< ciso
brief />
Tag Banner

All news with #infrastructure security tag

222 articles

AI-driven infrastructure across lifecycle stages

🤖 Microsoft describes how AI is being applied across the full hardware lifecycle—from design and supply chain to deployment and fleet operations—to accelerate learning and improve decision making. The company emphasizes a “Lean before AI” approach that simplifies processes, builds a governed data foundation, and preserves human judgment. Early results include dramatic reductions in planning cycle time, decreased manual effort, and fewer VM interruptions from disk failures.
read more →

MetaMask discloses infrastructure security incident

🛡️ MetaMask disclosed an ongoing infrastructure security incident affecting parts of its environment and is working with external partners and security advisors to address the issue. The company said there is no immediate threat to MetaMask wallets and that its staking operations remain non-custodial, with withdrawal keys retained by clients. As a precaution, MetaMask is exiting affected Ethereum validators in coordination with partners, an action that may incur downtime penalties and foregone rewards. Lido Finance confirmed MetaMask Staking has begun exiting validators, with the process expected to have final validators exited by October 7, 2026.
read more →

SQL Server on Azure Local Now Generally Available

🔔 Today Microsoft announced that SQL Server on Azure Local is generally available for both connected and disconnected operations, enabling organizations to run SQL Server on Azure-consistent infrastructure in customer datacenters and edge locations. The offering supports modernized deployments while preserving local control, data sovereignty, and licensing options. Customers can also preview Foundry Local to run AI inference alongside SQL Server on Azure Local.
read more →

OT Resilience Becomes a Boardroom Imperative

🔒 The long-standing assumption that operational technology (OT) is safe due to physical isolation is no longer valid. Integration of OT with IT and cloud has exposed nearly 20 million OT assets online, increasing risk and making operational resilience a strategic concern. Modern industrial environments require continuous verification, micro-segmentation, and governance to protect safety, availability, and business continuity.
read more →

Memorystore for Valkey 9.1 Boosts QPS and Features

🚀 Memorystore for Valkey 9.1 is now generally available on Google Cloud, delivering up to 3x queries per second at microsecond latencies compared to Memorystore for Redis Cluster. Valkey 9.1 introduces a lock-free multi-queue I/O architecture, a two-phase dynamic thread scaling engine, and several new commands (HGETDEL, MSETEX, HSETEX) plus topology-aware CLUSTERSCAN and database-level ACLs for improved security and observability. The release also expands node sizes and provides a managed migration workflow to simplify moving from self-managed Redis/Valkey to Google Cloud Memorystore.
read more →

How Google Cloud networking supports fluid AI compute

🔍 This article explains how Google Cloud networking accommodates fluid compute for AI workloads, with guidance for choosing GPUs or TPUs and their distinct backend networking needs. It outlines resource obtainment options—such as Flex-start VMs, calendar reservations, future and flex reservations, ComputeClasses, and Spot VMs—and describes four networking configurations: standard networking, accelerated GPU networking (TCPX/TCPXO and RoCEv2), TPU networking, and Cloud Run. The blog highlights deployment blueprints, GKE DRANET automation, and zonal profiles for RDMA, illustrating trade-offs for multi-node training and inference.
read more →

Maximize Apache Spark availability with flexible VMs

🔧 This article explains how Google’s Managed Service for Apache Spark uses flexible VMs to mitigate capacity stockouts that can disrupt Spark pipelines. Flexible VMs let teams specify ordered machine-family preferences for masters and workers, enabling multi-family blending, mixed storage support, and comprehensive cluster coverage. The post gives tiered machine-family and storage recommendations for common shapes (n2d, n1) and highlights the role of Hyperdisk Balanced. It also covers quota, CUDs, testing, and complementary strategies like AutoZone, autoscaling, smaller shapes, and regional fallbacks.
read more →

Cloudflare reclaims 100 TB RAM with hashing fix

🔎 This post describes how Cloudflare reduced memory usage in its Pingora Backend Router by optimizing consistent hashing. The team identified excessive memory in the pingora-ketama structures and analyzed how hash counts, weights, and collisions affect load distribution. A Rust-level storage change and mathematical analysis allowed them to safely shrink per-server hash counts and reclaim significant RAM without disrupting cache routing.
read more →

Amazon EC2 I7ie instances arrive in Israel

🚀 Amazon Web Services has launched Amazon EC2 I7ie instances in the AWS Israel (Tel Aviv) region. These high-density, storage-optimized instances use 5th Gen Intel Xeon processors and 3rd generation AWS Nitro SSDs to boost compute, storage throughput, and latency consistency versus prior I3en instances. I7ie offers up to 120TB local NVMe, higher vCPU and memory counts, and up to 100Gbps network and 60Gbps EBS bandwidth across nine sizes. They are aimed at large, I/O-intensive workloads that need fast, low-latency local storage.
read more →

AWS Transfer Family preserves SFTP client source IPs

🔒 AWS Transfer Family now preserves client source IPs using Proxy Protocol v2 (PPv2) when you place a Network Load Balancer (NLB) in front of a VPC-hosted SFTP endpoint. Previously, the NLB's private IP replaced the client's address in logs and during authentication, preventing IP-based auditing and access control. You can enable source IP preservation per server through the console, CLI, or API, and the feature is available in all Regions where AWS Transfer Family is offered.
read more →

Architecting a Secure Landing Zone in EUSC

🔒 This post explains how to design a secure, scalable landing zone for the AWS European Sovereign Cloud (aws-eusc), a partitioned AWS environment operated within the EU. It covers account structure and governance, identity as IaC, centralized logging to a SIEM, data protection, perimeter and network design, CI/CD and artifact distribution, and incident response. The guidance maps to the AWS Security Reference Architecture and the AWS Well-Architected Framework, and highlights which behaviors are partition boundaries versus configurable choices.
read more →

Microsoft named Leader in 2026 Distributed Hybrid MQ

🟦 Microsoft was named a Leader in the 2026 Gartner® Magic Quadrant™ for Distributed Hybrid Infrastructure, ranking highest for Ability to Execute. The post highlights how Azure Local and Azure Arc deliver a unified approach to manage infrastructure across datacenters, edge, multi-cloud, and sovereign environments. It explains options for sovereignty, disconnected operations, and AI inference at the edge with Foundry Local, emphasizing consistent management and operational simplicity.
read more →

AlloyDB Omni RPM Orchestrator Reaches General Availability

🚀 The AlloyDB Omni Red Hat RPM orchestrator is now generally available alongside AlloyDB Omni v18.3.0, bringing production-ready security, resiliency, and low-downtime operations for PostgreSQL workloads on VMs and bare metal. The release supports four deployment modes, including standalone RPM and RPM orchestrator for HA, and targets regulated, edge, and AI-ready environments. The orchestrator simplifies cluster lifecycle, offers read pools, automated backups to GCS/S3, SELinux support, advanced observability, and Low Downtime Maintenance for enterprise-scale operations.
read more →

AWS HealthOmics adds resource fallback for WDL

🔬 Today, AWS HealthOmics introduces the resource fallback directive, allowing users to specify an ordered list of preferred accelerator types — including a final CPU fallback — for tasks in Workflow Description Language (WDL) workflows. This feature reduces time spent diagnosing and resubmitting runs when accelerators are constrained and helps keep production workflows running. HealthOmics is HIPAA-eligible and available in multiple AWS Regions to support bioinformatics at scale.
read more →

AWS Gateway Load Balancer adds TCP Reset support

🔧 AWS Gateway Load Balancer (GWLB) now supports sending TCP Reset packets to accelerate failure recovery for client and server connections. Previously, GWLB exhibited fail-open behavior where traffic continued to be forwarded to unhealthy targets, causing prolonged interruptions due to TCP retries and back-off. TCP Reset can be enabled per target group via the Console, CLI, or API and responds to three independent triggers: target unhealthy, target deregistration after connection draining, and TCP idle timeout expiry. This capability is available in all GWLB regions at no additional cost and is off by default for backward compatibility.
read more →

AWS Outposts racks reach GovCloud US Regions

🚀 Second-generation AWS Outposts racks are now supported in the AWS GovCloud (US-East) and AWS GovCloud (US-West) Regions, extending AWS infrastructure, services, APIs, and tools to on-premises data centers and colocation spaces for a consistent hybrid experience. Organizations across startups, enterprises, and the public sector can order Outposts racks connected to these regions to optimize latency and data residency. Outposts enables local low-latency workloads while connecting to a home Region for management, and supports on-premises data processing to meet residency requirements. This expansion gives customers more flexibility in choosing the AWS Region their Outposts connect to.
read more →

AWS CloudFormation contract tests v2 for resource types

🔧 AWS CloudFormation now supports contract tests v2 via the --v2 flag on the cfn test command in the CloudFormation CLI. The new suite expands beyond basic CRUD checks to exercise resource type implementations across every handler operation, with live-state verification after create, update, and delete. New resource types can run these tests during registry submission, and Java-based resource types can run them locally with Docker and a built handler package. Additional checks include schema backward-compatibility, input linting, and detailed HTML and JUnit XML reports to reduce iteration cycles.
read more →

Cache Transcoding expands effective CDN cache capacity

🧩 Cloudflare prototyped Cache Transcoding to increase effective cache capacity by encoding eligible cache entries with Zstandard (zstd). The system encodes eligible responses on cache fill, stores them compressed on disk and transfers them compressed between tiers, then decodes before serving. In tests zstd level 3 reduced on-disk size to roughly one-third for eligible text assets while adding only a small CPU cost, improving storage density and inter-datacenter bandwidth efficiency.
read more →

Elastic Beanstalk adds Active Directory domain join

🔒 AWS Elastic Beanstalk now automatically joins Windows Server instances to an Active Directory domain managed with AWS Directory Service. Previously requiring custom join scripts, the new feature uses configuration options so every instance, including those launched by auto scaling, joins the domain at boot before application deployment. Domain-joined instances can use Windows-integrated authentication, group policy, and access domain resources, and the join process is resilient so failures don't block deployments.
read more →

Optimizing DNS cache memory for Cloudflare scale

🧠 Cloudflare’s Big Pineapple platform stores over 250 billion DNS cache entries and reduced per-entry memory by over 50% through five successive storage optimizations. These changes freed roughly 100 TB of RAM across the fleet while improving insert throughput by 43% and lowering lookup latency by 19%. The post details techniques like replacing Vec/String with Box, packing section offsets, inferring record owners, boxing large enum variants, and storing record data as a contiguous byte buffer to improve memory locality and reduce allocations.
read more →