AWS Security

AWS Security Blog The latest AWS security, identity, and compliance launches, announcements, and how-to posts.

  • We invited a direct competitor into Security Hub Extended. Here’s why.
    by Michael Fuller on August 31, 2026 at 7:00 pm

    When customers keep pointing you to a solution that overlaps with parts of your own offering, you have a choice to make. This post is about the choice we made with Upwind, and why we’d make it again. AWS Security Hub Extended exists because customers told us what was working for them in enterprise security

  • Automate IAM Identity Center governance with continuous discovery and reporting
    by Jonathan Nguyen on August 31, 2026 at 5:18 pm

    AWS IAM Identity Center integrates with external identity provider (IdP) to provide customers with a centralized authentication and authorization solution for AWS resources across AWS Organizations. AWS continues to invest into IAM Identity Center with a growing number of AWS services that natively integrate with IAM Identity Center. As your AWS organization scales, maintaining visibility

  • Extend your data perimeter to the AWS Management Console with Private Access
    by Madhur Kulkarni on August 28, 2026 at 6:53 pm

    Organizations in regulated industries such as financial services, government, defense, and healthcare restrict their sensitive workloads to isolated network environments with no access to the public internet. Until now, customers could restrict AWS Management Console access to authorized AWS accounts and corporate networks, but the console itself required internet connectivity. This was creating tension between

  • Extend Amazon Bedrock Guardrails to Tool Interactions Using the Strands Agents SDK
    by Stephan Traub on August 27, 2026 at 4:20 pm

    If you’re running AI agents in production, Amazon Bedrock Guardrails protects the model boundary. But your agents also invoke tools, fetch external data, and communicate with other systems. That data flows outside the model boundary, where model-level guardrails can’t reach. You can extend guardrail coverage to those interactions using three validation checkpoints built with the

  • ICYMI: July 2026 @AWS Security
    by Rodolfo Brenes on August 26, 2026 at 7:32 pm

    If you found time for a bit of vacation this summer, you might be in catch-up mode. Here’s a list to help: all the expert blog posts, new service capabilities, code samples, and workshops, in case you missed it, from July 2026. AWS Security Blog post This month’s AWS Security Blog posts covered AI agent

  • Detecting multi-stage attacks on AWS: A guide to cross-service signal correlation
    by Nisha Kashyap on August 26, 2026 at 5:39 pm

    A single alert from one security service tells you something happened. Read that signal alongside activity from other services and your own business context, and you will know whether what happened is part of a multi-stage attack. Consider a short sequence. An identity calls GetCallerIdentity from a source address it hasn’t previously used. Within minutes,

  • Fast Track ISM-ready cloud environments and IRAP Assessments with Landing Zone Accelerator on AWS
    by Kevin Donohue on August 25, 2026 at 9:53 pm

    This post announces the availability of a new independent assessment report available on AWS Artifact analyzing how Landing Zone Accelerator on AWS (LZA) can automatically deploy multi-account environments in Amazon Web Services (AWS) with Australian Government Information Security Manual (ISM) security controls coverage at scale. The report includes findings from an independent third-party analysis conducted

  • AWS Network Firewall now supports rule hit count
    by Preetkumar Shah on August 20, 2026 at 6:40 pm

    As firewall rule sets grow in complexity, security teams face a common challenge: manual log analysis is used to determine which rules are actively matching traffic and which are consuming capacity without being triggered. This lack of visibility creates operational and compliance gaps. Organizations with governance policies that require removal of dormant rules after a

  • Propagate user authorization context in AI agents with Amazon Bedrock AgentCore
    by Anshu Bathla on August 19, 2026 at 5:24 pm

    Many teams now deploy AI agents that pull from Amazon DynamoDB tables, document repositories, software as a service (SaaS) platforms, and internal knowledge bases to answer questions and automate workflows. A key risk in these deployments is that the agent has no awareness of who’s asking, so it might return data the user shouldn’t see.

  • Implement custom authentication for tools integration using request Lambda interceptor in AgentCore Gateway
    by Nishant Mainro on August 18, 2026 at 8:46 pm

    When deploying AI agents with Amazon Bedrock AgentCore, organizations benefit from built-in modern support for OAuth 2.0, AWS Identity and Access Management (IAM), and API key authentication through Amazon Bedrock AgentCore Gateway. However, some enterprise environments still use legacy authentication mechanisms such as HTTP Basic Authentication (Basic Auth) (RFC 7617). The extensible architecture of AgentCore

  • Security Hub Extended adds Supply Chain Security as its tenth category
    by Michael Fuller on August 18, 2026 at 5:04 pm

    Since February, we’ve grown AWS Security Hub Extended from 14 curated partners across 9 categories to 23 partners across 10. At Black Hat this month, 14 of those partners were at the Amazon Web Services (AWS) booth demoing live. Four of those partners delivered theater talks and ten were featured on SecurityLive streaming. We hosted

  • Updates to your AWS Sign-In experience
    by Vaibhav Chowla on August 17, 2026 at 5:22 pm

    Amazon Web Services (AWS) is gradually introducing updates to the AWS Sign-In and sign-up experience to a limited number of customers. We’re sharing these changes so you will know what to expect as we gradually make the updated experience available to more customers. These updates include new options for creating and accessing AWS accounts. To

  • AWS Certificate Manager will discontinue email validation to prove domain validation for certificates
    by Adam Aboudi on August 13, 2026 at 9:23 pm

    Today, we’re announcing that AWS Certificate Manager (ACM) will discontinue support for email-validated public certificates by September 30, 2027. If you use email validation for your ACM public certificates, you need to migrate to DNS validation before that date. This change aligns with the Certification Authority/Browser (CA/B) Forum’s industry-wide deprecation of email-based domain validation and

  • How AWS IAM role manager rethinks the starting point for IAM roles
    by Zach Jiang on August 12, 2026 at 10:16 pm

    When you build a new application or capability on Amazon Web Services (AWS), you want to focus on what you’re building. Getting a service running almost always begins with AWS Identity and Access Management (IAM). Many AWS services that act on your behalf need an IAM role, an identity the service assumes to access your

  • Landing Zone Accelerator Independent Assessment Report for C5:2020 now available on AWS Artifact
    by Kevin Donohue on August 11, 2026 at 9:50 pm

    Organizations operating in Germany and across Europe increasingly need to demonstrate cloud security compliance under the Cloud Computing Compliance Criteria Catalogue (C5:2020), published by Germany’s Federal Office for Information Security (BSI). Last year, we introduced Landing Zone Accelerator on AWS support for digital sovereignty and today we’re announcing the availability of a new independent assessment

  • Summer 2026 SOC 1 report is now available with 185 services in scope
    by Baj Bajwa on August 11, 2026 at 6:53 pm

    Amazon Web Services (AWS) is pleased to announce that the Summer 2026 System and Organization Controls (SOC) 1 report is now available. The reports cover 185 services over the 12-month period from July 1, 2025–June 30, 2026, giving customers a full year of assurance. These reports demonstrate our continuous commitment to adhering to the heightened

  • AWS successfully completed its 2025-26 NHS DSPT assessment
    by Tariro Dongo on August 11, 2026 at 4:12 pm

    Amazon Web Services (AWS) is pleased to announce its successful completion of the 2025-26 NHS Data Security and Protection Toolkit (NHS DSPT) assessment audit and achieving a status of Standards Exceeded. The NHS DSPT is an assessment that allows organizations to measure their performance against the National Data Guardian’s 10 data security standards. All organizations

  • AWS completes the 2026 Police-Assured Secure Facilities (PASF) audit in Europe (London)
    by Tariro Dongo on August 10, 2026 at 8:21 pm

    We’re excited to announce that our Europe (London) AWS Region has renewed its accreditation for United Kingdom (UK) Police-Assured Secure Facilities (PASF) for Official-Sensitive data. Since 2017, the Amazon Web Services (AWS) Europe (London) Region has been accredited under the PASF program. This demonstrates our continuous commitment to adhere to the heightened expectations of customers

  • 2026 AWS CyberVadis report now available for due diligence on third-party suppliers
    by Tariro Dongo on August 10, 2026 at 5:09 pm

    We’re excited to announce that Amazon Web Services (AWS) has completed theCyberVadis assessment of its security posture with the highest score (Mature) in all assessed areas. This demonstrates our continued commitment to meet the heightened expectations for cloud service providers. Customers can now use the 2026 AWS CyberVadis report and scorecard to reduce their supplier

  • A decade of enterprise identity in the cloud with AWS Managed Microsoft AD
    by Vladimir Provorov on August 7, 2026 at 7:37 pm

    Ten years ago, we launched AWS Directory Service for Microsoft Active Directory, a fully managed Microsoft Active Directory in the AWS Cloud. In that original announcement, Jeff Barr described a straightforward promise: “You will spend less time administering and more time working on your applications and your business.” A decade later, AWS Managed Microsoft AD

Share Websitecyber
We are an ethical website cyber security team and we perform security assessments to protect our clients.