📝 Cloudflare migrated its blog to EmDash, a CMS built for Astro and Cloudflare, moving on August 12. The redesign added dark mode, Kumo-aligned frontend patterns, and improved caching and performance. A staged rollout with a proxy Worker ensured zero downtime while enabling new agent-friendly features like a Model Context Protocol (MCP) server.
🔐 Partners can now authorize AWS Partner Central agents from third-party tools like Amazon Quick and Kiro using AWS Sign-In and OAuth, eliminating the need for separate SigV4 proxies or console sign-ins. This change lets partners use their existing AWS identities, IAM permissions, and governance controls to grant agent access without extra authentication software. Administrators retain control via IAM policies, token introspection and revocation, dynamic client registration, and CloudTrail auditing. OAuth support is available through the Partner Central agents MCP Server in US East (N. Virginia).
🔒 Cloudflare announces new Cloudflare One capabilities to detect and control Model Context Protocol (MCP) traffic. These features let administrators identify which users and servers are generating MCP requests, distinguish Portal-mediated connections from direct ones, and block unauthorized direct connections on managed network paths. The update combines Gateway protocol signals with MCP Server Portals to help teams find shadow MCP servers and enforce Portal-only access to trusted MCP endpoints.
🔧 The Amazon Cognito (aws-auth) skill is now included in the Agent Toolkit for AWS, enabling AI coding agents to set up, configure, secure, and troubleshoot Amazon Cognito using best-practice workflows. The skill supports user pools, app clients, OAuth 2.0 flows, token and JWT authorizer management, passkey/WebAuthn enrollment, threat protection, Lambda triggers, and identity pools. When used with the AWS MCP Server, commands run with IAM guardrails and CloudTrail audit logging; it also works standalone via the AWS CLI.
🔎 Cloudflare outlines the rise of software agents as a new class of web visitors and presents the concept of an "Agentic Internet" built to be readable, discoverable, callable, and payable. The post describes open standards and tools—like Web Bot Auth, PACT, Markdown for Agents, WebMCP, and Monetization Gateway—that enable cooperation between agents and domain owners. Cloudflare positions itself as a neutral platform offering these primitives while advocating for an open, standards-based future.
🛠️ The MCP 2026-07-28 specification makes the Model Context Protocol fully stateless, removing session handshakes and Mcp-Session-Id requirements. The update simplifies deployment by allowing MCP servers to run on request-scoped infrastructure like Cloudflare Workers, while preserving elicitation via Multi Round-Trip Requests and tightening authorization with CIMD and RFC 9207 issuer checks. SDKs and migration guidance accompany the release.
🧭 Today, AWS released the open source Context Ontology Accelerator to help organizations build machine-readable ontologies of products, customers, policies, and operational rules for more explainable and auditable AI agents. The accelerator connects to structured and unstructured data, uses AI to draft ontologies for domain experts to review, and stores the approved model in a knowledge graph using W3C standards. It includes a Model Context Protocol (MCP) server so any standards-based agent can consume the ontology.
🛡️ The AWS Security Hub MCP App preview introduces a local Model Context Protocol (MCP) server that brings Security Hub exposure findings into Claude Desktop to streamline investigations. The app enables natural-language investigation of top findings, attack and network paths, correlated findings, affected resource configurations, and remediation suggestions. The MCP server runs locally using existing AWS credentials and is read-only. This preview is available at no additional cost in all commercial Regions that support Security Hub.
🔐 In Google Cloud, IAM enforces the Principle of Least Privilege by combining predefined and custom roles with Allow and Deny policies across resource hierarchies. When resource-level bindings are not possible, IAM conditions let you scope broad roles to specific APIs, services, MCP servers, tools, or time windows. Use conditions alongside Deny policies to surgically remove excessive permissions and strengthen defense-in-depth.
Amazon OpenSearch Service integrates with Agent Toolkit
🛠️ Amazon OpenSearch Service integrates with the Agent Toolkit for AWS, enabling AI coding agents like Claude Code, Kiro, and Cursor to build, manage, and query OpenSearch Service domains and OpenSearch Serverless collections. The integration uses the AWS MCP server to execute API calls and the curated amazon-opensearch-service skill to translate natural-language requests into capabilities. It supports migration, operations, search, log analytics, and trace analytics across managed domains and serverless collections with no infrastructure changes and no additional charge.
Pentera Integrates Validation Into AI Security Workflows
🛡️Pentera enables AI assistants to use validated attack evidence rather than fragmented risk signals, helping teams prioritize and remediate real exploit paths. The platform emulates attacker techniques across environments, generating concrete attack paths with proof of techniques, credentials, privileges, and assets at risk. An MCP Server exposes Pentera validation data to AI workflows locally, preserving enterprise controls and auditability. This approach shifts workflows from inference to evidence-driven action, improving prioritization, ticketing, and revalidation.
🛠️ The new Amazon DocumentDB skill in the Agent Toolkit enables AI coding agents to provision, manage, migrate, optimize, and troubleshoot DocumentDB clusters using guided, best-practice workflows. The skill supports seven workflows including provisioning, schema design, MongoDB compatibility assessment, DMS migration with change data capture, performance tuning, a 41-check well-architected review, and major version upgrades. When used with the AWS MCP Server, agents can execute AWS CLI commands and diagnostic queries with IAM guardrails, CloudTrail logging, and sandboxed execution. The skill is also available standalone via the AWS CLI and is provided at no additional charge as part of the Agent Toolkit for AWS.
🛠️ Amazon EMR on EKS now integrates an Apache Spark troubleshooting agent that provides automated root cause analysis and PySpark recommendations through natural language, simplifying diagnosis of job failures. The agent inspects Spark History Server data, executor logs, and cluster configs to detect issues like memory errors, data skew, resource contention, and connectivity problems. Accessible via a "Troubleshoot with AI" option in the EMR on EKS console and via MCP with compatible AI coding agents, the feature is read-only, IAM-authenticated, logged in CloudTrail, and available in Regions with SageMaker Unified Studio.
🔐 AWS Sign-In now supports OAuth for connecting agents to the AWS MCP Server, enabling browser-based and headless authentication that leverages existing IAM, IAM Identity Center, and federated sign-in methods. The update includes dynamic client registration, token introspection and revocation, new CloudTrail elements, global condition keys, and a headless OAuth API. Agents discover OAuth endpoints, register via DCR, and use authorization code or client credentials flows to obtain short-lived tokens. Administrators can govern OAuth access using standard IAM policies plus OAuth-specific condition keys and monitor activity via CloudTrail.
🔐 You can now connect AI agents directly to the AWS MCP Server using AWS Sign-In and industry-standard OAuth. Agents may authenticate without extra software and reuse existing AWS identities, sign-in methods, IAM permissions, and governance controls. Developers can authorize agents interactively via a browser or programmatically with headless flows, while administrators govern access with IAM policies and new OAuth features.
🤖 AWS Partner Central introduces Partner Lead Prospecting, an AI-powered capability for ACE-eligible AWS Partners to accelerate lead conversion. Building on earlier lead enrichment features, it generates personalized sales plays, call scripts, and email outreach tailored to the customer's industry and each partner's solutions. The feature integrates a partner's portfolio into prospecting content to reduce manual research and drafting. Partner Lead Prospecting is available globally to all ACE-eligible partners via the Leads page or the MCP server.
🔒 This post describes a reference implementation using Cedar on AWS to prevent silent privilege escalation in multi-agent AI delegation chains. It outlines a three-layer policy model—agent-to-tool, agent-to-agent delegation, and originating user authorization—using verified token claims and HMAC-signed context. The architecture uses an MCP adapter Lambda and a Cedar evaluator Lambda to enforce policies sequentially and halt on the first deny. It includes schema, entity registrations, policy examples, deployment steps, and end-to-end test scenarios demonstrating how the model enforces least privilege.
🛡️ AWS Security Agent (now part of AWS Continuum) is available in Asia Pacific (Mumbai), Asia Pacific (Singapore), and South America (São Paulo). Customers in these regions can access STRIDE-based threat modeling (preview), full-repo and PR-level code reviews (preview) across major source platforms, managed compliance packs, and custom security requirements. New IDE plugins and MCP integration enable triggering threat modeling, code reviews, and remediation from Kiro or Claude Code, while on-demand penetration testing and retesting provide validated findings and fixes; simulated validation remains only in US East (N. Virginia).
Amazon WorkSpaces for AI agents now generally available
🖥️ Amazon WorkSpaces for agents is generally available, enabling AI agents to securely access and operate desktop applications inside managed WorkSpaces. The service lets agents interact with legacy ERP, CRM, mainframe, and proprietary tools without application modernization or custom integrations, while preserving identity controls, network isolation, and compliance boundaries. It supports any agent framework using the Model Context Protocol (MCP), and pricing is based on active session time.
Gemini Enterprise Agent Platform Remote MCP Server
🔗 The Gemini Enterprise Agent Platform remote MCP server lets external AI agents securely access Google Cloud Agent Platform resources. It acts as a standardized bridge so tools like Antigravity CLI or Claude Code can call models in Model Garden, manage Notebooks, and use shared prompts without leaving the IDE. Enable the API, configure your client, and use provided Toolset Endpoints to start integrating quickly while maintaining governance.