Search
Find merged stories by title or summary.
A decade of enterprise identity in the cloud with AWS Managed Microsoft AD
Ten years ago, we launched AWS Directory Service for Microsoft Active Directory , a fully managed Microsoft Active Directory in the AWS Cloud. In that original announcement, Jeff Barr described a straightforward promise: “You will spend less time administering and more time working on your applications and your business.” A decade later, AWS Managed Microsoft AD has become the identity backbone for thousands of enterprises worldwide. What started as a way to run directory-aware workloads in the cloud now powers SQL Server authentication, Amazon WorkSpaces virtual desktops, and Amazon FSx for Windows File Server for thousands of enterprises worldwide. The beginning: Solving a real customer problem In 2015, customers migrating Windows workloads to Amazon Web Services (AWS) faced a familiar challenge.
Securing your Amazon S3 buckets: Identifying and remediating over-permissioned access
Misconfigured Amazon Simple Storage Service (Amazon S3) buckets can expose your data to unauthorized access. Without proactive review, S3 bucket policies or Access Control Lists (ACLs) configured with broad access may go unnoticed in your environment. In this post, you learn how to identify and fix over-permissioned S3 buckets across your AWS environment, along with best practice recommendations and automation opportunities to help you prevent security gaps. This post provides a workflow framework and methodology recommendations for your security team to adapt. The focus of this post is on the what and why rather than a prescriptive implementation. You will need to customize the approach based on your organization’s requirements and existing security tooling.
Route Amazon Bedrock Guardrails interventions to Amazon Security Lake
Security teams investigating AI-related incidents need guardrail intervention data alongside their existing security telemetry. Routing Amazon Bedrock Guardrails violations to Amazon Security Lake makes this possible. With this integration, you can query guardrail events alongside identity, network, and application security data in a single layer. When a guardrail blocks a prompt injection attempt or redacts sensitive data, that intervention carries investigative value comparable to a failed sign-in or a network intrusion alert. Amazon Bedrock publishes this telemetry to Amazon CloudWatch metrics and model invocation logs for operational monitoring. By using Security Lake, organizations can extend this telemetry into their security data lake for unified correlation.
Caching KMS data keys in multi-thread environments: Per-tenant encryption for event-driven systems at scale
This post assumes familiarity with envelope encryption and the AWS Encryption SDK . When your encryption system generates millions of duplicate API calls per hour, costs spiral and performance degrades. That’s exactly the challenge NICE Actimize faced while operating their global-scale, event-driven financial crime detection platform on Amazon Web Services (AWS) . NICE Actimize, a leading provider of financial crime, risk, and compliance solutions, processes millions of encrypted messages daily across hundreds of tenants. By rethinking how they cache encryption keys, they reduced their AWS Key Management Service (AWS KMS) costs by 77% while maintaining strict security guarantees and per-tenant encryption isolation. In this post, we explore the cache stampede problem that emerges when envelope encryption meets high-concurrency, multi-tenant architectures.
AirPods Pro 3 plunge to $189 at Amazon, 30-day best price
Amazon has launched a steeper AirPods Pro 3 discount this August, dropping the earbuds to a 30-day low of $189.99. Grab AirPods Pro 3 at a 30-day low price of $189. 99. Amazon has dropped AirPods Pro 3 down to $189. 99 , reflecting a $60 discount off the premium earbuds. This is the lowest price we've seen since Prime Day 2026. Buy AirPods Pro 3 for $189.99 Continue Reading on AppleInsider • Discuss on our Forums
Amazon and Apple impersonated in “$149.99 unauthorized charge” scam
If you’ve spent any time browsing lately, you may have run into a full-screen popup warning you that your Apple ID or Amazon account was just used for a mysterious $149. 99 purchase. It looks urgent. It looks official. And if you look at two examples side by side, it becomes obvious that it’s neither. Below are two popups pulled from real pages—one dressed up as Apple Support, one as Amazon. Same con, two costumes Below, one popup is skinned as Apple Support, the other as Amazon. Swap the logo and color palette and the structure is identical: a warning icon, a claim that a $149. 99 purchase was just made “via Pre-Authorization,” and a phone number to call immediately. That phone number is exactly the same in both. Fake Apple alert Fake Amazon alert That reused phone number is the tell.
From 2 weeks to 2 minutes: Amazon Cognito launches Provisioned limits for self-service rate limit management
Imagine preparing for your biggest sales event of the year, and you want to ensure your customer identity management service can handle the elevated traffic for carrying out application activities. For security teams, business leaders, and technologists managing identity infrastructure at scale, this scenario has been all too familiar. Whether you’re a CISO evaluating security controls, a CFO managing cloud costs, traditional support ticket processes for adjusting Amazon Cognito rate limits meant waiting 10–14 days for capacity increases, requiring teams to plan weeks in advance or rush to escalate. Today, we’re announcing provisioned limits for Amazon Cognito, a capability that transforms how you manage authentication rate limits.
AWS Security Hub Adds Socket for Supply Chain Security
Amazon Web Services (AWS) customers can now adopt Socket directly through the AWS Security Hub Extended plan, apply committed AWS spend, and start with the first month free. Socket covers supply chain security in the program, with deep behavioral analysis that catches malicious packages signature-based tools miss. Supply chain security in the Extended plan # The AWS Security Hub Extended plan brings curated third-party security tools into AWS across 10 security categories, with pay-as-you-go pricing and no required upfront commitment. Socket adds supply chain security to that lineup, with a focus on catching malicious open source packages. Open source is where most modern applications get built, and it is also where attackers now go first.
Spring 2026 PCI DSS and PCI 3DS compliance packages for AWS now available
Amazon Web Services (AWS) is pleased to announce the successful completion of our Payment Card Industry (PCI) Data Security Standard (DSS) and Three Domain Secure (3DS) certifications. As part of this renewal, we have expanded the scope to include three additional AWS services and one additional AWS Region: Newly added AWS services: • Amazon Bedrock AgentCore • AWS Parallel Computing Service • AWS Skill Builder Newly added AWS Region: • Asia Pacific – New Zealand This certification means that customers can use these services while maintaining PCI DSS and PCI 3DS compliance, enabling innovation without compromising security. The full list of services can be found on the AWS Services in Scope by Compliance Program page .
Extend Amazon Inspector SBOM Generator with Plugins
Amazon Inspector is an automated vulnerability management service that continually scans Amazon Web Services (AWS) workloads for software vulnerabilities. The vulnerability management capabilities of Amazon Inspector are powered by an asset inventory engine known as the Amazon Inspector SBOM Generator (inspector-sbomgen), a standalone command-line tool that produces a software bill of materials (SBOM) from container images, directories, archives, local systems, compiled binaries, and more. Over the past two years, we’ve expanded inspector-sbomgen’s coverage across dozens of programming language ecosystems, operating systems, and widely deployed applications.
Read This Before You Buy That TV Streaming Stick
Security experts have been sounding the alarm for years about the risks of using generic TV boxes that promise unlimited content streaming for a one-time fee, warning that they secretly rent the user’s Internet connection out to strangers. But a groundbreaking new analysis finds these devices also routinely spoof themselves as mobile phones clicking ads on AI-generated websites as part of a sprawling operation that seeks to defraud online merchants and advertising networks. Pedro Falé is a threat researcher with the security firm Bitsight . Falé told KrebsOnSecurity he was able to peer inside a vast and complex ad fraud network by registering an expired domain name that was used to coordinate fake ad clicks across a particularly popular brand of these streaming devices known as H96 . An H96 TV streaming device currently advertised for sale on Amazon.
Amazon pins multiple open source compromises on North Korea
Amazon threat researchers found one threat actor behind four distinct open source compromises, including the March 2026 incident affecting the axios NPM library
Magnet Forensics Invites You To Share Your Thoughts On The Current State Of Enterprise DFIR
Help shape the future of enterprise DFIR by sharing your insights in Magnet Forensics’ annual survey by August 31, 2026, and receive early access to the findings – plus a chance to win one of two $500 Amazon gift cards.
Amazon identifies North Korean hacker group behind open-source supply chain attacks
Amazon is sharing new findings about how a threat actor linked to the Democratic People’s Republic of Korea (DPRK) is targeting open source software libraries, the shared building blocks that companies around the world use to develop applications. Amazon Threat Intelligence has linked several recent compromises of popular Node Package Manager (NPM) libraries to the same DPRK-linked threat actor, a connection that hasn’t been publicly reported until now. The analysis also describes how generative AI is already changing what malicious software packages look like and how threat actors are beginning to probe AI-based code systems. We’re sharing this research to help the open source community and security teams better identify and address these types of events.
Secure your npm and pip package updates in Amazon Linux
If you use and install packages from npm or PyPI, the first hours after a package is published are the riskiest because scanners can’t analyze packages before publication. Recent supply chain events affecting NodeJS and Python packages have been detected and removed within hours. However, while those packages were available to the general public, it’s possible that they were installed by users, creating the potential for a security incident. As you will see from the data that follows, if users had waited 1 day before accessing those packages, none of the recent supply chain security events would have had an impact. In this post, I show you a one-line configuration that you can use to eliminate this exposure in your environment: a dependency cooldown for npm and pip.
AWS KMS or AWS CloudHSM: Choose the right key management solution
Choosing the right cryptographic key management service on Amazon Web Services (AWS) starts with understanding the difference between AWS Key Management Service (AWS KMS) and AWS CloudHSM . Both provide key storage backed by a hardware security module (HSM) but serve very different needs. AWS KMS is a fully managed service that integrates with all AWS services and all AWS Regions, making it the right choice for most key management workloads. AWS CloudHSM is a specialized option for use cases where you have strict requirements for dedicated HSM instances or must support legacy applications built around traditional HSM interfaces. Quick comparison The following table shows the pricing, AWS Region availability, algorithms, and AWS service integrations as of July 2026.
2026 Phase 1a IRAP report is now available on AWS Artifact for Australian customers
Amazon Web Services (AWS) is excited to announce that the latest version of Information Security Registered Assessors Program (IRAP) report (Phase 1a – full assessment) is now available through AWS Artifact . An independent Australian Signals Directorate (ASD) certified IRAP assessor completed the IRAP assessment of AWS in June 2026. The new IRAP report includes four additional AWS services that are now assessed at the PROTECTED level under IRAP. This brings the total number of services assessed at the PROTECTED level to 167. The four newly assessed services are: • Amazon Bedrock AgentCore • AWS Parallel Computing Service • AWS Resilience Hub • AWS Security Incident Response For the full list of services, see the IRAP tab on the AWS Services in Scope by Compliance Program page.
Announcing the Cloud Security Alliance on AWS Compliance Guide
AWS Security Assurance Services is announcing the release of the Cloud Security Alliance (CSA) Compliance Guide on Amazon Web Service (AWS) , a new resource that maps the 17 control domains and 207 control objectives of the Cloud Controls Matrix v4. 1 (CCM) to AWS services and recommended implementation practices. The guide is intended to help organizations using AWS plan, implement, and evidence the controls relevant to their CCM scope, including those pursuing or maintaining CSA STAR certification. What is the Cloud Controls Matrix? The Cloud Security Alliance is a not-for-profit organization dedicated to defining and raising awareness of best practices for cloud security. AWS maintains CSA STAR Level 2 certification , which couples the requirements of ISO/IEC 27001:2022 with the CCM.
Accelerating AWS Network Firewall troubleshooting with AWS DevOps Agent
When an administrator introduces a rule change in AWS Network Firewall and network connectivity is disrupted, pinpointing the cause requires inspecting multiple points in the traffic path. The firewall gives you stateless and stateful rule engines, domain rules, and routing to the firewall endpoint inside your Amazon Virtual Private Cloud (Amazon VPC) . A network drop looks the same from the workload no matter where it started. Isolating the cause means correlating the alert and flow logs with the firewall configuration, route tables, and recent API calls in AWS CloudTrail that might have changed them. That manual correlation is exactly where AWS DevOps Agent helps, accelerating root cause analysis so you can restore connectivity in minutes instead of hours. AWS DevOps Agent does that correlation for you.
Enterprise security at machine speed: AWS Black Hat 2026 preview
Black Hat 2026 (Aug 1-6, 2026) brings together over 22,000 security practitioners, researchers, and CISOs who build, break, and defend enterprise infrastructure. They’re security professionals who push the limits of offensive and defensive security and demand proof over promises. As frontier security models like Mythos reshape the enterprise landscape, they need security that operates at the same speed as the events they face. This August, Amazon Web Services (AWS) returns to Las Vegas to meet with our customers and partners to show how we’re delivering enterprise security at machine speed. At Black Hat USA 2026 , connect with AWS through live demos, a practitioner session on autonomous security operations, and an executive roundtable on building durable AI security architectures, plus networking receptions with customers and partners. Here’s where to find us and what you’ll take away.
Lessons Learned from CISA’s Recent GitHub Leak
The Cybersecurity and Infrastructure Security Agency (CISA) has issued a postmortem on a recent data leak in which a contractor published dozens of internal CISA credentials — including AWS Govcloud keys — in a public GitHub repository for almost six months before being notified by KrebsOnSecurity. Experts say the gaps identified in the agency’s initial response provide important lessons that all security teams should absorb. On May 15, 2026, the security firm GitGuardian asked for help in notifying CISA about the existence of a public GitHub repository called “Private CISA” that included 844 MB of sensitive CISA-related data. One of the exposed files, titled “importantAWStokens,” included the administrative credentials to three Amazon AWS GovCloud servers. Another file — “AWS-Workspace-Firefox-Passwords.
Apache ActiveMQ Exploit Leads to LockBit Ransomware
Key Takeaways An audio version of this report can be found on Spotify, Apple, YouTube, Audible, & Amazon. This intrusion began in mid-February 2024 after a threat actor exploited a vulnerability (CVE-2023-46604) on an exposed Apache ActiveMQ server. The threat actor was able to perform remote code execution (RCE) by using a Java Spring class and a custom Java Spring […] The post Apache ActiveMQ Exploit Leads to LockBit Ransomware appeared first on The DFIR Report .
AgentHopper: An AI Virus
As part of the Month of AI Bugs, serious vulnerabilities that allow remote code execution via indirect prompt injection were discovered. There was a period of a few weeks where multiple arbitrary code execution vulnerabilities existed in popular agents, like GitHub Copilot, Amazon Q, AWS Kiro,… During that time I was wondering if it would be possible to write an AI virus. Hence the idea of AgentHopper was born.
Amazon Q Developer for VS Code Vulnerable to Invisible Prompt Injection
The Amazon Q Developer VS Code Extension (Amazon Q) is a very popular coding agent, with over 1 million downloads . In previous posts we showed how prompt injection vulnerabilities in Amazon Q could lead to: • Exfiltration of sensitive information from the user’s machine , and also to a • System compromise by running arbitrary code Today we will show how an attack can leverage invisible Unicode Tag characters that humans cannot see. However, the AI will interpret them as instructions, and this can be used to invoke tools and other nefarious actions.
Amazon Q Developer: Remote Code Execution with Prompt Injection
The Amazon Q Developer VS Code Extension (Amazon Q) is a popular coding agent, with over 1 million downloads . The extension is vulnerable to indirect prompt injection, and in this post we discuss a vulnerability that allowed an adversary (or also the AI for that matter) to run arbitrary commands on the host without the developer’s consent. The resulting impact of the vulnerability is the same as CVE-2025-53773 that Microsoft fixed in GitHub Copilot, however AWS did not issue a CVE when patching the vulnerabili
Amazon Q Developer: Secrets Leaked via DNS and Prompt Injection
The next three posts will cover high severity vulnerabilities in the Amazon Q Developer VS Code Extension (Amazon Q Developer), which is a very popular coding agent, with over 1 million downloads. It is vulnerable to prompt injection from untrusted data and its security depends heavily on model behavior. At a high level Amazon Q Developer can leak sensitive information from a developer’s machine, e. g. API keys, to external servers via DNS requests. An adversary can also exploit this behavior during an indirect
