AWS News - 2026-06-30
2026-06-30
最終更新: 2026-07-08 07:57:16 JST
AI による概要
この日はアーキテクチャ、セキュリティ、AI エージェント運用と幅広いトピックが揃いました。アーキテクチャブログでは、100 万個超の Lambda 関数へのスケール事例 (scale-to-zero やクォータ管理の教訓)、SageMaker AI での機械学習環境のデータ持ち出し防止、Nakama ゲームサーバーの Cognito 二要素トークン認証が解説されました。AI 領域では Bedrock AgentCore Observability による本番エージェントのデバッグ、Nova 2 Lite と Claude Sonnet 4.6 を組み合わせた低コスト文書処理、行レベルセキュリティを備えたマルチテナント LLM 分析が取り上げられました。注目は GovCloud での Claude Opus 4.8 提供開始、および多数の AWS サービスのメンテナンス移行・サンセット (Bedrock Agents Classic 化、Kendra、Q Business など) を告知した Service Availability Updates です。セキュリティでは AWS WAF の HTTP/2 マルチフレーム検査に関する CVE (2026-13762/13763) が公表されました。日本語では ElastiCache 向け Valkey 9.1、Kiro の Agent Focus・GitLab 対応、AWS 認定の再認定新方式が紹介されました。なお、この日付のエントリーには後日取得された AWS Security Hub のマルチクラウド対応も含まれます。Security Hub が Microsoft Azure のリソースを監視対象に加え、リスク分析・クラウドセキュリティ態勢管理・脆弱性管理・セキュリティ対応管理を AWS と Azure の両方にまたがって扱えるようになりました。両クラウドで別々のセキュリティツールを運用していた環境を単一の体験に統合できます。
主要トピック
大規模サーバーレス: 100 万 Lambda 関数へのスケール教訓、SageMaker AI でのデータ持ち出し防止アーキテクチャ
AI エージェント運用: Bedrock AgentCore Observability による本番エージェントのデバッグ、AgentCore Gateway への AWS WAF 保護 GA
コスト最適化 AI: Nova 2 Lite + Claude Sonnet 4.6 の二段パイプライン、マルチテナント LLM の行レベルセキュリティ
モデル/サービス動向: GovCloud で Claude Opus 4.8 提供開始、Kiro に GPT-5.4・Nemotron 3 Super 120B 追加
サービスライフサイクル: Bedrock Agents の Classic 化、Kendra・Q Business・Simple AD 等がメンテナンス/サンセットへ
セキュリティ: AWS WAF の HTTP/2 マルチフレーム検査に関する CVE-2026-13762/13763 公表 (CloudFront はサーバー側修正済)
国内: ElastiCache 向け Valkey 9.1、コンソールアクセスのネットワーク制限 (Sign-In リソースベースポリシー/RCP)、AWS 認定再認定の新方式
マルチクラウド: Security Hub が Microsoft Azure のリソース監視に対応、AWS と Azure のリスクを単一の体験で検出・対応
AWS What's New
Amazon MWAA Serverless now supports shared VPC configurations
- Link: https://aws.amazon.com/about-aws/whats-new/2026/06/amazon-mwaa-serverless-vpc/
- Published: 2026-06-30 02:19:00
- Fetched: 2026-06-30 06:22:18
Amazon Managed Workflows for Apache Airflow (Amazon MWAA) Serverless now supports shared VPC subnets. Previously, customers using subnets shared via AWS Resource Access Manager (AWS RAM) received a validation error when creating MWAA Serverless workflows. With this update, MWAA Serverless correctly validates subnet ownership in shared VPC configurations, consistent with MWAA Provisioned environments.
Sharing VPC subnets across accounts using AWS RAM is a common pattern in multi-account landing zone architectures. Organizations that centrally manage networking can now launch MWAA Serverless workflows in member accounts using shared subnets — no workarounds required. Customers using Amazon SageMaker Unified Studio Workflows also benefit from this update when their projects are configured with shared VPC networking.
This update is available in all AWS Regions where Amazon MWAA Serverless is supported. To learn more, see the Networking section of the Amazon MWAA Serverless User Guide.
AWS WAF adds support for Amazon Bedrock AgentCore Gateway
- Link: https://aws.amazon.com/about-aws/whats-new/2026/06/aws-waf-amazon-bedrock-agentcore/
- Published: 2026-06-30 07:00:00
- Fetched: 2026-06-30 09:00:14
Today, AWS announces general availability of AWS Web Application Firewall (AWS WAF) protection for Amazon Bedrock AgentCore Gateway, enabling you to protect your agentic AI workloads from common web exploits and abuse. As enterprises move agentic applications from prototype to production, this launch gives security and platform teams ability to apply consistent, customizable web protections at the Gateway layer.
You can now associate an AWS WAF protection pack with your AgentCore Gateway to enforce IP-based access controls, rate-based rules that throttle abusive traffic, and AWS Managed Rule Groups including common rule sets, known bad inputs, and Bot Control. You configure the protection pack once at the Gateway level and AWS WAF applies it consistently to every target behind that Gateway, so a single configuration protects all downstream tools, agents, and integrations.
Support for AWS WAF on AgentCore Gateway is available in all AWS Regions where both AWS WAF and Amazon Bedrock AgentCore Gateway are available.
To learn more, see the AWS WAF Developer Guide and the Amazon Bedrock AgentCore documentation.
AWS Clean Rooms now supports intermediate tables for SQL
- Link: https://aws.amazon.com/about-aws/whats-new/2026/06/aws-clean-rooms-intermediate-tables
- Published: 2026-06-30 15:00:00
- Fetched: 2026-07-01 08:07:27
AWS Clean Rooms now supports intermediate tables for SQL queries, offering increased flexibility for organizations running complex, multi-step analytical workflows with their partners. With this launch, customers can write the results of a SQL query to an intermediate table within a collaboration for reuse in subsequent analyses. Intermediate tables enable multi-step analytical workflows — from reusing complex joins to building shared ID mapping tables for downstream analyses — all within the privacy boundary of the collaboration. For example, a publisher and an advertiser can join their first-party data to build an ID mapping table in a collaboration, then reuse it across reach, frequency, and attribution analyses, reducing costs and optimizing performance for the subsequent analyses.
AWS Clean Rooms helps companies and their partners easily analyze and collaborate on their collective datasets without revealing or copying one another’s underlying data. For more information about the AWS Regions where AWS Clean Rooms is available, see the AWS Regions table. To learn more about collaborating with AWS Clean Rooms, visit AWS Clean Rooms.
AWS Service Availability Updates
- Link: https://aws.amazon.com/about-aws/whats-new/2026/06/aws-service-availability/
- Published: 2026-06-30 16:00:00
- Fetched: 2026-07-01 04:49:42
詳細を表示
We’re announcing availability changes to the following AWS services and features.
Services moving to Maintenance
Services moving to maintenance will no longer be accessible to new customers starting July 30, 2026. Customers already using these services and features can continue to do so. AWS will continue to operate and support these services and features. We recommend that customers learn about the changes in the product pages and documentation.
· Amazon Bedrock Agents (launched November 2023) is now Amazon Bedrock Agents Classic
· AWS Directory Service – Simple AD
· AWS IoT Device Defender – Detect (feature will no longer be accessible to new customers starting August 31, 2026)
· AWS Mainframe Modernization – Self-Managed Experience
· AWS Management Console – myApplications
· AWS Resource Groups – Group Lifecycle Events
· AWS Service Catalog – Application Registry
· AWS Systems Manager – Application Manager
· Amazon SageMaker AI Features
o A2I
o Clarify
o Debugger
o Profiler
Services entering Sunset
The following services are entering sunset, and we are announcing the date upon which we will end operations and support of the service. Customers using these services should click on the links below to understand the sunset timeline and begin planning migration to alternatives as recommended in the updated service web pages and documentation.
· AWS Managed Services (AMS) Advanced
Services reaching End of Support
The following services have reached end of support and are no longer available as of June 30, 2026.
· Amazon Chime SDK – Carrier Voice Focus
· Amazon SageMaker AI – Ground Truth Plus
· AWS Elemental MediaLive and MediaPackage – ADC Regions
For customers affected by these changes, we've prepared comprehensive migration guides, and our support teams are ready to assist with your transition. Visit AWS Product Lifecycle Page to learn more, and subscribe to the RSS feed for future updates.
Amazon CloudWatch pipelines now supports processing and enriching OpenTelemetry metrics
- Link: https://aws.amazon.com/about-aws/whats-new/2026/06/cloudwatch-pipelines-otel-metrics
- Published: 2026-06-30 16:27:00
- Fetched: 2026-07-01 17:07:53
詳細を表示
Amazon CloudWatch pipelines now supports processing and enriching OpenTelemetry (OTel) metrics during ingestion. CloudWatch pipelines is a fully managed service that ingests, transforms, and routes telemetry data to CloudWatch without requiring you to manage infrastructure.
Until now, customers who needed to enrich or transform OTel metrics before storage had to build custom processing layers or modify application instrumentation at the source. With OTel metric processing in CloudWatch pipelines, you can apply metric transformations centrally as part of the ingestion path with no new infrastructure required. With CloudWatch pipelines, you can enrich metrics by adding business context such as team ownership, cost center, and environment tags to metrics from sources you cannot modify. You can strip high-cardinality labels from custom workloads to reduce storage costs, and rename metrics and attributes to enforce consistent naming conventions across your organization. Processing is applied transparently to matched metrics with no changes to application instrumentation required.
OTel metric processing for CloudWatch pipelines is available in all AWS Regions where CloudWatch pipelines and CloudWatch native OpenTelemetry metrics are supported. Processing of OTel metrics via pipelines is offered at no additional cost. Standard CloudWatch pricing for OTel metrics ingestion apply. For pricing details, see CloudWatch Pricing.
To get started, open the Amazon CloudWatch console, navigate to pipelines under Ingestion, and select CloudWatch Metrics (OTel) as the source. To learn more, see the CloudWatch pipelines documentation.
Amazon GameLift Servers announces DDoS Protection client SDKs for C# and Unity
- Link: https://aws.amazon.com/about-aws/whats-new/2026/06/amazon-gamelift-servers-ddos-protection-unity
- Published: 2026-06-30 17:00:00
- Fetched: 2026-07-01 08:07:27
Amazon GameLift Servers now offers DDoS Protection client SDKs for C# and Unity, helping game developers protect session-based multiplayer games against denial-of-service and distributed denial-of-service attacks. This feature co-locates a relay network directly alongside your game servers and uses access token-based authentication to ensure only authorized client traffic reaches your servers. Game developers building multiplayer experiences can now defend against targeted disruptions to specific players or entire game sessions.
DDoS Protection provides proactive UDP-based traffic protection with negligible latency and is available at no additional cost to Amazon GameLift Servers customers. The feature enforces per-player traffic limits to prevent disruptions even from seemingly legitimate sources, eliminating the need for manual byte matching. The new client SDKs for C# and Unity join existing support for C++ and Unreal Engine, giving developers flexibility to implement protection regardless of their game engine or language.
Amazon GameLift Servers DDoS Protection is available in US East (N. Virginia), US West (Oregon), Europe (Frankfurt), Europe (Ireland), Asia Pacific (Sydney), Asia Pacific (Tokyo), and Asia Pacific (Seoul). To learn more, visit the Amazon GameLift Servers documentation.
OpenAI GPT-5.4 and NVIDIA Nemotron 3 Super 120B now available on Kiro in AWS GovCloud (US-West) Region
- Link: https://aws.amazon.com/about-aws/whats-new/2026/06/kiro-gpt-nemotron-launch-aws-govcloud-us/
- Published: 2026-06-30 18:00:00
- Fetched: 2026-06-30 20:42:28
Two new models are now available in the Kiro IDE and CLI for the AWS GovCloud (US-West) Region.
OpenAI GPT-5.4 is now available in Kiro for complex reasoning, coding, document analysis, and multi-step agentic workflows. It helps developers build AI applications and production workflows that can interpret context, interact with tools, operate software environments, and verify outputs across multiple steps. GPT-5.4 runs on Amazon Bedrock's next-generation inference engine with isolated queues and durable execution for resilient workloads. Available with a 272K context window and 1.2x credit multiplier.
NVIDIA Nemotron 3 Super 120B is now available in Kiro as an open weight model option. A hybrid mixture-of-experts model activating only 12B of its 120B parameters for high compute efficiency and fast inference on agentic tasks. 256K context window with 32K max output. Available with a 0.25x credit multiplier.
Ensure your IDE or CLI is updated to the latest version, then restart it to access the new models from the model selector. For more details about Kiro in AWS GovCloud (US), visit the GovCloud documentation or contact your AWS account team for more information. To learn more about Kiro, visit the Kiro product page.
Claude Opus 4.8 is now available in AWS GovCloud (US)
- Link: https://aws.amazon.com/about-aws/whats-new/2026/05/claude-opus-4.8-aws-govcloud-us
- Published: 2026-06-30 21:00:00
- Fetched: 2026-06-30 23:10:24
AWS GovCloud (US) now offers Claude Opus 4.8 -- Anthropic's most capable generally available model to date -- delivering meaningful advances across agentic coding, professional knowledge work, and long-running autonomous tasks for developers and enterprises building production AI applications.
Claude Opus 4.8 can perform longer autonomous runs, deeper reasoning, and consistency to be trusted with production work. For coding, the Opus 4.8 reads codebases like an engineer, plans before it edits, and holds context across long sessions in real repositories. For agentic tasks, it is better at finding paths around obstacles instead of stalling, recovering from its own errors, and knowing when to ask for help versus when to keep going. For knowledge work, it better synthesizes across long documents and complex sources, self-checks its output, and delivers structured deliverables that hold up to review.
Amazon Bedrock keeps your data within AWS infrastructure and provides access to Claude Opus 4.8 through a unified service with AWS-managed features like Guardrails, Knowledge Bases, and regional data residency. To learn more, see Amazon Bedrock documentation and regional availability.
AWS Security Hub extends unified security management to Microsoft Azure
- Link: https://aws.amazon.com/about-aws/whats-new/2026/06/aws-security-hub-supports-monitoring-microsoft-azure/
- Published: 2026-06-30 21:21:00
- Fetched: 2026-07-08 07:57:16
詳細を表示
Today, AWS announces that AWS Security Hub now monitors Microsoft Azure resources, extending risk analytics, cloud security posture management, vulnerability management, and security response management across both clouds. Many AWS customers running workloads in AWS and Azure have had to operate separate security tools for each environment, making it difficult to prioritize risks holistically or respond consistently. Security Hub now provides a single, unified experience to detect and respond to risks across your AWS and Azure environments.
Security Hub automatically discovers Azure resources, including Azure Virtual Machines (VMs), Azure Container Registry (ACR) container images, Azure Function Apps, and Azure identities, and evaluates them for misconfigurations, internet exposure, and software vulnerabilities. You receive posture checks against security standards including the CIS Benchmarks™ for Microsoft Azure Foundations, unified resource inventory, risk and exposure analysis, and automated response through existing EventBridge integrations. AWS and Azure findings appear in the same prioritized view with the same finding formats and automation workflows, so security teams can operate from one console rather than switching between tools.
Security Hub includes an independent 30-day free trial to monitor Azure resources that begins once you create your integration with Microsoft Azure. After the trial, you pay the same price for monitoring Azure resources and equivalent AWS resources. You can create an integration to Azure from all AWS Regions where Security Hub is available except Middle East (UAE), Middle East (Bahrain), Asia Pacific (Taipei), and Asia Pacific (New Zealand). You can also create integrations to Microsoft Azure for AWS Security Hub CSPM for posture management checks and Amazon Inspector for vulnerability management independently from AWS Security Hub. To learn more, see AWS Security Hub Pricing and AWS Security Hub documentation.
AWS News Blog
AWS Weekly Roundup, Agentic CX designer for Amazon Connect Customer, EC2 AMI Watermarks, Open Governance for MySQL, and more (June 29, 2026)
- Link: https://aws.amazon.com/blogs/aws/aws-weekly-roundup-agentic-cx-designer-for-amazon-connect-customer-ec2-ami-watermarks-open-governance-for-mysql-and-more-june-29-2026/
- Published: 2026-06-30 01:30:30
- Fetched: 2026-06-30 02:32:44
AWS Weekly Roundup: Agentic CX designer for Amazon Connect Customer, EC2 AMI Watermarks, Open Governance for MySQL, and more (June 29, 2026)
- Link: https://aws.amazon.com/blogs/aws/aws-weekly-roundup-agentic-cx-designer-for-amazon-connect-customer-ec2-ami-watermarks-open-governance-for-mysql-and-more-june-29-2026/
- Published: 2026-06-30 01:30:30
- Fetched: 2026-06-30 09:00:14
AWS Japan Blog
接客スキルの属人化に悩む企業へ ― プリモグローバルホールディングスがAmazon Bedrock で実現した AI ロールプレイ研修
- Link: https://aws.amazon.com/jp/blogs/news/%E6%8E%A5%E5%AE%A2%E3%82%B9%E3%82%AD%E3%83%AB%E3%81%AE%E5%B1%9E%E4%BA%BA%E5%8C%96%E3%81%AB%E6%82%A9%E3%82%80%E4%BC%81%E6%A5%AD%E3%81%B8-%E2%80%95-%E3%83%97%E3%83%AA%E3%83%A2%E3%82%B0%E3%83%AD%E3%83%BC/
- Published: 2026-06-30 10:03:53
- Fetched: 2026-06-30 13:19:33
Amazon ElastiCache 向け Valkey 9.1 のお知らせ
- Link: https://aws.amazon.com/jp/blogs/news/announcing-valkey-9-1-for-amazon-elasticache/
- Published: 2026-06-30 10:25:49
- Fetched: 2026-06-30 13:19:33
【ベータ開始】AWS 認定を最新の状態に保つ新しい方法
- Link: https://aws.amazon.com/jp/blogs/news/a-new-way-to-keep-your-aws-certification-current/
- Published: 2026-06-30 14:18:39
- Fetched: 2026-06-30 17:27:00
1 つのタスク、2 つのプロバイダー(GitLab と GitHub) をまたぐ変更を 1 セッションで調整する
- Link: https://aws.amazon.com/jp/blogs/news/coordinating-changes-across-gitlab-and-github-in-one-session/
- Published: 2026-06-30 14:20:24
- Fetched: 2026-06-30 17:27:00
Agent Focus の紹介
- Link: https://aws.amazon.com/jp/blogs/news/introducing-agent-focus/
- Published: 2026-06-30 14:23:26
- Fetched: 2026-06-30 17:27:00
AWS マネジメントコンソールへのアクセスを想定するネットワークに制限
- Link: https://aws.amazon.com/jp/blogs/news/restrict-aws-management-console-access-to-expected-networks-with-sign-in-resource-based-policies-and-rcps/
- Published: 2026-06-30 17:36:31
- Fetched: 2026-06-30 20:42:29
AWS Deadline Cloud の Wait and Save サービスマネージドフリートを使ってみる
- Link: https://aws.amazon.com/jp/blogs/news/jp-mne-getting-started-with-wait-and-save-service-managed-fleets-on-aws-deadline-cloud/
- Published: 2026-06-30 22:09:46
- Fetched: 2026-06-30 23:10:25
AWS Security Blog
What the June 2026 Threat Technique Catalog update means for your AWS environment
- Link: https://aws.amazon.com/blogs/security/what-the-june-2026-threat-technique-catalog-update-means-for-your-aws-environment/
- Published: 2026-06-30 04:30:59
- Fetched: 2026-06-30 04:51:22
AWS Security Bulletins
CVE-2026-13762 and CVE-2026-13763 - Issue with HTTP/2 multi-frame request body inspection in AWS WAF
- Link: https://aws.amazon.com/security/security-bulletins/rss/2026-048-aws/
- Published: 2026-06-30 05:07:32
- Fetched: 2026-06-30 06:22:19
Bulletin ID: 2026-048-AWS
Scope: AWS
Content Type: Important (requires attention)
Publication Date: 06/29/2026 11:15 PM PDT
Description:
AWS WAF is a web application firewall that monitors the HTTP(S) requests that are forwarded to your protected web application resources. We identified CVE-2026-13762 and CVE-2026-13763, which are issues affecting HTTP/2 multi-frame request body inspection by AWS WAF.
CVE-2026-13762 affects AWS WAF deployment with CloudFront. This issue was remediated server-side; no customer action is required.
CVE-2026-13763 affects AWS WAF deployment with AWS Application Load Balancer (ALB). Under certain conditions, a crafted multi-frame HTTP/2 request could cause only a partial request body to be inspected. This issue has been addressed on ALB, and customers can ensure full protection by configuring how AWS WAF inspects HTTP/2 request bodies on their ALB.
Please refer to the article below for the most up-to-date and complete information related to this AWS Security Bulletin.
AWS Architecture Blog
Dual-token authentication for Nakama game servers with Amazon Cognito on AWS
- Link: https://aws.amazon.com/blogs/architecture/dual-token-authentication-for-nakama-game-servers-with-amazon-cognito-on-aws/
- Published: 2026-06-30 02:09:54
- Fetched: 2026-06-30 02:32:45
Preventing data exfiltration in machine learning environments with Amazon SageMaker AI
- Link: https://aws.amazon.com/blogs/architecture/preventing-data-exfiltration-in-machine-learning-environments-with-amazon-sagemaker-ai/
- Published: 2026-06-30 02:16:48
- Fetched: 2026-06-30 02:32:45
Lessons learned from scaling to 1 million Lambda functions
- Link: https://aws.amazon.com/blogs/architecture/lessons-learned-from-scaling-to-1-million-lambda-functions/
- Published: 2026-06-30 02:21:05
- Fetched: 2026-06-30 02:32:45
AWS Machine Learning Blog
Debugging production agents with Amazon Bedrock AgentCore Observability
- Link: https://aws.amazon.com/blogs/machine-learning/debugging-production-agents-with-amazon-bedrock-agentcore-observability/
- Published: 2026-06-30 02:25:21
- Fetched: 2026-06-30 02:32:45
Build an agentic AI healthcare claims pipeline with Amazon Bedrock and AWS HealthLake
- Link: https://aws.amazon.com/blogs/machine-learning/build-an-agentic-ai-healthcare-claims-pipeline-with-amazon-bedrock-and-aws-healthlake/
- Published: 2026-06-30 02:36:34
- Fetched: 2026-06-30 04:51:23
Multi-tenant LLM analytics with row-level security: How we built a secure agent on AWS
- Link: https://aws.amazon.com/blogs/machine-learning/multi-tenant-llm-analytics-with-row-level-security-how-we-built-a-secure-agent-on-aws/
- Published: 2026-06-30 02:39:29
- Fetched: 2026-06-30 04:51:23
Pair Nova 2 Lite with Claude for cost-optimized document processing
- Link: https://aws.amazon.com/blogs/machine-learning/pair-nova-2-lite-with-claude-for-cost-optimized-document-processing/
- Published: 2026-06-30 02:52:33
- Fetched: 2026-06-30 04:51:23
Implement a backup strategy for Amazon Quick Sight BI assets
- Link: https://aws.amazon.com/blogs/machine-learning/implement-a-backup-strategy-for-amazon-quick-sight-bi-assets/
- Published: 2026-06-30 03:15:14
- Fetched: 2026-06-30 04:51:23