versus OR2 and up to 33% versus I8g in AWS internal benchmarks. OI2 is offered with pay-as-you-go and reserved pricing and is available in 12 AWS regions globally.
read more →

AWS Adds R8g (Graviton4) EC2 Instances in Paris, Hyderabad

🚀 Starting today, Amazon EC2 R8g instances powered by AWS Graviton4 are available in AWS Europe (Paris) and Asia Pacific (Hyderabad). These memory-optimized instances deliver up to 30% better performance compared to Graviton3-based R7g instances and offer larger sizes—up to 48xlarge and 1.5 TB of memory. R8g provides up to 50 Gbps enhanced networking and up to 40 Gbps EBS bandwidth, and is built on the AWS Nitro System to improve performance and platform-level security; it is ideal for databases, in-memory caches, and real-time big data analytics.
read more →

Amazon Redshift Serverless Adds Dual-Stack IPv6 Support

🌐 Amazon Redshift Serverless is now generally available in a dual-stack mode that supports IPv6 alongside IPv4. Administrators can create new workgroups or modify existing workgroups to enable IPv6 addressing or choose IPv4-only configurations within AWS VPCs. This capability allows Redshift warehouses to be deployed in IPv6-enabled subnets and lets applications communicate using either protocol. The feature is available in all AWS commercial regions.
read more →

Amazon EC2 M8g Instances Expand to New Regions and UAE

🚀 Amazon EC2 M8g instances are now available in Asia Pacific (Thailand, Jakarta, Melbourne) and AWS Middle East (UAE) regions. Powered by AWS Graviton4, they deliver up to 30% better performance compared to Graviton3-based instances and offer larger sizes with up to 3× more vCPUs and memory than M7g. M8g provides up to 50 Gbps enhanced networking and up to 40 Gbps EBS bandwidth across 12 instance sizes, including two bare metal options. Built on the AWS Nitro System, these general-purpose instances target application servers, microservices, gaming servers, midsize data stores, and caching fleets.
read more →