For you Ai Security Dev Cloud Hardware Startups Releases General

From AWS Security Blog · 40 stories

25 sources 366 reports 17h ago Updated 20h ago

Strategic Frameworks and Systems Vital for Successful AI Integration in Enterprises

AI's integration in enterprises is moving beyond model development to focus on creating robust systems for execution and governance. This shift highlights the importance of developing adaptable frameworks to support AI's role across various functions such as finance, HR, and operations. It reflects a broader industry trend where the focus is on building the necessary infrastructure to ensure AI's ongoing, safe, and productive incorporation into real-world workflows, addressing the current challenges and limitations.

ai enterprise microsoft systems dev
7 sources 143 reports 2h ago Updated 2h ago

Amazon Bedrock Enhances AI Capabilities with Security and Operational Features

Amazon Bedrock has introduced several updates to improve the security and operational management of AI applications, emphasizing capabilities for multi-tenant AI, data retention policies, and compliance with US government standards. Key features include resource-based policies, managed entitlements for model subscriptions, zero data retention enforcement, and AI model support in AWS GovCloud. These advancements aim to streamline AI adoption across diverse sectors while maintaining security and governance standards.

ai amazon cloud security bedrock
7 sources 9 reports 55d ago

Dependabot introduces default three-day cooldown for version updates

Dependabot now includes a default three-day cooldown before opening version update pull requests. This change aims to reduce the risk of merging compromised versions immediately after their release, enhancing supply chain security for developers.

dev dependabot github software security
3 sources 18 reports 31d ago

AWS Unveils New AI and Security Features at NYC Summit

Amazon Web Services introduced new AI and security features at the NYC Summit, including Amazon Bedrock AgentCore and AWS Continuum. These updates enhance AI applications and security, offering capabilities for organizational knowledge access and proactive security measures. The announcements indicate a focus on advancing AI operations and cybersecurity strategies.

cloud aws coding development security
2 sources 2 reports 66d ago

Amazon launches GuardDuty investigation agent for AI-powered threat assessment

Amazon introduced the GuardDuty investigation agent in public preview, enhancing threat assessments across AWS environments. This tool automates investigation processes, reducing time from hours to minutes and providing structured risk assessments and actionable recommendations.

security guardduty aws threat assessment ai
2 sources 2 reports 83d ago

AWS & Google Cloud Designated as Critical Third Parties to UK's Financial Sector

HM Treasury has designated Amazon Web Services and Google Cloud as critical third parties to the UK financial sector. Under the Critical Third Party (CTP) regime effective January 1, 2025, these tech giants will be subject to oversight from UK regulators such as the Bank of England. This move aims to enhance the operational resilience of the financial sector amidst increasing reliance on cloud services.

cloud aws financial uk google
1 source 1 report 3d ago

AWS European Sovereign Cloud to Demonstrate Independent Operation on October 24, 2026

AWS will conduct an exercise on October 24, 2026, to demonstrate that its European Sovereign Cloud can operate independently of non-EU infrastructure. During this period, the cloud will function without a connection to the AWS Global Network backbone, with traffic rerouted over the public internet, to verify its operational independence for European customers.

cloud aws europe sovereignty
1 source 1 report 8d ago

AWS enforces MFA for all root users across all account types by June 2025

AWS completed comprehensive multi-factor authentication (MFA) enforcement for root users across all account types by June 2025, a phased rollout that began in May 2024. This move supports the Australian Signals Directorate's (ASD) campaign to encourage MFA adoption, aiming to prevent over 99% of password-related attacks.

security aws mfa authentication
1 source 1 report 14d ago

AWS STS simplifies session token size limits to 4,096 bytes and adds monitoring

AWS Security Token Service (STS) has replaced its two session token size limits with a single 4,096-byte limit, providing more space for session policies and tags. STS now reports session token size in API responses, CloudWatch metrics, and CloudTrail events, allowing users to monitor and optimize token usage.

cloud aws sts security cloudwatch
1 source 1 report 14d ago

Amazon Cognito Introduces Multi-Region Replication for Enhanced Authentication Resilience

Amazon Cognito now offers Multi-Region Replication (MRR), automatically replicating user pools across AWS Regions with near-real-time synchronization. This feature simplifies building resilient authentication systems by handling user data synchronization, consistency, and failover, reducing operational overhead for businesses scaling globally.

cloud aws cognito authentication replication
1 source 1 report 14d ago

AWS Releases Security Reference Architecture Deep Dive for PCI DSS Compliance

Amazon Web Services (AWS) has published a new AWS Security Reference Architecture (SRA) Payment Card Industry (PCI) Data Security Standard (DSS) Deep Dive guide. This guide provides prescriptive architectural guidance for organizations handling cardholder data on AWS, extending the core AWS SRA to address specific PCI DSS compliance requirements.

security aws compliance pci dss
1 source 1 report 34d ago

AWS Management Console Private Access Now Supports VPCs Without Internet Connectivity

AWS Management Console Private Access is now generally available, allowing organizations to route all console traffic through AWS PrivateLink VPC endpoints without requiring internet connectivity. This update enables regulated industries to access the AWS Management Console from isolated network environments, addressing a previous limitation where static assets and console-only APIs still needed internet access.

cloud aws security networking
1 source 1 report 37d ago

AWS Releases Independent Report on Landing Zone Accelerator for Australian Government ISM Compliance

AWS has released an independent assessment report on how Landing Zone Accelerator (LZA) on AWS can deploy multi-account environments with Australian Government Information Security Manual (ISM) security controls. This report, conducted by gwi.digital, provides Australian customers with a documented foundation to accelerate IRAP assessment readiness, which is crucial for public sector, defense, and critical infrastructure agencies.

cloud aws security compliance
1 source 1 report 42d ago

AWS Network Firewall adds rule hit count support for stateful rules

AWS Network Firewall now includes a rule hit count feature that tracks how often stateful rules match network traffic. This capability helps security teams identify unused rules, improve incident response, and validate security control effectiveness for compliance frameworks like PCI 4.0 and DORA.

cloud aws network firewall security
1 source 1 report 44d ago

AWS Security Hub Extended adds Supply Chain Security as its tenth category

AWS Security Hub Extended now includes Supply Chain Security as its tenth category, integrating solutions from partners like Chainguard and Socket. This addition addresses growing concerns about software supply chain risks, offering a consolidated approach to security management within the AWS ecosystem.

security aws supply chain cloud
1 source 2 reports 49d ago

AWS Certificate Manager Adds ACME Support, Deprecates Email Validation by September 2027

AWS Certificate Manager (ACM) now supports the Automated Certificate Management Environment (ACME) protocol for automated public certificate issuance and renewal, addressing the operational burden of reduced certificate validity periods. Concurrently, ACM will discontinue support for email-validated public certificates by September 30, 2027, requiring users to migrate to DNS validation in alignment with CA/B Forum standards.

security aws certificates automation cloud
1 source 1 report 50d ago

AWS introduces IAM role manager to automate IAM role creation for services

AWS has launched IAM role manager, a new feature that automates the creation and configuration of IAM roles when building applications in supported service consoles. This feature simplifies the initial setup process for developers by automatically provisioning necessary roles, allowing them to refine permissions later.

cloud aws iam automation
1 source 1 report 57d ago

Amazon Cognito Introduces Self-Service Provisioned Limits for Rate Limit Management

Amazon Cognito now offers provisioned limits, allowing users to adjust authentication rate limits on-demand through the AWS Management Console. This change reduces the time required for capacity increases from up to two weeks to minutes, enabling better cost optimization and responsiveness to traffic fluctuations.

cloud aws amazon cognito identity management
1 source 1 report 58d ago

AWS renews PCI DSS and PCI 3DS compliance, expands scope to new services and region

AWS has renewed its Payment Card Industry Data Security Standard (PCI DSS) and Three Domain Secure (PCI 3DS) certifications, adding three new services and the Asia Pacific (New Zealand) region to its compliance scope. This update allows customers to use these additional AWS services and the new region for handling payment card data while maintaining compliance, reducing their compliance overhead.

security aws pci dss pci 3ds compliance
1 source 1 report 62d ago

AWS Releases HIPAA Security Rule Technical Safeguards Implementation and Readiness Guidance

AWS has released new guidance to help healthcare entities configure and implement HIPAA Security Rule Technical Safeguards when using AWS services. This guidance covers current regulations and proposed 2025 NPRM changes, including mandatory encryption and multi-factor authentication, providing a practical reference for compliance.

security aws hipaa compliance
1 source 1 report 63d ago

Amazon Inspector SBOM Generator Adds Plugin System for Custom Package Collectors

Amazon Inspector's SBOM Generator (inspector-sbomgen) now includes a plugin system, allowing users to create custom package collectors for unsupported software ecosystems. This update enables immediate inventorying of new or niche package formats without requiring source code compilation or official releases, addressing a previous visibility gap for security teams.

security aws sbom vulnerability-management
1 source 1 report 64d ago

Amazon links North Korean group to multiple open-source supply chain attacks on NPM libraries

Amazon Threat Intelligence has identified a North Korean-linked threat actor as responsible for recent compromises of popular Node Package Manager (NPM) libraries, including axios, debug, chalk, and typo-crypto. This connection, previously unreported, highlights the increasing sophistication of software supply chain attacks and the evolving tactics of state-sponsored groups targeting open-source infrastructure.

security supply chain npm north korea
1 source 1 report 65d ago

AWS releases 2026 Phase 1a IRAP report for Australian customers, adding four services

AWS has made its 2026 Phase 1a IRAP report available to Australian customers via AWS Artifact, which includes four new services assessed at the PROTECTED level. This update increases the total number of PROTECTED-level services to 167, providing Australian government and critical infrastructure customers with more options for secure cloud deployments.

cloud aws irap australia security
1 source 1 report 66d ago

AWS Shield Advanced Adopts WAF Anti-DDoS Managed Rule Group for Application-Layer Protection

AWS Shield Advanced is integrating the AWS WAF Anti-DDoS managed rule group as its default and eventually sole application-layer DDoS protection. This change, starting July 27, enhances detection and mitigation of HTTP request floods by profiling traffic and reacting within seconds, improving upon existing automatic mitigations.

security aws ddos waf
1 source 2 reports 66d ago

AWS expands ISO and CSA STAR certificates to include two additional services

Amazon Web Services (AWS) has completed an audit adding two new services to its ISO and CSA STAR certifications. This expansion reflects AWS's ongoing commitment to quality management and information security in its cloud offerings.

cloud aws certifications security cloud security alliance
1 source 2 reports 72d ago

AWS Enhances Bot Traffic Security with Web Bot Authentication in WAF Bot Control

AWS WAF Bot Control now includes Web Bot Authentication (WBA), using cryptographic signatures to distinguish legitimate AI bot traffic from malicious activity. This update addresses security challenges in multi-tenant environments such as Amazon Bedrock AgentCore, where traditional IP-based methods fall short. The method leverages two IETF drafts to verify bot identities securely.

security aws bot automation waf
1 source 1 report 79d ago

Security Hub adds AI workload protection, supports Microsoft Azure

Security Hub introduces AI workload protection and support for Microsoft Azure. These enhancements address customer demand for integrated security management across multiple cloud environments, allowing for streamlined risk assessment and response.

security azure cloud workload
1 source 1 report 80d ago

HITRUST i1 Compliance Guidance Released for AWS Users

AWS has published a new guide for healthcare organizations seeking HITRUST i1 compliance. This guidance outlines how to implement the certification's requirements on AWS, covering 11 technical control domains relevant to healthcare data security.

cloud hitrust aws compliance healthcare
1 source 1 report 84d ago

AWS MCP Server Introduces OAuth Support for Enhanced Security

AWS MCP Server now supports OAuth sign-in methods for improved user authentication. This change enables IAM federation and simplifies access management for cloud users, facilitating better integration and security features within AWS services.

cloud aws oauth security
1 source 1 report 85d ago

Security Focus on System Prompt Leakage in Generative AI Applications

System prompts, essential for LLMs, face leakage issues due to prompt injection risks. This risk highlights the need for robust security measures in generative AI designs.

security generative ai aws prompt leakage
1 source 1 report 87d ago

Cedar enables least-privilege authorization for multi-agent AI systems

Cedar introduces a three-layer authorization model for multi-agent AI systems to prevent privilege abuse. This model addresses risks by enforcing least-privilege authorization as tasks are delegated through AI agents, crucial for maintaining security in complex systems.

dev authorization ai security cedar
1 source 1 report 91d ago

AWS Network Firewall introduces container attribute-based rules for EKS and ECS

AWS Network Firewall now supports container attribute-based rules for Amazon EKS and ECS, enhancing security for traffic in Kubernetes environments. This feature allows users to define firewall rules based on container attributes instead of transient IP addresses, addressing challenges in dynamic container workloads.

cloud aws network security containers
1 source 1 report 91d ago

AWS CIRT updates Threat Technique Catalog, focusing on container security

The AWS Customer Incident Response Team updated the Threat Technique Catalog, adding five new entries focused on container security, organization-level trust, and compute hijacking. This update provides essential insights into recent security threats, particularly around AWS Elastic Kubernetes Service, helping organizations mitigate risks in their cloud environments.

security aws containers kubernetes
1 source 1 report 91d ago

AWS adds resource-based policies for console access control from specific networks

AWS introduced resource-based policies and resource control policies to restrict AWS Management Console access to specific networks. This change allows organizations to enforce network-based restrictions for compliance and security purposes, significantly enhancing AWS account security.

cloud aws security compliance
1 source 1 report 91d ago

AWS emphasizes egress controls to prevent data exfiltration in cloud workloads

Amazon Web Services (AWS) highlights the importance of egress controls to prevent data exfiltration in cloud environments. With traditional threats and emerging AI architectures posing risks, proper egress monitoring is necessary to detect unauthorized data flows and secure workloads.

cloud aws security egress
1 source 1 report 91d ago

Kiro CLI simplifies AWS security investigations with AI assistance

Kiro has introduced Kiro CLI, an AI-powered tool that assists security teams in investigating AWS incidents. It streamlines the process by providing AWS CLI command suggestions and explanations, significantly reducing the time required for investigations.

security aws tools automation
1 source 2 reports 91d ago

AWS Releases Spring 2026 SOC Reports with 188 Services, Now in OSCAL Format

AWS has released its Spring 2026 System and Organization Controls (SOC) 1, 2, and 3 reports, covering 188 services. The SOC 1 and 2 reports are available in both PDF and OSCAL formats for the first time, enhancing automation and efficiency in compliance workflows. These reports provide AWS customers with assurance spanning April 2025 to March 2026, reflecting AWS's ongoing commitment to meeting cloud service compliance standards.

security aws cloud compliance oscal
1 source 1 report 91d ago

AWS Launches Continuum for Automated Security Vulnerability Management

AWS introduced Continuum for code vulnerabilities, designed to automate the security lifecycle from discovery to resolution. It aims to prioritize vulnerabilities using contextual data and machine reasoning, addressing the increasing backlog of threats facing enterprises.

security aws vulnerabilities machine-learning
1 source 1 report 91d ago

AWS security maturity roadmap provides phased improvement strategy

A new maturity roadmap for AWS security operations introduces a six-phase process aimed at improving security practices. By integrating AWS Security Hub and Amazon GuardDuty, organizations can enhance their threat detection and overall security posture.

security aws operations cloud
1 source 1 report 91d ago

Amazon Cognito enhances services with high-throughput, encryption, and replication features

Amazon Cognito has introduced high-throughput performance, customer-managed keys, and multi-Region replication capabilities. These enhancements support modern applications and improve data security and business continuity.

cloud amazon cognito security
More stories →