AWS

AWS limits AI agents’ data access, even when manipulated

AWS limits AI agents’ data access, even when manipulated 2026-08-20 at 14:17 By Anamarija Pogorelec AWS has detailed an approach for propagating user authorization context through AI agents, allowing access controls to be enforced by infrastructure and downstream services rather than relying on the agent itself. Customers using Amazon Bedrock AgentCore can build AI agents […]

AWS limits AI agents’ data access, even when manipulated Read More »

AWS Certificate Manager sets 2027 end date for email-validated certificate renewals

AWS Certificate Manager sets 2027 end date for email-validated certificate renewals 2026-08-14 at 11:25 By Anamarija Pogorelec AWS Certificate Manager (ACM) will phase out email validation for public certificates throughout 2027, ahead of the Certification Authority/Browser (CA/B) Forum’s March 15, 2028 deadline for ending email-based domain validation. The CA/B Forum sets standards that browsers and

AWS Certificate Manager sets 2027 end date for email-validated certificate renewals Read More »

Weak IAM affects up to 98% of cloud environments

Weak IAM affects up to 98% of cloud environments 2026-08-14 at 08:00 By Anamarija Pogorelec Misconfiguration remains one of the leading threats to cloud environments because a single configuration error can result in public network access, unrotated keys, missing encryption, exposed services, and logging gaps. CISA now mandates baseline cloud configuration practices for US federal

Weak IAM affects up to 98% of cloud environments Read More »

AWS to retire Shield Advanced L7 automatic mitigation on January 1, 2027

AWS to retire Shield Advanced L7 automatic mitigation on January 1, 2027 2026-07-28 at 12:23 By Anamarija Pogorelec AWS Shield Advanced, a managed service that protects applications from external threats, is adding the Anti-DDoS managed rule group, designed for application-layer (L7) DDoS protection, to eligible web access control lists (ACLs) in Count mode. The addition

AWS to retire Shield Advanced L7 automatic mitigation on January 1, 2027 Read More »

Claude Opus 5 sharpens coding and cybersecurity work on AWS

Claude Opus 5 sharpens coding and cybersecurity work on AWS 2026-07-27 at 01:30 By Anamarija Pogorelec Claude Opus 5 went live on Amazon Bedrock and Claude Platform on AWS. Anthropic says the model improves on Claude Opus 4.8’s cyber capabilities, coding through cybersecurity. Anyone with an AWS account in a supported region can call it.

Claude Opus 5 sharpens coding and cybersecurity work on AWS Read More »

AWS wants GuardDuty to automate the first steps of threat investigations

AWS wants GuardDuty to automate the first steps of threat investigations 2026-07-21 at 12:14 By Anamarija Pogorelec Amazon GuardDuty investigation agent is now in public preview. The feature provides AI-powered investigations of GuardDuty findings, AWS accounts and AWS organizations, helping security teams reduce investigation time. During the public preview, the investigation agent is available at

AWS wants GuardDuty to automate the first steps of threat investigations Read More »

AWS retools Security Hub for AI and multicloud threats

AWS retools Security Hub for AI and multicloud threats 2026-07-15 at 11:56 By Anamarija Pogorelec AWS added AI workload protection and Microsoft Azure security monitoring to Security Hub, its centralized security platform for collecting and prioritizing security findings across cloud environments. Support for additional cloud platforms will follow. “Collecting findings was never the hard part.

AWS retools Security Hub for AI and multicloud threats Read More »

“Context bombs” can frustrate AI-driven attacks, researchers found

“Context bombs” can frustrate AI-driven attacks, researchers found 2026-07-14 at 15:27 By Zeljka Zorz A new approach tried out by Tracebit researchers has proven very effective at stopping AI agents from fully compromising targeted environments. What makes it notable isn’t the technique – prompt injection is old news – but the direction it’s pointed: not

“Context bombs” can frustrate AI-driven attacks, researchers found Read More »

Cynative: Open-source deep research agent

Cynative: Open-source deep research agent 2026-07-13 at 09:00 By Mirko Zorz Running a large language model against a live cloud account to hunt for security holes comes with an obvious hazard. An agent that holds real credentials and a mandate to poke around can delete a bucket, flip a permission, or leak a secret on

Cynative: Open-source deep research agent Read More »

AWS gives its ERP agent deny-by-default rules and a separate identity

AWS gives its ERP agent deny-by-default rules and a separate identity 2026-07-10 at 08:00 By Sinisa Markovic Accounts receivable teams at large companies spend hours each day matching incoming bank payments to invoices by hand. When those payments sit unmatched for days, cash flow suffers and days sales outstanding climbs. The same pattern repeats across

AWS gives its ERP agent deny-by-default rules and a separate identity Read More »

AWS centralizes access, spending, and governance for Claude

AWS centralizes access, spending, and governance for Claude 2026-07-09 at 11:37 By Anamarija Pogorelec Claude apps gateway for AWS is a self-hosted control plane that gives organizations a single point of control over access, costs, and policies for Claude Code and Claude Desktop. It replaces per-developer cloud credentials, manual distribution of managed settings to developer

AWS centralizes access, spending, and governance for Claude Read More »

AWS Continuum brings AI models to code vulnerability management

AWS Continuum brings AI models to code vulnerability management 2026-06-18 at 07:33 By Sinisa Markovic AWS Continuum for code vulnerabilities, a system built to handle a vulnerability across its lifecycle, from discovery through to a fix, is now available in gated preview. It reasons over a customer’s environment, confirms which findings are real, and works

AWS Continuum brings AI models to code vulnerability management Read More »

The assembly line behind 1.5 million malicious domains

The assembly line behind 1.5 million malicious domains 2026-06-12 at 11:07 By Anamarija Pogorelec Attackers registered roughly 1.5 million malicious domains during the first five months of 2026. The registration patterns resemble industrial output. Most of the domains were created by attackers, put to use within weeks, and concentrated among a small set of registrars,

The assembly line behind 1.5 million malicious domains Read More »

OpenAI brings frontier AI to existing AWS environments

OpenAI brings frontier AI to existing AWS environments 2026-06-02 at 11:55 By Anamarija Pogorelec OpenAI frontier models and Codex are now available on AWS, giving customers access to OpenAI capabilities within AWS environments and the controls needed to move more quickly from evaluation to deployment. OpenAI capabilities on Amazon Bedrock These capabilities are available through

OpenAI brings frontier AI to existing AWS environments Read More »

Zapier exploit chain shows how known anti-patterns compose into critical risk

Zapier exploit chain shows how known anti-patterns compose into critical risk 2026-05-28 at 16:00 By Mirko Zorz A five-stage exploit chain disclosed by Token Security researchers turned a free Zapier account into write access on Zapier’s public developer SDK packages and on internal packages that load in every authenticated zapier.com session. Each link in the

Zapier exploit chain shows how known anti-patterns compose into critical risk Read More »

Amazon Quick authorization bypass let users reach blocked AI chat agents

Amazon Quick authorization bypass let users reach blocked AI chat agents 2026-05-12 at 20:12 By Mirko Zorz Enterprises running Amazon Quick, the AWS business intelligence and agentic AI service, rely on a feature called custom permissions to restrict who inside an account can use AI chat agents. Fog Security founder Jason Kao discovered that those

Amazon Quick authorization bypass let users reach blocked AI chat agents Read More »

25 open-source cybersecurity tools that don’t care about your budget

25 open-source cybersecurity tools that don’t care about your budget 2026-04-27 at 10:30 By Anamarija Pogorelec Regardless of the operating system you use, managing secrets, apps, cloud, compliance, and security operations can be overwhelming. The free, open-source tools presented in this article can help you detect threats, increase visibility, enforce controls, and investigate and respond

25 open-source cybersecurity tools that don’t care about your budget Read More »

AWS, Wasabi, Cloudflare, and Backblaze go head-to-head in new cloud storage test

AWS, Wasabi, Cloudflare, and Backblaze go head-to-head in new cloud storage test 2026-04-03 at 01:25 By Anamarija Pogorelec Cloud storage buyers rarely get vendor-provided performance data that includes the vendor’s own weak spots. Backblaze’s Q1 2026 Performance Stats report, attempts to do exactly that, sharing benchmark results for Backblaze B2, AWS S3, Cloudflare R2, and

AWS, Wasabi, Cloudflare, and Backblaze go head-to-head in new cloud storage test Read More »

Amazon sends AI agents into pen testing and DevOps

Amazon sends AI agents into pen testing and DevOps 2026-03-31 at 20:31 By Sinisa Markovic Amazon’s latest AI capabilities bring on-demand penetration testing through the AWS Security Agent, alongside the AWS DevOps Agent. “These agents are changing the way we secure and operate software. AWS Security Agent compresses penetration testing timelines from 2-6 weeks to

Amazon sends AI agents into pen testing and DevOps Read More »

TeamPCP Moves From OSS to AWS Environments

TeamPCP Moves From OSS to AWS Environments 2026-03-31 at 17:42 By Ionut Arghire After validating stolen credentials using TruffleHog, the hacking group started AWS services enumeration and lateral movement activities. The post TeamPCP Moves From OSS to AWS Environments appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

TeamPCP Moves From OSS to AWS Environments Read More »

Scroll to Top