From AWS Security Blog · 11 stories
AWS London Region Renews UK Police-Assured Secure Facilities (PASF) Accreditation
The AWS Europe (London) Region has renewed its Police-Assured Secure Facilities (PASF) accreditation for Official-Sensitive data, confirming its compliance for UK law enforcement workloads. This renewal allows UK police and law enforcement organizations to continue using the AWS London Region for critical applications processing police data.
AWS completes CyberVadis assessment with highest score, report available for due diligence
Amazon Web Services (AWS) has completed its annual CyberVadis security assessment, achieving the highest score of "Mature" in all assessed areas. This report is now available to customers to assist with third-party supplier due diligence.
AWS Managed Microsoft AD Celebrates Ten Years of Enterprise Identity in the Cloud
AWS Managed Microsoft AD marks its tenth anniversary, reflecting on its evolution from a solution for running directory-aware workloads to a core identity service for thousands of enterprises. The service addressed the operational overhead of managing Microsoft Active Directory by providing a fully managed offering.
NICE Actimize Reduces AWS KMS Costs by 77% with Custom Key Caching for Multi-Tenant Encryption
NICE Actimize, a financial crime detection platform, reduced its AWS Key Management Service (KMS) costs by 77% by implementing a custom caching solution for encryption keys in its multi-tenant, event-driven system. This approach addresses the "cache stampede problem" in high-concurrency environments while maintaining per-tenant encryption isolation and security guarantees.
AWS Workload Credentials Provider enables cross-account secret retrieval
AWS introduced features in the Workload Credentials Provider for cross-account secret retrieval and latency reduction via prefetching. This allows faster access to secrets, improving application performance across multiple AWS accounts.
Guide on Detecting and Preventing Subdomain Takeovers
This article outlines how to identify and prevent subdomain takeovers, a tactic where threat actors exploit dangling DNS records. It stresses the importance of managing DNS configurations to mitigate risks associated with this security vulnerability.
Using Amazon Cognito and Verified Permissions for Access Control in B2C Apps
Developers can implement fine-grained access control in B2C applications using Amazon Cognito and Amazon Verified Permissions. This framework aids in managing user authentication and authorization efficiently, minimizing development efforts while enhancing security.
AWS provides guidance for identifying and remediating over-permissioned S3 buckets
AWS published a guide detailing a five-phase workflow to detect, remediate, and continuously monitor over-permissioned Amazon S3 buckets. This workflow helps security teams prevent unauthorized data access due to misconfigured S3 policies or ACLs.
AWS KMS vs. AWS CloudHSM: Choosing the Right Key Management Solution
AWS published a guide differentiating between AWS Key Management Service (KMS) and AWS CloudHSM for cryptographic key management. The guide clarifies that AWS KMS is suitable for most use cases due to its full management and integration, while AWS CloudHSM is for specific needs like dedicated HSM instances or legacy application support.
AWS DevOps Agent aids Network Firewall troubleshooting by correlating logs and configurations
AWS DevOps Agent can now accelerate troubleshooting for AWS Network Firewall disruptions by automatically correlating firewall configurations, logs, and recent API calls. This capability helps identify root causes of network connectivity issues more quickly, reducing resolution times from hours to minutes.
AWS to Showcase AI-Powered Security Solutions at Black Hat USA 2026
Amazon Web Services (AWS) will present its AI-powered security offerings at Black Hat USA 2026, focusing on autonomous security operations and AI security architectures. The company will demonstrate how its services address enterprise security challenges with machine-speed remediation and AI-driven investigations.