< ciso
brief />
Tag Banner

All news with #network security tag

191 articles

AWS Identity Store adds network access controls

🔒 IAM Identity Center now supports network access controls for the Identity Store and SCIM APIs, letting you restrict API requests by VPC endpoints, source VPCs, or IP ranges. You can apply different restrictions per API and exempt AWS service requests; controls are optional and disabled by default. Configuration is done via the Identity Store API using AWS SDKs or AWS CLI and is available in all Regions where IAM Identity Center is offered.
read more →

Route 53 DNS Analytics and Insights via CloudWatch

🔍 Amazon Route 53 Global Resolver and DNS Firewall now integrate with Amazon CloudWatch to provide DNS analytics and insights. These features let network and security teams observe DNS query patterns, evaluate DNS Firewall rule effectiveness, detect anomalies, and optimize DNS performance. An Analytics tab in the Global Resolver and DNS Firewall consoles centralizes access, and CloudWatch Metrics and Contributor Insights enable metric filters, searches, and alarms. Standard CloudWatch pricing applies to opted-in metrics.
read more →

Kinesis Video Streams adds VPC PrivateLink support

🔒 Amazon Kinesis Video Streams now supports interface VPC endpoints powered by AWS PrivateLink, enabling private connectivity from your Amazon VPC. Traffic between your VPC and Kinesis Video Streams remains on the AWS network for control plane, ingestion, and playback data planes, avoiding the public internet. Customers can ingest, store, and play back video from private subnets without internet gateways, NAT, or public IPs, and can create endpoints via the console, AWS CLI, or SDKs with endpoint policies to control access.
read more →

Cloudflare adds IPsec downgrade protection extension

🔒 Cloudflare and the IETF developed and implemented a mitigation for downgrade attacks against IPsec to guard against quantum-capable adversaries. The company has rolled out beta support across IPsec products including Cloudflare WAN and Magic Transit, enabling customers to request an ipsec_downgrade_protection flag. The upgrade helps ensure post-quantum key agreement is not bypassed by active attackers during protocol negotiation.
read more →

Benefits and trade-offs of VPNs on routers

🔒 Turning on a VPN on your router protects every device on your home network automatically, eliminating per-device setup and covering gadgets that can’t run VPNs themselves. A router-based VPN counts as a single device against subscription limits, reduces battery and CPU load on client devices, and can enforce an “always-on” protection model with a router-level kill switch. It also simplifies managing server or protocol changes and allows nested corporate and personal VPNs. Trade-offs include potential compatibility issues with services that block VPNs and the need for a router that supports VPNs or additional setup like dual-network or split-tunneling configurations. Kaspersky VPN supports OpenVPN and WireGuard and provides router configuration guides.
read more →

AWS launches Network Security Manager in US East

🔒 Today AWS announces the general availability of AWS Network Security Manager, a centralized network security management solution that simplifies policy deployment and enforcement at scale. It supports AWS WAF and AWS Shield Advanced today, with AWS Network Firewall support coming soon. The service enables consistent enforcement of firewall and DDoS protections across an AWS organization and is available in US East (N. Virginia).
read more →

Hidden SSID Risks and Better Wi‑Fi Protections

🔒 Hiding a Wi‑Fi SSID may seem like added security, but it’s ineffective and can expose sensitive data. Devices trying to connect to hidden networks broadcast known SSIDs, allowing attackers to capture names and map routers via BSSID. Hidden SSIDs also degrade performance and drain battery, especially in 6GHz. Use WPA3 with a long password, disable WPS, and avoid revealing SSIDs for stronger protection.
read more →

Mixed Device Segments Increase Lateral Movement Risk

🔍 Forescout's analysis of 47,700 real-world network segments found many contain mixed device types—IT, OT, IoT and IoMT—broadening attack surfaces and increasing lateral movement risk. The study shows only a minority of OT or IoMT segments are isolated, with common co-location like IP cameras alongside workstations enabling single-point compromises. Forescout recommends continuous visibility, device prioritization, tighter segmentation and policy-based controls to prevent breaches spreading to critical systems.
read more →

AWS PrivateLink adds tunnel VPC endpoint

🔒 AWS PrivateLink now supports a new VPC tunnel endpoint that lets customers privately and securely access network segments in another VPC or account. Instead of sharing individual resources, owners can create a Resource Configuration for a CIDR range and share it via AWS Resource Access Manager (RAM). Vendors create a tunnel endpoint and use GENEVE encapsulation to access the specified CIDR range. Pricing includes an hourly tunnel endpoint fee plus per-GB data charges.
read more →

AWS Transfer Family preserves SFTP client source IPs

🔒 AWS Transfer Family now preserves client source IPs using Proxy Protocol v2 (PPv2) when you place a Network Load Balancer (NLB) in front of a VPC-hosted SFTP endpoint. Previously, the NLB's private IP replaced the client's address in logs and during authentication, preventing IP-based auditing and access control. You can enable source IP preservation per server through the console, CLI, or API, and the feature is available in all Regions where AWS Transfer Family is offered.
read more →

Securing Unpatchable Systems Amid AI-Driven Finding

🔒 AI-assisted analysis is exposing decades of unpatched technical debt, leaving operational technology and legacy systems with known vulnerabilities that cannot easily be fixed. Inventory and visibility enable identification of at-risk devices, while network controls such as micro-segmentation, VLANs, ACLs, and NGFW/IPS provide compensating protections. Full air-gapping or data diodes can help but are often bypassed in practice, so defenders must assume imperfect isolation and apply layered controls and monitoring.
read more →

CloudWatch Network Monitoring adds TGW inter‑Region NHI

🛰️ Amazon CloudWatch Network Monitoring now reports network health indicators for paths that traverse Transit Gateway inter‑Region peering using synthetic monitors. This extends previous NHI coverage that applied only to paths using AWS Direct Connect, enabling operators to determine whether performance degradation across a Transit Gateway peering link is caused by the AWS network. The indicator covers the AWS network path up to the Transit Gateway peering connection and is published to your CloudWatch account for dashboards and alarms. This feature is available in all Regions except AWS GovCloud (US) and China Regions.
read more →

Android 17 Adds ECH to Strengthen Connection Privacy

🔒 Android 17 introduces network protections including support for Encrypted Client Hello (ECH) to hide visited domain metadata and work alongside private DNS. The platform-level ECH support encrypts the TLS Client Hello hostname, reducing ISP and Wi‑Fi operator visibility when using compatible apps and browsers. ECH will be enabled by default for apps targeting Android 17 that use supported networking libraries, with a GREASE fallback for non‑ECH servers to avoid detection.
read more →

AWS Security: July 2026 updates and guidance

🛡️ This recap highlights AWS Security blog posts, new capabilities, code samples, and guidance published in July 2026. Topics include AI agent security, data protection, network and infrastructure protections, threat detection enhancements, compliance guidance, and 21 security bulletins addressing vulnerabilities. Vendors and practitioners can use the code samples and workshops to implement recommended controls and apply patches promptly.
read more →

Uber reduces hybrid AI risk with Cloud Interconnect

🚦Uber adopted application awareness on Cloud Interconnect to prioritize business-critical traffic across its hybrid networks. As an early design partner, Uber deployed the feature in multiple locations to classify and queue application traffic using DSCP marking, protecting low-latency services during congestion. The approach improved bandwidth utilization, reduced the need for costly overprovisioning, and enabled safer migration of strategic workloads to Google Cloud.
read more →

Microsoft: Patch Window Is Collapsing, Adopt Network Controls

🛡️ Microsoft warns that the interval between vulnerability disclosure and exploitation is rapidly shrinking, outpacing many organizations' ability to safely deploy patches. Igor Sakhnov, Azure Networking GM, urges a shift to network-level controls as a temporary control plane to limit exposure while patches are tested and rolled out. Analysts note the model suits mature cloud environments but faces practical challenges such as poor asset visibility and risks that temporary measures become permanent liabilities.
read more →

AWS Network Firewall adds rule hit count visibility

🔒 This post announces a new AWS Network Firewall capability—rule hit count—that provides visibility into how often stateful rules match network traffic across custom and managed rule groups. Rule hit counts increment when matches produce alert logs (alert, drop, reject), and pass rules can be tracked by adding the alert keyword. Alert logs include aws_metadata with resource ARN and signature ID, are delivered to CloudWatch Logs or S3, and drive the Top Rule Hits dashboard for monitoring and compliance validation.
read more →

Storage Gateway adds FIPS PrivateLink support

🔒 AWS Storage Gateway now supports FIPS 140-3 validated endpoints over AWS PrivateLink for Tape Gateway and Volume Gateway. Previously restricted to the public internet, FIPS traffic can now stay on the private AWS network, simplifying use for regulated workloads. To use it, create a FIPS interface VPC endpoint and choose the FIPS option when activating your gateway; gateways must run software version 3.2.7 or later. The feature is available in eight Regions, including US East, US West, and AWS GovCloud.
read more →

RFC 9234: BGP Role Model and OTC Adoption

🛡️ RFC 9234 introduces a BGP Role capability and an Only to Customer (OTC) path attribute to encode neighbor relationships and prevent route leaks directly in the protocol. Cloudflare measured adoption by monitoring which peers send OTC to its network and discovered that two large Tier‑1 networks strip OTC. The post explains how Roles and OTC function, why OTC stripping undermines deployment, and offers guidance for operators to enable Roles for route leak protection.
read more →

AWS Network Firewall adds stateful rule hit counts

🔍 AWS Network Firewall now reports rule hit counts for stateful rules, giving administrators visibility into how often each stateful rule in a firewall policy matches traffic. This capability helps accelerate incident response, uncover shadow or redundant rules, and validate policy changes by confirming new rules match intended traffic. Hit counts are enabled by default for custom and managed rule groups, refresh at intervals as low as five minutes, and are available at no additional charge in supported Regions except UAE and Bahrain.
read more →