AWS Security Blog The latest AWS security, identity, and compliance launches, announcements, and how-to posts.
- OSPAR 2026 report now available with 167 services in scopeby James Chang on September 4, 2026 at 6:13 pm
We’re pleased to confirm the successful completion of our annual Amazon Web Services (AWS) Outsourced Service Provider’s Audit Report (OSPAR) assessment on July 29, 2026, in line with the OSPAR version 2.0 framework. The Association of Banks in Singapore (ABS) established the Guidelines on Control Objectives and Procedures for Outsourced Service Providers (ABS Guidelines) to
- Incident response guide for AWS CloudTrail investigations – Part 2by Oscar Diaz on September 3, 2026 at 9:15 pm
In Part 1 of this guide, we examined two common incident scenarios: cross-account Amazon Simple Storage Service (Amazon S3) data deletion with ransomware implications, and cryptocurrency mining deployed through AWS CloudFormation using exposed AWS Management Console credentials. We also introduced key incident response terminology and investigative frameworks for analyzing AWS CloudTrail events. In this second
- Incident response guide for AWS CloudTrail investigations – Part 1by Oscar Diaz on September 3, 2026 at 9:15 pm
AWS CloudTrail logs contain the evidence you need when investigating suspicious activity in your AWS environment, but knowing which fields matter and how to interpret them can mean the difference between surface-level analysis and uncovering the full scope of an incident. This guide walks you through real-world scenarios, showing you how to analyze CloudTrail events
- Managing identity source transition for AWS IAM Identity Centerby Xiaoxue Xu on September 2, 2026 at 8:36 pm
September 2, 2026: This post was republished to include Active Directory migration strategies and automation for permission sets. AWS IAM Identity Center manages user access to Amazon Web Services (AWS) resources, including both AWS accounts and applications. You can use IAM Identity Center to create and manage user identities within the Identity Center identity store
- Agentic security: Detection and response at machine speedby Gee Rittenhouse on September 2, 2026 at 6:36 pm
After talking with enterprise security leaders over the past year, one thing has become clear: the rise of autonomous AI agents is the most significant shift in security posture since the move to cloud. Organizations across every industry are adopting AI agents that authenticate on behalf of users, execute multistep workflows, and make decisions across
- We invited a direct competitor into Security Hub Extended. Here’s why.by Michael Fuller on August 31, 2026 at 7:00 pm
When customers keep pointing you to a solution that overlaps with parts of your own offering, you have a choice to make. This post is about the choice we made with Upwind, and why we’d make it again. AWS Security Hub Extended exists because customers told us what was working for them in enterprise security
- Automate IAM Identity Center governance with continuous discovery and reportingby Jonathan Nguyen on August 31, 2026 at 5:18 pm
AWS IAM Identity Center integrates with external identity provider (IdP) to provide customers with a centralized authentication and authorization solution for AWS resources across AWS Organizations. AWS continues to invest into IAM Identity Center with a growing number of AWS services that natively integrate with IAM Identity Center. As your AWS organization scales, maintaining visibility
- Extend your data perimeter to the AWS Management Console with Private Accessby Madhur Kulkarni on August 28, 2026 at 6:53 pm
Organizations in regulated industries such as financial services, government, defense, and healthcare restrict their sensitive workloads to isolated network environments with no access to the public internet. Until now, customers could restrict AWS Management Console access to authorized AWS accounts and corporate networks, but the console itself required internet connectivity. This was creating tension between
- Extend Amazon Bedrock Guardrails to Tool Interactions Using the Strands Agents SDKby Stephan Traub on August 27, 2026 at 4:20 pm
If you’re running AI agents in production, Amazon Bedrock Guardrails protects the model boundary. But your agents also invoke tools, fetch external data, and communicate with other systems. That data flows outside the model boundary, where model-level guardrails can’t reach. You can extend guardrail coverage to those interactions using three validation checkpoints built with the
- ICYMI: July 2026 @AWS Securityby Rodolfo Brenes on August 26, 2026 at 7:32 pm
If you found time for a bit of vacation this summer, you might be in catch-up mode. Here’s a list to help: all the expert blog posts, new service capabilities, code samples, and workshops, in case you missed it, from July 2026. AWS Security Blog post This month’s AWS Security Blog posts covered AI agent
- Detecting multi-stage attacks on AWS: A guide to cross-service signal correlationby Nisha Kashyap on August 26, 2026 at 5:39 pm
A single alert from one security service tells you something happened. Read that signal alongside activity from other services and your own business context, and you will know whether what happened is part of a multi-stage attack. Consider a short sequence. An identity calls GetCallerIdentity from a source address it hasn’t previously used. Within minutes,
- Fast Track ISM-ready cloud environments and IRAP Assessments with Landing Zone Accelerator on AWSby Kevin Donohue on August 25, 2026 at 9:53 pm
This post announces the availability of a new independent assessment report available on AWS Artifact analyzing how Landing Zone Accelerator on AWS (LZA) can automatically deploy multi-account environments in Amazon Web Services (AWS) with Australian Government Information Security Manual (ISM) security controls coverage at scale. The report includes findings from an independent third-party analysis conducted
- AWS Network Firewall now supports rule hit countby Preetkumar Shah on August 20, 2026 at 6:40 pm
As firewall rule sets grow in complexity, security teams face a common challenge: manual log analysis is used to determine which rules are actively matching traffic and which are consuming capacity without being triggered. This lack of visibility creates operational and compliance gaps. Organizations with governance policies that require removal of dormant rules after a
- Propagate user authorization context in AI agents with Amazon Bedrock AgentCoreby Anshu Bathla on August 19, 2026 at 5:24 pm
Many teams now deploy AI agents that pull from Amazon DynamoDB tables, document repositories, software as a service (SaaS) platforms, and internal knowledge bases to answer questions and automate workflows. A key risk in these deployments is that the agent has no awareness of who’s asking, so it might return data the user shouldn’t see.
- Implement custom authentication for tools integration using request Lambda interceptor in AgentCore Gatewayby Nishant Mainro on August 18, 2026 at 8:46 pm
When deploying AI agents with Amazon Bedrock AgentCore, organizations benefit from built-in modern support for OAuth 2.0, AWS Identity and Access Management (IAM), and API key authentication through Amazon Bedrock AgentCore Gateway. However, some enterprise environments still use legacy authentication mechanisms such as HTTP Basic Authentication (Basic Auth) (RFC 7617). The extensible architecture of AgentCore
- Security Hub Extended adds Supply Chain Security as its tenth categoryby Michael Fuller on August 18, 2026 at 5:04 pm
Since February, we’ve grown AWS Security Hub Extended from 14 curated partners across 9 categories to 23 partners across 10. At Black Hat this month, 14 of those partners were at the Amazon Web Services (AWS) booth demoing live. Four of those partners delivered theater talks and ten were featured on SecurityLive streaming. We hosted
- Updates to your AWS Sign-In experienceby Vaibhav Chowla on August 17, 2026 at 5:22 pm
Amazon Web Services (AWS) is gradually introducing updates to the AWS Sign-In and sign-up experience to a limited number of customers. We’re sharing these changes so you will know what to expect as we gradually make the updated experience available to more customers. These updates include new options for creating and accessing AWS accounts. To
- AWS Certificate Manager will discontinue email validation to prove domain validation for certificatesby Adam Aboudi on August 13, 2026 at 9:23 pm
Today, we’re announcing that AWS Certificate Manager (ACM) will discontinue support for email-validated public certificates by September 30, 2027. If you use email validation for your ACM public certificates, you need to migrate to DNS validation before that date. This change aligns with the Certification Authority/Browser (CA/B) Forum’s industry-wide deprecation of email-based domain validation and
- How AWS IAM role manager rethinks the starting point for IAM rolesby Zach Jiang on August 12, 2026 at 10:16 pm
When you build a new application or capability on Amazon Web Services (AWS), you want to focus on what you’re building. Getting a service running almost always begins with AWS Identity and Access Management (IAM). Many AWS services that act on your behalf need an IAM role, an identity the service assumes to access your
- Landing Zone Accelerator Independent Assessment Report for C5:2020 now available on AWS Artifactby Kevin Donohue on August 11, 2026 at 9:50 pm
Organizations operating in Germany and across Europe increasingly need to demonstrate cloud security compliance under the Cloud Computing Compliance Criteria Catalogue (C5:2020), published by Germany’s Federal Office for Information Security (BSI). Last year, we introduced Landing Zone Accelerator on AWS support for digital sovereignty and today we’re announcing the availability of a new independent assessment






















