< ciso
brief />
Tag Banner

All news with #aws tag

2926 articles · page 97 of 147

Amazon: Russian GRU Targets Misconfigured Edge Devices

🔒 Amazon Threat Intelligence has attributed with high confidence a years‑long campaign to Russia’s GRU, noting a shift in 2025 from exploiting software flaws to compromising misconfigured customer network edge devices. The actor has targeted enterprise routers, VPN concentrators, network management appliances and cloud-hosted edge instances, including some hosted on AWS, to gain initial access. This tactic supports credential harvesting, replay attacks and lateral movement while reducing attacker exposure and resource expenditure.
read more →

Amazon Quick Suite Adds Memory for Personalized Chat Agents

🧠 Amazon Quick Suite now adds memory to its chat agents, enabling personalized responses based on prior conversations and stated preferences. The feature stores inferred user preferences—such as response format, acronyms, dashboards, and integrations—and lets users view and remove any remembered items. Users may also choose Private Mode, in which chats are not used to infer memories. Memory is currently available in US East (N. Virginia) and US West (Oregon).
read more →

Amazon Quick Suite Extension Adds Quick Flows in Browser

🔁 The Amazon Quick Suite browser extension now supports Amazon Quick Flows, enabling users to run workflows directly in their web browser without manually extracting page data. You can invoke flows you created or that were shared with you and pass web page content as input while staying on the site. This supports routine tasks like contract analysis and dashboard report generation. The capability is available in select regions with no extra extension fees beyond standard Quick Flows usage.
read more →

AWS Clean Rooms publishes EventBridge notifications

🔔 AWS Clean Rooms now publishes events to Amazon EventBridge to signal new member invitations and table readiness. Invited collaborators receive immediate EventBridge notifications when added to a collaboration, and members are alerted when AWS Entity Resolution resources (ID mapping tables and namespaces) are associated. This enables automated, near-real-time workflows, reduces manual polling, and shortens time-to-action from hours to minutes. Organizations can more quickly start analyses and increase transparency between collaborators.
read more →

Route 53 adds CloudWatch metrics for Resolver endpoints

📊 You can now enable CloudWatch metrics for Route 53 Resolver endpoints to monitor per-endpoint DNS performance and the health of target name servers. The metrics include query response latency plus counts of SERVFAIL, NXDOMAIN, REFUSED and FORMERR responses, and timeouts for outbound target servers. These details make it easier to troubleshoot hybrid DNS resolution issues and build alerts and dashboards; standard CloudWatch and Resolver endpoint charges apply.
read more →

AWS Response and Lessons from npm Supply-Chain Attacks

🔒AWS Security details its incident response to multiple high-scale npm supply chain campaigns, including the compromised Nx package, the Shai-Hulud worm, and a token-farming operation detected by Amazon Inspector. Teams enacted rapid containment (repository blocklisting, OpenSSF registration), performed deep analysis using AI-assisted detonation in sandboxes, and automated disclosures to protect customers. The effort produced improved behavioral detections, GenAI prompt guardrails for Amazon Q, and strengthened collaboration with the security community to reduce future exposure.
read more →

Amazon EVS Now Available in Additional AWS Regions

🚀Amazon Elastic VMware Service (Amazon EVS) is now available in all availability zones within six additional AWS Regions, expanding options for running VMware workloads on AWS Nitro-powered EC2 bare-metal. You can deploy a complete VMware Cloud Foundation environment in hours using the guided workflow or CLI automation, accelerating migrations and data center exits. This expansion improves latency, supports data residency requirements, and adds redundancy choices for high availability.
read more →

Amazon Connect adds multiple-choice and date fields

📣 Amazon Connect now supports two new evaluation question types to capture deeper insights on human and AI agent performance. Managers can add multiple-selection questions to record several items—such as products a customer was interested in—and date fields to log events like when an application was submitted and approved. These features are available in all regions where Amazon Connect is offered.
read more →

Amazon Managed Service for Apache Flink Now in Auckland

🚀 Starting today, Amazon Managed Service for Apache Flink is available in the AWS Asia Pacific (Auckland) Region to help customers build and operate real-time stream processing applications with lower latency and simpler operations. The managed service reduces the complexity of deploying and maintaining Apache Flink applications and integrates with Amazon MSK, Amazon Kinesis Data Streams, Amazon OpenSearch Service, DynamoDB Streams, Amazon S3 and custom connectors. This regional launch enables local teams to accelerate streaming analytics, continuous ETL, monitoring, and event-driven processing while avoiding direct cluster management.
read more →

AWS cost allocation using workforce user attributes

📊 AWS now supports cost allocation using workforce user attributes imported into IAM Identity Center. Customers can enable attributes such as cost center, division, organization, and department as cost allocation tags to automatically attribute per-user subscription and on-demand application fees to internal business units. Costs are visible in AWS Cost Explorer and AWS CUR 2.0 and the capability is generally available in all Regions except GovCloud (US) and China (Beijing and Ningxia).
read more →

Amazon EKS Adds Cluster-wide and DNS-based Network Policies

🔐 Amazon EKS now offers centralized network policy controls with ClusterNetworkPolicy and DNS-based egress filtering to improve protection for Kubernetes workloads and their external integrations. These enhancements build on existing Kubernetes NetworkPolicies in the Amazon VPC CNI and enable cluster-wide enforcement of access filters. The features are available for new EKS clusters running Kubernetes 1.29+ in all commercial AWS Regions; support for existing clusters will follow. ClusterNetworkPolicy requires VPC CNI v1.21.0+, while DNS-based policies are supported in EKS Auto Mode-launched EC2 instances.
read more →

AWS Billing Dashboards: PDF Export and CSV Download

📄 AWS now lets you export customized Billing and Cost Management Dashboards as formatted PDF reports and download individual widget data as CSV files. These features eliminate screenshots and manual formatting by preserving dashboard layouts for stakeholder reports and enabling granular analysis in spreadsheet tools. The exports are available at no additional cost in all AWS commercial Regions (excluding AWS China Regions). To begin, open the Billing and Cost Management console and select Dashboards.
read more →

Google Links Additional Chinese Groups to React2Shell

🔒 Google's Threat Intelligence Group linked five additional China-aligned cyber-espionage groups to active exploitation of the maximum-severity CVE-2025-55182 React2Shell remote code execution flaw affecting React and Next.js server components. Attackers are executing commands and exfiltrating AWS configuration files and credentials from vulnerable hosts; Palo Alto and AWS reported widespread breaches. Shadowserver and GreyNoise are tracking tens of thousands of exposed systems and hundreds of exploit attempts. Organizations should urgently patch affected React 19.0–19.2.0 releases and apply mitigations.
read more →

Amazon EC2 M7a Instances Now Available in London Region

🚀 Amazon EC2 M7a instances are now available in the AWS Europe (London) Region. Powered by 4th Gen AMD EPYC (Genoa) processors with up to 3.7 GHz, these general-purpose instances deliver up to 50% higher performance compared to M6a instances. M7a is offered across purchase models (Savings Plans, Reserved, On-Demand, Spot) and can be launched via the AWS Management Console, CLI, or SDKs. With London added, M7a is available in multiple global regions including US East (Ohio, N. Virginia), US West (Oregon), Asia Pacific (Sydney, Tokyo), and several other European regions.
read more →

ACM automates certificate lifecycle for Kubernetes workloads

🔐 AWS Certificate Manager (ACM) now automates provisioning and distribution of exportable public and private certificates directly to Kubernetes workloads via AWS Controllers for Kubernetes (ACK). The ACK controller handles the complete lifecycle — certificate request, validation, export, Kubernetes Secret creation, and automatic renewal updates. This removes the need to export certificates and rotate Secrets manually for pods, service meshes, and third-party ingress controllers. The feature supports Amazon EKS and hybrid or edge Kubernetes environments and is available in commercial, GovCloud (US), and China regions where ACM is offered.
read more →

Implementing HSTS Across AWS Services for Cloud Apps

🔒 This AWS Security Blog post explains how to implement HTTP Strict Transport Security (HSTS) consistently across distributed AWS architectures using Amazon API Gateway, Application Load Balancers, and Amazon CloudFront. It presents concrete, service-specific configuration steps, example mappings and code snippets, and recommended curl commands to validate header delivery. The guidance highlights centralized header enforcement options to reduce fragmentation and align with the AWS Well-Architected Framework security principles. Practical advice covers testing, header override behaviors, and phased rollout using conservative max-age values before enabling preload in production.
read more →

AWS Dedicated Local Zones: Expanded Services for Sovereignty

🔒 AWS has expanded service availability for Dedicated Local Zones, enhancing options for compute, storage, backup, and recovery to address strict data residency and digital sovereignty requirements. The announcement adds newer EC2 generation 7 instance types with accelerated computing, EBS gp3 and io1 volumes, and additional Amazon S3 One Zone storage classes. It also introduces EBS Local Snapshots and local AMI support to keep backups and images within customer-specified perimeters, helping regulated and government customers meet compliance needs.
read more →

Amazon MSK Replicator Expands to Ten More AWS Regions

🚀 Amazon has expanded MSK Replicator availability to ten additional AWS Regions: Bahrain, UAE, Jakarta, Hong Kong, Osaka, Melbourne, Cape Town, Milan, Zurich, and Tel Aviv. MSK Replicator enables automatic asynchronous replication of streaming data and Kafka metadata (topic configurations, ACLs, consumer group offsets) across MSK clusters without custom code or manual infrastructure. The service scales automatically and can be configured via the Amazon MSK console or AWS CLI, bringing coverage to 35 Regions to support regionally resilient streaming and failover.
read more →

Amazon EMR Managed Scaling Expands to Additional Regions

🚀 Amazon announces that EMR Managed Scaling is now available to EMR on EC2 customers in Asia Pacific (Malaysia, New Zealand, Taipei, Thailand), Canada West (Calgary), Mexico (Central), and US Gameday Northeast (Illinois). The feature automatically resizes EC2 instances to optimize performance and cost; you set minimum and maximum compute limits and EMR adjusts capacity using workload-driven algorithms. It supports Apache Spark, Apache Hive and YARN-based workloads on EMR on EC2 versions 6.14 and above and can use EC2 Spot Instances for additional savings.
read more →

AWS Shield Network Security Director Adds Multi-Account

🔒 AWS Shield Network Security Director is now available in preview with multi-account network security management, allowing delegated administrator accounts to run continuous analysis across an AWS Organization. It centralizes per-account network topology, security findings, and recommended remediations for missing or misconfigured network security services. The capability can summarize and report misconfigurations from within Amazon Q Developer and chat applications, and it is now available in five additional AWS regions.
read more →