AWS News - 2026-07-15

2026-07-15
最終更新: 2026-07-21 14:46:15 JST

AI による概要

35 記事

この日は AI ワークロードそのものを守るセキュリティ機能が揃いました。Amazon GuardDuty AI Protection が登場し、脅威検出の対象が Amazon Bedrock や SageMaker といった AWS の AI サービスへ拡大されました。AWS Security Hub は組織全体の AI 資産を継続的に把握する AI インベントリを追加し、あわせて Microsoft Azure を含むマルチクラウド対応と AI ワークロード保護も発表されています。AWS WAF Bot Control では正規の AI エージェントトラフィックを認証する手法が解説されました。開発体験では Lambda コンソールにコーディングエージェントのワンクリックセットアップが追加され、Managed Service for Apache Flink と OpenSearch Service は Agent Toolkit for AWS のスキルとして利用できるようになっています。運用面では CloudWatch Logs のルックアッププロセッサによるログ拡充、Elastic Disaster Recovery の復旧時間短縮、Lambda の自己管理コードストレージが追加されました。

主要トピック
  • AI セキュリティ: GuardDuty AI Protection が Bedrock・SageMaker を脅威検出の対象に追加

  • AI ガバナンス: Security Hub が組織全体の AI 資産を可視化する AI インベントリを提供

  • マルチクラウド: Security Hub が Microsoft Azure に対応し AI ワークロード保護を追加

  • ボット対策: AWS WAF Bot Control で正規の AI エージェントトラフィックを認証する方法

  • 開発体験: Lambda コンソールにコーディングエージェントのワンクリックセットアップ、Flink と OpenSearch が Agent Toolkit のスキルに

  • 運用: CloudWatch Logs のルックアッププロセッサでログをテーブル参照により拡充

  • 災害対策: Elastic Disaster Recovery が AWS 間ワークロードの復旧時間を短縮、EBS 初期化レートにも対応

  • 脆弱性: HealthLake MCP Server の SSRF (CVE-2026-15643)、Load Balancer Controller のクロス名前空間傍受 (CVE-2026-15738)

AI (Claude Opus 5) が生成 · 2026-08-28 09:25:46 JST

AWS What's New

Amazon WorkSpaces Personal simplifies bulk PCoIP to DCV protocol migration

Amazon WorkSpaces Personal now provides automated rollback and support for PCoIP to DCV protocol migration of stopped WorkSpaces, building on the recently launched console-based migration workflow and checkpoint snapshot support. These new capabilities enable administrators to migrate WorkSpaces at scale with minimal manual intervention.

Amazon DCV is a high-performance streaming protocol built by AWS that powers Amazon WorkSpaces services. By migrating to DCV, customers gain access to broader operating system support including Windows 11 and Windows Server 2025, enhanced security features such as certificate-based authentication and WebAuthN redirection, and improved streaming performance. With this launch, if a protocol modification fails, the WorkSpace automatically rolls back to the pre-migration snapshot, ensuring it returns to a known healthy state without manual intervention. Additionally, administrators can now initiate migration for WorkSpaces in a stopped state, removing the need to manually start each stopped WorkSpace before modifying its protocol. This helps customers significantly speed up large scale migrations.

These enhancements are available in all AWS commercial and AWS GovCloud (US) Regions where Amazon WorkSpaces Personal is supported.

To get started, sign in to the Amazon WorkSpaces console. For more information, see Modify protocols section in the Amazon WorkSpaces Administration Guide. To learn more about Amazon WorkSpaces, visit the Amazon WorkSpaces product page.

AWS Security Hub now provides AI inventory for organization-wide visibility of AI assets

詳細を表示

Today, AWS announces that AWS Security Hub now provides an AI inventory, giving central security teams a continuously updated, organization-wide view of AI assets and their security posture. As organizations rapidly deploy AI agents, models, and pipelines, security teams may lack visibility into what AI assets exist across their organization. Without centralized visibility connecting AI assets to active threats and misconfigurations, organizations cannot secure what they don't know exists.

Security Hub AI inventory automatically discovers and catalogs AI workloads across your AWS environment through three discovery methods. For managed AI services, Security Hub inventories AWS Config resources from Amazon Bedrock, Bedrock AgentCore and Amazon SageMaker, with no additional configuration. For self-hosted AI workloads, Security Hub leverages the software bill of materials (SBOM) analysis from Amazon Inspector, which has been enhanced to identify inference endpoints, models and AI agents installed on Amazon EC2 instances and Amazon ECR container images, including frameworks such as Ollama, vLLM, Hugging Face TGI, and others. Security Hub also leverages Amazon GuardDuty DNS telemetry to discover external AI API endpoints (such as calls to third-party model providers) being accessed from your EC2 instances, revealing third-party AI dependencies that may not have been previously identified.

 Each discovered AI asset is mapped to its underlying infrastructure and correlated with security findings from across the AWS security stack, including threat findings from Amazon GuardDuty. Teams can filter, group, and query their AI inventory by account, resource type, discovery method, and specific model identity, enabling them to prioritize remediation based on which AI workloads are actively under threat and carry the highest organizational risk.

AI Inventory is included with Security Hub Essentials at no additional cost and requires no new enablement. It is available in all AWS commercial Regions where Security Hub is offered. To learn more, see the AWS Security Hub User Guide and the AWS Security Hub product page.

Amazon Aurora DSQL is now available in Europe (Spain)

Starting today, Amazon Aurora DSQL is available for single-Region clusters in the Europe (Spain) Region. Aurora DSQL is the fastest serverless, distributed SQL database, with active-active high availability and multi-Region strong consistency. It enables you to build always-available applications with virtually unlimited scalability, the highest availability, and zero infrastructure management, making scaling and resilience effortless for your applications.

With this launch, Aurora DSQL is available in the following AWS Regions: US East (N. Virginia), US East (Ohio), US West (Oregon), Canada (Central), Canada West (Calgary), South America (São Paulo), Europe (Frankfurt), Europe (Ireland), Europe (London), Europe (Paris), Europe (Spain), Europe (Stockholm), Asia Pacific (Hong Kong), Asia Pacific (Melbourne), Asia Pacific (Mumbai), Asia Pacific (Osaka), Asia Pacific (Seoul), Asia Pacific (Singapore), Asia Pacific (Sydney), and Asia Pacific (Tokyo).

Get started with Aurora DSQL for free with the AWS Free Tier. To learn more, visit the Aurora DSQL webpage and documentation.

Amazon Managed Service for Apache Flink now offers AI Agent Skills to simplify building and operating Flink applications

Amazon Managed Service for Apache Flink now offers AI Agent Skills that give AI coding assistants expert, up-to-date guidance for building and operating Flink applications. The skills provide expert guidance for common tasks such as creating applications, troubleshooting, scaling, monitoring, networking configuration, and cost optimization.

Customers can leverage these skills to keep Flink applications healthy and performant, accelerate development of new streaming applications, and easily upgrade to latest versions of Apache Flink like Flink 2.2. The skills turn tasks that once required specialized Apache Flink knowledge into a guided experience developers can complete on their own.

You can use the Managed Service for Apache Flink skills with your existing AI coding agent, including Kiro, Claude Code, or Cursor. To get started, configure the Agent Toolkit for AWS using the AWS CLI, then ask your coding agent a question, such as "How do I create a new Flink application on MSF?" or "My Flink application is unhealthy — what's wrong?"

Introducing Amazon GuardDuty AI Protection for AWS AI workloads

Amazon GuardDuty now offers AI Protection, expanding threat detection to AWS AI services including Amazon Bedrock and Amazon SageMaker. As organizations rapidly adopt AI, security teams may lack visibility into threats specifically targeting AI workloads, such as anomalous model invocations, cost harvesting attacks, and prompt injection attempts. GuardDuty AI Protection continuously monitors these workloads so security teams can detect and respond to AI-specific threats without manual configuration or custom tooling.

GuardDuty AI Protection analyzes both CloudTrail management and data events from AWS AI services to identify suspicious activity, including unusual invocation patterns, cost harvesting attacks where threat actors force AI resources to consume excessive GPU time and tokens, and prompt injection attempts through integration with Amazon Bedrock Guardrails. Threat findings flow directly into AWS Security Hub, giving teams a single view of AI assets and threats for prioritized response. GuardDuty AI Protection can be enabled with a few steps in the GuardDuty or Security Hub console, and using AWS Organizations, can be centrally enabled for all accounts in an organization.

GuardDuty AI Protection is available to GuardDuty customers with a 30-day free trial. For pricing details, visit the Amazon GuardDuty pricing page. To learn more, see the Amazon GuardDuty User Guide and the Amazon GuardDuty product page. For the full list of supported Regions, see the AWS Regional Services List.

Connect Customer Outbound Campaigns now in Cape Town Africa

Connect Customer Outbound Campaigns digital channels (SMS, WhatsApp, and email) are now available in the Africa (Cape Town) Region. Businesses in the Region can now use Connect Customer's proactive outreach capabilities to create targeted, personalized engagement campaigns for service updates, promotional offers, appointment reminders, and product usage tips. Organizations configure and manage these campaigns through the Connect Customer admin website and Outbound Campaigns APIs.

A retail business in the Region can segment customers by purchase behavior, then run a coordinated campaign that sends promotional offers over SMS, appointment reminders over WhatsApp, and product usage tips over email, with each message personalized to the recipient. Built-in analytics show which messages drove engagement, and event-based triggers start campaigns automatically from customer actions such as a completed purchase or a missed appointment.

To learn more, see Outbound campaigns in the Amazon Connect Administrator Guide. To get started, visit the Amazon Connect Customer product page. For all Regions where Connect Customer Outbound Campaigns is available, see the AWS Region table.

AWS IAM Identity Center achieves FedRAMP Class C Certification

AWS IAM Identity Center is now in scope for FedRAMP Class C in the US East (Ohio), US East (N. Virginia), US West (N. California), and US West (Oregon) Regions. You can now use IAM Identity Center to enable workforce access to AWS accounts and applications that are subject to FedRAMP Class C compliance.

The Federal Risk and Authorization Management Program (FedRAMP) is a US government-wide program that delivers a standard approach to the security assessment, certification, and continuous monitoring for cloud products and services. AWS IAM Identity Center is the recommended service for managing your workforce access to AWS accounts and applications.

To learn more about FedRAMP, visit the AWS services compliance page and AWS compliance resources page. To learn more about IAM Identity Center, visit the User Guide.

AWS Lambda console provides a one-click setup prompt for coding agents

詳細を表示

AWS Lambda console now provides a one-click setup prompt for coding agents that configures your agent with AWS Serverless skills and the Serverless Model Context Protocol (MCP) server, embedding serverless best practices from the start. This setup is available on the Lambda console wherever the developers start their Lambda journey: whether they are getting started with Lambda, exploring its capabilities, or have created their first function.

Developers use coding agents to build, test, and deploy Lambda functions, but setting up an agent for serverless development previously required navigating across multiple documentation pages to find the right configuration. The one-click setup prompt eliminates this friction as it provides a prompt that instructs the agent to install AWS Serverless skills (hosted in Agent Toolkit for AWS) and the Serverless MCP server directly in the developer's preferred coding agent. The prompt references the Lambda agent setup guide, which includes installation commands for Claude Code, Kiro, Cursor, GitHub Copilot, Codex, Devin Desktop, and OpenCode, for the AWS Serverless skills, three specialized Lambda skills (MicroVM, Managed Instances, durable functions), and Serverless MCP server configuration. If a developer does not have local AWS authentication configured, the prompt guides them to connect using the signing-in-to-aws skill.

This capability is available in all commercial AWS Regions (except Middle East (Bahrain) and Middle East (UAE)) and AWS GovCloud (US) Regions where Lambda is available. Get started by visiting the AWS Lambda console or learn more in the Lambda agent setup guide.

 

Amazon EC2 M8in, M8idn, M8ib, M8idb instances are now available in additional regions

Starting today, Amazon Elastic Compute Cloud (Amazon EC2) M8in, M8idn network optimized, and M8ib, M8idb EBS optimized instances are available in the AWS US East (Ohio), Europe (Ireland), and Asia Pacific (Tokyo) regions. The new instances are powered by custom sixth generation Intel Xeon Scalable processors available only on AWS and deliver up to 43% higher performance compared to previous generation instances. These instances also feature the latest sixth generation AWS Nitro cards.

M8in, M8idn instances deliver 600 Gbps network bandwidth, the highest network bandwidth among enhanced networking EC2 instances, and are ideal for workloads such as real-time big data analytics, distributed web scale in-memory caches, caching fleets for AI/ML clusters, and Telco applications such as 5G User Plane Function (UPF). 
 
M8ib, M8idb instances deliver up to 300Gbps EBS bandwidth, the highest among non-accelerated compute EC2 instances, and are best suited for workloads that benefit from high block storage performance, such as high-performance file systems and NoSQL databases.

M8idn instances are ideal for network-intensive workloads that benefit from low-latency local storage, such as distributed compute, data analytics, and high-performance file systems. M8idb instances are ideal for storage-intensive workloads such as large commercial databases, data lakes, and NoSQL databases that benefit from both high EBS throughput and low-latency local NVMe storage. 

M8in, M8idn, M8ib, M8idb instances are available in US East (N. Virginia, Ohio), US West (Oregon), Europe (Ireland), Asia Pacific (Tokyo), and Europe (Spain) regions, via Savings Plans, On-Demand, and Spot instances. For more information, visit the Amazon EC2 M8i instance page.

Amazon Redshift adds rg.large and rg.12xlarge instance sizes

詳細を表示

Amazon Redshift announces the general availability of two new RG instance sizes - rg.large and rg.12xlarge. These new sizes deliver the same Graviton-powered performance benefits as existing RG instances, including up to 2.4x faster query performance than previous-generation RA3 instances at 30% lower price per vCPU, giving you more flexibility to right-size your provisioned clusters for any workload.

rg.large and rg.12xlarge instance sizes are available on the current track (P202) only. Customers on the trailing track (P201) can continue to use rg.xlarge and rg.4xlarge. Existing RA3 clusters can migrate to RG instances using Snapshot and Restore, Elastic Resize, or Classic Resize. RG instances are available with flexible pricing options, including On-Demand, and 1-year and 3-year Reserved Instances with No Upfront payment.

The new rg.large and rg.12xlarge instance sizes are now available in the following AWS Regions: US East (N. Virginia), US East (Ohio), US West (Oregon), US West (N. California), Canada (Central), Mexico (Central), South America (São Paulo), Europe (Ireland), Europe (Frankfurt), Europe (London), Europe (Paris), Europe (Stockholm), Europe (Spain), Africa (Cape Town), Asia Pacific (Tokyo), Asia Pacific (Seoul), Asia Pacific (Singapore), Asia Pacific (Sydney), Asia Pacific (Mumbai), Asia Pacific (Jakarta), Asia Pacific (Hong Kong), Asia Pacific (Osaka), Asia Pacific (Malaysia), Asia Pacific (Hyderabad), Asia Pacific (Taiwan), Asia Pacific (Thailand), and Asia Pacific (Melbourne).

To get started, refer to the following resources:

AWS Elastic Disaster Recovery reduces recovery time for AWS-to-AWS workloads

AWS Elastic Disaster Recovery (AWS DRS) now recovers your AWS-based workloads faster. For source servers running on Amazon EC2, DRS can now skip preparation steps that these workloads no longer need, reducing recovery time by up to 65% for Windows and up to 40% for Linux.

During a disaster or a drill, every minute matters. Because workloads already running on AWS come with AWS-compatible drivers and configuration, DRS can launch them with fewer steps — helping you bring applications back online sooner and with greater confidence. Networking, drivers, and licensing are still applied automatically, so recovery stays simple and hands-off. You remain in control: turn on faster recovery across your whole account or for individual servers and change the setting whenever your needs change.

This capability is available in all AWS Regions where AWS DRS is offered, at no additional cost. To learn more, visit the AWS Elastic Disaster Recovery User Guide.

Amazon CloudWatch announces lookup processor for log enrichment

Amazon CloudWatch now supports lookup processor, enabling you to enrich log events with additional context by matching fields in your logs against a lookup table directly within your CloudWatch Pipeline.

With the lookup processor, you can upload CSV files containing reference data and configure your pipeline to match incoming log fields against this data to add enriched metadata. For example, you can upload a CSV mapping IP addresses to application teams and automatically tag VPC Flow Logs with team ownership information as logs are ingested. The lookup processor matches fields in your log events against fields in a lookup table and adds specified fields from matching rows to your log events. This enables data enrichment scenarios such as mapping user IDs to user details, product codes to product information, or error codes to human-readable error descriptions, thereby eliminating the need to build and maintain custom enrichment logic outside of CloudWatch. By enriching logs at ingestion time, your queries, dashboards, and alarms immediately benefit from the added context without any post-processing.

The lookup table processor is available in all AWS commercial regions that support Amazon CloudWatch pipelines. You can add a lookup processor to your pipeline using the AWS Management Console, AWS CLI, or AWS SDKs. To get started, see the Amazon CloudWatch Logs documentation.

AWS Elastic Disaster Recovery now supports Amazon EBS volume initialization rate

AWS Elastic Disaster Recovery (AWS DRS) now supports the Amazon EBS volume initialization rate, helping recovered volumes reach full performance faster during drills and recoveries. When DRS restores EBS volumes from snapshots, the data loads from Amazon S3 in the background, and I/O to blocks that haven't loaded yet can be slower until initialization finishes. With this launch, you can set a volume initialization rate on your DRS-managed EC2 launch template, and DRS applies it automatically when it creates volumes during recovery — bringing your applications to full storage performance on a predictable timeline.

This is especially valuable for I/O-intensive workloads such as databases, where fast, consistent storage performance is critical to meeting your recovery time objectives. You set the rate once on the launch template, and DRS preserves it across the updates it makes for rightsizing or disk changes. If the rate cannot be applied for a given recovery, DRS completes recovery without it, so your recovery is never blocked.

AWS DRS support for the EBS volume initialization rate is available in all AWS Regions and environments where the EBS volume initialization rate is offered. You are charged per GB based on the full snapshot size and the rate you specify; for details, see Amazon EBS pricing. To learn more, see the AWS Elastic Disaster Recovery User Guide.

AWS Lambda announces self-managed code storage

詳細を表示

AWS Lambda now supports self-managed Amazon S3 buckets for code storage, enabling you to reference source code directly from your own S3 buckets without Lambda creating intermediate copies. This eliminates code storage limits and reduces function activation time after function creates and updates by removing the copy step.

AWS Lambda is a serverless compute service that runs your code without requiring you to manage servers. Customers who deploy many functions and additional code as Lambda layers often need more than 75GB of code storage per Region, requiring support tickets to increase this quota. Previously, Lambda always copied your deployment package to Lambda-managed storage during function and layer creation, counting against this limit. Now, with self-managed code storage, Lambda references your code directly in your Amazon S3 bucket without creating a copy, so you can store as much function and layer code as your bucket allows. You maintain a single source of truth for your deployment packages in your own account. No additional Lambda charges apply for self-managed storage; you only pay for standard Amazon S3 storage and, where applicable, cross-Region data transfer rates. In addition, Lambda has increased the default limit for Lambda-managed code storage from 75GB to 300GB per Region per account.

Self-managed Amazon S3 code storage is available in all commercial AWS Regions.

To get started, set the `S3ObjectStorageMode` parameter to `REFERENCE` when creating or updating functions and layers through the AWS CLI, AWS CloudFormation, AWS SAM, or AWS SDKs. You must grant the Lambda service principal `s3:GetObject` and `s3:GetObjectVersion` permissions on your S3 bucket. You can also update a function to use self-managed code storage via the Lambda Console. To learn more, visit the AWS Lambda Developer Guide.

Amazon RDS for Db2 is now available in additional AWS Commercial regions

Amazon Relational Database Service (Amazon RDS) for Db2 is now available in the Asia Pacific (Thailand), Asia Pacific (Malaysia), Asia Pacific (Taipei), Mexico (Central), and Canada West (Calgary) Regions. Amazon RDS for Db2 makes it easy to set up, operate, and scale Db2 databases in the cloud. Customers can deploy a Db2 database in minutes with automatically configured parameters for optimal performance. For databases setup with Multi-AZ configuration, Amazon RDS performs synchronous replication to a standby instance in a different Availability Zone to provide high availability.

To use Amazon RDS for Db2, customers can purchase a Db2 license from the AWS Marketplace for hourly, pay-as-you-go pricing, or use Bring Your Own License (BYOL). Both hourly and BYOL licensing are available in Standard and Advanced Editions. You can also choose to use the latest Db2 Community Edition that provides all the features available in Standard and Advanced Editions, with no commercial software licensing charges for development and test applications. This allows you to easily start developing and testing Db2 applications with a managed database service without worrying about software licensing.

To learn more about Amazon RDS for Db2, refer to documentation and pricing pages.

 

Amazon OpenSearch Service now supports the Agent Toolkit for AWS with a curated skill

Amazon OpenSearch Service now integrates with the Agent Toolkit for AWS, enabling you to build, manage, and query OpenSearch Service domains and OpenSearch Serverless collections directly from AI coding agents such as Claude Code, Kiro, and Cursor. The integration is powered by the AWS MCP (Model Context Protocol) server, which executes AWS API calls on your behalf, paired with the curated amazon-opensearch-service skill that automatically routes natural-language requests to the right capability.

With this skill, you can describe a goal in plain language and the agent handles the rest across five areas. Migration moves you from self-managed OpenSearch into OpenSearch Service or OpenSearch Serverless. Operations provisions and manages domains and collections. Search builds vector, semantic, hybrid, and RAG search. Log analytics analyzes logs with PPL and OpenSearch Ingestion. Trace analytics investigates distributed traces with OpenTelemetry. The integration works with both managed domains and collections across all versions, requires no changes to your existing infrastructure, and is available at no additional charge. To learn more about these capabilities, see our documentation.

Support is available in all AWS Regions where Amazon OpenSearch Service and OpenSearch Serverless are offered. To get started, install the aws-data-analytics plugin in your agent — it bundles the AWS MCP Server configuration and the OpenSearch skill in a single step. For setup instructions, see MCP Server and Agent Skills

AWS Japan Blog

AI と一緒に進める AWS Well-Architected Framework レビュー のすすめ

「セキュリティは大丈夫だろうか」「障害が起きたときに復旧できるだろうか」「このアーキテクチャはベストプラクティスに沿っているだろうか」AWS 上にシステムを構築・運用する中で、このような不安を感じたことはないでしょうか。こうした潜在的リスクを体系的に炙り出し、改善していくためのフレームワークとして有用なのが AWS Well-Architected Framework です。 しかし、Well-Architected レビューの実施には「フレームワークの内容を理解するのが難しい」「いつでも気軽に相談できるアドバイザーが欲しい」「時間がなくてレビューを実施できない」という悩みの声を耳にします。そこで本記事では、AI を活用して Well-Architected レビューを加速する 3 つのアプローチを紹介します。(AWS Summit Japan 2026 の Well-Architected ブース展示内容)

【開催報告】AWS Summit Japan 2026 — AI エージェントで危機対応:小売×消費財の混乱を AI と人が即座に解決

サプライチェーンの「想定外」に AI エージェントと人間が即応するデモを AWS Summit Japan 2026 で展示しました。BCP 訓練の実態、Human-in-the-Loop の仕組み、来場者との対話から見えた課題と期待、そして今日から試せるワークショップまでを一本にまとめた開催報告です。

AWS Weekly Roundup: AWS Builder Center 1 周年、セキュリティハブにおけるネットワークスキャン、Loom for AWS など (2026 年 7 月 13 日)

AWS Builder Center は 2026年 7 月 6 日週、提供開始から 1 周年を迎えました。2 […]

【開催報告】AWS GenAI Catapult! 〜AI 駆動型ハッカソンイベント:ユースケース創出から Kiro によるプロトタイプ開発まで〜

2026年6月11日(木)、12日(金)の2日間、AWS 麻布台オフィスにて AI 駆動型ハッカソンイベント「 […]

月刊 AWS 製造 2026 年 7 月号

みなさん、こんにちは。ソリューションアーキテクトの吉川です。FIFA ワールドカップ 2026 がいよいよ佳境 […]

Kiro でテスト駆動開発(TDD):こうあるべき体験

私のキャリアの初期に、所属していた組織は、コード品質の向上と自信を持ってリファクタリングできる体制づくりのために、本格的にユニットテストを導入するという正しい判断を下しました。私たちは テスト駆動開発(TDD) の導入を試みました。その利点は理解していたものの、TDD を実践する作業自体が負担に感じられ、エンジニアたちにこの手法を一貫して適用してもらえませんでした。私自身、TDD というアイデアは大好きでしたが、実際の作業は嫌いでした。本記事では、Kiro を使って TDD を実践する方法を紹介し、red-green-refactor サイクルに沿ったテストを手作業で書くという苦痛を伴うことなく、TDD の恩恵を受ける方法をお見せします。

AWS Security Blog

Authenticate legitimate AI agent traffic with AWS WAF Bot Control

As AI agents and automated tools increasingly access web applications, distinguishing legitimate bot traffic from malicious attempts has become a critical security challenge. Traditional approaches such as IP-based filtering and reverse DNS lookups fail in multi-tenant systems (such as Amazon Bedrock AgentCore) where thousands of distinct workloads share the same IP space. Attackers can easily […]

Security Hub adds AI workload protection and multicloud support for Microsoft Azure

Security Hub is our foundation for full-stack enterprise security across clouds. It centralizes your security operations and turns raw signals into prioritized insights, so your team spends its time managing real risk instead of stitching tools together. Today that foundation grows in two directions our customers asked for most. We are adding purpose-built protection for […]

ICYMI: June 2026 @AWS Security

Read all about the latest AWS security features, compliance updates, and hands-on resources in our new, monthly digest posts. You’ll find expert blog posts, new service capabilities, code samples, and workshops. AWS Security Blog posts This month’s AWS Security Blog posts covered identity and access management, threat intelligence, network security, AI-powered security tooling, and multi-account […]

AWS Security Bulletins

CVE-2026-15643 - AWS HealthLake MCP Server SSRF via Unvalidated Pagination URL

Bulletin ID: 2026-054-AWS
Scope: AWS
Content Type: Important (requires attention)
Publication Date: 07/14/2026 13:00 PM PDT

Description:

AWS HealthLake MCP Server (awslabs.healthlake-mcp-server) is a Model Context Protocol server that enables AI assistants to interact with AWS HealthLake FHIR datastores. We identified CVE-2026-15643, a server-side request forgery in the pagination handling component in AWS awslabs.healthlake-mcp-server before 0.0.14 on all platforms might allow a remote authenticated user to exfiltrate AWS temporary security credentials to an arbitrary endpoint via a crafted next_token parameter. The server does not validate that pagination URLs point back to the expected HealthLake endpoint, allowing an actor to redirect subsequent requests to an actor-controlled server.

Impacted versions: < 0.0.14

Please refer to the article below for the most up-to-date and complete information related to this AWS Security Bulletin.

CVE-2026-15738 - Issue with AWS Load Balancer Controller Cross-Namespace Traffic Interception via HTTPRoute/GRPCRoute Priority Ordering

Bulletin ID: 2026-055-AWS
Scope: AWS
Content Type: Important (requires attention)
Publication Date: 07/14/2026 13:30 PM PDT

Description:

The AWS Load Balancer Controller is an open-source Kubernetes controller that manages AWS Elastic Load Balancing resources for Kubernetes clusters. We identified CVE-2026-15738, an incorrect rule precedence ordering issue in the Gateway API listener rule generation logic. When both an HTTPRoute and a GRPCRoute are attached to the same Application Load Balancer (ALB) HTTPS listener with the same hostname, the controller assigns ALB listener rule priorities based on route kind rather than route specificity. This causes all HTTPRoute-derived rules to receive lower ALB priority numbers, evaluated first by the ALB, than GRPCRoute-derived rules, regardless of which route is more specific. A namespace-scoped user with permission to create HTTPRoute objects in a namespace admitted by a shared Gateway can create a catch-all HTTPRoute that intercepts traffic intended for a more-specific GRPCRoute in another namespace.

Impacted versions: AWS Load Balancer Controller v3.4.1 and any version that includes support for attaching both HTTPRoute and GRPCRoute to the same listener (introduced in PR #4794)

Please refer to the article below for the most up-to-date and complete information related to this AWS Security Bulletin.

AWS Architecture Blog

How Mapfre USA modernized fraud claims with Amazon EMR Serverless

Insurance fraud remains a significant challenge for the insurance industry because fraudulent claims can increase loss costs, reduce trust, and consume investigation capacity that could otherwise be focused on serving customers. Traditional fraud detection approaches typically rely on rules-based controls, manual investigation triggers, historical claim patterns, and structured-data-only analysis. These approaches are useful for known […]

How Mapfre Insurance modernized fraud claims with Amazon EMR Serverless

Insurance fraud remains a significant challenge for the insurance industry because fraudulent claims can increase loss costs, reduce trust, and consume investigation capacity that could otherwise be focused on serving customers. Traditional fraud detection approaches typically rely on rules-based controls, manual investigation triggers, historical claim patterns, and structured-data-only analysis. These approaches are useful for known […]

AWS Machine Learning Blog

ScienceSoft’s HIPAA-compliant AI voice scheduler built on AWS

In this post, you will learn how ScienceSoft, an Amazon Web Services (AWS) Services Partner, integrated Amazon Nova 2 Sonic with Amazon Bedrock Guardrails to build a Health Insurance Portability and Accountability Act (HIPAA)-compliant AI voice scheduler. You will see how the solution addresses healthcare scheduling challenges while maintaining privacy, compliance, and responsible AI standards, and how you can apply the same architecture to your own workflows.

Scaling medical content review at Flo Health with Amazon Bedrock – Part 2

In this post, we share how Flo Health’s engineering team turned a proof of concept (PoC) from the AWS Generative AI Innovation Center into a production-grade, AI-powered medical content review and generation system built on Amazon Bedrock. T

Scaling UX testing with Amazon Nova Act: A new approach to user flow analysis

Using generative AI enables parallel execution of comprehensive user flow testing at scale. This solution demonstrates how to build a cloud-deployed UX testing platform that automatically generates test scenarios from documentation, executes user flows at scale using the intelligent navigation capabilities of Nova Act, and provides actionable insights through automated analysis.

Accelerating software delivery with agentic QA automation using Amazon Nova Act – Part 2

In this post, we extend that foundation to demonstrate how QA Studio addresses batch regression testing and pipeline integration through test suites that organize and parallelize execution, and a command-line interface that brings agentic testing into automated CI/CD pipelines.

Multi-agent social intelligence with Strands Agents and Amazon Bedrock

This post shows how Thrad.ai deployed a multi-agent system with Strands Agents and Amazon Bedrock AgentCore that automates the pipeline from prospect discovery through personalized email generation. The post compares two orchestration patterns (Swarm and Graph) with head-to-head benchmarks on latency, cost, and email quality. You’ll also learn how the system scores prospects using weighted criteria, intent classification, and temporal decay, plus governance controls for production deployment.

AWS Compute Blog

Introducing modularized kernel cryptography in Amazon Linux

We are introducing modularized kernel cryptography in Amazon Linux 2023, an approach that separates Federal Information Processing Standard (FIPS) 140-3 cryptographic components into an independent kernel module that can be certified once and reused across subsequent kernel versions. In this post, we describe how this modular approach works, what it means for FIPS compliance workflows, […]