AWS

AWS spent years rebuilding its routing control plane without taking the network down

AWS spent years rebuilding its routing control plane without taking the network down 2026-09-09 at 07:52 By Anamarija Pogorelec Every AWS API call, CloudFront video stream, and Route 53 lookup crosses the same infrastructure, which AWS calls its border network. It now runs on a routing system rebuilt from scratch over several years. The system […]

AWS spent years rebuilding its routing control plane without taking the network down Read More »

Your AI agent’s system prompt is not a security control

Your AI agent’s system prompt is not a security control 2026-09-03 at 10:53 By Anamarija Pogorelec An AI agent told in its system prompt to show a user only what that user is cleared to see will hand over more the moment someone talks it into doing so. Gee Rittenhouse, who oversees Security Hub, GuardDuty, […]

Your AI agent’s system prompt is not a security control Read More »

DuckDB stays open source while the team behind it goes to work for Amazon

DuckDB stays open source while the team behind it goes to work for Amazon 2026-09-02 at 09:29 By Anamarija Pogorelec Hannes Mühleisen and Mark Raasveldt started as AWS employees. The two built DuckDB, an analytical database that runs inside your process instead of on a server somebody has to administer. If you ship anything on […]

DuckDB stays open source while the team behind it goes to work for Amazon Read More »

AWS Console Private Access can block sign-ins to personal accounts

AWS Console Private Access can block sign-ins to personal accounts 2026-08-31 at 14:57 By Anamarija Pogorelec The AWS Management Console now loads inside a network with no path to the public internet. Console Private Access became generally available on August 28 for virtual private clouds, the isolated networks customers run inside AWS, that have no […]

AWS Console Private Access can block sign-ins to personal accounts Read More »

AWS makes it easier to spot firewall rules that have gone quiet

AWS makes it easier to spot firewall rules that have gone quiet 2026-08-24 at 07:00 By Anamarija Pogorelec AWS Network Firewall’s rule hit count capability gives security teams visibility into which stateful firewall rules are matching traffic, helping them identify unused or redundant rules and validate whether security controls are working as intended. The capability […]

AWS makes it easier to spot firewall rules that have gone quiet Read More »

AWS limits AI agents’ data access, even when manipulated

AWS limits AI agents’ data access, even when manipulated 2026-08-20 at 14:17 By Anamarija Pogorelec AWS has detailed an approach for propagating user authorization context through AI agents, allowing access controls to be enforced by infrastructure and downstream services rather than relying on the agent itself. Customers using Amazon Bedrock AgentCore can build AI agents […]

AWS limits AI agents’ data access, even when manipulated Read More »

AWS Certificate Manager sets 2027 end date for email-validated certificate renewals

AWS Certificate Manager sets 2027 end date for email-validated certificate renewals 2026-08-14 at 11:25 By Anamarija Pogorelec AWS Certificate Manager (ACM) will phase out email validation for public certificates throughout 2027, ahead of the Certification Authority/Browser (CA/B) Forum’s March 15, 2028 deadline for ending email-based domain validation. The CA/B Forum sets standards that browsers and […]

AWS Certificate Manager sets 2027 end date for email-validated certificate renewals Read More »

Weak IAM affects up to 98% of cloud environments

Weak IAM affects up to 98% of cloud environments 2026-08-14 at 08:00 By Anamarija Pogorelec Misconfiguration remains one of the leading threats to cloud environments because a single configuration error can result in public network access, unrotated keys, missing encryption, exposed services, and logging gaps. CISA now mandates baseline cloud configuration practices for US federal […]

Weak IAM affects up to 98% of cloud environments Read More »

AWS to retire Shield Advanced L7 automatic mitigation on January 1, 2027

AWS to retire Shield Advanced L7 automatic mitigation on January 1, 2027 2026-07-28 at 12:23 By Anamarija Pogorelec AWS Shield Advanced, a managed service that protects applications from external threats, is adding the Anti-DDoS managed rule group, designed for application-layer (L7) DDoS protection, to eligible web access control lists (ACLs) in Count mode. The addition […]

AWS to retire Shield Advanced L7 automatic mitigation on January 1, 2027 Read More »

Claude Opus 5 sharpens coding and cybersecurity work on AWS

Claude Opus 5 sharpens coding and cybersecurity work on AWS 2026-07-27 at 01:30 By Anamarija Pogorelec Claude Opus 5 went live on Amazon Bedrock and Claude Platform on AWS. Anthropic says the model improves on Claude Opus 4.8’s cyber capabilities, coding through cybersecurity. Anyone with an AWS account in a supported region can call it. […]

Claude Opus 5 sharpens coding and cybersecurity work on AWS Read More »

AWS wants GuardDuty to automate the first steps of threat investigations

AWS wants GuardDuty to automate the first steps of threat investigations 2026-07-21 at 12:14 By Anamarija Pogorelec Amazon GuardDuty investigation agent is now in public preview. The feature provides AI-powered investigations of GuardDuty findings, AWS accounts and AWS organizations, helping security teams reduce investigation time. During the public preview, the investigation agent is available at […]

AWS wants GuardDuty to automate the first steps of threat investigations Read More »

AWS retools Security Hub for AI and multicloud threats

AWS retools Security Hub for AI and multicloud threats 2026-07-15 at 11:56 By Anamarija Pogorelec AWS added AI workload protection and Microsoft Azure security monitoring to Security Hub, its centralized security platform for collecting and prioritizing security findings across cloud environments. Support for additional cloud platforms will follow. “Collecting findings was never the hard part. […]

AWS retools Security Hub for AI and multicloud threats Read More »

“Context bombs” can frustrate AI-driven attacks, researchers found

“Context bombs” can frustrate AI-driven attacks, researchers found 2026-07-14 at 15:27 By Zeljka Zorz A new approach tried out by Tracebit researchers has proven very effective at stopping AI agents from fully compromising targeted environments. What makes it notable isn’t the technique – prompt injection is old news – but the direction it’s pointed: not […]

“Context bombs” can frustrate AI-driven attacks, researchers found Read More »

Cynative: Open-source deep research agent

Cynative: Open-source deep research agent 2026-07-13 at 09:00 By Mirko Zorz Running a large language model against a live cloud account to hunt for security holes comes with an obvious hazard. An agent that holds real credentials and a mandate to poke around can delete a bucket, flip a permission, or leak a secret on […]

Cynative: Open-source deep research agent Read More »

AWS gives its ERP agent deny-by-default rules and a separate identity

AWS gives its ERP agent deny-by-default rules and a separate identity 2026-07-10 at 08:00 By Sinisa Markovic Accounts receivable teams at large companies spend hours each day matching incoming bank payments to invoices by hand. When those payments sit unmatched for days, cash flow suffers and days sales outstanding climbs. The same pattern repeats across […]

AWS gives its ERP agent deny-by-default rules and a separate identity Read More »

AWS centralizes access, spending, and governance for Claude

AWS centralizes access, spending, and governance for Claude 2026-07-09 at 11:37 By Anamarija Pogorelec Claude apps gateway for AWS is a self-hosted control plane that gives organizations a single point of control over access, costs, and policies for Claude Code and Claude Desktop. It replaces per-developer cloud credentials, manual distribution of managed settings to developer […]

AWS centralizes access, spending, and governance for Claude Read More »

AWS Continuum brings AI models to code vulnerability management

AWS Continuum brings AI models to code vulnerability management 2026-06-18 at 07:33 By Sinisa Markovic AWS Continuum for code vulnerabilities, a system built to handle a vulnerability across its lifecycle, from discovery through to a fix, is now available in gated preview. It reasons over a customer’s environment, confirms which findings are real, and works […]

AWS Continuum brings AI models to code vulnerability management Read More »

The assembly line behind 1.5 million malicious domains

The assembly line behind 1.5 million malicious domains 2026-06-12 at 11:07 By Anamarija Pogorelec Attackers registered roughly 1.5 million malicious domains during the first five months of 2026. The registration patterns resemble industrial output. Most of the domains were created by attackers, put to use within weeks, and concentrated among a small set of registrars, […]

The assembly line behind 1.5 million malicious domains Read More »

OpenAI brings frontier AI to existing AWS environments

OpenAI brings frontier AI to existing AWS environments 2026-06-02 at 11:55 By Anamarija Pogorelec OpenAI frontier models and Codex are now available on AWS, giving customers access to OpenAI capabilities within AWS environments and the controls needed to move more quickly from evaluation to deployment. OpenAI capabilities on Amazon Bedrock These capabilities are available through […]

OpenAI brings frontier AI to existing AWS environments Read More »

Zapier exploit chain shows how known anti-patterns compose into critical risk

Zapier exploit chain shows how known anti-patterns compose into critical risk 2026-05-28 at 16:00 By Mirko Zorz A five-stage exploit chain disclosed by Token Security researchers turned a free Zapier account into write access on Zapier’s public developer SDK packages and on internal packages that load in every authenticated zapier.com session. Each link in the […]

Zapier exploit chain shows how known anti-patterns compose into critical risk Read More »

Scroll to Top