< ciso
brief />
Tag Banner

All news with #infrastructure security tag

200 articles

MediaConnect Router Adds Configurable Latency Modes

πŸ”§ AWS Elemental MediaConnect Router now lets customers set internal recovery latency per output. Customers can choose between balanced mode (default behavior) and low-latency mode to optimize recovery time for latency-sensitive workflows. The setting is configurable via the MediaConnect API, AWS Management Console, or AWS CLI, and a new CloudWatch metric, RouteFabricRecoveryLatency, exposes recovery latency per route. This feature is available in all regions where MediaConnect Router is deployed.
read more β†’

AWS adds fourth Availability Zone in London region

πŸš€ AWS has added a fourth Availability Zone to the Europe (London) Region (eu-west-2), increasing capacity for cloud compute and AI/ML workloads. The new zone provides next-generation accelerated instances such as Trn3 and P6, plus general-purpose EC2, enabling customers to run training and inference locally within the London region. It improves fault isolation for resilient, highly available architectures and is accessible via the AWS Console, APIs, and existing workflows at standard regional pricing.
read more β†’

Amazon MSK adds cluster-level custom domain support

πŸ”§ Amazon MSK Provisioned clusters now support configuring custom domain names at the cluster level for both ZooKeeper and KRaft metadata modes. This removes the need to set domains per broker and ensures persistent endpoints across scaling, migrations, and failovers. The setting persists through cluster operations and is available for new and existing clusters in all Regions where MSK Provisioned is offered, at no extra cost.
read more β†’

AWS Client VPN adds CLI and enterprise controls

πŸ› οΈ The rebuilt AWS VPN Client v6.0.x now includes a fully featured command-line interface (CLI), enterprise administrative controls, and faster connection establishment, enabling automation and centralized device management. The CLI matches GUI functionality and supports background operations so VPN connections can be scripted into workflows and infrastructure-as-code. Administration controls let organizations scope and enforce profiles per user or provide global device profiles, removing the need to distribute profiles manually. Built on OpenVPN3, the client preserves backward compatibility with existing AWS Client VPN endpoints and runs concurrently with the GUI; it is available today for Windows, macOS, and Linux with no additional charges beyond standard AWS Client VPN pricing.
read more β†’

Google expands subsea network with Americas Connect

🌐 Google announces the Americas Connect expansion with three new subsea cable systems β€” Alisios, Canoa, and OlaLuz β€” plus a new branch on Firmina. These routes will link the Dominican Republic, Panama, Chile, Bermuda, and Florida, enhancing capacity and resilience between Latin America, the Caribbean, the U.S. East and West Coasts, and Europe. The program complements prior investments in Curie, Nuvem, and Sol to strengthen regional connectivity.
read more β†’

Cloudflare’s Agents Week: Building an Agentic Internet

πŸ€– Over Agents Week, Cloudflare outlined how agents are shaping a new class of software and detailed the platform work required to support AI-native applications. The company presented daily briefings covering runtime and infrastructure, the Agent Development Lifecycle (ADLC), Zero Trust for agents, the concept of an Agentic Internet, and measurement tools for agent behavior on the web. Cloudflare emphasized secure execution layers, developer primitives, and community collaboration as core to this evolution.
read more β†’

Amazon EC2 adds application-level status checks

πŸ› οΈ Amazon EC2 now offers application status checks that detect application-level failures such as web servers not accepting requests, stopped Docker daemons, or broken networking. Customers specify protocol, port, path, and healthy response codes to create checks, then associate them with instances by ID or tag. EC2 sends HTTP/HTTPS probes every 60 seconds and reports application health alongside existing instance and system checks, enabling Auto Scaling groups to replace instances flagged as unhealthy. This feature is available in all commercial AWS Regions and AWS GovCloud (US).
read more β†’

VPC IPAM adds BGP route protection and delegated RPKI

πŸ›‘οΈ Amazon VPC IPAM now supports BGP route protection monitoring and delegated RPKI management for BYOIP prefixes, enabling centralized monitoring of RPKI validity, ROA strength, and route overlap across accounts and regions. Administrators can detect invalid or missing ROAs, identify potential hijacks via overlap detection, and differentiate strict versus permissive ROA configurations. With Delegated RPKI, after a one-time setup with ARIN, RIPE, APNIC, or LACNIC, IPAM automates ROA creation, renewal, and management for both BYOIP and on-premises prefixes. The capability is available in all commercial AWS Regions except AWS GovCloud (US) and the China regions.
read more β†’

Sharded Hub-and-Spoke to Mitigate Noisy Neighbors

πŸ”Ž This article explains how shifting from a monolithic data pipeline to a sharded hub-and-spoke architecture reduces the impact of "noisy neighbor" tenants. The Hub acts as a lightweight router while Spokes provide isolated processing with Pub/Sub buffers between them. The design enables independent scaling, fault isolation, tiered pipelines for priority tenants, and spoke-level best practices such as DLQs, strict connection pooling, and asynchronous I/O.
read more β†’

AWS expands EC2 C8g (Graviton4) to four regions

πŸš€ Amazon EC2 C8g instances, powered by AWS Graviton4 processors, are now available in AWS Europe (Paris), AWS Africa (Cape Town), AWS Israel (Tel Aviv), and AWS Canada West (Calgary). These compute-optimized instances deliver up to 30% better performance than Graviton3-based instances and are built on the AWS Nitro System to improve performance and security. C8g offers 12 sizes, including bare metal, enhanced networking up to 50 Gbps, and up to 40 Gbps EBS bandwidth for compute-intensive workloads.
read more β†’

Amazon EC2 I8g storage-optimized instances now GA

πŸ”§ Amazon announces general availability of Amazon EC2 Storage Optimized I8g instances in AWS Europe (Paris) and Asia Pacific (Jakarta). Powered by AWS Graviton4, I8g delivers leading compute for storage-intensive workloads using third-generation AWS Nitro SSDs that improve storage throughput and reduce latency versus I4g. Built on the AWS Nitro System, these instances offer enhanced performance and security for I/O-intensive databases, analytics, and AI preprocessing.
read more β†’

AWS Transit Gateway Adds Policy-Based Routing

πŸ”§ AWS Transit Gateway now supports Policy-Based Routing (PBR), allowing forwarding decisions based on packet attributes such as source and destination IPs, ports, and protocol instead of destination alone. PBR reduces the need for complex multi-VPC architectures and extra routing hops by enabling administrators to attach policy tables to Transit Gateway attachments and define ordered rule sets. Rules classify traffic and direct matches to specified route tables using first-match-wins logic, supporting traffic steering, inspection, and environment isolation. PBR is available in all commercial AWS Regions where Transit Gateway is offered and can be configured via the Console, CLI, or SDK with no additional charge beyond standard Transit Gateway fees.
read more β†’

CISA's Six-Step Blueprint for Infrastructure Isolation

πŸ”’ The US CISA and Five Eyes partners published CI Fortify, a six-step guide to isolate and protect critical infrastructure during cyber incidents. The guide outlines identifying vital systems and customers, classifying trust levels, mapping interconnections, and building separation points. It emphasizes physical isolation and phased isolation plans while acknowledging operational constraints and the need for encryption and robust risk management.
read more β†’

Old BMC Vulnerability Exposes Data Center Management

πŸ”’ Lava researchers found tens of thousands of internet-exposed Baseboard Management Controllers (BMCs) vulnerable to a 2013 IPMI authentication flaw, allowing rapid access by guessing weak or factory-set passwords. BMCs provide out-of-band control of servers and often sit outside standard monitoring, enabling persistent, hard-to-detect compromises that can span shared data center and AI/GPU infrastructure. Vendors including Supermicro and HPE were among the most impacted.
read more β†’

AWS Outposts racks now supported in Mumbai

πŸ”” Second-generation AWS Outposts racks are now supported in the Asia Pacific (Mumbai) Region. Outposts racks extend AWS infrastructure, services, APIs, and tools to on-premises data centers or colocation spaces to provide a consistent hybrid experience. Customers in and outside India can order Outposts racks connected to this region to optimize latency and meet data residency needs. The expansion increases flexibility in region connectivity for Outposts deployments.
read more β†’

EC2 Dedicated Hosts add flexible Host Resource Groups

πŸ›‘οΈ Starting today, Amazon EC2 Dedicated Hosts support creating Host Resource Groups (HRGs) without requiring Self-Managed Licenses (SMLs). This change benefits customers who use Dedicated Hosts for hardware-level isolation or EC2 Mac Instances, while customers with BYOL needs can still opt to create HRGs with SMLs to restrict AMIs and track license consumption. To create an HRG without an SML, uncheck the "Restrict to AMIs associated with self-managed license" option in the EC2 Console or set instance-launch-option to license-configuration-required via the AWS CLI. The feature is available in all Regions that support Host Resource Groups.
read more β†’

AWS PCS adds node lifecycle actions for compute nodes

πŸ”§ AWS announces general availability of node lifecycle actions in AWS Parallel Computing Service (PCS), letting users run custom scripts automatically at defined points in a compute node's lifecycle. Use cases include mounting shared storage, joining directory services, installing software, or setting up monitoring. Scripts are defined in compute node group configurations, sourced from Amazon S3 or HTTPS URIs, and support arguments, lifecycle stage selection, reboot re-run options, and error-handling behavior. AWS PCS writes action output to dedicated logs for visibility and the feature is available in all Regions that support PCS.
read more β†’

AWS launches KNFSD File Cache for scalable NFS

πŸš€ KNFSD File Cache is now available as an open-source, Apache-2.0 licensed NFS caching solution on AWS. It mounts exports from on-premises, cross-region, or multicloud NFS servers and re-exports them to NFS clients in AWS, caching frequently read data in memory and local NVMe for low-latency access. Built on standard Linux kernel components and deployed via AMIs and Terraform, it supports NFS v3, v4.1, and v4.2 and targets read-heavy burst compute workloads. The preview is available in all AWS Regions with no licensing fees; customers pay only for consumed AWS resources.
read more β†’

AFT auto re-apply customizations on account move

πŸ”§ AWS Control Tower Account Factory for Terraform (AFT) can now automatically re-apply an account's customizations when the account is moved to a different Organizational Unit (OU). Previously, moving an enrolled account required a manual trigger, increasing operational overhead and risk of configuration drift. You can opt in by setting aft_customization_triggers = ["account_move"], and exclude specific accounts with account_skip_customization_triggers = "true". The re-application run skips bootstrap and provisioning phases for faster execution and includes additional improvements such as custom Terraform Cloud/Enterprise workspace naming, tighter logging bucket access controls, and better scaling for Enterprise Support enrollment.
read more β†’

AWS launches M8in/M8idn and M8ib/M8idb instances

πŸ”” AWS has made new Amazon EC2 instance families (M8in, M8idn, M8ib, M8idb) available in US East (Ohio), Europe (Ireland), and Asia Pacific (Tokyo). These sixth-generation Intel Xeon Scalable processor–based instances deliver up to 43% higher performance and include the latest sixth-generation AWS Nitro cards. M8in/M8idn provide up to 600 Gbps network bandwidth for network-intensive workloads, while M8ib/M8idb offer up to 300 Gbps EBS bandwidth for storage-heavy applications. The instances are available across multiple regions and purchasing options including Savings Plans, On-Demand, and Spot.
read more β†’