< ciso
brief />
Tag Banner

All news with #cloud security tag

659 articles · page 4 of 33

Amazon EC2 U7i High Memory Now in Zurich

🚀 Amazon EC2 High Memory U7i instances with 12TB (u7i-12tb.224xlarge) are now available in the AWS Europe (Zurich) region. These 7th-generation U7i instances use custom 4th-gen Intel Xeon Scalable Processors (Sapphire Rapids) and provide 12TiB of DDR5 memory to support large in-memory workloads. The instances deliver 896 vCPUs, up to 100Gbps EBS and network bandwidth, and support ENA Express, targeting mission-critical databases such as SAP HANA, Oracle, and SQL Server.
read more →

Enforce Zero Data Retention on Amazon Bedrock

🛡️ This post explains how Amazon Bedrock’s data retention modes work and the tools you can use to enforce zero retention across accounts and projects. It covers account-level modes (none, default, inherit, provider_data_share), how model requirements interact with your configured ceiling, and APIs that mandate retention. The article also describes project-level isolation via bedrock-mantle, organization-wide enforcement using SCPs, and practical steps to lock accounts to none.
read more →

Top BGP Route Policy Uses by Customer Demand

🛡️ Cloud Router's BGP route policies give administrators programmatic control to filter, modify, and propagate routes using CEL expressions. Customers now use these policies to enforce strict route filtering, implement traffic steering via MED and AS-PATH prepending, and achieve stateful traffic symmetry through BGP community tagging. Policy named sets simplify managing large lists of prefixes and communities across multiple routers.
read more →

Amazon EVS adds support for VMware Cloud Foundation 9

🆕 Amazon Elastic VMware Service (EVS) now supports VMware Cloud Foundation (VCF) 9.0 and 9.1, enabling customers to run VCF directly within their Amazon VPC on EC2 bare-metal instances. You retain full control over installation, operations, and management of the VMware virtualization stack and can continue using existing tools, processes, and skills. AWS also launched the Solutions for EVS GitHub repository with examples, templates, and infrastructure-as-code artifacts to accelerate deployments. The release is available in all regions where Amazon EVS is offered.
read more →

Five key CSPM insights from Frost & Sullivan 2025

🔒 Frost & Sullivan’s 2025 Frost Radar reframes Cloud Security Posture Management (CSPM) as a continuous, risk‑based governance layer inside CNAPPs rather than a periodic compliance exercise. The report forecasts CSPM market growth through 2030 and highlights integration of posture with workload protection, identity, data security, and DevSecOps. It underscores Microsoft’s leadership in unifying posture with runtime telemetry and SecOps workflows.
read more →

EC2 Dedicated Hosts Now Support AMD SEV‑SNP

🔒 Amazon EC2 now supports AMD Secure Encrypted Virtualization‑Secure Nested Paging (SEV‑SNP) on Dedicated Hosts, allowing confidential computing workloads to run on physical servers dedicated to a single customer. Customers can allocate a Dedicated Host with SEV‑SNP enabled and launch compliant instances while retaining control over instance placement and host affinity. The host is provisioned with AMD security firmware at allocation to keep confidential environments current. Dedicated Host SEV‑SNP is available in all AWS commercial Regions with AMD instances.
read more →

AWS Config adds eight new resource types

🔔 AWS Config now supports eight additional resource types across key services including Amazon API Gateway, Amazon EC2, Amazon S3 Vectors, Network Firewall, OpenSearch Serverless, and OSIS. If you have recording enabled for all resource types, AWS Config will automatically begin tracking these new resources. The new types are also available for use in Config rules and Config aggregators, expanding discovery, assessment, audit, and remediation coverage.
read more →

CloudWatch Adds Alarms Directly From Log Queries

🔔 Amazon CloudWatch now lets you create alarms directly from log queries, enabling anomaly alerts without leaving the log analysis workflow. You can set thresholds on query results without first creating metric filters or custom metrics, simplifying monitoring and alerting. Alarms support standard CloudWatch actions such as Amazon SNS notifications and Amazon EventBridge integrations, and are available in all commercial AWS Regions except UAE and Bahrain. Configure these alarms via the CloudWatch console, AWS CLI, CloudFormation, or AWS SDKs.
read more →

Microsoft named a leader in Frost Radar for CARS

🔒 Microsoft highlights its recognition in Frost & Sullivan’s 2026 Frost Radar for Cloud/Application Runtime Security, emphasizing a shift from visibility to contextual risk reduction across cloud infrastructure, applications, APIs, and runtimes. The post explains how Microsoft Defender for Cloud integrated with Microsoft Defender XDR correlates posture, identity, data, and runtime signals to prioritize exploitable attack paths. It argues that unified platforms reduce alert fatigue, speed remediation, and enable continuous risk operations across development and runtime.
read more →

CloudWatch Logs adds resource tag enrichment

🔍 Amazon CloudWatch Logs now enriches log events with AWS resource tags at ingestion, enabling filtering, searching, and analysis by metadata such as team ownership, environment, cost center, or application name without changing logging instrumentation. Tags are applied at ingestion so you can use them immediately in log queries to scope analysis and incident investigations. The feature is available in all commercial AWS Regions except UAE, Bahrain, and Israel (Tel Aviv). Enable resource tags on telemetry in Amazon CloudWatch Settings, via the AWS CLI, or SDKs; tag enrichment is provided at no extra cost.
read more →

Amazon RDS IAM Database Authentication Scales Dynamically

🔒 Amazon RDS now supports dynamic connection rate scaling for IAM database authentication, so authentication throughput scales with instance resources. This allows enterprise workloads to use IAM authentication for high-volume connection patterns while depending on available CPU and memory. AWS recommends reusing IAM principals or authentication tokens to optimize performance. The feature is available in all Regions, including AWS GovCloud (US), for Aurora, PostgreSQL, MySQL, and MariaDB.
read more →

Amazon Neptune adds dual‑stack IPv6 support

🔷 Amazon Neptune now supports dual‑stack mode, allowing database clusters to accept connections over IPv4, IPv6, or both simultaneously. This enables organizations to adopt IPv6 while preserving compatibility with existing IPv4 deployments. Dual‑stack offers Private mode for internal, non‑internet IPv6 endpoints and Public mode for internet‑accessible IPv6 endpoints to support hybrid and internet‑facing applications. The feature is available in all AWS Regions that support Amazon Neptune.
read more →

EC2 Time Sync Adds Microsecond Accuracy to More Instances

🔧 Amazon Time Sync Service now supports microsecond accurate time on 26 additional EC2 instance types across all commercial regions. Built on the AWS Nitro System, the feature exposes nanosecond precision hardware timestamps from reference clocks in Nitro, enabling ordered event logging, one-way latency measurement, and faster distributed transactions. Customers enable this by creating a Precision Time Placement Group (PTPG) to launch instances with PHC enabled and can associate PTPGs with Cluster Placement Groups for combined low-latency and precise timing benefits.
read more →

EC2 Auto Scaling adds reservations‑then‑balanced AZ strategy

🔔 Amazon EC2 Auto Scaling introduces a new reservations-then-balanced Availability Zone distribution strategy that prioritizes launching instances into your capacity reservations before distributing remaining capacity across AZs. You can configure it in the AvailabilityZoneDistribution of your Auto Scaling group and target reservations by Capacity Reservation Group ARN or individual Capacity Reservation IDs. The feature is available today in all AWS commercial Regions at no extra charge beyond standard EC2 pricing for reservations, On-Demand, and Spot instances.
read more →

AWS Security Hub Adds AI Security Best Practices

🛡️ AWS Security Hub CSPM introduces the AI Security Best Practices standard, offering 31 automated controls to detect misaligned AI resources. The standard evaluates Amazon Bedrock, Bedrock AgentCore, and Amazon SageMaker workloads against recommended configurations without manual rule creation. It covers domains like network isolation, encryption, VPC placement, KMS usage, private registries, and authorization, producing findings to help teams remediate issues. Available in all Regions where Security Hub CSPM operates, including GovCloud (US) and China.
read more →

AlloyDB Omni: Secure hybrid database for finance

🔒 Google Cloud introduces AlloyDB Omni, a hybrid deployment of AlloyDB for PostgreSQL designed to modernize financial services databases while preserving data residency and regulatory compliance. The offering promises PostgreSQL compatibility to reduce vendor lock-in, high transactional performance, and integrated analytics and AI capabilities delivered on-premises, at the edge, or in hybrid clouds. It targets legacy licensing, sovereignty, and real-time insights gaps, and highlights customer outcomes demonstrating faster transactions and accelerated analytics.
read more →

Cloud Monitoring adds long-lookback PromQL alerts

🔔 Google Cloud announces preview support for long-lookback alert policies in Cloud Monitoring using PromQL, enabling queries across up to two years of metric history. The feature unlocks dynamic thresholding—alerts that compare recent behavior to historical baselines—helping catch anomalies that static thresholds miss. Google outlines example algorithms (moving averages, z-score, and seasonal time-offsets), discusses trade-offs like flakiness for new workloads, and shows a practical use case for preventing runaway spend.
read more →

Designing Azure IaaS for Long-Term Cost Efficiency

🔍 This third post in the Azure IaaS series outlines best practices to design, build, and optimize cloud infrastructure for sustained cost efficiency. It explains how compounded architectural choices across compute, storage, and networking drive costs and offers Azure capabilities—such as VM families, automated tiering, and resilient networking—to align resources with workload needs and reduce TCO.
read more →

AWS Security Hub Adds Microsoft Azure Monitoring

🔒 AWS Security Hub now monitors Microsoft Azure resources, extending risk analytics, cloud security posture management, vulnerability management, and security response across both clouds. The service auto-discovers Azure VMs, ACR images, Function Apps, and identities, evaluating misconfigurations, internet exposure, and software vulnerabilities. Findings from AWS and Azure appear in a single prioritized view with consistent formats and automation workflows, and a 30-day free trial for Azure monitoring is available.
read more →

June 2026 Threat Technique Catalog Update for AWS

🛡️ The AWS CIRT updated the Threat Technique Catalog for June 2026, adding five new entries focused on container security, organization-level trust, and compute hijacking. The update documents EKS workload modification, exploitation of public-facing Kubernetes services, sts:AssumeRoot abuse across AWS Organizations, compute hijacking in clusters, and account invitations into attacker-controlled organizations. It also refreshes three existing entries with expanded detection and mitigation guidance.
read more →