AWS News - 2026-07-07
2026-07-07
最終更新: 2026-07-08 20:43:56 JST
AI による概要
この日は Amazon Redshift の大型アップデートが集中しました。Graviton 搭載の新インスタンス RG が一般提供となり、RA3 比で最大 2.2 倍の性能を 30% 低いコストで実現、Iceberg クエリは最大 2.4 倍高速化します。あわせてクエリ起動最適化により初回クエリの P50 コンパイル時間が 4.3 秒から 170 ミリ秒へ短縮され、追加費用なしで既定有効になりました。マルチウェアハウス機能の強化や Tableau 統合、Bedrock を使った AI パフォーマンス推奨の構築方法も公開されています。SageMaker では HyperPod の Disaggregated Prefill and Decode 対応、Hugging Face からのワンクリック連携、Unified Studio の MWAA 環境インポートが追加されました。セキュリティ面では ACM が ACME プロトコルに対応し、Security Hub が露出検出に影響分析を追加、Cedar によるマルチエージェント連鎖の最小権限認可が解説されました。EKS Auto Mode は GPU 管理手数料を最大 60% 引き下げています。
主要トピック
Redshift 刷新: Graviton 搭載 RG が GA、RA3 比 2.2 倍の性能を 30% 低コストで、Iceberg クエリは 2.4 倍高速
Redshift 性能: クエリ起動最適化で初回クエリの P50 コンパイル時間が 4.3 秒→170 ミリ秒、追加費用なしで既定有効
SageMaker: HyperPod の Disaggregated Prefill and Decode 対応、Hugging Face ワンクリック連携、Unified Studio の MWAA インポート
証明書: ACM が ACME プロトコルに対応し、45 日有効の公開 TLS 証明書をマネージド ACME エンドポイントから発行
セキュリティ: Security Hub が露出検出に影響分析を追加、Cedar でマルチエージェント連鎖の最小権限認可を強制
コスト: EKS Auto Mode が GPU・アクセラレーテッドインスタンスの管理手数料を最大 60% 削減
脆弱性: CVE-2026-14471 mcp-gateway-registry の認証済み SQL インジェクション (Important)
国内: 中央省庁との国会答弁対応プロトタイピング、AI-DLC Unicorn Gym による 3 日間の開発変革
AWS What's New
AWS Certificate Manager now supports the ACME protocol for public certificates
- Link: https://aws.amazon.com/about-aws/whats-new/2026/07/aws-certificate-manager-acme/
- Published: 2026-07-07 00:00:00
- Fetched: 2026-07-07 01:16:49
AWS Certificate Manager (ACM) now allows you to provision a fully managed ACME server endpoint that issues public TLS certificates with a 45 day validity from Amazon Trust Services using any ACMEv2-compatible client, including Certbot, cert-manager for Kubernetes, and acme.sh. With the CA/Browser Forum mandating 47-day certificate lifetimes by 2029, manual management of public certificates becomes untenable. ACME support in ACM gives developers a standards-based path to fully automate certificate issuance and renewal.
PKI administrators can create managed ACME endpoints with centralized governance controls: define domain scopes to restrict which certificates each client can issue, enforce policies on wildcard usage, and delegate certificate requests to application teams without distributing DNS credentials. Domain validation is performed once at the endpoint level, while application owners use standard ACME clients to request certificates. All activity is visible in the ACM console with AWS CloudTrail logging and Amazon CloudWatch metrics for auditability.
ACME support in ACM is available in all commercial AWS Regions. For pricing details, see the ACM pricing page. To get started, visit the AWS News blog post or read the documentation.
CloudWatch Application Signals now automatically captures errors, performance anomalies, and deployment events
- Link: https://aws.amazon.com/about-aws/whats-new/2026/06/cloudwatch-service-events/
- Published: 2026-07-07 00:00:00
- Fetched: 2026-07-07 05:50:06
Today, AWS announces Service Events for Amazon CloudWatch Application Signals, which automatically captures exception and latency event snapshots, function-level performance data, and deployment events from instrumented services without additional code changes. Customers can now quickly identify whether a deployment has introduced new exceptions by navigating to CloudWatch > Application Signals > [Service] > Errors in the CloudWatch console.
Service Events is available to any application with CloudWatch Application Signals enabled. Customers instrument their applications with the ADOT SDKs or the Amazon CloudWatch Observability EKS add-on. Once Application Signals is active, Service Events begins capturing exception and latency event snapshots and deployment events automatically. Optionally, customers can gain deeper performance visibility by turning on function-call metrics.
Service Events is available in all commercial AWS Regions. Supported languages are Java, Python, and JavaScript.
To get started, see Monitor service events in the Amazon CloudWatch User Guide. Service Events data is captured as logs. Function call metrics are captured as OpenTelemetry metrics. Standard CloudWatch pricing applies. For details, see CloudWatch pricing.
Amazon EVS VCF 9.0 and 9.1 support
- Link: https://aws.amazon.com/about-aws/whats-new/2026/07/amazon-evs-vcf9
- Published: 2026-07-07 02:29:00
- Fetched: 2026-07-07 05:50:06
Today, we are announcing that Amazon Elastic VMware Service (EVS) now supports VMware Cloud Foundation (VCF) 9.0 and 9.1.
Amazon EVS lets you run the latest VCF software directly within your Amazon Virtual Private Cloud (VPC) on EC2 bare-metal instances. With this latest announcement, you now have complete control of the installation, operations, and management of the VMware virtualization solution running the VCF 9.0 and recently released VCF 9.1 versions. You can continue to use the same tools, processes, and skills on Amazon EVS that you use in your data center today, managing your VCF environment yourself or with an experienced AWS partner. With this, we’re also launching the Solutions for EVS GitHub repository with examples, templates, and infrastructure as code artifacts to help you get started.
This release is available in all regions where Amazon EVS is offered.
For more details, visit the launch blog, the Amazon EVS product detail page and user guide.
AWS introduces declarative controls for VPC Encryption Controls
- Link: https://aws.amazon.com/about-aws/whats-new/2026/07/vpc-encryption-controls-declarative-controls/
- Published: 2026-07-07 03:19:00
- Fetched: 2026-07-08 06:20:05
You can now use declarative policies to turn on VPC Encryption Controls in monitor or enforce mode across all VPCs in your environment. This enhancement allows you to centrally define and manage your desired VPC Encryption Controls settings and apply it everywhere. You can exercise these controls for your account, organization or specific organizational unit.
VPC Encryption Controls offers you simple tools to audit and enforce encryption in transit within and across Amazon Virtual Private Clouds (VPCs), and to demonstrate compliance with encryption standards such as HIPAA, FedRAMP, and PCI. Before today, customers would turn on Encryption Controls in monitor or enforce mode and set up exclusions on each VPC separately. Security teams often want to exercise these controls centrally and consistently across their environment. With this launch, you can define and maintain a single declarative policy to enforce your desired encryption controls settings across all existing and future VPCs. This enhancement also gives you central visibility into the Encryption Controls status of all accounts and VPCs in your organization.
Declarative policies for VPC Encryption Controls are available in all AWS regions that support VPC Encryption Controls. There is no additional charge to use declarative policies in AWS Organizations. To learn more about this feature, see our documentation.
Amazon SageMaker Studio now integrates with Hugging Face for one-click model deployment and customization
- Link: https://aws.amazon.com/about-aws/whats-new/2026/07/sagemaker-studio-hugging-face-integration/
- Published: 2026-07-07 05:30:00
- Fetched: 2026-07-07 09:04:10
詳細を表示
Amazon SageMaker Studio now supports direct integration from Hugging Face, letting you go from discovering a model to working with it inside a fully configured Studio environment in a single click. Select any supported model on Hugging Face and choose "Customize on SageMaker AI" or "Deploy on SageMaker AI" to land directly on the corresponding workflow page with the model pre-loaded and ready to use.
Previously, getting from model discovery to a working environment required navigating the AWS Console to find SageMaker AI, configuring an environment, setting up IAM permissions for serverless model customization, and in many cases requesting GPU quota increases through Service Quotas before running a first job. Now, new customers complete a standard AWS sign-up and receive a SageMaker Studio environment created in seconds with pre-configured permissions for serverless model customization jobs including fine-tuning with custom reward functions for reinforcement learning, model evaluation, and deployment to SageMaker or Bedrock endpoints. Verified customers receive default GPU access to G5, G6, and G4dn instances across endpoint deployments, training jobs, and notebooks without requesting quota increases, and quota limit and utilization information is visible for each instance type directly inside the Studio environment. Returning customers signing in from Hugging Face or SageMaker product pages select their environment and land directly inside SageMaker Studio with the model ready to use.
This feature is available in all AWS Commercial Regions where Amazon SageMaker Studio is supported. To get started, visit any supported model on Hugging Face and select "Customize on SageMaker AI" or "Deploy on SageMaker AI," or click Get Started from the SageMaker Studio page. To learn more, see Service quotas for Studio in the Amazon SageMaker documentation.
Amazon Cognito now supports self-service provisioned API rate limits
- Link: https://aws.amazon.com/about-aws/whats-new/2026/07/cognito-provisioned-limits
- Published: 2026-07-07 06:00:00
- Fetched: 2026-07-07 09:04:10
Amazon Cognito now allows you to increase or decrease your provisioned API rate limits on demand. Cognito has default rate limits for the maximum number of operations per second that you can perform in your user pools in each AWS Region, and you can purchase additional limits on adjustable API categories. With the new on-demand model, you can adjust your rate limits up or down more quickly to match your application’s traffic patterns.
Previously, to adjust your Cognito API rate limits, you would request an increase through Service Quotas, where requests are manually reviewed. This meant you had to plan rate limits in advance ahead of anticipated traffic spikes. Now, you have a new self-service experience to set your desired Cognito rate limit up to the account-level max limit using the Amazon Cognito console or the new limit provisioning API operations. Rate limit changes take effect immediately.
Self-service provisioned limits are available for adjustable API categories in all AWS Regions where Amazon Cognito is available. For pricing details of this add-on feature, see Amazon Cognito pricing page. To get started, see developer guide.
Amazon SageMaker HyperPod now supports disaggregated prefill and decode
- Link: https://aws.amazon.com/about-aws/whats-new/2026/7/amazon-sagemaker-hyperpod-dpd/
- Published: 2026-07-07 06:29:00
- Fetched: 2026-07-07 07:10:30
詳細を表示
Amazon SageMaker HyperPod now supports Disaggregated Prefill and Decode (DPD), an inference optimization that separates the two phases of large language model (LLM) inference — prefill and decode — onto dedicated GPU pools and transfers the key-value (KV) cache between them over Elastic Fabric Adapter (EFA) using GPU-Direct RDMA. Customers running LLMs in production for chat assistants, agentic pipelines, retrieval-augmented generation, and long-document analysis need consistent per-token latency and predictable throughput under mixed traffic, but when prefill and decode share the same GPU, a single long-context request can stall token generation for every concurrent request and force customers to over-provision one phase to protect the other.
With DPD, customers run compute-bound prefill on one set of GPUs and memory-bandwidth-bound decode on another, so the two phases no longer contend for the same resources. This delivers more consistent per-token latency under sustained concurrency, higher goodput at strict latency SLOs, and the ability to scale prefill and decode capacity independently to match the input and output distribution of the workload. An intelligent router automatically directs long-context requests through the disaggregated path and sends shorter prompts directly to the decoder, so customers get the benefit on the traffic that needs it without paying transfer overhead on short prompts. Customers enable DPD by adding a `pdSpec` section to the same `InferenceEndpointConfig` custom resource they already use for inference endpoints on the HyperPod Inference Operator, and DPD is composable with the existing KV cache offloading and intelligent routing features on HyperPod.
DPD is available for SageMaker HyperPod clusters using the EKS orchestrator on EFA-capable instance types in all AWS Regions where Amazon SageMaker HyperPod is available. To learn more, see Disaggregated Prefill and Decode for HyperPod inference in the Amazon SageMaker AI Developer Guide.
AWS Security Hub adds impact analysis for exposure findings
- Link: https://aws.amazon.com/about-aws/whats-new/2026/07/impact-analysis-aws-security-hub/
- Published: 2026-07-07 06:45:00
- Fetched: 2026-07-08 02:10:00
Today, AWS Security Hub adds impact analysis to exposure findings, helping security teams understand the full scope of what an attacker could reach if an exposure is exploited. Impact analysis extends exposure findings by mapping the downstream resources that could be compromised beyond the initially exposed resource, giving teams deeper visibility into organizational risk.
Security Hub analyzes the effective permissions of IAM principals associated with exposed resources to identify privilege escalation paths to other resources in your account. The resulting scope of impact is displayed in the potential attack path graph, and a new Impact Assessment tab shows the prioritized chains of resources an attacker could traverse along with the specific permissions at each step. Security Hub factors the scope of impact into its severity scoring for exposure findings, and adjusts existing exposures as their scope of impact is identified or changes, so that exposures with greater downstream reach are prioritized appropriately.
To learn more, see Understanding exposure findings in the AWS Security Hub User Guide and the AWS Security Hub product page. For the full list of AWS Regions where Security Hub is available, see the AWS Regional Services List.
Amazon SageMaker Unified Studio now supports importing existing MWAA environments
- Link: https://aws.amazon.com/about-aws/whats-new/2026/07/amazon-sagemaker-unified-studio-import-existing-mwaa-environments/
- Published: 2026-07-07 11:00:00
- Fetched: 2026-07-08 12:18:04
Amazon SageMaker Unified Studio now supports connecting existing Amazon Managed Workflows for Apache Airflow (MWAA) environments to projects. Data engineers and platform teams who already operate MWAA environments can now manage their Airflow workflows from the same interface they use for analytics and machine learning, without recreating configurations or migrating DAGs.
To connect an existing environment, open the Workflows tool in your Studio project and select "Add connection" in the connection selector. Provide the Airflow configuration options that reference your domain and project. Once connected, project members can sync, trigger, and monitor workflows directly from Amazon SageMaker Unified Studio. Environments running Apache Airflow 3 or later also get access to the visual authoring experience for creating new workflows using the drag-and-drop editor.
This feature is available in all AWS Regions where Amazon SageMaker Unified Studio is available. To get started, see Workflow environments in Amazon SageMaker Unified Studio in the Amazon SageMaker Unified Studio User Guide.
AWS Systems Manager simplifies Azure VM management and hybrid node pricing
- Link: https://aws.amazon.com/about-aws/whats-new/2026/06/aws-systems-manager-multicloud-vm/
- Published: 2026-07-07 17:00:00
- Fetched: 2026-07-08 20:43:56
You can now connect and manage Azure Virtual Machines in AWS Systems Manager without manual agent installation or per-instance tier fees. Create a Cloud Connector and automatically deploy the SSM Agent to your Azure VMs at scale. Once connected, Azure VMs appear alongside EC2 instances in a unified view, and you can connect to them using Session Manager, run Automation runbooks, Run Command, State Manager, Patch Manager, and Inventory across both AWS and Azure from a single workflow.
This release also eliminates the Advanced Instances Tier entirely. This means that you can now connect any number of hybrid and multicloud nodes to Systems Manager with no upfront per-node fees. Beginning September 30, 2026, pay-as-you-go pricing takes effect for Session Manager sessions and Run Command invocations on non-EC2 nodes. This pricing model removes cost barriers for organizations managing multicloud environments at scale.
AWS Systems Manager multicloud management is available starting today. To learn more and get started, visit AWS Systems Manager.
Amazon EKS Auto Mode reduces GPU management fees by up to 60%
- Link: https://aws.amazon.com/about-aws/whats-new/2026/07/amazon-eks-auto-mode-gpu-price
- Published: 2026-07-07 21:00:00
- Fetched: 2026-07-08 06:20:05
Amazon Elastic Kubernetes Service (Amazon EKS) Auto Mode now offers significantly reduced management fees for GPU and accelerated instance types. Beginning July 1, 2026, G-series Auto Mode management fees are reduced by 35%, and P-series and AWS Trainium fees are reduced by 60%. These reductions apply automatically to all EKS Auto Mode clusters and no action is required from customers already using GPU instances with Auto Mode.
EKS Auto Mode simplifies Kubernetes operations by automatically provisioning and managing infrastructure for machine learning inference, fine-tuning, rendering, and batch processing workloads. It includes capabilities built for accelerated workloads: automatic parallel image pulling and unpacking on GPU instances with local NVMe storage, so large container and model images start faster, and accelerator-aware node repair that detects GPU hardware failures and automatically replaces unhealthy nodes. With today's price reduction, customers can run GPU workloads on Auto Mode at lower management fees, making its fully managed infrastructure more cost-effective.
This pricing update is available in all AWS Regions where EKS Auto Mode is available. Amazon ECS is implementing identical management fee reductions for GPU instances on ECS Managed Instances. See the ECS What's New post for details.
To get started with GPU workloads on EKS Auto Mode, see the EKS for AI/ML documentation. For the complete updated rate table, see Amazon EKS pricing.
Amazon S3 Express One Zone is now available in the AWS Europe (Frankfurt) Region
- Link: https://aws.amazon.com/about-aws/whats-new/2026/07/s3-express-one-zone-europe-frankfurt/
- Published: 2026-07-07 22:00:00
- Fetched: 2026-07-08 12:18:04
The Amazon S3 Express One Zone storage class is now available in the AWS Europe (Frankfurt) Region.
Amazon S3 Express One Zone is a high-performance, single-Availability Zone storage class purpose-built to deliver consistent single-digit millisecond data access for your most frequently accessed data and latency-sensitive applications. S3 Express One Zone delivers data access speed up to 10x faster and request costs up to 80% lower than S3 Standard. It enables workloads such as machine learning training, interactive analytics, and key-value caching in AI search engines to achieve fast data access with high durability and availability.
With this expansion, S3 Express One Zone is now available in 8 AWS Regions. For pricing details, visit the S3 pricing page. To learn more, visit the product page and documentation.
AWS News Blog
AWS Weekly Roundup: Claude Sonnet 5 on AWS, Amazon WorkSpaces for AI agents, AWS service availability updates, and more (July 6, 2026)
- Link: https://aws.amazon.com/blogs/aws/aws-weekly-roundup-claude-sonnet-5-on-aws-amazon-workspaces-for-ai-agents-aws-service-availability-updates-and-more-july-6-2026/
- Published: 2026-07-07 00:46:43
- Fetched: 2026-07-07 01:16:49
AWS Japan Blog
Amazon Redshift Serverless と Tableau の統合を最適化する
- Link: https://aws.amazon.com/jp/blogs/news/optimize-your-tableau-integration-with-amazon-redshift-serverless/
- Published: 2026-07-07 08:48:42
- Fetched: 2026-07-07 09:04:11
Amazon Redshift が BI ダッシュボードとリアルタイム分析のパフォーマンスを向上
- Link: https://aws.amazon.com/jp/blogs/news/amazon-redshift-delivers-faster-performance-for-bi-dashboards-and-real-time-analytics/
- Published: 2026-07-07 08:50:31
- Fetched: 2026-07-07 09:04:11
Amazon Redshift のマルチウェアハウス機能強化でアナリティクスをスケール
- Link: https://aws.amazon.com/jp/blogs/news/scale-analytics-with-amazon-redshift-multi-warehouse-enhancements/
- Published: 2026-07-07 08:52:04
- Fetched: 2026-07-07 09:04:11
AI を活用した Amazon Redshift のパフォーマンスレコメンデーション
- Link: https://aws.amazon.com/jp/blogs/news/ai-powered-performance-recommendations-for-amazon-redshift/
- Published: 2026-07-07 08:54:04
- Fetched: 2026-07-07 09:04:11
Amazon Redshift RG: Graviton 搭載でより高速、より低コスト
- Link: https://aws.amazon.com/jp/blogs/news/amazon-redshift-rg-faster-and-lower-cost-graviton-powered/
- Published: 2026-07-07 08:56:10
- Fetched: 2026-07-07 09:04:11
国会答弁対応業務の高度化と効率化に向けた中央省庁とのプロトタイピングプログラムの取り組み
- Link: https://aws.amazon.com/jp/blogs/news/prototyping-program-with-central-government-agencies-for-diet-response-operations/
- Published: 2026-07-07 14:42:46
- Fetched: 2026-07-07 17:19:16
エムシーディースリー株式会社様:AI-DLC Unicorn Gym による3日間の開発変革
- Link: https://aws.amazon.com/jp/blogs/news/mcd3-aidlc/
- Published: 2026-07-07 17:06:37
- Fetched: 2026-07-07 17:19:16
AWS Security Blog
Enforce least-privilege authorization in multi-agent AI chains using Cedar
- Link: https://aws.amazon.com/blogs/security/enforce-least-privilege-authorization-in-multi-agent-ai-chains-using-cedar/
- Published: 2026-07-07 01:52:23
- Fetched: 2026-07-07 03:52:31
AWS Security Bulletins
CVE-2026-14471 - Authenticated SQL injection in the metrics-service retention policy subsystem of mcp-gateway-registry
- Link: https://aws.amazon.com/security/security-bulletins/rss/2026-052-aws/
- Published: 2026-07-07 05:50:20
- Fetched: 2026-07-07 07:10:32
Bulletin ID: 2026-052-AWS
Scope: AWS
Content Type: Important (requires attention)
Publication Date: 07/06/2026 13:45 PM PDT
Description:
Amazon mcp-gateway-registry is an open-source gateway and registry for Model Context Protocol (MCP) servers, providing centralized discovery, authentication/authorization, and proxying of MCP tools for AI agents. We identified CVE-2026-14471, an issue in the metrics-service retention policy management component where a caller-supplied table_name value is interpolated into SQL statements in identifier position without proper neutralization. An authenticated remote user is able to supply a crafted table_name value to execute arbitrary SQL queries against the metrics database. This allows the user to read stored data (including API key material) and to delete or alter stored data.
Impacted versions: >=1.0.3 AND <=1.0.12
Please refer to the article below for the most up-to-date and complete information related to this AWS Security Bulletin.
AWS Machine Learning Blog
Streaming benchmark and recommendation results to MLflow with Amazon SageMaker AI
- Link: https://aws.amazon.com/blogs/machine-learning/streaming-benchmark-and-recommendation-results-to-mlflow-with-amazon-sagemaker-ai/
- Published: 2026-07-07 01:53:38
- Fetched: 2026-07-07 03:52:32
Automatically redact PII in images with Amazon Nova
- Link: https://aws.amazon.com/blogs/machine-learning/automatically-redact-pii-in-images-with-amazon-nova/
- Published: 2026-07-07 01:55:02
- Fetched: 2026-07-07 03:52:32
Deploying Multi-Turn RL Infrastructure for Amazon Nova on Amazon SageMaker HyperPod
- Link: https://aws.amazon.com/blogs/machine-learning/deploying-multi-turn-rl-infrastructure-for-amazon-nova-on-amazon-sagemaker-hyperpod/
- Published: 2026-07-07 01:58:13
- Fetched: 2026-07-07 03:52:32
Run MiniMax models on Amazon Bedrock
- Link: https://aws.amazon.com/blogs/machine-learning/run-minimax-models-on-amazon-bedrock/
- Published: 2026-07-07 02:00:44
- Fetched: 2026-07-07 03:52:32
Teaching models to forget: Selective unlearning with Amazon Nova
- Link: https://aws.amazon.com/blogs/machine-learning/teaching-models-to-forget-selective-unlearning-with-amazon-nova/
- Published: 2026-07-07 07:23:45
- Fetched: 2026-07-07 09:04:12
From Hugging Face to Amazon SageMaker Studio in one click
- Link: https://aws.amazon.com/blogs/machine-learning/from-hugging-face-to-amazon-sagemaker-studio-in-one-click-2/
- Published: 2026-07-07 07:35:55
- Fetched: 2026-07-07 09:04:12
AWS Compute Blog
Uncover new performance insights using Amazon detailed performance statistics on Windows
- Link: https://aws.amazon.com/blogs/compute/uncover-new-performance-insights-using-amazon-detailed-performance-statistics-on-windows/
- Published: 2026-07-07 02:00:08
- Fetched: 2026-07-07 03:52:33