For you Ai Security Dev Cloud Hardware Startups Releases General

From AWS Security Blog · 30 stories

1 source 1 report 91d ago

AWS Shield Advanced introduces DDoS attack flow logs for enhanced visibility

AWS Shield Advanced now includes attack flow logs that capture traffic metadata during DDoS attacks. This enables better analysis of attack traffic, showing the origins and mitigating actions taken, integrating seamlessly with existing monitoring tools.

security aws ddos cloud
1 source 1 report 91d ago

Amazon Cognito introduces Lambda trigger for federated sign-in customization

Amazon Cognito has launched an inbound federation Lambda trigger, allowing developers to programmatically manage federated authentication flows. This feature enables customization of user attributes received from external identity providers before they are mapped in the Cognito user pool, addressing challenges in identity federation.

dev amazon cognito lambda authentication
1 source 1 report 91d ago

AWS KMS launches GetKeyLastUsage API for key management

AWS has introduced the GetKeyLastUsage API, allowing users to check when KMS keys were last utilized. This tool simplifies auditing and reduces reliance on AWS CloudTrail logs, enhancing key management efficiency and compliance tracking.

cloud aws kms security
1 source 1 report 91d ago

AWS Network Firewall Supports Transit Gateway Attachment for Cost Optimization

AWS Network Firewall now allows attachment to Transit Gateway, streamlining traffic routing without needing a central inspection VPC. This simplifies network architecture and enables flexible cost allocation for traffic inspection, making it more efficient for AWS users.

cloud aws networking firewall
1 source 1 report 91d ago

AWS Network Firewall introduces URL and Domain Category filtering for easier policy management

AWS Network Firewall now enables URL and domain category filtering, allowing security teams to manage access via predefined categories rather than individual domains. This update simplifies policy management and ensures domain lists stay current automatically, particularly benefiting organizations overseeing rapidly changing areas like AI services.

cloud aws firewall policy network
1 source 1 report 85d ago

Post-quantum cryptography guidance released for CISOs

Over a dozen economies issued guidance on post-quantum cryptography (PQC) adoption. The focus is on strategic organization-wide changes required for compliance and modernization beyond just algorithm updates.

security cryptography CISO PQC
1 source 1 report 8d ago

AWS Security Releases August 2026 Digest with 20 Blog Posts

AWS Security released its August 2026 digest, summarizing 20 blog posts across various categories. Key updates include self-service rate limits for Amazon Cognito, a redesigned AWS sign-in experience, and new features for AWS Management Console Private Access.

security aws identity cloud
1 source 1 report 27d ago

AWS completes OSPAR 2026 assessment, expanding scope to 167 services in Singapore

AWS has completed its annual Outsourced Service Provider’s Audit Report (OSPAR) assessment for 2026, now covering 167 services in the AWS Asia Pacific (Singapore) Region. This certification helps financial institutions in Singapore meet regulatory compliance requirements for cloud services.

cloud aws compliance singapore
1 source 1 report 31d ago

AWS Security Hub Extended Integrates Upwind for Cloud Workload Protection

AWS Security Hub Extended has integrated Upwind, a cloud security company, into its program. This integration provides customers with Upwind's runtime-first cloud workload protection directly through their existing AWS relationship, offering choice even with overlapping services.

security aws cloud upwind
1 source 1 report 45d ago

AWS updates sign-in experience with redesigned page and new account creation options

Amazon Web Services (AWS) is rolling out updates to its sign-in and sign-up experience, introducing a redesigned sign-in page and new options for creating and accessing AWS accounts. These changes aim to provide a more consistent user experience, though existing customers will continue using their current sign-in methods.

cloud aws identity ux
1 source 1 report 51d ago

AWS Releases Independent Assessment Report for Landing Zone Accelerator's C5:2020 Compliance

AWS has made an independent assessment report available on AWS Artifact for its Landing Zone Accelerator (LZA) solution, detailing its alignment with the C5:2020 cloud security compliance standard. This report helps organizations in Europe demonstrate compliance by showing how LZA implements security controls for "security in the cloud" aspects of C5:2020.

cloud aws compliance security
1 source 1 report 51d ago

AWS releases Summer 2026 SOC 1 report covering 185 services for 12 months

Amazon Web Services (AWS) has released its Summer 2026 SOC 1 report, which covers 185 services for the period of July 1, 2025, to June 30, 2026. This report provides customers with compliance assurance for a full year, aiding in their architectural and regulatory requirements.

cloud aws compliance security
1 source 1 report 51d ago

AWS Completes 2025-26 NHS DSPT Assessment with "Standards Exceeded" Status

Amazon Web Services (AWS) has successfully completed its 2025-26 NHS Data Security and Protection Toolkit (DSPT) assessment, achieving a "Standards Exceeded" status. This assessment demonstrates AWS's compliance with data security standards required for organizations accessing NHS patient data and systems.

security aws nhs compliance
1 source 1 report 52d ago

AWS London Region Renews UK Police-Assured Secure Facilities (PASF) Accreditation

The AWS Europe (London) Region has renewed its Police-Assured Secure Facilities (PASF) accreditation for Official-Sensitive data, confirming its compliance for UK law enforcement workloads. This renewal allows UK police and law enforcement organizations to continue using the AWS London Region for critical applications processing police data.

cloud aws cloud security uk government compliance
1 source 1 report 52d ago

AWS completes CyberVadis assessment with highest score, report available for due diligence

Amazon Web Services (AWS) has completed its annual CyberVadis security assessment, achieving the highest score of "Mature" in all assessed areas. This report is now available to customers to assist with third-party supplier due diligence.

security aws compliance cybervadis
1 source 1 report 10d ago

Transforming AWS Bedrock Guardrails Events into OCSF with CloudWatch

AWS Bedrock Guardrails intervention data can now be transformed into Open Cybersecurity Schema Framework (OCSF) Detection Finding records and stored in the CloudWatch unified data store. This allows security teams to integrate AI-related security events with existing security telemetry for comprehensive analysis.

security aws ai cloudwatch
1 source 1 report 14d ago

Automating AWS IAM Least Privilege Remediation via CI/CD Pipelines

A new workflow automates the remediation of overly permissive AWS Identity and Access Management (IAM) roles by integrating with CI/CD pipelines. This automation classifies roles by creation method and generates specific remediation artifacts, such as pull requests for Infrastructure-as-Code (IaC) managed roles or issues for manually created ones. The workflow addresses the challenge of maintaining least privilege at scale by bridging the gap between IAM Access Analyzer's detection capabilities and persistent action.

security aws iam ci/cd
1 source 2 reports 28d ago

AWS releases multi-part guide for CloudTrail incident investigations

AWS has published a two-part incident response guide for investigating suspicious activity using AWS CloudTrail logs. The guide details how to analyze CloudTrail events to uncover unauthorized access, cryptocurrency mining, and AI service abuse, including a complex multi-stage attack targeting Amazon Bedrock services across multiple AWS Regions.

security aws cloudtrail incident response
1 source 1 report 55d ago

AWS Managed Microsoft AD Celebrates Ten Years of Enterprise Identity in the Cloud

AWS Managed Microsoft AD marks its tenth anniversary, reflecting on its evolution from a solution for running directory-aware workloads to a core identity service for thousands of enterprises. The service addressed the operational overhead of managing Microsoft Active Directory by providing a fully managed offering.

cloud aws microsoft ad identity
1 source 1 report 56d ago

NICE Actimize Reduces AWS KMS Costs by 77% with Custom Key Caching for Multi-Tenant Encryption

NICE Actimize, a financial crime detection platform, reduced its AWS Key Management Service (KMS) costs by 77% by implementing a custom caching solution for encryption keys in its multi-tenant, event-driven system. This approach addresses the "cache stampede problem" in high-concurrency environments while maintaining per-tenant encryption isolation and security guarantees.

security aws encryption kms caching
1 source 1 report 91d ago

AWS Workload Credentials Provider enables cross-account secret retrieval

AWS introduced features in the Workload Credentials Provider for cross-account secret retrieval and latency reduction via prefetching. This allows faster access to secrets, improving application performance across multiple AWS accounts.

cloud aws security
1 source 1 report 91d ago

Guide on Detecting and Preventing Subdomain Takeovers

This article outlines how to identify and prevent subdomain takeovers, a tactic where threat actors exploit dangling DNS records. It stresses the importance of managing DNS configurations to mitigate risks associated with this security vulnerability.

security aws dns
1 source 1 report 91d ago

Using Amazon Cognito and Verified Permissions for Access Control in B2C Apps

Developers can implement fine-grained access control in B2C applications using Amazon Cognito and Amazon Verified Permissions. This framework aids in managing user authentication and authorization efficiently, minimizing development efforts while enhancing security.

dev amazon security cognito permissions
1 source 1 report 14d ago

Architecting a Secure Landing Zone in AWS European Sovereign Cloud

This article details how to architect a secure, scalable landing zone within the new AWS European Sovereign Cloud (aws-eusc) partition. It covers account structure, identity management, logging, data protection, networking, CI/CD, and incident response, aligning with AWS Security Reference Architecture and Well-Architected Framework.

cloud aws sovereign cloud security
1 source 2 reports 29d ago

AWS provides solution for automated IAM Identity Center governance and reporting

AWS has released a sample solution to automate discovery and reporting for IAM Identity Center, addressing challenges in tracking access assignments and enforcing governance policies as AWS organizations scale. This solution helps answer questions about user and group access to AWS applications and generates reports for compliance audits or security reviews.

security aws iam governance identity management
1 source 1 report 36d ago

AWS guide details detecting multi-stage attacks using cross-service signal correlation

AWS published a guide for security engineers on detecting multi-stage attacks by correlating signals from various AWS security services with business context. This approach helps identify attack sequences rather than triaging individual findings, improving overall security posture. The guide provides examples using Amazon CloudWatch Logs Insights and outlines how to build automated pipelines for correlation.

security aws cloud detection
1 source 1 report 55d ago

AWS provides guidance for identifying and remediating over-permissioned S3 buckets

AWS published a guide detailing a five-phase workflow to detect, remediate, and continuously monitor over-permissioned Amazon S3 buckets. This workflow helps security teams prevent unauthorized data access due to misconfigured S3 policies or ACLs.

security aws s3 cloud
1 source 1 report 65d ago

AWS KMS vs. AWS CloudHSM: Choosing the Right Key Management Solution

AWS published a guide differentiating between AWS Key Management Service (KMS) and AWS CloudHSM for cryptographic key management. The guide clarifies that AWS KMS is suitable for most use cases due to its full management and integration, while AWS CloudHSM is for specific needs like dedicated HSM instances or legacy application support.

cloud aws kms cloudhsm security
1 source 1 report 69d ago

AWS DevOps Agent aids Network Firewall troubleshooting by correlating logs and configurations

AWS DevOps Agent can now accelerate troubleshooting for AWS Network Firewall disruptions by automatically correlating firewall configurations, logs, and recent API calls. This capability helps identify root causes of network connectivity issues more quickly, reducing resolution times from hours to minutes.

cloud aws network firewall devops troubleshooting
1 source 1 report 70d ago

AWS to Showcase AI-Powered Security Solutions at Black Hat USA 2026

Amazon Web Services (AWS) will present its AI-powered security offerings at Black Hat USA 2026, focusing on autonomous security operations and AI security architectures. The company will demonstrate how its services address enterprise security challenges with machine-speed remediation and AI-driven investigations.

security aws ai blackhat