< ciso
brief />
Tag Banner

All news with #cloud security tag

723 articles · page 2 of 37

AWS DataSync Adds Integrated Monitoring Dashboard

📊 The AWS DataSync console now includes a monitoring dashboard that gives visibility into data transfers across your account, showing status, transfer rates, duration, and totals for each task execution. You can filter executions by status, task, mode, execution ID, or start time and see summarized results including counts of successful and failed runs and cumulative data transferred. The dashboard highlights configured tasks, locations, and agents and provides real-time aggregate transfer rates, with the ability to inspect errors for failed executions. This feature is available at no extra cost in all commercial and AWS GovCloud (US) Regions where DataSync is offered.
read more →

AWS launches Network Security Manager in US East

🔒 Today AWS announces the general availability of AWS Network Security Manager, a centralized network security management solution that simplifies policy deployment and enforcement at scale. It supports AWS WAF and AWS Shield Advanced today, with AWS Network Firewall support coming soon. The service enables consistent enforcement of firewall and DDoS protections across an AWS organization and is available in US East (N. Virginia).
read more →

EMR on EKS adds interactive Spark Connect sessions

🔥 Amazon EMR on EKS now supports interactive Apache Spark sessions via Spark Connect, enabling data engineers and scientists to develop and debug Spark applications from managed notebooks in Amazon SageMaker Unified Studio or their own IDEs like Jupyter and VS Code. An interactive session provides a persistent Spark context that spans cells and scripts, blending local Python execution with remote Spark operations on EKS. Sessions run as pods on virtual clusters secured by IAM execution roles and tagged by project and user, and Spark Connect is available in EMR release 7.14 (Spark 3.5) and emr-spark-8.1.0 (Spark 4.1) across AWS Commercial Regions.
read more →

GKE Adds Native Scale-to-Zero Capabilities

🚀 GKE 1.37 introduces native scale-to-zero so workloads can fully scale down to zero replicas and stop consuming compute while idle. The feature uses HPA with the new AutoscalingMetric CRD and KEP-2021 support for minReplicas: 0 to wake workloads based on external signals such as Pub/Sub or Cloud Monitoring. Capacity buffers provide pooled warm capacity to eliminate cold-start latency and balance cost with instant responsiveness.
read more →

Amazon Connect adds routing step data to data lake

📊 Amazon Connect Customer now delivers routing step data into its analytics data lake, enabling easier insight generation from routing decisions. Using the data lake, customers can use Amazon Athena and Amazon Quick to analyze trends like contacts queued and contacts joined at each routing step without building complex pipelines. Analysts can report on contact progression, pinpoint where agent matching criteria were relaxed, and measure routing impacts on wait times and agent utilization.
read more →

Cloud Intrusions Escalate to Machine-Speed Threats

🔍 The 2026 Cloud-Native Threat Landscape Report, based on FortiCNAPP intelligence, shows that adversaries are automating cloud attacks to find, exploit, and monetize vulnerabilities at unprecedented speed. The report documents billions of reconnaissance, brute-force, and exploitation attempts and stresses that identity compromise and misconfigurations remain prime intrusion vectors. It urges security teams to adopt AI-driven, automated defenses across the entire application lifecycle to detect and respond at machine speed.
read more →

Security Hub AI Inventory Adds Azure Self‑Hosted Support

🔐 AWS Security Hub AI Inventory now discovers and catalogs AI assets on self‑hosted Microsoft Azure instances, extending visibility beyond AWS. It uses enhanced Amazon Inspector SBOM analysis to identify inference endpoints, models, and AI agents on Azure VMs, including frameworks like Ollama, vLLM, and Hugging Face TGI. Discovered assets are mapped to underlying infrastructure and correlated with security findings for filtering and querying across AWS and Azure. This capability is included with Security Hub Essentials at no extra cost and is available in all commercial Regions where Security Hub is offered.
read more →

Route 53 Resolver Now on Gen2 AWS Outposts

🖧 Amazon Route 53 Resolver is now generally available on second-generation AWS Outposts, offering local managed recursive DNS resolution directly on your Outpost. DNS queries are resolved locally to reduce latency and avoid traversing the Service Link to the parent AWS Region. Resolver maintains cached records during Service Link disconnections to ensure continuity, and runs on AWS-managed infrastructure without customer compute requirements.
read more →

Global multi-cluster GKE inference for GPUs and TPUs

🧭 This post describes a layered routing architecture that makes globally scattered accelerator capacity behave like a single pool behind one entry point. The multi-cluster GKE Inference Gateway performs global traffic distribution and high availability while an LLM-d router applies memory-aware scheduling to maximize utilization across GPUs and TPUs. Benchmarks across three regions and 17,000 nodes showed near-linear throughput scaling and <1% routing overhead while maintaining ~99.9% success rates under heavy concurrency.
read more →

Maximize Apache Spark availability with flexible VMs

🔧 This article explains how Google’s Managed Service for Apache Spark uses flexible VMs to mitigate capacity stockouts that can disrupt Spark pipelines. Flexible VMs let teams specify ordered machine-family preferences for masters and workers, enabling multi-family blending, mixed storage support, and comprehensive cluster coverage. The post gives tiered machine-family and storage recommendations for common shapes (n2d, n1) and highlights the role of Hyperdisk Balanced. It also covers quota, CUDs, testing, and complementary strategies like AutoZone, autoscaling, smaller shapes, and regional fallbacks.
read more →

Identity Visibility Foundation for Modern IAM

🔍 This article defines identity visibility in IAM as the continuous ability to discover every identity, map its entitlements, and observe runtime access usage. It explains why cloud and multicloud environments, machine identities, and application-local accounts create an expanding identity attack surface. The piece surveys identity visibility tool capabilities and vendor approaches, and outlines how visibility complements IAM, IGA, PAM, and zero trust efforts.
read more →

Gyazo breach exposes millions of user records

🛡️ Gyazo, a cloud-based screenshot and screen-recording service, confirmed a data breach after attackers exploited a server vulnerability on September 11, 2026, stealing roughly 23.62 million user records. The company detected the activity on September 12, patched the flaw, and has taken the service offline for maintenance while investigating with external experts. Exposed data may include names, emails, password hashes, session tokens, image metadata, and more, prompting recommendations that users change reused credentials and watch for suspicious communications.
read more →

AWS RTB Fabric adds configurable AZ affinity

🛠️ AWS RTB Fabric now supports configurable Availability Zone affinity for responder gateways, letting partners connect either within their own AZ or to any AZ the gateway spans. This option helps AdTech companies optimize infrastructure use and avoid underutilized capacity without additional RTB Fabric charges. Configurable AZ affinity is available in all Regions where RTB Fabric is offered; check the AWS RTB Fabric User Guide for fleet requirements before enabling.
read more →

Amazon S3 Express One Zone expands to seven regions

🚀 Amazon S3 Express One Zone is now available in seven additional AWS Regions: Singapore, São Paulo, N. California, Canada (Central), Paris, Sydney, and Seoul. This single-Availability Zone storage class is engineered for consistent single-digit millisecond access and is optimized for latency-sensitive workloads. S3 Express One Zone offers up to 10x faster data access and up to 80% lower request costs versus S3 Standard. The expansion brings the storage class to 15 AWS Regions overall.
read more →

Architecting a Secure Landing Zone in EUSC

🔒 This post explains how to design a secure, scalable landing zone for the AWS European Sovereign Cloud (aws-eusc), a partitioned AWS environment operated within the EU. It covers account structure and governance, identity as IaC, centralized logging to a SIEM, data protection, perimeter and network design, CI/CD and artifact distribution, and incident response. The guidance maps to the AWS Security Reference Architecture and the AWS Well-Architected Framework, and highlights which behaviors are partition boundaries versus configurable choices.
read more →

How Orange Mobilized Teams for FinOps Success

🔍 At Orange, engineers participate in collaborative FinOps Clean Days and gamified hackathons to drive cost optimization and learning, producing an internal Net Promoter Score above 70 for its 100+ person FinOps community. The company treats FinOps as a business change problem, emphasizing shared responsibility, a Community of Practice, and protected time for optimization. Orange pairs these cultural practices with AI agents to scale engagement: read-only agents for insights and suggested fixes, then execution-capable agents when trust and governance are established. The approach follows McKinsey’s change-building blocks—conviction, formal mechanisms, role modeling, and skills—so cultural foundation comes first, then agent-driven automation to reduce friction and extend FinOps practices across thousands of engineers.
read more →

Amazon Keyspaces expands availability to 11 Regions

🚀 Amazon Keyspaces (for Apache Cassandra) is now generally available in 11 additional AWS Regions, enabling customers to run Cassandra-compatible applications with lower latency and meet regional data residency requirements. Amazon Keyspaces is a managed, serverless, and highly available Cassandra-compatible database service that scales for high throughput and storage demands. Customers pay only for resources used and can serve thousands of requests per second with virtually unlimited capacity. New Region availability details are provided in AWS region capability listings.
read more →

CISA and NIST Issue Final Cloud Token Guidance

🔐 The Cybersecurity and Infrastructure Security Agency (CISA) and the National Institute of Standards and Technology (NIST) published Interagency Report 8587 on September 15 to protect cloud identity tokens and assertions used in SSO, identity federation and API access. The guidance, which is voluntary, warns that adversaries are increasingly targeting tokens to move laterally and access sensitive data. It prescribes short token lifetimes, scoped key usage, hardware-backed key storage for moderate impact and above, and strict logging and audience validation rules.
read more →

Google Cloud introduces granular session controls

🔐 Google Cloud has rolled out a 16-hour default session length and expanded session management into a granular, Context-Aware Access (CAA) feature. Administrators can now configure session controls via Terraform, gcloud, and REST APIs for DevSecOps workflows. Policies can target Google Groups and specific applications like the Cloud Console, gcloud, and OAuth apps, and policy management is being integrated into the Google Cloud Console preview. These updates aim to reduce credential theft and account takeover risk while preserving developer productivity.
read more →

Cloud reliability incident handling best practices

🔧 This blog summarizes Google Cloud’s recommended “Verify→Investigate→Report→Resolve→Review” workflow for handling reliability incidents and advises preparing in advance by designing for failure, ensuring observability data, maintaining playbooks, and running drills. It distinguishes how to detect incidents via Personalized Service Health, Cloud Service Health, and observability tools, and provides guidance on scoping blast radius, diagnosing causes, and when to open and escalate support cases. It also covers mitigation steps while waiting for resolution and emphasizes blameless post-mortems to improve future response.
read more →