< ciso
brief />
Tag Banner

All news with #identity security tag

194 articles

Amazon Redshift adds IAM Identity Center via EVR

πŸ”’ Amazon Redshift now supports AWS IAM Identity Center authentication for provisioned clusters and serverless workgroups configured with enhanced VPC routing (EVR). This enables single sign-on using corporate credentials while keeping traffic inside your Amazon VPC and on the AWS network, meeting data residency and network-isolation requirements. Redshift validates and exchanges IAM Identity Center tokens over AWS PrivateLink interface VPC endpoints inside the VPC and supports multi-Region Identity Center replication.
read more β†’

Automate IAM Identity Center governance and reporting

πŸ” This post explains how to plan and automate governance for AWS IAM Identity Center across an AWS Organization. It outlines integration with external IdPs, recommended delegation and IAM permissions, and naming conventions to improve discoverability. The article describes a sample solution that uses AWS CDK to deploy reporting and remediation stacks to discover Identity Center applications, generate CSV reports, and optionally enforce assignment policies. It emphasizes cross-team planning, detective controls, and testing before remediation.
read more β†’

Elastic Beanstalk adds Active Directory domain join

πŸ”’ AWS Elastic Beanstalk now automatically joins Windows Server instances to an Active Directory domain managed with AWS Directory Service. Previously requiring custom join scripts, the new feature uses configuration options so every instance, including those launched by auto scaling, joins the domain at boot before application deployment. Domain-joined instances can use Windows-integrated authentication, group policy, and access domain resources, and the join process is resilient so failures don't block deployments.
read more β†’

Why Identity Fabric Matters for Modern Security

πŸ” An Identity Fabric unifies fragmented identity systems to provide runtime visibility across applications, APIs, and infrastructure. It bridges design-time policies with runtime behavior to reveal identity drift, orphaned credentials, and unobserved attack paths. The approach is essential for hybrid and multi-cloud environments, especially to govern non-human and AI identities and enable continuous least-privilege enforcement.
read more β†’

IAM Roles Anywhere Java SDK v2 plugin available

πŸ› οΈ The AWS Identity and Access Management (IAM) Roles Anywhere plugin for the AWS SDK for Java v2 lets applications running outside AWS obtain temporary credentials directly inside the Java process. The JVM-hosted plugin removes the need for a separate credential helper or credential_process configuration and integrates with client builders to auto-resolve and refresh credentials. It supports RSA, EC, and ML-DSA keys, requires Java 8+, and is available across all AWS Regions at no extra charge.
read more β†’

Black Hat roundup: Security vendors and AI trends

πŸ” Andy Ellis reviews the vendor landscape at Black Hat, highlighting pervasive AI influence across booths and product messaging. He notes that while many vendors emphasize AI in Identity, SaaS, AppSec, and Data, nearly half did not explicitly reference agents or AI in their taglines. Ellis also identifies a market trichotomy: tools that report risk, tools that stop adversaries, and tools that prevent incidents, with diagnostic tools arguably overrepresented.
read more β†’

Amazon EKS adds support for multiple OIDC providers

πŸ”’ Amazon Elastic Kubernetes Service (Amazon EKS) now lets you associate up to 10 external OpenID Connect (OIDC) identity providers with a single cluster. This enables distinct user populationsβ€”employees, contractors, CI/CD systemsβ€”to authenticate directly without consolidating providers or using an identity broker. Each provider is configured and managed independently and coexists with existing IAM authentication. You add providers via the AWS Management Console or the AssociateIdentityProviderConfig API at no extra cost in all EKS regions.
read more β†’

Communication Channels and Identity Risks in SaaS Era

πŸ›‘οΈ Enterprise collaboration platforms are now central to business workflows and have become part of the identity attack surface. Threat actors increasingly misuse trusted collaboration tools for identity phishing, impersonation, credential theft and malware delivery, often leveraging compromised accounts, external federation or guest access. Unit 42 observations show a significant rise in malicious activity tied to collaboration tools, and defenders may lack visibility into actions that occur after authentication. The report reviews techniques attackers use and offers detection and mitigation guidance, noting enhanced protection through Palo Alto Networks products.
read more β†’

SageMaker notebooks add trusted identity propagation

🧭 Amazon SageMaker Notebooks now support Trusted Identity Propagation (TIP) with Amazon Athena, Amazon Redshift, and Amazon EMR Serverless, enabling per-user access control for data analytics. When connected to a TIP-enabled compute in a TIP-enabled Project, each notebook user's IAM Identity Center identity flows through to AWS Lake Formation, ensuring they see only the tables, columns, and rows their permissions allow. TIP provides per-user data boundaries, full audit attribution with CloudTrail, and reduces admin friction by automatically propagating identity through existing compute connections without extra logins or role management. The feature is available in all Regions where Amazon SageMaker Unified Studio is available.
read more β†’

AWS IAM Adds Outbound Federation in EU Sovereign Cloud

πŸ” AWS Identity and Access Management (IAM) now supports outbound identity federation in the AWS European Sovereign Cloud (Germany), enabling workloads to obtain short-lived JSON Web Tokens (JWTs) to authenticate with external services. This feature allows secure access to third-party clouds, SaaS, and self-hosted applications without long-term credentials. Administrators can enforce token properties and control generation via IAM policies and audit usage with CloudTrail to meet sovereignty and compliance needs.
read more β†’

AWS updates sign-in and session selection experience

πŸ”’ Amazon Web Services is rolling out a redesigned AWS Sign-In and session selection experience to a subset of customers, introducing a unified email entry point and refreshed session management. Existing sign-in methods and credentials continue to work, and sign-in with supported identity providers is available only for accounts created with those providers. Organizations using IAM Identity Center or federation should continue to use their existing portals, and administrators who rely on browser automation should review the changes for compatibility.
read more β†’

Security leaders confident but unprepared for rogue AI

πŸ”’ A majority of IT and security leaders say they can detect malfunctioning AI agents, but few can trace and mitigate downstream impact quickly. A WanAware survey found 90% confident in detection while only 26% can trace impacts within minutes, and over 45% say it would take hours. Experts warn agents act at machine speed, spread via shared credentials and multiple platforms, and require built-in identities, narrow permissions, audit trails, and hard kill switches to contain incidents.
read more β†’

AWS IAM launches Account Access Manager feature

πŸ” AWS Identity and Access Management (IAM) introduced Account Access Manager, simplifying assignment of IAM roles to workforce users and groups from AWS IAM Identity Center. Administrators can now manage role assignments centrally while retaining per-account role flexibility, using the AWS IAM console, SDKs, CloudFormation, and CDK. The feature consolidates permissions management, user awareness, and a single federation point at no additional cost.
read more β†’

Identity-Driven Attacks and SOC Response Trends

πŸ” Unit 42 finds identity compromises underpin most modern incidents, with the 2026 Global Incident Response Report showing identity weaknesses in nearly 90% of investigations and 65% of initial access events. Attackers increasingly use phishing, social engineering, MFA manipulation and third-party account misuse to gain entry, then move laterally, escalate privileges and blend into administrative behavior. Unit 42 recommends correlating identity, endpoint, cloud and network telemetry, applying AI-driven correlation and centralized investigations, and investing in continuous threat hunting and SOC engineering to detect and contain identity-driven intrusions earlier.
read more β†’

A decade of AWS Managed Microsoft AD evolution

πŸ”’ Over ten years, AWS Managed Microsoft AD evolved from a basic managed Microsoft Active Directory offering into a foundational enterprise identity service integrated across more than 20 AWS services. The service reduced operational overhead by handling domain controllers, HA, backups, patching, and replication while adding features like schema extensions, gMSA, multi-Region replication, and CRUD APIs. Recent additions include Hybrid Edition, self-service edition upgrades, and integrations for database, file, and remote-access authentication.
read more β†’

One-click multi-Region option for IAM Identity Center

πŸ”’ AWS IAM Identity Center now offers a one-click multi-Region option when creating a new organization instance, simplifying what previously required multiple manual steps. The multi-Region instance choice automatically creates a customer managed multi-Region KMS key and replicates the instance to an additional Region to provide resilient access. Customers can also choose single-Region or custom instances, with custom allowing use of existing customer managed KMS keys and fine-grained Region configuration.
read more β†’

Practical lessons for securing AI in enterprise

πŸ›‘οΈ Organizations deploying AI at scale face more than model vulnerabilities; the hardest risks arise when AI is integrated into business workflows. Identity and authorization are necessary but insufficient β€” runtime governance must evaluate behavior in context. Practical controls include least-privilege access, human approval gates, and recording an agent’s decisions and touched systems to ensure accountability.
read more β†’

AWS Identity Center makes account management optional

πŸ”’ AWS IAM Identity Center now lets administrators choose whether to enable AWS account access management when creating a new instance. This option permits using Identity Center solely for managing access to AWS applications, without provisioning access to AWS accounts. The setting is available during initial configuration, does not affect existing instances, and can be changed later via instance settings or the UpdateInstance API. The capability is available in all Regions where IAM Identity Center is offered.
read more β†’

Cloudflare Identity-Aware AI Gateway Launch

πŸ›‘οΈ Cloudflare announces Identity-aware AI Gateway with Cloudflare Access in open beta and User Insights generally available to AI Gateway customers. The integration attaches verified user identities to each request as cf.user_id, enabling per-user spend limits, filtering, and auditing. AI Gateway centralizes model access (OpenAI, Anthropic, Google, Workers AI) and routes agent harnesses like Copilot through a single control plane. User Insights builds behavioral baselines from traffic to surface anomalous accounts and cost inefficiencies without blocking traffic.
read more β†’

AlloyDB adds IAM group authentication for enterprises

πŸ”’ Google Cloud announced preview support for Identity and Access Management (IAM) group authentication in AlloyDB, extending an identity-driven, passwordless access model to enterprise database workloads. The feature aligns AlloyDB with Cloud SQL by enabling group-based access controls to reduce individual account sprawl, simplify on- and off-boarding, and improve auditing. It also helps secure AI agents by ensuring actions map to user identities and limiting privilege escalation.
read more β†’