< ciso
brief />
Tag Banner

All news with #cloud security tag

659 articles

AWS Direct Connect adds inbound prefix controls

⚙️ AWS Direct Connect announced inbound prefix controls that let customers allocate and manage inbound route-prefix allocations for private and transit virtual interfaces (VIFs) based on workload needs. You can now assign up to 1,000 prefixes each for IPv4 and IPv6 on dedicated and hosted connections, up from a 100-prefix limit. New prefix capacity pools exist at the dedicated connection and Direct Connect gateway (DXGW) levels, and allocations are configurable via the console or CLI/API. This feature is available at no extra cost in all commercial AWS Regions, AWS GovCloud, and the China Regions operated by Sinnet and NWCD.
read more →

Airlock Digital completes IRAP assessment at PROTECTED

🔒 Airlock Digital announced completion of an independent IRAP assessment at the PROTECTED classification, conducted by an ASD-endorsed assessor against the Australian Government ISM. The assessment gives Australian organisations additional independent evidence of Airlock Digital’s security controls and alignment with expectations such as the ISM and PSPF. Airlock Digital supports flexible deployment across cloud, on-premises and constrained environments and positions allowlisting as a governance-led, organisation-owned control.
read more →

Amazon Bedrock expands Web Search with external access

🔎 Today AWS expanded Amazon Bedrock's Web Search to support an external_web_access parameter, allowing models to fetch live public web content while preserving control over data egress. Grant the bedrock-websearch:ExternalWebAccess IAM permission to enable live fetches; leaving the parameter false restricts results to Amazon's in-AWS index. The capability is available in US East (N. Virginia), US East (Ohio), and US West (Oregon).
read more →

CloudWatch Centralization Adds Tag Propagation

🔔 Amazon CloudWatch Centralization now copies log group tags from source accounts to destination log groups created by centralization rules. Tag propagation preserves cost, ownership, and compliance tags so teams can scope access and report spend centrally. The feature syncs tags based on propagation behavior chosen in the centralization rule and is available in all Regions where CloudWatch Centralization is offered.
read more →

Sakura Internet breach exposes up to 1.36M accounts

🔒 Japanese cloud provider Sakura Internet disclosed unauthorized access to its sales management system storing customer contract and membership data. The company said the incident was discovered during a separate investigation into a smaller breach at its Sakura Rental Server service and that up to 1,360,563 accounts may have been affected. Sakura reported no confirmed data exfiltration, noted stored passwords are hashed and no credit card data is kept in the compromised system, and is notifying affected customers and authorities.
read more →

Microsoft named a Leader in Frost Radar 2026

🔒 Microsoft has been named a visionary leader in Frost & Sullivan’s Frost Radar™: Cloud Workload Protection Platforms, 2026. The report highlights a market shift from isolated scanning to a unified runtime security model that connects code, cloud resources, identities, and SOC workflows. Frost & Sullivan cites Microsoft Defender for Cloud’s scale, deep runtime telemetry, and integration with Defender XDR, Sentinel, GitHub, and Copilot as key strengths. This positioning reflects Microsoft’s estimated >22% share of the global CWPP market and emphasizes runtime depth, container and Kubernetes security, and AI workload protection.
read more →

AWS adds fourth Availability Zone in London region

🚀 AWS has added a fourth Availability Zone to the Europe (London) Region (eu-west-2), increasing capacity for cloud compute and AI/ML workloads. The new zone provides next-generation accelerated instances such as Trn3 and P6, plus general-purpose EC2, enabling customers to run training and inference locally within the London region. It improves fault isolation for resilient, highly available architectures and is accessible via the AWS Console, APIs, and existing workflows at standard regional pricing.
read more →

Serverless Lakehouse Catalog Modernizes Apache Hive Metastore

🛠️ The blog explains how legacy Apache Hive Metastores become bottlenecks as enterprises scale their data lakes and adopt multiple query engines. It introduces the Google Cloud Lakehouse runtime catalog, a serverless metadata registry built on the Apache Iceberg REST Catalog specification that supports both legacy Hive tables and modern table formats. The post outlines common pain points — scaling, governance, and operational TCO — and describes a migration path that extracts Hive table definitions and registers them into the serverless catalog. The result is unified governance, zero-data-copy access across engines, and reduced operational overhead.
read more →

Storage Gateway adds FIPS PrivateLink support

🔒 AWS Storage Gateway now supports FIPS 140-3 validated endpoints over AWS PrivateLink for Tape Gateway and Volume Gateway. Previously restricted to the public internet, FIPS traffic can now stay on the private AWS network, simplifying use for regulated workloads. To use it, create a FIPS interface VPC endpoint and choose the FIPS option when activating your gateway; gateways must run software version 3.2.7 or later. The feature is available in eight Regions, including US East, US West, and AWS GovCloud.
read more →

Amazon S3 Metadata and Annotations Reach GovCloud

🔎 Amazon S3 Metadata and annotations are now available in AWS GovCloud (US-East) and AWS GovCloud (US-West), enabling faster discovery, understanding, and enrichment of S3 data. S3 Metadata captures system-defined details like object size and source and stores them in Amazon S3 Tables for near real-time tabular queries. Annotations let you attach rich business context in JSON, XML, or YAML (up to 1 GB per object) that travels with the object and follows durability and consistency properties.
read more →

OpenSearch adds semantic enrichment for VPC domains

🔒 Amazon OpenSearch Service now supports automatic semantic enrichment for VPC-enabled domains, allowing customers with private network configurations to use AI-powered semantic search without exposing domains to the public internet. The feature converts keyword searches into context-aware retrieval, handling all semantic processing automatically and removing the need to manage ML models. It requires OpenSearch version 2.19 or later and is available across 11 Regions globally.
read more →

Cloudflare One updates for MCP security

🔒 Cloudflare announces new Cloudflare One capabilities to detect and control Model Context Protocol (MCP) traffic. These features let administrators identify which users and servers are generating MCP requests, distinguish Portal-mediated connections from direct ones, and block unauthorized direct connections on managed network paths. The update combines Gateway protocol signals with MCP Server Portals to help teams find shadow MCP servers and enforce Portal-only access to trusted MCP endpoints.
read more →

Amazon Quick adds per-user resource limits

🔒 Amazon Quick now lets administrators set per-user limits on index storage and agent hours to control subscription costs. With limits management, admins can create limit profiles that cap individual consumption and assign them at the user, role, or account level with a priority hierarchy. When a user reaches their limit, new consumption is blocked but existing content is preserved. The feature is available for Professional and Enterprise plans in supported AWS Regions.
read more →

Landing Zone Accelerator C5:2020 Assessment Report Now Available

🔒 Landing Zone Accelerator now has an independent assessment report for C5:2020 available on AWS Artifact, evaluating how LZA's baseline implements nearly 200 native security controls. The report, prepared by AWS partner Schellman, maps LZA's Universal Configuration and security control baseline to C5:2020 technical criteria and describes architecture, best practices, and scoping considerations. LZA supports standard multi-account and container deployments in the AWS European Sovereign Cloud and is accompanied by a Compliance Workbook to help customers accelerate evidence collection and assessment preparation.
read more →

Google Cloud roadmap to post-quantum readiness

🔒 Google Cloud publishes an updated roadmap to migrate its infrastructure and services to post-quantum cryptography by 2029, addressing risks like Store Now, Decrypt Later and signature forgery. The plan prioritizes API endpoints, load balancers, Cloud KMS, and key management while collaborating on standards such as NIST and IETF. Google outlines domain-specific timelines through 2027–2028 and emphasizes shared responsibilities with customers for operational readiness.
read more →

AWS Clean Rooms adds SQL analysis log export

📥 AWS Clean Rooms now supports exporting privacy-enhanced analysis logs for SQL analyses to an S3 bucket, giving customers improved optimization and troubleshooting capabilities. Collaboration owners can grant members permission to export logs when creating a collaboration or via change requests for existing collaborations. After a query runs, privacy-enhanced Spark execution details can be exported to a chosen S3 path to help identify issues like data skew and reduce resolution time and costs.
read more →

AWS CyberVadis 2026 Report Eases Supplier Due Diligence

🔒 Amazon Web Services (AWS) completed the 2026 CyberVadis assessment and achieved the highest score (Mature) across all evaluated areas, demonstrating commitment to elevated cloud-security expectations. The report and scorecard are now available to help customers reduce third-party due-diligence burdens and map AWS controls to common industry frameworks. Customers can download the full assessment via the CyberVadis portal or AWS Artifact and contact their AWS account team with questions.
read more →

Amazon OpenSearch Serverless raises collection limits

🔔 The next generation of Amazon OpenSearch Serverless now supports up to 10,000 collections within a single collection group, increased from the previous limit of 1,500. Collection groups let multiple collections share OpenSearch Compute Units (OCUs) even when encrypted with different AWS KMS keys. This change enables greater consolidation, improved compute utilization, and reduced per-collection costs for multi-tenant workloads. The higher limit applies automatically to new and existing nextgen collection groups in all available AWS Regions.
read more →

BigQuery DTS expands integrations and features

🚀 BigQuery Data Transfer Service (DTS) reduces engineering overhead by automating zero-code data ingestion into BigQuery, enabling teams to shift focus from pipeline maintenance to analytics. Recent additions include Open Lakehouse ingestion to Apache Iceberg, a managed Model Context Protocol (MCP) Server, expanded database connectors (PostgreSQL, MySQL, SQL Server), SaaS connectors (Shopify, Klaviyo, HubSpot, Mailchimp), and a Snowflake migration path. DTS emphasizes free ingestion for many first-party sources, low consumption-based pricing for third-party SaaS, integrated Cloud IAM security, and a 99.99% SLA for resilient data pipelines.
read more →

Securing Amazon S3: Identify and Remediate Over‑Permissions

🔒 This post explains how to detect and remediate over‑permissioned Amazon S3 buckets across single‑ or multi‑account AWS environments. It outlines a five‑phase workflow—setup, detection, remediation, continuous monitoring, and cleanup—while recommending AWS Config, Security Hub, EventBridge, IAM Access Analyzer, and Lambda‑based scanning scripts. The guidance focuses on methodology and customization for security engineers, cloud architects, and DevOps teams.
read more →