< ciso
brief />
Tag Banner

All news with #cloud security tag

659 articles · page 5 of 33

Azure Files boosts Linux workloads with NFS enhancements

📣 Azure Files provides fully managed file storage tailored for modern Linux workloads, combining familiar file access with built-in performance, resilience, and security. The service supports AI inferencing, cloud-native Kubernetes deployments, and enterprise migrations by exposing standard NFS and SMB endpoints and integrating with Azure services. New features like zonal placement, provisioned v2, and faster provisioning improve scale, latency, and cost management for shared file scenarios.
read more →

Turner Industries’ secure cloud-first infrastructure

🔒 Turner Industries migrated to ChromeOS, Google Workspace, Chrome Enterprise Premium, and Cameyo to reduce costs and improve security. The shift extended device lifecycles, cut per-device costs by 40–50%, and saved an estimated $700,000 on new hardware plus $600,000 by converting existing devices with ChromeOS Flex. Faster deployments and simplified management freed IT to focus on strategic work while maintaining strong endpoint protection and legacy app access.
read more →

EC2 AMI Watermarks for Provenance and Governance

🔒 Amazon EC2 now supports AMI watermarks that embed custom identifiers into private AMIs and persist through copies and derived AMIs. Watermarks include metadata such as AMI ID, owner ID, region, and timestamps to support provenance and tracking. You can apply watermarks via the AWS Management Console, AWS CLI, SDKs, or EC2 Image Builder. Watermarks integrate with Allowed AMIs and Declarative Policies to enforce AMI usage across organizations.
read more →

CNAPP evolution: Microsoft aligns with cloud risk platforms

🔍 Cloud security is shifting from mere visibility to context-aware risk reduction across multicloud, Kubernetes, APIs, and AI workloads. The Frost & Sullivan 2026 Frost Radar positions CNAPP as an operational cloud risk platform that correlates posture, workload, identity, data, and runtime signals. Microsoft Defender for Cloud is highlighted among leading vendors for connecting findings into prioritized, actionable attack paths and enabling continuous risk validation across the application lifecycle.
read more →

Amazon Bedrock AgentCore Memory adds cross-account access

🔒 Amazon Bedrock AgentCore Memory now supports cross-account access, enabling multi-account architectures where memory resources and consuming agents span AWS accounts. Administrators can attach resource-based policies to memory resources to grant principals in other accounts permission to call memory data plane APIs by referencing the full memory ARN. Cross-account delivery destinations let memory resources stream payloads and events to Amazon S3, Amazon SNS, and Amazon Kinesis Data Streams in separate accounts. This capability is available in all Regions where AgentCore Memory is supported.
read more →

Agentic cloud operations: insight to governed action

🧭 Agentic cloud operations use AI-powered agents to turn continuous observability into governed, auditable actions across the cloud lifecycle. Microsoft describes how Azure Copilot’s observability agent—now generally available—analyzes telemetry, traces dependencies, and surfaces grouped signals and contextual recommendations to speed incident resolution and reduce noise. Built-in governance and policy guardrails ensure actions respect controls and remain human-reviewed, while cost and usage intelligence integrate into developer tools to enable continuous optimization.
read more →

AI-assisted Migration Assistant for OpenSearch Service

🚀 Migration Assistant for Amazon OpenSearch Service now includes an AI-assisted experience that simplifies moving self-managed Apache Solr, Elasticsearch, or OpenSearch deployments to OpenSearch Serverless or Managed Clusters. The assistant integrates with AI tools like Kiro and Claude Code to plan migrations, deploy infrastructure, and execute both historical and live traffic migration. It also adds live traffic capture and replay support for Solr and is available in all commercial AWS Regions and AWS GovCloud (US) Regions where OpenSearch Service is offered.
read more →

AWS Transform expands migration target regions

🔁 AWS Transform for migrations now supports deployment to all AWS commercial regions as migration targets, enabling customers to select where migrated resources are provisioned, including landing zones and network infrastructure. The announcement lists newly supported regions such as US East (N. California), Africa (Cape Town), multiple Asia Pacific and European locations, Canada (Calgary), Mexico (Querétaro), and Middle East (Tel Aviv). Target region selection is integrated into the AWS Transform for migrations workflow and documentation lists the current supported target regions.
read more →

Implementing Egress Controls to Prevent Data Exfiltration

🔒 This post outlines an architecture and controls for preventing data exfiltration from AWS environments by combining centralized network inspection, DNS filtering, and data perimeter policies. It explains a hub-and-spoke pattern using Transit Gateway, AWS Network Firewall, and Route 53 Resolver DNS Firewall to inspect and block unauthorized outbound traffic, including scenarios involving compromised workloads and agentic AI. The article details layered preventive, detective, and corrective measures using AWS services such as GuardDuty, Security Hub, IAM Access Analyzer, EventBridge, and Firewall Manager to automate detection and response.
read more →

Amazon EKS adds customer-routed control plane egress

🔐 Amazon EKS now supports customer-routed control plane egress, allowing outbound Kubernetes API server traffic to traverse your Amazon VPC. This includes admission webhook callbacks, OpenID Connect (OIDC) provider lookups, and aggregate API server requests. By routing through your VPC you can manage routing, security groups, and egress paths to meet data perimeter and compliance needs. Enable the feature by setting controlPlaneEgressMode to CUSTOMER_ROUTED and enforce it org-wide with the eks:controlPlaneEgressMode IAM condition key.
read more →

NCSC: 75% of CNI Incidents Linked to Hostile States

🛡️ Richard Horne, CEO of the UK National Cyber Security Centre, told the RUSI Annual Security Lecture that three-quarters of cyber incidents affecting UK critical national infrastructure over the past year were traced to nation-state actors or hostile states. The NCSC handled around 200 incidents between June 2025 and May 2026, with threats described across three contested digital spaces: far, mid and near. Horne warned that AI and cloud supply-chain exploitation increase attacker scale and urged organisations to prioritise continuous defence, fix legacy vulnerabilities and close IT-OT knowledge gaps.
read more →

Google Vertex AI SDK bucket squatting enables RCE

🔒 A design flaw in the Vertex AI SDK for Python allowed attackers to hijack model staging buckets across projects by predicting bucket names derived from project ID and region. Unit 42 researchers called this class of issue Bucket Squatting, where global bucket name uniqueness enabled pre-creation and silent takeover. The flaw could lead to cross-tenant model poisoning and remote code execution via pickle deserialization. Google issued fixes in SDK versions 1.144.0 and 1.148.0 and users should upgrade.
read more →

Oracle Autonomous AI Database Serverless on AWS

🛠️ Oracle Autonomous AI Database Serverless (ADB-S) is now available on Oracle Database@AWS through AWS Marketplace with Bring Your Own License and License Included options. ADB-S runs on Exadata infrastructure as a fully managed service that automates patching, tuning, scaling, backups, and high availability. It supports four workload types—AI Transaction Processing, AI Lakehouse, AI JSON Database, and Oracle APEX—with independent compute and storage scaling. Integrations include AWS KMS for encryption, Amazon CloudWatch for monitoring, and Amazon EventBridge for events.
read more →

Detecting and Preventing Subdomain Takeover Risks

🔎 This post explains how subdomain takeover occurs when dangling DNS CNAME records point to deleted AWS resources and how attackers can reclaim those names to serve malicious content. It describes which AWS services use globally claimable namespaces (notably S3, CloudFront, and Elastic Beanstalk), outlines potential impacts such as reputation damage and phishing, and recommends detection using AWS Config inventory checks rather than DNS resolution. The article also summarizes a reference implementation that deploys a Lambda-based Config rule, Security Hub findings, optional SNS alerts, and mitigation best practices including deleting DNS records before resources and adopting account regional S3 namespaces where applicable.
read more →

Plan and Migrate Data with Azure Storage

📌 This blog explains a structured approach to enterprise storage migration using Microsoft tools. It emphasizes planning, assessment, and choosing the right migration path based on data volume, connectivity, and downtime tolerance. Key solutions covered include Azure Migrate, Azure Storage Mover, Azure Data Box, and a preview Azure Copilot Migration Agent. The post illustrates phased strategies, real customer examples, and guidance for regulated and AI use cases.
read more →

Palo Alto DNS Security Preview for Route 53 Resolver

🛡️ Amazon Web Services announces a preview integration of Palo Alto Networks Advanced DNS Security with Route 53 Resolver DNS Firewall. Security teams can now subscribe to PANW protections directly from the DNS Firewall console and apply categories like Command and Control, Malware, and Phishing without deploying separate firewalls. The integration supports hybrid traffic, AWS multi-account management, centralized visibility via AWS Security Hub, and preview availability across multiple regions.
read more →

AWS Cost Explorer preserves billing history for accounts

📊 AWS announces Cost Explorer historical data retention for accounts in billing groups. Customers using AWS Billing Conductor and Billing Transfer can map accounts to billing groups and view billing data priced at the payer or Bill-Transfer account's pro forma rates. Previously, billing group mapping restricted access to historical billing data priced at AWS billable rates. Accounts already onboarded will retain access to their historical Cost Explorer data with no additional action required.
read more →

AWS Lambda Managed Instances adds tag propagation

🔔 AWS Lambda Managed Instances (LMI) now supports tag propagation to automatically apply tags to managed resources such as Amazon EC2 instances, Amazon EBS volumes, and ENIs. This enables consistent cost allocation, enforcement of service control policies, and compliance across resources provisioned by LMI. Configure the PropagateTags setting via CreateCapacityProvider or UpdateCapacityProvider in Explicit mode and provide key-value pairs; the feature is available in all commercial Regions where LMI is GA.
read more →

Amazon unveils CloudWatch metrics centralization

📣 Amazon Web Services announced general availability of CloudWatch Metrics Centralization, enabling replication of CloudWatch and OpenTelemetry metrics cross-account and cross-region into a single destination account. Enterprise teams can use AWS Organizations to define centralization rules that automatically replicate metrics for unified querying, alarming, compliance, and governance. The feature supports Metrics Insights, dashboards, alarms, Metric Math, anomaly detection, Metric Streams, and PromQL and is available in multiple global AWS Regions.
read more →

Sovereign Cloud Alone Won’t Solve AI Risk

🔒 European enterprises tested sovereign cloud under regulatory pressure and found residency alone doesn’t equal control. Vendors offer sovereignty features, but practitioners at EIC 2026 emphasized that identity governance — not just data location — determines operational sovereignty for AI workloads. Weak identity controls, especially for non-human AI agents, undermine claims of control despite customer-managed keys or regional data centers.
read more →