AWS News - 2026-05-14
2026-05-14
最終更新: 2026-05-15 07:06:49 JST
AI による概要
この日はセキュリティと生成AIエージェントの話題が中心でした。セキュリティ速報ではLinuxカーネルの権限昇格 問題であるCopy.fail/DirtyFragクラス(CVE-2026-43284)と、その関連のFragnesia(CVE-2026-46300、 espintcp経由。Amazon Linuxは非対象)に関する2件の速報が公表され、パッチ適用が推奨されました。 セキュリティブログではAWS Payment CryptographyのPCI PIN/P2PE準拠、責任あるAI導入のためのGRCガイド更新、 GuardDutyによる暗号通貨マイニング検知が解説。機械学習ブログではNova 2 Sonicとの音声ストリーミング、 CiscoとのMCP/A2Aエージェント保護、Databricks Unity CatalogとSageMakerでのLLMファインチューニングなどが 公開されました。サービス面ではFSx for OpenZFSが共有VPCでのMulti-AZ作成に対応、SageMaker Data AgentがIAM Identity Centerドメインに対応、CloudFrontがmTLS向けOCSP失効確認に対応。日本語ではハノーバーメッセ2026の ブースレポートやSAPPHIRE 2026でのSAP協業拡大も紹介されています。
主要トピック
セキュリティ速報: Linuxカーネル権限昇格 Copy.fail/DirtyFrag、Fragnesia(CVE-2026-46300)
AWSセキュリティ: Payment CryptographyのPCI準拠、GuardDutyによるマイニング検知
生成AI: Nova 2 Sonic音声ストリーミング、CiscoとのMCP/A2Aエージェント保護
サービス拡張: FSx for OpenZFS共有VPC Multi-AZ、SageMaker Data AgentのIdC対応
CloudFront: viewer mTLS向けOCSP失効確認に対応
日本語: ハノーバーメッセ2026、SAPPHIRE 2026でのSAP協業
AWS What's New
Amazon FSx for OpenZFS now supports creating Multi-AZ file systems in shared VPCs
- Link: https://aws.amazon.com/about-aws/whats-new/2026/05/amazon-fsx-openzfs-multi-az-vpcs/
- Published: 2026-05-14 04:00:00
- Fetched: 2026-05-14 07:06:54
Amazon FSx for OpenZFS now allows you to create Multi-AZ file systems in shared VPCs within your AWS organization, making it easier for you to decentralize network and storage administration.
VPC sharing is a feature that allows resource owners ("owner accounts") to share one or more VPC subnets with other accounts ("participant accounts") in their AWS organization. Participant accounts can then view, create, modify, delete, and manage their application resources in the subnets shared with them. Previously, participant accounts could create Single-AZ OpenZFS file systems in VPCs shared with them, but could only create Multi-AZ file systems in VPCs they owned. Starting today, participant accounts can create any FSx for OpenZFS file system in a shared VPC, allowing organizations to run highly available file systems with centralized network management.
You can create Multi-AZ FSx for OpenZFS file systems from shared VPC participant accounts in all AWS Regions where Amazon FSx for OpenZFS is available. To learn more, visit the FSx for OpenZFS documentation and the FSx for OpenZFS product page.
Amazon CloudFront announces support for OCSP Revocation for Mutual TLS (Viewer)
- Link: https://aws.amazon.com/about-aws/whats-new/2026/05/amazon-cloudfront-ocsp-tls/
- Published: 2026-05-14 06:05:00
- Fetched: 2026-05-15 07:06:49
Amazon CloudFront now supports Online Certificate Status Protocol (OCSP) revocation checking for viewer mTLS, enabling you to validate client certificate revocation status in real time during connection establishment. This enables customers using mutual TLS (mTLS) on CloudFront to verify that client certificates haven't been revoked before accepting connections—a common requirement for regulated industries and zero-trust architectures.
Previously, customers implemented certificate revocation using CloudFront Functions and KeyValueStore, maintaining static revocation lists that were only as current as the last manual update. With OCSP, CloudFront queries the responder URL embedded in the client certificate at connection time, validating revocation status directly with the issuing Certificate Authority. CloudFront caches OCSP responses for up to 30 minutes to minimize latency impact on subsequent connections. The OCSP result is exposed in the connection function, enabling customers to implement custom logic—such as grace periods for certificate rotation, IP-based exceptions, or combining OCSP with their own revocation lists.
OCSP revocation checking for viewer mTLS is available at no additional cost. To learn more, visit CloudFront mutual TLS (viewer).
Amazon SageMaker Data Agent now available for IAM Identity Center domains
- Link: https://aws.amazon.com/about-aws/whats-new/2026/05/amazon-sagemaker-data-agent-idc/
- Published: 2026-05-14 06:53:00
- Fetched: 2026-05-14 11:47:46
Amazon SageMaker Data Agent is now available in SageMaker Unified Studio domains configured with IAM Identity Center. Data Agent extends its AI-powered capabilities to help data analysts and engineers streamline their analytics workflows across both SageMaker notebooks and Query Editor environments, eliminating the need to manually write complex SQL joins, aggregations, and Python code.
With Data Agent, you can describe your analysis goals in plain English and receive working Python or SQL code tailored to your connected data sources, including Amazon Athena, Amazon Redshift, Amazon S3, and AWS Glue Data Catalog. The agent maintains conversational context across notebook cells, selected tables, and query history, proposing step-by-step plans before generating code. Use it to calculate quarterly revenue growth rates, generate visualizations, transform DataFrames, or optimize query performance—all through natural language interaction. The "Fix with AI" feature provides intelligent debugging by analyzing execution errors and suggesting corrections, accelerating your development cycle.
This capability is available in all commercial AWS Regions where Amazon SageMaker Unified Studio is supported. To get started, navigate to a project in SageMaker Unified Studio, open a notebook or Query Editor, and select the Data Agent panel. To learn more, visit the Amazon SageMaker Unified Studio page and refer to "Use the SageMaker Data Agent" in the Amazon SageMaker Unified Studio User Guide.
AWS RTB Fabric supports custom domains for real-time bidding workloads
- Link: https://aws.amazon.com/about-aws/whats-new/2026/05/aws-rtb-fabric-custom-domains/
- Published: 2026-05-14 21:00:00
- Fetched: 2026-05-15 05:26:12
詳細を表示
AWS RTB Fabric now supports custom domains for real-time bidding transactions received through external links. This capability helps advertising technology (AdTech) companies preserve their public endpoints and use owned domains—without requiring their partners to update their endpoint configurations.
Endpoints (like bid.company.com/path) for real-time bidding workloads are typically representative of established, long-term traffic contracts. Modifying these endpoints requires coordination across multiple organizations, applications, and domains—which can slow set up between AdTech partners. With custom domains, AdTech companies can use their own domain name system (DNS) and configure canonical name (CNAME) public endpoints. They can also define routing rules to direct traffic to specific RTB Fabric links based on URL patterns. For example, a demand side platform (DSP) or supply side platform (SSP) can point their existing DNS server to RTB Fabric and define routing rules to map URL patterns to specific traffic sources. This allows them to seamlessly route all partner traffic through RTB Fabric without altering their own endpoint configurations. Supply partners also do not need to change their configurations.
AWS RTB Fabric helps you connect with your AdTech partners such as Amazon Ads, GumGum, Kargo, MobileFuse, Sovrn, TripleLift, Viant, Yieldmo, and more in three steps while delivering single-digit millisecond latency through a private, high-performance network environment. RTB Fabric reduces standard cloud networking costs by up to 80% and does not require upfront commitments. This capability is available in all AWS Regions where AWS RTB Fabric is supported: US East (N. Virginia), US West (Oregon), Asia Pacific (Singapore), Asia Pacific (Tokyo), Europe (Frankfurt), and Europe (Ireland). To learn more, visit the documentation or AWS RTB Fabric product page.
AWS Japan Blog
Hannover Messe 2026 AWS ブースレポート
- Link: https://aws.amazon.com/jp/blogs/news/hannover-messe-2026-aws-booth-report/
- Published: 2026-05-14 07:55:41
- Fetched: 2026-05-14 08:53:33
Amazon Aurora スナップショットから Amazon Aurora DSQL へのデータ移行
- Link: https://aws.amazon.com/jp/blogs/news/migrating-data-from-an-amazon-aurora-snapshot-into-amazon-aurora-dsql/
- Published: 2026-05-14 09:00:05
- Fetched: 2026-05-14 11:47:47
「人がいない」を、AIが埋める ── 養鶏・防災・建設・化学の中堅・中小企業4社が示すDX最前線
- Link: https://aws.amazon.com/jp/blogs/news/scale-customer-study-blog-2026/
- Published: 2026-05-14 11:21:59
- Fetched: 2026-05-14 11:47:47
データレイククエリエンジンが統合された AWS Graviton ベースの RG インスタンスが Amazon Redshift に導入されました
- Link: https://aws.amazon.com/jp/blogs/news/amazon-redshift-introduces-aws-graviton-based-rg-instances-with-an-integrated-data-lake-query-engine/
- Published: 2026-05-14 15:27:55
- Fetched: 2026-05-14 18:31:18
SAPPHIRE 2026: AWS が SAP のお客様のより迅速な移行とさらなる構築を支援
- Link: https://aws.amazon.com/jp/blogs/news/sapphire-2026-how-aws-is-helping-sap-customers-move-faster-and-build-more/
- Published: 2026-05-14 17:15:34
- Fetched: 2026-05-14 18:31:18
AWS Security Blog
PCI PIN and P2PE compliance packages for AWS Payment Cryptography are now available
- Link: https://aws.amazon.com/blogs/security/pci-pin-and-p2pe-compliance-packages-for-aws-payment-cryptography-are-now-available/
- Published: 2026-05-14 01:16:38
- Fetched: 2026-05-14 03:53:58
Introducing the updated AWS User Guide to Governance, Risk, and Compliance for Responsible AI Adoption
- Link: https://aws.amazon.com/blogs/security/introducing-the-updated-aws-user-guide-to-governance-risk-and-compliance-for-responsible-ai-adoption/
- Published: 2026-05-14 04:07:42
- Fetched: 2026-05-14 05:28:47
Detecting and preventing crypto mining in your AWS environment
- Link: https://aws.amazon.com/blogs/security/detecting-and-preventing-crypto-mining-in-your-aws-environment/
- Published: 2026-05-14 06:47:27
- Fetched: 2026-05-14 07:06:55
AWS Security Bulletins
Ongoing updates on Copy.fail and variants
- Link: https://aws.amazon.com/security/security-bulletins/rss/2026-030-aws/
- Published: 2026-05-14 11:15:52
- Fetched: 2026-05-14 11:47:47
Bulletin ID: 2026-030-AWS
Scope: AWS
Content Type: Important (requires attention)
Publication Date: 05/13/2026 10:00 PM PDT
This is an ongoing issue. This bulletin will be updated as more information becomes available.
Description:
AWS is aware of the copy.fail or DirtyFrag class of issues - a set of privilege escalation issues affecting the Linux Kernel. We will update this bulletin as more information becomes available.
Please see below for current patching timelines for affected services related to the Copy.fail kernel issue and all its variants. AWS recommends that customers apply all updates addressing these issues as soon as they are available.
See more details at Security Bulletin (ID: 2026-030-AWS).
Fragnesia Local Privilege Escalation report via ESP-in-TCP in the Linux Kernel
- Link: https://aws.amazon.com/security/security-bulletins/rss/2026-029-aws/
- Published: 2026-05-14 11:17:18
- Fetched: 2026-05-14 11:47:47
Bulletin ID: 2026-029-AWS
Scope: AWS
Content Type: Important (requires attention)
Publication Date: 05/13/2026 18:45 PM PDT
This is an ongoing issue. Information is subject to change. Please refer to our Security Bulletin (ID: 2026-030-AWS) for the most updated patching information.
Description:
Amazon is aware of CVE-2026-46300, a report of an additional privilege escalation issue in the Linux kernel related to the DirtyFrag, copy.fail class of issues (CVE-2026-43284). The proof of concept uses a vector via the loadable module espintcp. Amazon Linux does not provide this module, and is not affected.
As defense in depth we will include a correctness patch to the core networking code to harden against possible similar issues in network protocol implementations that rely on this behavior.
AWS Architecture Blog
Streaming CloudWatch metrics to VPC-based OpenTelemetry collectors using Lambda
- Link: https://aws.amazon.com/blogs/architecture/streaming-cloudwatch-metrics-to-vpc-based-opentelemetry-collectors-using-lambda/
- Published: 2026-05-14 00:45:50
- Fetched: 2026-05-14 01:15:22
AWS Machine Learning Blog
Fine-tune LLM with Databricks Unity Catalog and Amazon SageMaker AI
- Link: https://aws.amazon.com/blogs/machine-learning/fine-tune-llm-with-databricks-unity-catalog-and-amazon-sagemaker-ai/
- Published: 2026-05-14 02:22:42
- Fetched: 2026-05-14 03:53:59
Securing AI agents: How AWS and Cisco AI Defense scale MCP and A2A deployments
- Link: https://aws.amazon.com/blogs/machine-learning/securing-ai-agents-how-aws-and-cisco-ai-defense-scale-mcp-and-a2a-deployments/
- Published: 2026-05-14 02:33:16
- Fetched: 2026-05-14 03:53:59
Build real-time voice streaming applications with Amazon Nova Sonic and WebRTC
- Link: https://aws.amazon.com/blogs/machine-learning/build-real-time-voice-streaming-applications-with-amazon-nova-sonic-and-webrtc/
- Published: 2026-05-14 02:46:19
- Fetched: 2026-05-14 03:53:59
Build financial document processing with Pulse AI and Amazon Bedrock
- Link: https://aws.amazon.com/blogs/machine-learning/build-financial-document-processing-with-pulse-ai-and-amazon-bedrock/
- Published: 2026-05-14 03:00:06
- Fetched: 2026-05-14 03:53:59