< ciso
brief />
Tag Banner

All news with #iam tag

261 articles · page 2 of 14

Organizations Deploy AI Without Adequate Permissions Checks

🔍 A Syskit study finds rapid enterprise AI adoption on Microsoft 365 outpaces permission reviews and governance controls. 76% of organizations have deployed or piloted AI tools like Copilot, yet only 43% completed thorough permissions reviews before rollout. The survey highlights widespread misconfigurations, orphaned content and gaps in access reporting, leaving many environments exposed.
read more →

Amazon ECS expands IAM condition key support

🆕 Amazon Elastic Container Service (Amazon ECS) now supports IAM condition keys for CPU and memory on the RunTask and StartTask APIs, enabling administrators to enforce consistent resource limits across all task launch methods. Previously, ecs:task-cpu and ecs:task-memory were limited to RegisterTaskDefinition, CreateService, and UpdateService; the extension ensures IAM policy evaluation also applies when tasks are started with RunTask and StartTask. This change is available in all AWS Regions where ECS is offered at no additional cost, helping organizations prevent cost overruns and maintain resource-policy conformity.
read more →

Amazon Quick adds always-on agents and enterprise controls

🔔 Today, Amazon Quick introduces capabilities to improve organization, governance, and answer trust across desktop and mobile. Scheduled tasks and monitoring agents now run continuously in the cloud, delivering results even when devices are offline. A refined activity feed offers top-level filters, improved catch-up views, a thrice-daily briefing, and seven-day search. Administrators gain MDM support, per-user permissions, and Microsoft Purview DLP integration, while collaboration, native desktop apps, inline citations, and expanded agent hours simplify enterprise use.
read more →

AWS Systems Manager expands EC2 diagnosis reach

🔍 AWS Systems Manager now diagnoses six additional root causes preventing Amazon EC2 instances and hybrid-activated nodes from becoming managed. The expanded checks include IAM permissions, SSM Agent version, instance status checks, operating system configuration, Default Host Management Configuration, and hybrid activation, in addition to prior network connectivity diagnostics. The console reports specific issues with step-by-step guidance and can run Automation runbooks to remediate some problems directly.
read more →

Investigation of Amazon Bedrock LLMjacking Incident

🛡️ FortiGuard Labs examines an AWS incident where a long-lived IAM access key with Administrator privileges was abused to create identities, subscribe to foundation models on AWS Marketplace, and invoke those models for profit. The report outlines the concept of LLMjacking, the steps observed in the compromise, and why valid cloud credentials make detection challenging. It also lists FortiCNAPP (Lacework) detections and recommended posture changes to reduce risk.
read more →

Reframe cybersecurity leadership with a CSO role

🔒 The article argues that asking CISOs to become full business leaders misses a structural problem: alignment is an organizational design issue, not just communication. It proposes a distinct CSO role that sits above cybersecurity to coordinate enterprise protection across data, resilience, regulation and operations. The CSO would provide authority to reconcile competing priorities while the CISO remains accountable for technical delivery, creating clearer ownership and better business protection.
read more →

Managing Identity Source Transitions for IAM Identity Center

🔐 This AWS blog explains how to plan and execute an identity source transition in AWS IAM Identity Center, focusing on migrations such as Active Directory to Okta. It outlines destructive and non‑destructive transition scenarios, a five‑step migration runbook, and prerequisites including backup, validation, SCIM configuration, and restore processes. The post also references sample scripts and a migration tool on GitHub to automate prechecks, cutover, validation, and cleanup.
read more →

Amazon Bedrock Web Search now in AWS GovCloud

🔎 Amazon Bedrock's Web Search tool is now available in AWS GovCloud (US-West), enabling grounded web results with citations for supported OpenAI GPT models. Web Search keeps request data inside the AWS boundary by default and is governed by IAM so administrators can control access at account, organization, and Region levels. At launch it supports GPT-5.4, GPT-5.6 Terra, and Luna models and joins other US Regions where the capability is already available.
read more →

Amazon Cognito adds GetClientToken for M2M use

🔒 Amazon Cognito now supports the GetClientToken API, enabling app clients to obtain access tokens for machine-to-machine authorization without requiring a user pool domain. The API lets an app client authenticate with its client ID and secret to receive access tokens for custom scopes on resource servers and integrates with AWS SDKs, AWS WAF, and VPC interface endpoints. The domain-based OAuth 2.0 client-credentials flow remains available, and the feature is live in all regions where Cognito user pools exist.
read more →

Automate IAM Identity Center governance and reporting

🔍 This post explains how to plan and automate governance for AWS IAM Identity Center across an AWS Organization. It outlines integration with external IdPs, recommended delegation and IAM permissions, and naming conventions to improve discoverability. The article describes a sample solution that uses AWS CDK to deploy reporting and remediation stacks to discover Identity Center applications, generate CSV reports, and optionally enforce assignment policies. It emphasizes cross-team planning, detective controls, and testing before remediation.
read more →

AWS adds one‑click install for Workload Credentials

🛠️ AWS Secrets Manager now offers one‑click installation for the AWS Workload Credentials Provider (AWCP) on Amazon Linux and Windows, replacing a prior multi‑step build-from-source flow. Pre-built, code-signed binaries for Linux (x86_64, ARM64) and Windows (x64) are available via public download and the Amazon Linux repository, enabling one-command install on Amazon Linux EC2. AWCP resolves secrets from AWS Secrets Manager, caches them in memory, and exposes them via a local HTTP endpoint; it also retrieves certificates from AWS Certificate Manager. The feature is available in all Regions where Secrets Manager is offered at no extra charge beyond standard Secrets Manager pricing.
read more →

AgentCore Memory Adds Fine-Grained Access Control

🔒 Amazon Bedrock’s AgentCore Memory now supports fine-grained access control (FGAC), allowing per-user and per-tenant memory isolation via AgentCore Gateway without custom authorization code. Administrators can configure OAuth (JWT) authentication and attach Cedar policies to restrict access by caller identity, namespace claims, or specific Memory operations. The feature moves access enforcement into the infrastructure using cryptographic identity proof, and is implemented through the managed AgentCore Memory connector exposing 12 Memory operations as Cedar actions.
read more →

AWS Lambda adds full IAM resource-based policy support

🔒 AWS Lambda functions now support full Identity and Access Management (IAM) resource-based policies, enabling platform and security teams to define granular permissions for multiple principals and actions within a single policy. This replaces the previous per-principal permission model and permits the use of the full range of IAM condition keys, such as source IP or principal tag restrictions. Policies can be managed via the Lambda console JSON editor, AWS CLI, SDKs, CloudFormation, and SAM. The feature is available in all AWS commercial Regions at no extra cost.
read more →

CloudWatch Centralization Adds Tag Propagation

🔔 Amazon CloudWatch Centralization now copies log group tags from source accounts to destination log groups created by centralization rules. Tag propagation preserves cost, ownership, and compliance tags so teams can scope access and report spend centrally. The feature syncs tags based on propagation behavior chosen in the centralization rule and is available in all Regions where CloudWatch Centralization is offered.
read more →

Amazon DynamoDB Streams Adds ABAC Support

🔒 Amazon DynamoDB Streams now supports attribute-based access control (ABAC), allowing tag-based conditions in IAM policies to control stream access. You can attach up to 50 tags per stream and use them to permit or deny actions, enabling environment and team segregation without proliferating IAM policies. Stream tags are independent from table tags, available in all commercial AWS Regions and AWS GovCloud (US), and there is no additional cost to use this feature.
read more →

SageMaker notebooks add trusted identity propagation

🧭 Amazon SageMaker Notebooks now support Trusted Identity Propagation (TIP) with Amazon Athena, Amazon Redshift, and Amazon EMR Serverless, enabling per-user access control for data analytics. When connected to a TIP-enabled compute in a TIP-enabled Project, each notebook user's IAM Identity Center identity flows through to AWS Lake Formation, ensuring they see only the tables, columns, and rows their permissions allow. TIP provides per-user data boundaries, full audit attribution with CloudTrail, and reduces admin friction by automatically propagating identity through existing compute connections without extra logins or role management. The feature is available in all Regions where Amazon SageMaker Unified Studio is available.
read more →

Propagate user authorization in AI agents with Bedrock

🛡️ This post demonstrates patterns for propagating user authorization context when building AI agents with Amazon Bedrock AgentCore, ensuring each user only sees data they’re allowed to access. It explains how to embed department or custom claims in tokens via Amazon Cognito pre token generation triggers and how the AgentCore Runtime inbound JWT authorizer validates those claims before invoking agent code. The guidance shows moving enforcement into infrastructure—using STS session tags, per-request AssumeRoleWithWebIdentity for DynamoDB, metadata filters for Bedrock Knowledge Bases, and on‑behalf‑of token exchange for external SaaS—to reduce risk from compromised agents.
read more →

IAM Policy Autopilot adds Terraform plan support

🔧 IAM Policy Autopilot now accepts Terraform plan files to generate baseline IAM policies. The open source tool, launched at re:Invent 2025, deterministically analyzes a plan to produce scoped policies that reference specific resource ARNs where possible. This capability complements existing Terraform-aware analysis and addresses the most requested feature since launch. IAM Policy Autopilot runs locally at no additional cost.
read more →

UT San Antonio IT Systems Taken Offline After Incident

🔒 The University of Texas San Antonio took several IT systems offline after detecting attempted unauthorized activity at the network edge, prompting containment measures by University Technology Solutions and partners. Officials say there is no evidence of data access or exfiltration so far, though the outage disrupted online registration, tuition payments and phone systems ahead of term start. Students were granted extensions and instructed to reset passphrases as remediation steps continue.
read more →

Practical IAM Compliance: Requirements and Best Practices

🔐 This guide defines IAM compliance as proving that identity and access controls are not only documented but enforced across users, applications, infrastructure, and non-human identities. It explains key obligations from frameworks like SOX, PCI DSS, HIPAA, ISO/IEC 27001, NIST SP 800-53, and GDPR, and highlights evidence gaps between policy intent and runtime execution. The article outlines core controls—least privilege, segregation of duties, MFA, lifecycle management—and urges continuous, application-layer verification rather than periodic reviews.
read more →