As firewall rule sets grow in complexity, security teams face a common challenge: manual log analysis is used to determine which rules are actively…
Category: AWS Security Blog
Propagate user authorization context in AI agents with Amazon Bedrock AgentCore
Many teams now deploy AI agents that pull from Amazon DynamoDB tables, document repositories, software as a service (SaaS) platforms, and internal…
Implement custom authentication for tools integration using request Lambda interceptor in AgentCore Gateway
When deploying AI agents with Amazon Bedrock AgentCore, organizations benefit from built-in modern support for OAuth 2.0, AWS Identity and Access…
Security Hub Extended adds Supply Chain Security as its tenth category
Since February, we’ve grown AWS Security Hub Extended from 14 curated partners across 9 categories to 23 partners across 10. At Black Hat this month, 14…
Updates to your AWS Sign-In experience
Amazon Web Services (AWS) is gradually introducing updates to the AWS Sign-In and sign-up experience to a limited number of customers. We’re sharing these…
AWS Certificate Manager will discontinue email validation to prove domain validation for certificates
Today, we’re announcing that AWS Certificate Manager (ACM) will discontinue support for email-validated public certificates by September 30, 2027. If you…
Landing Zone Accelerator Independent Assessment Report for C5:2020 now available on AWS Artifact
Organizations operating in Germany and across Europe increasingly need to demonstrate cloud security compliance under the Cloud Computing Compliance…
Summer 2026 SOC 1 report is now available with 185 services in scope
Amazon Web Services (AWS) is pleased to announce that the Summer 2026 System and Organization Controls (SOC) 1 report is now available. The reports cover…
AWS successfully completed its 2025-26 NHS DSPT assessment
Amazon Web Services (AWS) is pleased to announce its successful completion of the 2025-26 NHS Data Security and Protection Toolkit (NHS DSPT) assessment…
How AWS IAM role manager rethinks the starting point for IAM roles
When you build a new application or capability on Amazon Web Services (AWS), you want to focus on what you’re building. Getting a service running almost…
Landing Zone Accelerator Independent Assessment Report for C5:2020 now available on AWS Artifact
Organizations operating in Germany and across Europe increasingly need to demonstrate cloud security compliance under the Cloud Computing Compliance…
Summer 2026 SOC 1 report is now available with 185 services in scope
Amazon Web Services (AWS) is pleased to announce that the Summer 2026 System and Organization Controls (SOC) 1 report is now available. The reports cover…
AWS successfully completed its 2025-26 NHS DSPT assessment
Amazon Web Services (AWS) is pleased to announce its successful completion of the 2025-26 NHS Data Security and Protection Toolkit (NHS DSPT) assessment…
AWS completes the 2026 Police-Assured Secure Facilities (PASF) audit in Europe (London)
We’re excited to announce that our Europe (London) AWS Region has renewed its accreditation for United Kingdom (UK) Police-Assured Secure Facilities…
2026 AWS CyberVadis report now available for due diligence on third-party suppliers
We’re excited to announce that Amazon Web Services (AWS) has completed theCyberVadis assessment of its security posture with the highest score (Mature) in…
A decade of enterprise identity in the cloud with AWS Managed Microsoft AD
Ten years ago, we launched AWS Directory Service for Microsoft Active Directory, a fully managed Microsoft Active Directory in the AWS Cloud. In that…
Securing your Amazon S3 buckets: Identifying and remediating over-permissioned access
Misconfigured Amazon Simple Storage Service (Amazon S3) buckets can expose your data to unauthorized access. Without proactive review, S3 bucket policies…
Automate certificates with ACME support in AWS Certificate Manager
Customers tell us that managing TLS certificates at scale is one of their biggest operational concerns. The Certification Authority Browser Forum…
Route Amazon Bedrock Guardrails interventions to Amazon Security Lake
Security teams investigating AI-related incidents need guardrail intervention data alongside their existing security telemetry. Routing Amazon Bedrock…
Caching KMS data keys in multi-thread environments: Per-tenant encryption for event-driven systems at scale
This post assumes familiarity with envelope encryption and the AWS Encryption SDK. When your encryption system generates millions of duplicate API calls…
