< ciso
brief />
Tag Banner

All news with #infrastructure security tag

222 articles · page 2 of 12

Amazon EVS adds i7i.metal-48xl bare-metal support

🛠️ Amazon Elastic VMware Service (Amazon EVS) now supports the i7i.metal-48xl bare-metal Amazon EC2 instance, providing a higher core-count option with 5th generation Intel Xeon Scalable processors. This instance class delivers up to 23% better compute and >10% better price performance versus i4i instances, plus larger memory and storage to host more VMs per EVS host. The feature is available in Regions where both Amazon EVS and EC2 i7i are offered and enables VCF 9.x capabilities and onboarding automations.
read more →

Best practices for dynamic capacity management

🚀 This post outlines practical strategies for dynamic capacity management to support large-scale AI and agent workloads, emphasizing predictable cost and performance. It describes three implementations: scheduling capacity for planned events, creating automated fallback plans with managed instance groups, and automating the lifecycle with GKE and Custom ComputeClasses. The guidance highlights tools like Dynamic Workload Scheduler, instance flexibility, Spot VMs, Hyperdisk, and dynamic resource allocation to improve utilization and resilience.
read more →

MediaConnect Router Adds Configurable Latency Modes

🔧 AWS Elemental MediaConnect Router now lets customers set internal recovery latency per output. Customers can choose between balanced mode (default behavior) and low-latency mode to optimize recovery time for latency-sensitive workflows. The setting is configurable via the MediaConnect API, AWS Management Console, or AWS CLI, and a new CloudWatch metric, RouteFabricRecoveryLatency, exposes recovery latency per route. This feature is available in all regions where MediaConnect Router is deployed.
read more →

AWS adds fourth Availability Zone in London region

🚀 AWS has added a fourth Availability Zone to the Europe (London) Region (eu-west-2), increasing capacity for cloud compute and AI/ML workloads. The new zone provides next-generation accelerated instances such as Trn3 and P6, plus general-purpose EC2, enabling customers to run training and inference locally within the London region. It improves fault isolation for resilient, highly available architectures and is accessible via the AWS Console, APIs, and existing workflows at standard regional pricing.
read more →

Amazon MSK adds cluster-level custom domain support

🔧 Amazon MSK Provisioned clusters now support configuring custom domain names at the cluster level for both ZooKeeper and KRaft metadata modes. This removes the need to set domains per broker and ensures persistent endpoints across scaling, migrations, and failovers. The setting persists through cluster operations and is available for new and existing clusters in all Regions where MSK Provisioned is offered, at no extra cost.
read more →

AWS Client VPN adds CLI and enterprise controls

🛠️ The rebuilt AWS VPN Client v6.0.x now includes a fully featured command-line interface (CLI), enterprise administrative controls, and faster connection establishment, enabling automation and centralized device management. The CLI matches GUI functionality and supports background operations so VPN connections can be scripted into workflows and infrastructure-as-code. Administration controls let organizations scope and enforce profiles per user or provide global device profiles, removing the need to distribute profiles manually. Built on OpenVPN3, the client preserves backward compatibility with existing AWS Client VPN endpoints and runs concurrently with the GUI; it is available today for Windows, macOS, and Linux with no additional charges beyond standard AWS Client VPN pricing.
read more →

Google expands subsea network with Americas Connect

🌐 Google announces the Americas Connect expansion with three new subsea cable systems — Alisios, Canoa, and OlaLuz — plus a new branch on Firmina. These routes will link the Dominican Republic, Panama, Chile, Bermuda, and Florida, enhancing capacity and resilience between Latin America, the Caribbean, the U.S. East and West Coasts, and Europe. The program complements prior investments in Curie, Nuvem, and Sol to strengthen regional connectivity.
read more →

Cloudflare’s Agents Week: Building an Agentic Internet

🤖 Over Agents Week, Cloudflare outlined how agents are shaping a new class of software and detailed the platform work required to support AI-native applications. The company presented daily briefings covering runtime and infrastructure, the Agent Development Lifecycle (ADLC), Zero Trust for agents, the concept of an Agentic Internet, and measurement tools for agent behavior on the web. Cloudflare emphasized secure execution layers, developer primitives, and community collaboration as core to this evolution.
read more →

Amazon EC2 adds application-level status checks

🛠️ Amazon EC2 now offers application status checks that detect application-level failures such as web servers not accepting requests, stopped Docker daemons, or broken networking. Customers specify protocol, port, path, and healthy response codes to create checks, then associate them with instances by ID or tag. EC2 sends HTTP/HTTPS probes every 60 seconds and reports application health alongside existing instance and system checks, enabling Auto Scaling groups to replace instances flagged as unhealthy. This feature is available in all commercial AWS Regions and AWS GovCloud (US).
read more →

VPC IPAM adds BGP route protection and delegated RPKI

🛡️ Amazon VPC IPAM now supports BGP route protection monitoring and delegated RPKI management for BYOIP prefixes, enabling centralized monitoring of RPKI validity, ROA strength, and route overlap across accounts and regions. Administrators can detect invalid or missing ROAs, identify potential hijacks via overlap detection, and differentiate strict versus permissive ROA configurations. With Delegated RPKI, after a one-time setup with ARIN, RIPE, APNIC, or LACNIC, IPAM automates ROA creation, renewal, and management for both BYOIP and on-premises prefixes. The capability is available in all commercial AWS Regions except AWS GovCloud (US) and the China regions.
read more →

Sharded Hub-and-Spoke to Mitigate Noisy Neighbors

🔎 This article explains how shifting from a monolithic data pipeline to a sharded hub-and-spoke architecture reduces the impact of "noisy neighbor" tenants. The Hub acts as a lightweight router while Spokes provide isolated processing with Pub/Sub buffers between them. The design enables independent scaling, fault isolation, tiered pipelines for priority tenants, and spoke-level best practices such as DLQs, strict connection pooling, and asynchronous I/O.
read more →

AWS expands EC2 C8g (Graviton4) to four regions

🚀 Amazon EC2 C8g instances, powered by AWS Graviton4 processors, are now available in AWS Europe (Paris), AWS Africa (Cape Town), AWS Israel (Tel Aviv), and AWS Canada West (Calgary). These compute-optimized instances deliver up to 30% better performance than Graviton3-based instances and are built on the AWS Nitro System to improve performance and security. C8g offers 12 sizes, including bare metal, enhanced networking up to 50 Gbps, and up to 40 Gbps EBS bandwidth for compute-intensive workloads.
read more →

Amazon EC2 I8g storage-optimized instances now GA

🔧 Amazon announces general availability of Amazon EC2 Storage Optimized I8g instances in AWS Europe (Paris) and Asia Pacific (Jakarta). Powered by AWS Graviton4, I8g delivers leading compute for storage-intensive workloads using third-generation AWS Nitro SSDs that improve storage throughput and reduce latency versus I4g. Built on the AWS Nitro System, these instances offer enhanced performance and security for I/O-intensive databases, analytics, and AI preprocessing.
read more →

AWS Transit Gateway Adds Policy-Based Routing

🔧 AWS Transit Gateway now supports Policy-Based Routing (PBR), allowing forwarding decisions based on packet attributes such as source and destination IPs, ports, and protocol instead of destination alone. PBR reduces the need for complex multi-VPC architectures and extra routing hops by enabling administrators to attach policy tables to Transit Gateway attachments and define ordered rule sets. Rules classify traffic and direct matches to specified route tables using first-match-wins logic, supporting traffic steering, inspection, and environment isolation. PBR is available in all commercial AWS Regions where Transit Gateway is offered and can be configured via the Console, CLI, or SDK with no additional charge beyond standard Transit Gateway fees.
read more →

CISA's Six-Step Blueprint for Infrastructure Isolation

🔒 The US CISA and Five Eyes partners published CI Fortify, a six-step guide to isolate and protect critical infrastructure during cyber incidents. The guide outlines identifying vital systems and customers, classifying trust levels, mapping interconnections, and building separation points. It emphasizes physical isolation and phased isolation plans while acknowledging operational constraints and the need for encryption and robust risk management.
read more →

Old BMC Vulnerability Exposes Data Center Management

🔒 Lava researchers found tens of thousands of internet-exposed Baseboard Management Controllers (BMCs) vulnerable to a 2013 IPMI authentication flaw, allowing rapid access by guessing weak or factory-set passwords. BMCs provide out-of-band control of servers and often sit outside standard monitoring, enabling persistent, hard-to-detect compromises that can span shared data center and AI/GPU infrastructure. Vendors including Supermicro and HPE were among the most impacted.
read more →

AWS Outposts racks now supported in Mumbai

🔔 Second-generation AWS Outposts racks are now supported in the Asia Pacific (Mumbai) Region. Outposts racks extend AWS infrastructure, services, APIs, and tools to on-premises data centers or colocation spaces to provide a consistent hybrid experience. Customers in and outside India can order Outposts racks connected to this region to optimize latency and meet data residency needs. The expansion increases flexibility in region connectivity for Outposts deployments.
read more →

EC2 Dedicated Hosts add flexible Host Resource Groups

🛡️ Starting today, Amazon EC2 Dedicated Hosts support creating Host Resource Groups (HRGs) without requiring Self-Managed Licenses (SMLs). This change benefits customers who use Dedicated Hosts for hardware-level isolation or EC2 Mac Instances, while customers with BYOL needs can still opt to create HRGs with SMLs to restrict AMIs and track license consumption. To create an HRG without an SML, uncheck the "Restrict to AMIs associated with self-managed license" option in the EC2 Console or set instance-launch-option to license-configuration-required via the AWS CLI. The feature is available in all Regions that support Host Resource Groups.
read more →

AWS PCS adds node lifecycle actions for compute nodes

🔧 AWS announces general availability of node lifecycle actions in AWS Parallel Computing Service (PCS), letting users run custom scripts automatically at defined points in a compute node's lifecycle. Use cases include mounting shared storage, joining directory services, installing software, or setting up monitoring. Scripts are defined in compute node group configurations, sourced from Amazon S3 or HTTPS URIs, and support arguments, lifecycle stage selection, reboot re-run options, and error-handling behavior. AWS PCS writes action output to dedicated logs for visibility and the feature is available in all Regions that support PCS.
read more →

AWS launches KNFSD File Cache for scalable NFS

🚀 KNFSD File Cache is now available as an open-source, Apache-2.0 licensed NFS caching solution on AWS. It mounts exports from on-premises, cross-region, or multicloud NFS servers and re-exports them to NFS clients in AWS, caching frequently read data in memory and local NVMe for low-latency access. Built on standard Linux kernel components and deployed via AMIs and Terraform, it supports NFS v3, v4.1, and v4.2 and targets read-heavy burst compute workloads. The preview is available in all AWS Regions with no licensing fees; customers pay only for consumed AWS resources.
read more →