< ciso
brief />
Tag Banner

All news with #cloud security tag

659 articles · page 3 of 33

NOAA and Google Cloud Modernize Weather Supercomputing

🌤️ NOAA has selected Google Cloud as the primary provider of high-performance computing for the Weather and Climate Operational Supercomputing System (WCOSS). This move marks a shift toward cloud-first infrastructure, using H4D VMs powered by fifth-generation AMD EPYC™ processors to support compute-intensive numerical weather prediction. The collaboration builds on years of joint projects in data sharing, wildfire tracking, and advanced modeling, aiming to improve forecast accuracy and public safety.
read more →

Visibility Alone Fails AI Agent Security Controls

🔎 AI agent discovery is necessary but insufficient; security must move from visibility to enforcement. Organizations find agents across SaaS, cloud, developer tools, and internal systems, but inventory without context leaves risk unmanaged. Effective controls require correlating ownership, identities, intent, access, usage, and lifecycle to create purpose-driven, platform-agnostic rules. The goal is an identity-centric control plane that can discover, understand, and enforce agent behavior.
read more →

Organizations Delay Microsoft Copilot Over Data Risk

🔒 Two-thirds of organizations have delayed or cancelled Microsoft Copilot deployments due to fears the AI assistant could expose confidential SharePoint data. CoreView’s State of Microsoft 365 Security and Governance 2026 report (21 July) highlights confusion over Copilot's access and permissions and widespread concerns about data leakage. C-level executives are most likely to pause rollouts, and respondents link hesitation to prior Microsoft 365 security incidents and missing foundational controls.
read more →

AWS WAF dynamic label interpolation for bot signals

🛡️ AWS WAF now supports dynamic label interpolation, allowing labels applied to requests (including managed Bot Control and ATP labels) to be referenced by namespace instead of enumerating individual values. Use the ${namespace:} syntax in custom request/response headers and response bodies to forward matched labels and synthetic values (client IP, request ID, JA3/JA4) to your origin or embed them in challenge and block pages. This reduces rule maintenance, supports hundreds of evolving bot categories, enables per-device signals, and lets applications make nuanced decisions—such as challenges, redirects, or routing—based on WAF classifications.
read more →

Amazon ECS adds Action Logs for deployment visibility

📘 Amazon Elastic Container Service (Amazon ECS) now provides Action Logs, an observability feature that records detailed, timestamped actions ECS performs during service deployments and Managed Daemon updates. These logs surface previously invisible service-side operations to help monitor and troubleshoot workloads without contacting AWS Support. You can enable Action Logs at the cluster level via the console or CloudWatch vended logs APIs and deliver them to CloudWatch Logs, S3, or Kinesis Data Firehose. Amazon Q in the ECS console integrates with Action Logs to detect deployment issues and provide root cause analysis and remediation guidance; standard CloudWatch/S3/Firehose pricing applies.
read more →

AWS adds standardized Bedrock product metadata to CUR

📢 AWS now includes standardized product metadata for Amazon Bedrock in AWS Data Exports (Cost and Usage Report), enabling FinOps and cloud teams to consistently attribute Bedrock spend. The update exposes attributes like model provider, model name, pricing unit, inference type, and feature, plus a unified product family name, available by default at no extra cost. CUR 2.0 surfaces these fields in the product map and pricing unit column for easy export to S3 and analysis with Athena or data warehouses.
read more →

AWS launches Athens Local Zone for Greece

📣 The Athens Local Zone by AWS is now generally available, offering localized infrastructure in Greece to support data residency and low-latency use cases. It provides EC2 C7i/M7i/R7i instances, Amazon S3 (including One Zone-IA), Amazon EBS with Local Snapshots and multiple volume types, ECS, EKS, VPC, Direct Connect, and Application Load Balancer. Customers can enable the zone (eu-central-1-ath-1a) via AWS Global View or API and use standard AWS pricing models and APIs with no minimum commitment.
read more →

Amazon Managed Grafana Gains FedRAMP High in GovCloud

🛡️ Amazon Managed Grafana is now FedRAMP High authorized in AWS GovCloud (US-East) and AWS GovCloud (US-West). The fully managed service, built on open-source Grafana, enables federal agencies and public sector organizations to visualize, query, and alert on operational metrics while meeting strict compliance requirements. FedRAMP provides the standardized security assessment and continuous monitoring required for US government cloud services. Customers should consult the GovCloud documentation or their AWS account team for implementation details.
read more →

AWS adds Cost Efficiency widget to BCM Dashboards

📊 AWS Billing and Cost Management (BCM) now offers a Cost Efficiency widget for BCM Dashboards, allowing teams to view efficiency trends alongside Cost Explorer, Budgets, and Savings Plans and Reserved Instance reports. The widget displays efficiency scores over time by account, region, or overall, with adjustable granularity and links to the Cost Optimization Hub. Widgets support exports, scheduled email reports, CSV/PDF downloads, and cross-account sharing, and are available in all AWS commercial Regions at no extra charge.
read more →

Amazon MQ adds configurable EBS storage for RabbitMQ

📣 Amazon MQ now lets you configure EBS Disk storage size for RabbitMQ brokers independently of instance type. This applies to RabbitMQ M7g brokers on version 4.2+ using cluster deployments, with storage selectable in 5 GB increments from the M7g default to the instance-specific maximum. You can set storage via the AWS Console, CloudFormation, CLI, or CDK; changes take effect after a broker reboot and follow standard Amazon MQ storage pricing.
read more →

Security Hub expands to AI protections and Azure

🔒 Security Hub now adds native AI workload protection and Microsoft Azure monitoring to centralize enterprise security across clouds. It discovers Azure resources, evaluates posture against CIS benchmarks, and prioritizes findings alongside AWS signals using the same formats and workflows. New GuardDuty AI Protection detects anomalous model invocations and cost-harvesting, while AI-powered investigations accelerate triage. A continuous AI inventory catalogs models and agents across accounts, and Security Hub Extended integrates 21 curated partners to broaden coverage.
read more →

Amazon Aurora DSQL now available in Spain

🚀 Amazon Aurora DSQL is now available for single-Region clusters in the Europe (Spain) Region. Aurora DSQL is a serverless, distributed SQL database offering active-active high availability and multi-Region strong consistency, designed for virtually unlimited scalability and zero infrastructure management. The service is now available in multiple AWS Regions and can be tried via the AWS Free Tier.
read more →

Jurassic Park and the Myth of Cyber Control

🦖 The article compares Jurassic Park’s failed containment to modern cybersecurity, arguing that visibility is often mistaken for control. It asserts that tooling, dashboards, and backups provide friction but not guaranteed survivability, and that dynamic cloud and AI-driven change invalidate static recovery assumptions. The piece recommends continuous resilience engineering, dependency awareness, and validation to operate through inevitable disruptions rather than assume they can be prevented.
read more →

AWS DMS Schema Conversion Adds Offline Source Support

🛡️ AWS DMS Schema Conversion now supports Offline Source for Microsoft SQL Server, letting users extract metadata locally and upload it for conversion without direct database connectivity. This prevents firewall or VPN changes and simplifies security approvals while producing the same conversion results as connected workflows. Offline Source is suited for environments with strict access controls and is available for all DMS Schema Conversion targets at no extra conversion charge.
read more →

AWS Client VPN adds four more regions globally

🔒 AWS Client VPN is now available in Canada West (Calgary), Mexico (Central), New Zealand, and Taipei. The fully managed service lets remote workers securely connect to AWS and on-premises resources without hardware VPN appliances. It uses a pay-as-you-go model and provides centralized management and monitoring through a single console. Customers can consult AWS product, documentation, and pricing pages for details.
read more →

Forg365 PhaaS Targets Microsoft 365 with AI

🛡️ Forg365 is a phishing-as-a-service platform that targets Microsoft 365 accounts by combining adversary-in-the-middle (AiTM) and device-code phishing with integrated AI-assisted lure generation. The service offers an admin dashboard for campaign management, OAuth and SMTP configuration, token handling, and a browser extension called ForgCookie for persistent cookie harvesting. Researchers at ZeroBEC found the operation uses legitimate delivery services like Amazon SES and SendGrid-hosted resources to blend malicious emails into normal traffic.
read more →

AI gateway compromise raises cloud security concerns

🔒 Researchers report an AWS EC2 instance acting as a LiteLLM proxy for Amazon Bedrock was compromised and used to deploy XMRig cryptomining malware. The intrusion highlights risk from AI gateways that centralize identities, permissions, and model access, making them high-value targets. Analysts observed SSH exposure, probable brute-force attempts, and suspicious IAM activity tied to model enumeration and persistence efforts. Darktrace assisted in timely detection and containment while urging tighter controls and telemetry correlation.
read more →

AWS Config adds 191 new managed rules

🛡️ AWS Config has expanded its set of managed rules with 191 additional checks covering services such as Amazon Bedrock, SageMaker, ECS, EKS, RDS, Redshift, S3, and CloudTrail. The new rules evaluate encryption, logging, public access, network security, data protection, and operational best practices. You can deploy rules individually or as part of a conformance pack in supported AWS Regions.
read more →

AWS Security Hub adds internet Network Scanning

🔍 AWS Security Hub now includes Network Scanning to identify resources that are actually reachable from the public internet. The feature probes public IPs, VMs, and load balancers across AWS and Azure, detects reachable ports, and identifies services running behind them. Findings are created per reachable port and correlated by Security Hub Exposures to assess broader risk. Existing customers can enable the feature per account, region, or organization; it is enabled by default for new customers and included with Security Hub Essentials at no extra cost in supported commercial Regions.
read more →

Microsoft details SFI AI system to harden cloud

🚀 Microsoft describes a multi-agent AI system within the Secure Future Initiative (SFI) that continuously evaluates and hardens its cloud services. The system combines code, configuration, identity, network, and runtime evidence to find composite vulnerabilities and assess layered defenses. It generates assurance trees tailored to each service and produces high-quality, actionable findings that speed remediation. Microsoft reports the system compresses deep security reviews from weeks to hours and that over 90% of findings were validated by engineers.
read more →