< ciso
brief />
Tag Banner

All news with #network security tag

175 articles

AWS Network Firewall adds rule hit count visibility

🔒 This post announces a new AWS Network Firewall capability—rule hit count—that provides visibility into how often stateful rules match network traffic across custom and managed rule groups. Rule hit counts increment when matches produce alert logs (alert, drop, reject), and pass rules can be tracked by adding the alert keyword. Alert logs include aws_metadata with resource ARN and signature ID, are delivered to CloudWatch Logs or S3, and drive the Top Rule Hits dashboard for monitoring and compliance validation.
read more →

Storage Gateway adds FIPS PrivateLink support

🔒 AWS Storage Gateway now supports FIPS 140-3 validated endpoints over AWS PrivateLink for Tape Gateway and Volume Gateway. Previously restricted to the public internet, FIPS traffic can now stay on the private AWS network, simplifying use for regulated workloads. To use it, create a FIPS interface VPC endpoint and choose the FIPS option when activating your gateway; gateways must run software version 3.2.7 or later. The feature is available in eight Regions, including US East, US West, and AWS GovCloud.
read more →

RFC 9234: BGP Role Model and OTC Adoption

🛡️ RFC 9234 introduces a BGP Role capability and an Only to Customer (OTC) path attribute to encode neighbor relationships and prevent route leaks directly in the protocol. Cloudflare measured adoption by monitoring which peers send OTC to its network and discovered that two large Tier‑1 networks strip OTC. The post explains how Roles and OTC function, why OTC stripping undermines deployment, and offers guidance for operators to enable Roles for route leak protection.
read more →

AWS Network Firewall adds stateful rule hit counts

🔍 AWS Network Firewall now reports rule hit counts for stateful rules, giving administrators visibility into how often each stateful rule in a firewall policy matches traffic. This capability helps accelerate incident response, uncover shadow or redundant rules, and validate policy changes by confirming new rules match intended traffic. Hit counts are enabled by default for custom and managed rule groups, refresh at intervals as low as five minutes, and are available at no additional charge in supported Regions except UAE and Bahrain.
read more →

Delta investigates in-flight Wi‑Fi deauth and rogue AP

✈️ Delta Air Lines is investigating an unauthorized Wi‑Fi network that briefly appeared aboard Flight 591 from Las Vegas to Atlanta, carrying passengers who attended DEF CON 34. The carrier said the incident did not affect passenger safety or aircraft systems and that cabin crew disabled Wi‑Fi for about 30 minutes while authorities investigate. Federal law enforcement and aviation regulators will be involved in the probe.
read more →

GKE introduces ClusterNetworkPolicy for cluster-wide control

🔒 ClusterNetworkPolicy (CNP) is a new cluster-scoped network policy API added to GKE to let administrators enforce deterministic, non-bypassable network guardrails across namespaces. CNP introduces a hierarchical tier model—admin, network policy, and baseline—with top-to-bottom evaluation and an explicit Pass action to delegate final decisions. Built with the Kubernetes SIG-Policy WG and implemented with Cilium, CNP is open source and intended to improve scalability, compliance, and portability of network security controls in multi-tenant clusters.
read more →

VPC IPAM adds BGP route protection and delegated RPKI

🛡️ Amazon VPC IPAM now supports BGP route protection monitoring and delegated RPKI management for BYOIP prefixes, enabling centralized monitoring of RPKI validity, ROA strength, and route overlap across accounts and regions. Administrators can detect invalid or missing ROAs, identify potential hijacks via overlap detection, and differentiate strict versus permissive ROA configurations. With Delegated RPKI, after a one-time setup with ARIN, RIPE, APNIC, or LACNIC, IPAM automates ROA creation, renewal, and management for both BYOIP and on-premises prefixes. The capability is available in all commercial AWS Regions except AWS GovCloud (US) and the China regions.
read more →

NatJack NAT manipulation hijacks TCP sessions

🔒 Researcher Malcolm Stagg disclosed NatJack, a class of attacks that manipulates NAT connection state to hijack TCP sessions, spoof DNS responses, expose mapped ports, and exhaust NAT tables. Presented at Black Hat USA 2026, the work found vulnerable behaviors across multiple implementations including Windows and Linux, with two CVEs assigned: CVE-2026-56181 and CVE-2026-63913. Mitigations include applying vendor updates, segregating untrusted workloads, encrypting internal traffic, and employing IP Source Guard where possible.
read more →

NatJack at Black Hat: NAT trust model under test

🛡️ At Black Hat USA 2026, researcher Malcolm Stagg disclosed NatJack, a class of attacks that manipulates NAT connection tracking tables to hijack TCP connections, poison DNS, and cause DoS without needing IP spoofing or Layer 2 access. Testing across 32 products revealed vulnerabilities in every implementation examined. Vendor responses varied from patches and CVEs to arguments that the issues reflect design limitations rather than security flaws. Stagg recommended monitoring NAT tables, enabling source IP protections, segmenting untrusted traffic, and disabling loose connection tracking modes as mitigations.
read more →

OpenSearch UI adds network access controls

🔒 Amazon OpenSearch Service now supports network access controls for OpenSearch UI applications, enabling administrators to restrict access to approved networks using IAM condition keys like aws:SourceVpce, aws:SourceVpc, and aws:SourceIp. You can enforce restrictions via identity-based policies, VPC endpoint policies, and organization-wide resource control policies (RCPs), which can block off-network users before authentication. This feature is available in all Regions where OpenSearch UI is offered.
read more →

AWS Network Firewall Adds Explicit Forward Proxy

🔒 AWS reintroduces explicit forward proxy functionality within Network Firewall, allowing customers to use existing firewall policies across both proxy and transparent modes. The feature supports managed rule groups, active threat defense, Geo-IP, URL/category filtering, and container attribute rules for Amazon EKS and ECS. Available in a no-source-preservation deployment during public preview in US East (Ohio), the preview is free and intended for testing and validation.
read more →

Redefining Network Security for the Frontier AI Era

🔒 PAN-OS 12.2 Ceres introduces Advanced Virtual Patching, Advanced IP Defense, and AI-powered Network Security Agents to confront Frontier AI–driven threats, surging traffic, and cryptographic upheaval. The release emphasizes near-zero exposure windows by using AI to discover vulnerabilities and deploy network-level protections instantly, while integrating with industry partners and Project Lightwell. These innovations aim to protect critical OT, healthcare, and IoT environments without downtime and to automate routine admin tasks via Strata Cloud Manager.
read more →

Six hard truths from CI Fortify guidance

🔒 The Five Eyes’ CI Fortify guidance urges critical infrastructure operators to be able to isolate operational technology deliberately and sustain services during a crisis. The advisory rates VLANs and MPLS as insufficient long-term segregation and cautions against trusting carrier services or native OT encryption. It warns that software-defined controls are convenient but not equivalent to physical separation, and that isolation introduces its own operational risks requiring planning and testing.
read more →

Zero Networks adds network controls for AI agents

🔒 Zero Networks has introduced Least Agency Enforcement, a network-layer capability to implement OWASP’s emerging Least Agency principle for enterprise AI. Built on the company’s identity-based micro-segmentation platform, it restricts which systems AI agents can contact, what resources they can access, and when human approval is required. The feature uses automated policy generation and just-in-time MFA to block lateral movement and sensitive actions even after an agent authenticates.
read more →

Cloudflare launches provisioned MoQ relay scopes

🛰️ Cloudflare has added isolation and access controls to its global Media over QUIC (MoQ) network by introducing a provisioning API that creates isolated relays (scopes) and issues publish/subscribe tokens. The relays are available across Cloudflare’s network within seconds with no servers to deploy and support draft-14 and draft-16 MoQ transport features; the beta is free to use. Tokens are scoped, revocable, and manageable via API or dashboard, and Cloudflare is documenting the control-plane model as an IETF Internet-Draft for broader interoperability.
read more →

AWS Direct Connect adds BGP route visibility

🔍 AWS Direct Connect now provides visibility into Border Gateway Protocol (BGP) routes exchanged between AWS and your on-premises routers for private, transit, and public virtual interfaces (VIFs). You can view accepted and advertised routes, including prefix, address family, AS path, community values, and installation timestamp, via the Direct Connect console or the ListVirtualInterfaceRoutes API. Filters let you narrow results by prefix, AS path, community, or address family, helping troubleshoot routing, validate BGP policies, and monitor hybrid connectivity. The feature is available in all AWS commercial Regions and AWS China Regions.
read more →

AWS Transit Gateway Adds Policy-Based Routing

🔧 AWS Transit Gateway now supports Policy-Based Routing (PBR), allowing forwarding decisions based on packet attributes such as source and destination IPs, ports, and protocol instead of destination alone. PBR reduces the need for complex multi-VPC architectures and extra routing hops by enabling administrators to attach policy tables to Transit Gateway attachments and define ordered rule sets. Rules classify traffic and direct matches to specified route tables using first-match-wins logic, supporting traffic steering, inspection, and environment isolation. PBR is available in all commercial AWS Regions where Transit Gateway is offered and can be configured via the Console, CLI, or SDK with no additional charge beyond standard Transit Gateway fees.
read more →

AWS Glue REST connector adds VPC, filters, partitions

🔐 AWS Glue's REST API connector now supports VPC connections, filter pushdown, and partitioning to improve secure, efficient ingestion from REST endpoints. With VPC support you can reach private subnets, VPNs, or AWS PrivateLink without exposing traffic publicly. Filter pushdown converts query predicates into API-native parameters to reduce transferred data, and partition support enables parallel reads across Spark workers for faster ingestion. These features are available in all AWS commercial regions.
read more →

Accelerating Network Firewall Troubleshooting with DevOps Agent

🛡️ This post shows how AWS DevOps Agent accelerates root-cause analysis for AWS Network Firewall issues by correlating CloudWatch alarms, firewall logs, route tables, and CloudTrail events. It walks through three reproducible failure scenarios—domain deny list, stateless rule priority inversion, and asymmetric cross-AZ routing—deployed via an AWS CDK app. The CDK stack includes a sample workload, test endpoint, status page, and a webhook pipeline so alarms trigger investigations and the agent returns mitigation plans for operator review.
read more →

BGP ORIGIN Attribute Manipulation and Impact

📘 Cloudflare examines the BGP ORIGIN attribute, a mandatory path attribute intended to signal how a route was injected into BGP. Their experiments show widespread modification of ORIGIN values—predominantly to IGP—by many networks, including Tier-1s, altering route selection and diverting traffic for commercial advantage. The report describes methodology, measurements across IPv4/IPv6, and the resulting routing and economic impacts.
read more →