< ciso
brief />
Tag Banner

All news with #cloud security tag

723 articles · page 3 of 37

AWS Security Reference Architecture PCI DSS Deep Dive

🔒 Amazon Web Services publishes the AWS Security Reference Architecture (SRA) PCI DSS Deep Dive, providing prescriptive architecture-level guidance for organizations that store, process, or transmit cardholder data on AWS. The guide extends the core AWS SRA to map patterns to PCI DSS intent across account scoping, segmentation, encryption, logging, and access control. It includes downloadable diagrams and control mapping tables and can be used alongside SRA verify or with AWS Professional Services and partners for implementation.
read more →

DDRop attack undermines cloud confidential computing

🔒Researchers disclosed DDRop, a cheap active interposer attack that silently drops writes to DDR5 memory, defeating freshness assumptions in Intel TDX, Scalable SGX, and AMD SEV‑SNP. The exploit requires brief physical access to insert a small board between CPU and DIMM and lets an attacker with existing software control read or manipulate protected VM memory. Vendors were notified and have acknowledged the findings; hardware redesign is needed for a full fix.
read more →

AWS Glue zero-ETL adds ownership conflict detection

🔧 AWS Glue zero-ETL integrations now detect table property conflicts and track integration ownership. When you configure a source and target catalog, Glue assigns table properties to the owning integration so two integrations cannot target the same table without detection. This behavior spans Amazon S3 Tables and SageMaker Lakehouse catalogs and is available in all supported AWS Commercial and GovCloud (US) Regions.
read more →

CloudWatch Network Monitoring adds TGW inter‑Region NHI

🛰️ Amazon CloudWatch Network Monitoring now reports network health indicators for paths that traverse Transit Gateway inter‑Region peering using synthetic monitors. This extends previous NHI coverage that applied only to paths using AWS Direct Connect, enabling operators to determine whether performance degradation across a Transit Gateway peering link is caused by the AWS network. The indicator covers the AWS network path up to the Transit Gateway peering connection and is published to your CloudWatch account for dashboards and alarms. This feature is available in all Regions except AWS GovCloud (US) and China Regions.
read more →

Cloud Web Applications Threat Matrix Overview

🛡️ Microsoft introduces a MITRE ATT&CK-aligned Cloud web applications threat matrix to help defenders map and prioritize threats against cloud-hosted web apps and serverless platforms. The framework organizes attack techniques across application code, managed runtimes, identities, deployment pipelines, and connected cloud resources to surface cross-layer attack paths. The blog describes selected techniques and actionable defensive priorities to reduce exposure in cloud-native environments.
read more →

Design framework for zone-resilient Azure workloads

🛡️ This post argues that zone resiliency should be decided per component rather than applied as a single setting across a workload. It explains Azure availability zones, contrasts service-managed zone redundancy with user-managed zonal designs, and outlines common component categories and when two or three zones are appropriate. The guidance emphasizes validating service-specific behavior, modeling cost and capacity tradeoffs, and documenting failover, capacity, and operational responsibilities.
read more →

AWS Transform arrives in GovCloud (US-West)

🔒 AWS Transform is now available in the AWS GovCloud (US-West) Region, enabling government agencies and regulated organizations to plan and execute large-scale migrations to AWS. The service automates server migrations within an isolated environment for sensitive data and supports migrating servers to both AWS GovCloud (US-East) and GovCloud (US-West) target Regions. Supported sources include VMware, bare metal, Hyper-V, and databases; however, modernization, custom transformation, and assessment features remain available only in commercial Regions.
read more →

AWS HealthOmics adds resource fallback for WDL

🔬 Today, AWS HealthOmics introduces the resource fallback directive, allowing users to specify an ordered list of preferred accelerator types — including a final CPU fallback — for tasks in Workflow Description Language (WDL) workflows. This feature reduces time spent diagnosing and resubmitting runs when accelerators are constrained and helps keep production workflows running. HealthOmics is HIPAA-eligible and available in multiple AWS Regions to support bioinformatics at scale.
read more →

Cloud Security Index Shows Provider Risk Divergence

🔍 Intruder's 2026 Cloud Security Index analyzed misconfiguration data from 3,000 organizations across AWS, Azure, and Google Cloud and found that risk profiles differ dramatically by provider. Weak IAM and missing logging are nearly universal, while exposed services, permissive firewalls, weak encryption, and misconfigured services vary widely. AWS shows high prevalence in exposed services and permissive network controls, Azure's top issues center on storage and identity, and Google Cloud's dominant problems are IAM-related. Larger organizations generally have fewer exposure-style misconfigurations but worse IAM issues, and midmarket firms take the longest to remediate.
read more →

AWS OSPAR 2026: Expanded Coverage for Singapore Banks

🔒 AWS has completed its annual OSPAR assessment (version 2.0) on July 29, 2026, confirming 167 services in scope for the AWS Asia Pacific (Singapore) Region. The OSPAR framework aligns with the Association of Banks in Singapore (ABS) Guidelines, addressing cyber hygiene, technology risk, business continuity, data security, cryptography, and software development controls. This cycle adds five services to the scope and reinforces AWS’s adherence to security expectations for Singapore’s financial services industry. Customers can obtain the report via AWS Artifact and consult the included service list for compliance reviews.
read more →

Yahoo reduces Spark provisioning failures with flexible VMs

🚀 Yahoo adopted flexible VM instance rankings in Managed Service for Apache Spark to absorb regional capacity fluctuations and keep analytics pipelines running. By enabling Auto-Zone placement and listing ranked fallback machine shapes, clusters can provision across zones and avoid stalls when preferred VM types are unavailable. The approach requires uniform core/memory ratios for autoscaling, and may need explicit YARN/Spark property overrides when mixing shapes. Yahoo reports an 85% reduction in provisioning failures and improved pipeline reliability.
read more →

Amazon MWAA adds integrated CloudWatch monitoring

🛠️ Amazon Managed Workflows for Apache Airflow (MWAA) now includes a built-in monitoring experience on the environment detail page in the AWS Management Console. A new metrics dashboard consolidates key Amazon CloudWatch metrics with optional toggles to overlay suggested warning ranges to highlight potential issues. The page also lists associated CloudWatch alarms and offers a one-click Create Recommended Alarms action to provision alarms from an AWS-managed template. This capability is available for MWAA Provisioned environments in all supported regions; standard CloudWatch pricing applies.
read more →

Google named a Leader in Gartner Magic Quadrant

🚀 For the ninth consecutive year, Gartner has positioned Google as a Leader in the 2026 Gartner Magic Quadrant for Strategic Cloud Platform Services, ranked furthest for Completeness of Vision. Google highlights a co-designed technology stack from custom silicon to agentic applications, a dynamic infrastructure for secure global scale, and flexible digital sovereignty options. The post emphasizes AI-driven modernization, workload-optimized compute, hybrid/multicloud operation, and sovereign cloud deployments.
read more →

Amazon Bedrock Web Search now in AWS GovCloud

🔎 Amazon Bedrock's Web Search tool is now available in AWS GovCloud (US-West), enabling grounded web results with citations for supported OpenAI GPT models. Web Search keeps request data inside the AWS boundary by default and is governed by IAM so administrators can control access at account, organization, and Region levels. At launch it supports GPT-5.4, GPT-5.6 Terra, and Luna models and joins other US Regions where the capability is already available.
read more →

AWS Config expands support to 60 new resource types

🟢 AWS Config now supports 60 additional AWS resource types across services such as Amazon Bedrock, Amazon EC2, Amazon SageMaker, and AWS Organizations. If recording for all resource types is enabled, AWS Config will automatically start tracking these resources. The new types are available for use in Config rules and Config aggregators, enhancing discovery, assessment, auditing, and remediation across Regions.
read more →

AWS UXC Now Available Across Commercial Regions

🎛️ AWS User Experience Customization (UXC) is now available in all commercial AWS Regions, allowing account administrators to set a custom account color and control which services and Regions appear in the AWS Management Console. Previously limited to US East (N. Virginia), UXC can now be managed from any commercial Region using the AWS CLI, AWS SDKs, or AWS CloudFormation. The feature is available at no additional charge and integrates with existing infrastructure automation for easier console configuration.
read more →

How partners can maximize cloud marketplace value

🛒 Cloud marketplaces are becoming a primary procurement route and offer partners a chance to move beyond transactions to deliver services and long-term value. Palo Alto Networks highlights the importance of meeting customers where they buy, understanding CSP commitments and leveraging the NextWave Partner Program for commercial benefits. Partners can combine platform technology with services to drive adoption, modernize infrastructure and secure emerging priorities like AI. Effective collaboration among partners, CSPs and vendor teams is key to converting marketplace opportunities into strategic customer outcomes.
read more →

AWS partners with Upwind to extend Security Hub

🔒 AWS invited Upwind to join Security Hub Extended after customers repeatedly cited Upwind as a complementary solution. Upwind integrated deeply, offering runtime-first protection, pay-as-you-go pricing, and aligned go-to-market efforts that have driven strong joint deal activity. The integration enables unified findings in OCSF across build-to-runtime tools, simplified procurement on one AWS bill, and no custom integrations for customers.
read more →

Preparing cloud security for AI-driven attack agents

🔒 Cloud architectures built to resist human attackers now face a new class of threat: autonomous AI agents that can enumerate identities, chain misconfigurations, and exploit paths at machine speed. Recent incidents, including the OpenAI–Hugging Face example, illustrate how agents can escalate privileges by combining otherwise low-severity flaws. Experts warn organizations must shift from point-in-time vulnerability scanning to continuous, graph-based attack-path validation, enforce ephemeral credentials and strict workload identities, and adopt account-level segmentation to reduce blast radius.
read more →

Extend data perimeter to AWS Management Console

🔒 AWS announces general availability of AWS Management Console Private Access, enabling VPCs with no internet connectivity to access supported service consoles via AWS PrivateLink endpoints. This routes authentication, static assets, console-only APIs, and service API calls through interface VPC endpoints, removing the need for an internet gateway or NAT. The feature is available in all AWS commercial Regions for a select set of consoles and integrates with sign-in resource control policies, VPC endpoint policies, and service control policies to enforce identity, resource, and network perimeters.
read more →