AWS News - 2026-07-16

2026-07-16
最終更新: 2026-07-18 03:02:06 JST

AI による概要

37 記事

この日は Oracle Database@AWS の日本語解説がまとめて公開されたのが最大の特徴です。ワークロード適性を見極める 5 つの質問から、CloudFormation / Terraform でのプロビジョニング、バックアップとリカバリ、高性能ネットワーキング、クロスアカウント共有、トラフィックの集中検査まで、導入から運用までを一通り網羅する構成になっています。Amazon OpenSearch Service には書き込み可能なウォームストレージが加わり、UltraWarm で必要だったホストとの往復なしにウォーム層へ直接書き込めるようになってインフラコストを最大 48% 削減できます。CloudWatch Logs はストレージのインテリジェント階層化と Logs Insights の 25 個の新コマンド・関数を追加しました。Aurora DSQL は FedRAMP Moderate の対象となり、AWS Backup は論理的にエアギャップされた保管庫と復元テストを複数リージョンへ拡大しています。

主要トピック
  • Oracle Database@AWS: 適性判断・IaC プロビジョニング・バックアップ・ネットワーキング・共有・検査までの日本語解説シリーズを公開

  • 検索基盤: OpenSearch Service の書き込み可能なウォームストレージでインフラコスト最大 48% 削減、更新は数秒に

  • ログ運用: CloudWatch Logs がストレージのインテリジェント階層化に対応、Logs Insights に 25 の新コマンド・関数

  • コンプライアンス: Aurora DSQL が FedRAMP Moderate の対象に

  • バックアップ: 論理的にエアギャップされた保管庫と復元テストを 6〜7 リージョンへ拡大

  • データベース: RDS が 24 時間あたり 4 回までのストレージ変更に対応、Cognito はパスワードハッシュ付きユーザーインポートをサポート

  • 脆弱性: Strands Agents Tools の elasticsearch_memory における認証情報漏洩 (CVE-2026-15746)

AI (Claude Opus 5) が生成 · 2026-08-28 09:25:46 JST

AWS What's New

AWS Glue SAP OData connector and zero-ETL integrations are now available in AWS GovCloud (US) regions

AWS Glue SAP OData connector and zero-ETL integrations are now available in AWS GovCloud (US-West) and AWS GovCloud (US-East) Regions, with support for Amazon DynamoDB, Salesforce, and SAP OData as sources. Customers operating in regulated environments can now replicate data from these sources into Amazon Redshift, Amazon S3, or other supported destinations without building or maintaining custom data pipelines.

The SAP OData connector allows you to extract data from SAP systems exposing OData services, eliminating the need for custom extraction logic or third-party middleware. The zero-ETL integrations are fully managed by AWS and minimize the need to build ETL data pipelines. With this new zero-ETL integration, you can efficiently extract and load valuable data from your Amazon DynamoDB databases or Salesforce and SAP applications into your data lake and data warehouse for analysis. Zero-ETL integration reduces your operational burden and saves the weeks of engineering effort needed to design, build, and test data pipelines. By selecting a few settings in the no-code interface, you can quickly set up your zero-ETL integration to automatically ingest and continually maintain an up-to-date replica of your data in the data lake and data warehouse. Zero-ETL integrations help you focus on deriving insights from your application data, breaking down data silos in your organization and improving operational efficiency.

To get started, navigate to the AWS Glue console and create a new zero-ETL integration. For more information, visit the AWS Glue zero-ETL integrations documentation.

Amazon RDS now supports up to four storage modifications in 24 hours

Amazon RDS now allows up to four storage modifications per database instance within a rolling 24-hour window. These modifications let you increase the size, change the type, and adjust the performance of your RDS storage volumes. You can start a new modification right after storage optimization for the previous modification is complete without having to wait for the six-hour cool-off period to complete.

This enhancement improves operational agility for scaling storage capacity or adjusting performance during sudden data growth or unexpected workload spikes. With RDS storage modifications, you can modify your volumes without downtime, keeping applications running with minimal performance impact.

The feature is automatically enabled on all Amazon RDS for PostgreSQL, Amazon RDS for MariaDB, Amazon RDS for MySQL, Amazon RDS for Db2, Amazon RDS for Oracle, and Amazon RDS for Microsoft SQL Server instances in all commercial AWS Regions and the AWS GovCloud (US) Regions. To learn more, refer the Amazon RDS User Guide.

Amazon RDS and Aurora now support R8g and M8g database instances in additional AWS Regions

詳細を表示

AWS Graviton4-based R8g database instances are now generally available for Amazon Aurora (MySQL and PostgreSQL compatibility) and Amazon RDS for PostgreSQL, MySQL, and MariaDB in Asia Pacific (Hyderabad, Melbourne, Malaysia), Europe (London, Paris, Zurich), AWS GovCloud (US-East), South America (Sao Paulo), and Mexico (Central) regions. Additionally, M8g instances are now supported for Amazon RDS for PostgreSQL, MySQL, and MariaDB in US West (N. California), Asia Pacific (Mumbai, Sydney, Hong Kong, Seoul, Malaysia, Singapore), Canada West (Calgary), Europe (Zurich, Milan, Paris), South America (Sao Paulo) and Africa (Cape Town) regions. 

AWS Graviton4-based instances provide up to 40% performance improvement and up to 29% price/performance improvement for on-demand pricing over Graviton3-based instances of equivalent sizes on Amazon Aurora and Amazon RDS databases, depending on database engine, version, and workload. Built on the AWS Nitro System, the new R8g database instances introduce 24xlarge and 48xlarge sizes, delivering up to 192 vCPUs, an 8:1 ratio of memory to vCPU with the latest DDR5 memory, up to 50Gbps enhanced networking bandwidth, and up to 40Gbps of bandwidth to Amazon Elastic Block Store (Amazon EBS).

You can easily launch R8g or M8g database instances through the Amazon RDS Management Console or by using the AWS Command Line Interface (CLI). For detailed information about specific engine versions that support these database instance types, please refer to the Aurora and RDS documentation. For complete information on pricing and regional availability, please refer to the Amazon RDS pricing page

Amazon RDS and Aurora expand R8gd and M8gd to additional Regions

詳細を表示

Amazon Relational Database Service (RDS) now supports R8gd database instances in 12 additional regions and and M8gd database instances in 6 additional Regions with Optimized Reads for Amazon Aurora PostgreSQL, RDS for PostgreSQL, RDS for MySQL, and RDS for MariaDB.

R8gd and M8gd instances deliver up to 165% better throughput and up to 120% better price-performance over R6g instances for Aurora PostgreSQL. Optimized Reads uses local NVMe-based SSD block storage to store ephemeral data such as temporary tables, reducing network storage access and improving query latency. The result is improved query performance for complex queries and faster index rebuild operations. Aurora PostgreSQL Optimized Reads instances using the I/O-Optimized configuration also use the local storage to extend their caching capacity. Database pages that are evicted from the in-memory buffer cache are cached in local storage to speed subsequent retrieval of that data.

Customers can get started with Optimized Reads through the AWS Management Console, CLI, and SDK by modifying their existing Aurora and RDS databases or creating a new database using R8gd or M8gd instances. R8gd instances are available in the following additional regions: Europe (Ireland), Asia Pacific (Seoul), Asia Pacific (Malaysia), Europe (London), US West (N. California), Asia Pacific (Sydney), Canada (Central), Asia Pacific (Jakarta), Africa (Cape Town), Canada West (Calgary), South America (Sao Paulo) and Asia Pacific (Hong Kong). M8gd instances are available in the following additional regions: Europe (Ireland), Asia Pacific (Malaysia), Europe (London), Asia Pacific (Sydney), South America (Sao Paulo) and Canada (Central). For complete information on pricing and regional availability, please refer to the pricing page. For information on specific engine versions that support these DB instance types, please see the Aurora and RDS documentation.

Amazon MSK Express Brokers adds support for Apache Kafka version 4.2

Amazon Managed Streaming for Apache Kafka (Amazon MSK) Express Brokers now supports Apache Kafka version 4.2. This release includes Eligible Leader Replicas (ELR) enhancements that strengthen availability with improved leader election correctness. It also introduces a new consumer rebalance protocol that helps ensure smoother and faster group rebalances, and a new Streams Rebalance Protocol that extends broker coordination capabilities to Kafka Streams for optimized task assignments. For a complete list of improvements and bug fixes, please refer to the Apache Kafka release notes for version 4.2.

MSK Express Brokers are designed to deliver up to three times more throughput per broker, scale up to 20 times faster, and reduce recovery time by 90 percent. This launch brings the latest open-source reliability and performance improvements to MSK Express.

To get started, simply select version 4.2.x when creating a new cluster with Express Brokers via the AWS Management Console, AWS CLI, or AWS SDKs. You can also upgrade existing MSK Express Brokers with an in-place rolling update. Amazon MSK orchestrates broker restarts to maintain availability and protect your data during the upgrade. Kafka version 4.2 support is available today across all AWS regions where Amazon MSK Express Brokers is offered. To learn how to get started, see the Amazon MSK Developer Guide.

Amazon Cognito now supports importing users with password hashes

Amazon Cognito now supports importing users with password hashes in CSV user imports. Previously, users imported from a CSV file had to reset their passwords on first sign-in. Now, you can include password hashes in your CSV file so that imported users can sign in immediately with their existing credentials.

When creating a CSV import, you specify the password hashing algorithm used by your source system. Amazon Cognito imports these users and verifies their password against the imported hash on first sign-in. Supported algorithms include bcrypt, scrypt, Argon2id, and PBKDF2 with SHA-256. All imported hashes receive an additional layer of cryptographic protection before storage.

Password hash import is available in all AWS Regions where Amazon Cognito is available. To get started, create a user import using the AWS Management Console, AWS Command Line Interface (CLI), or AWS Software Development Kits (SDKs). See the developer guide for instructions.

Amazon EC2 G7e instances now available in additional regions

Starting today, Amazon Elastic Compute Cloud (Amazon EC2) G7e instances accelerated by NVIDIA RTX PRO 6000 Blackwell Server Edition GPUs are now available in the AWS Europe (Frankfurt, Stockholm) and Asia Pacific (Mumbai) Regions. G7e instances offer up to 2.3x inference performance compared to G6e.

Customers can use G7e instances to deploy large language models (LLMs), agentic AI models, multimodal generative AI models, and physical AI models. G7e instances offer the highest performance for spatial computing workloads as well as workloads that require both graphics and AI processing capabilities. G7e instances feature up to 8 NVIDIA RTX PRO 6000 Blackwell Server Edition GPUs, with 96 GB of memory per GPU, and 5th Generation Intel Xeon processors. They support up to 192 virtual CPUs (vCPUs) and up to 1600 Gbps of networking bandwidth. G7e instances support NVIDIA GPUDirect Peer to Peer (P2P) that boosts performance for multi-GPU workloads. Multi-GPU G7e instances also support NVIDIA GPUDirect Remote Direct Memory Access (RDMA) with EFA in EC2 UltraClusters, reducing latency for small-scale multi-node workloads.

You can use G7e instances for Amazon EC2 in the following AWS Regions: US West (Oregon), US East (N. Virginia, Ohio), Europe (Spain, London, Frankfurt, Stockholm) and Asia Pacific (Tokyo, Seoul, Mumbai). You can purchase G7e instances as On-Demand Instances, Spot Instances, or as part of Savings Plans.

To get started, visit the AWS Management Console, AWS Command Line Interface (CLI), and AWS SDKs. To learn more, visit G7e instances.

Amazon MQ now supports configurable storage for RabbitMQ brokers

Amazon MQ now allows you to configure the EBS Disk storage size for RabbitMQ brokers independently of instance type. When creating or updating a broker, you can define a custom storage size, allowing you to right-size storage independently of your instance size to match your specific messaging workload requirements. Configurable storage is available for RabbitMQ M7g brokers on version 4.2 or later using cluster deployments only.

With configurable storage, you can choose a storage size from the default value on M7g to the maximum allowed value depending on your instance size in increments of 5 GB. You can specify the Storage Size using the using the AWS Console, AWS CloudFormation, AWS Command Line Interface (CLI), or the AWS Cloud Development Kit (CDK). Storage changes are applied during the next broker reboot. 

Standard Amazon MQ storage pricing applies based on the disk size as per Amazon MQ pricing. Configurable storage is available in all commercial AWS Regions where Amazon MQ for RabbitMQ is offered. To learn more, see the Amazon MQ Developer Guide.

Amazon CloudWatch Logs announces intelligent tiering for storage

Amazon CloudWatch Logs now supports intelligent storage tiering, which automatically classifies your log data across three storage tiers - Standard (existing), Infrequent Access, and Archive Instant Access based on access patterns. This allows you to store logs in Amazon CloudWatch for extended periods at lower-cost tiers without any operational overhead.

With today's launch, customers can now retain high-volume verbose logs needed to be stored for longer periods at a lower cost in Amazon CloudWatch. Instead of filtering these logs or exporting them, you can now keep them natively in Amazon CloudWatch and benefit from the same query experience regardless of which tier your data resides in. Amazon CloudWatch monitors access patterns and automatically reclassifies data not accessed for 30 days to the Infrequent Access tier, and data not accessed for 90 days to the Archive Instant Access tier. When you access older data, it is automatically promoted back to the Standard tier for 30 days. By consolidating all your logs in CloudWatch, you get full visibility in one tool, thereby eliminating the operational overhead of managing multiple storage solutions and reducing your Mean Time to Resolution (MTTR) by analyzing, and alerting on all your logs in a single place.

Amazon CloudWatch Logs Intelligent-Tiering is available in all AWS commercial regions except Middle East (Bahrain) and Middle East (UAE). You can enable intelligent tiering at the account level in the AWS Management Console, AWS SDKs or through AWS CLI. Learn more about CloudWatch Logs intelligent tiering pricing and documentation.

Amazon CloudWatch Logs Insights adds 25 new query commands and functions

Amazon CloudWatch Logs Insights query language now supports 25 new commands and functions that expand your ability to query, transform, correlate, and analyze logs. Customers analyzing logs in CloudWatch Logs Insights often need to perform statistical aggregation, handle null values in time-series data, compare logs across time windows, detect outliers, and enrich events with lookup data.

With this launch, CloudWatch Logs Insights adds type conversion and encoding functions (hexToAscii, hexToDec, decToHex), date and time functions (parseDate, formatDate, queryStartTime, queryEndTime, queryTimeRange), string functions (messageSize), JSON inspection functions (jsonArraySize, jsonArrayContains), and a conditional validation function (isNumeric). It also introduces statistical commands (variance, topk, countFrequent), row-sequencing and null-handling commands (autoregress, accum, filldown, fillmissing), sessionization and time-comparison commands (sessionize, logcompare), a data analysis command (outlier), query-composition and join commands (where, appendcols), and a lookup enrichment command (cidrlookup).

These commands and functions are available today in all commercial AWS Regions. To learn more, see the Amazon CloudWatch Logs documentation.

Amazon Aurora DSQL is now in scope for FedRAMP Moderate

Amazon Aurora DSQL is now in scope for FedRAMP Moderate in the US East (Ohio), US East (N. Virginia), and US West (Oregon) Regions. You can now use Aurora DSQL to build applications and run workloads that are subject to FedRAMP Moderate compliance requirements.

The Federal Risk and Authorization Management Program (FedRAMP) is a US government-wide program that delivers a standard approach to the security assessment, authorization, and continuous monitoring for cloud products and services. Amazon Aurora DSQL is the fastest serverless, distributed SQL database, with active-active high availability and multi-Region strong consistency. It enables you to build always-available applications with virtually unlimited scale, the highest availability, and zero infrastructure management.

To learn more about FedRAMP, visit the AWS services in scope page. To learn more about Amazon Aurora DSQL, visit the Aurora DSQL webpage and documentation.

AWS Control Tower Account Factory for Terraform now re-applies customizations when accounts move between OUs

AWS Control Tower Account Factory for Terraform (AFT) can now automatically re-apply an account's customizations when that account moves to a different Organizational Unit (OU). Previously, moving an enrolled account between OUs required manually triggering customization re-application, creating operational overhead and risk of configuration drift. With this capability, you can opt in to automatic re-application in your AFT deployment, so accounts stay consistent with their OU-specific configuration as soon as they're moved.

To enable this capability, set aft_customization_triggers = ["account_move"] in your AFT configuration. The re-application workflow skips the bootstrap and provisioning phases, running only global and account-level customizations for faster execution. Individual accounts can be excluded from this behavior by setting account_skip_customization_triggers = "true", giving teams precise control over which accounts participate in automated re-application.

This release also includes additional improvements: support for custom Terraform Cloud and Enterprise workspace naming variables, tighter access controls on the AFT logging bucket, and improved scaling for large-scale AWS Enterprise Support enrollment. Organizations enforcing compliance or security baselines tied to OU membership will benefit most from these combined enhancements.

This capability is available today across all AWS regions where AWS Control Tower Account Factory for Terraform is offered. To learn more about enabling automatic customization re-application and upgrading to the latest AFT release, visit the AFT documentation and review the AFT release notes on GitHub.

AWS Backup extends logically air-gapped vault support to six additional AWS Regions

AWS Backup logically air-gapped vaults are now available in six additional AWS Regions: Asia Pacific (Taipei), Asia Pacific (Malaysia), Asia Pacific (New Zealand), Asia Pacific (Thailand), Mexico (Central), and Canada West (Calgary).

With logically air-gapped vaults now available in these Regions, you can store immutable, isolated backups that are locked by default and encrypted using AWS owned keys or customer-managed keys. You can back up directly to logically air-gapped vaults, copy backups across accounts and Regions, share vaults for recovery using AWS Resource Access Manager (RAM), and safeguard vault access during account compromise using Multi-party approval.

To get started, visit the AWS Backup console, AWS Command Line Interface (CLI), or AWS SDKs. For a complete list of supported Regions and features, visit the AWS Backup documentation. To learn more about logically air-gapped vaults, visit the feature documentation and pricing page.

AWS Backup extends restore testing support to six additional AWS Regions

AWS Backup restore testing is now available in six additional AWS Regions: Asia Pacific (Taipei), Asia Pacific (Malaysia), Asia Pacific (New Zealand), Asia Pacific (Thailand), Mexico (Central), and Canada West (Calgary).

Restore testing helps you automate and periodically run restore tests of supported AWS resources across storage, compute, and database services. You can create restore testing plans that automatically select recovery points, run restores on a schedule, and measure restore job completion time against your recovery time objectives (RTO). This helps you evaluate recovery readiness and meet regulatory and compliance requirements for disaster recovery and business continuity.

To get started, visit the AWS Backup console, AWS Command Line Interface (CLI), or AWS SDKs. For a complete list of supported Regions and features, visit the AWS Backup documentation To learn more about restore testing, visit the feature documentation and pricing page.

AWS Backup extends logically air-gapped vault support to seven additional AWS Regions

AWS Backup logically air-gapped vaults are now available in seven additional AWS Regions: Asia Pacific (Taipei), Asia Pacific (Malaysia), Asia Pacific (New Zealand), Asia Pacific (Thailand), Israel (Tel Aviv), Mexico (Central), and Canada West (Calgary).

With logically air-gapped vaults now available in these Regions, you can store immutable, isolated backups that are locked by default and encrypted using AWS owned keys or customer-managed keys. You can back up directly to logically air-gapped vaults, copy backups across accounts and Regions, share vaults for recovery using AWS Resource Access Manager (RAM), and safeguard vault access during account compromise using Multi-party approval.

To get started, visit the AWS Backup console, AWS Command Line Interface (CLI), or AWS SDKs. For a complete list of supported Regions and features, visit the AWS Backup documentation. To learn more about logically air-gapped vaults, visit the feature documentation and pricing page.

AWS Backup extends restore testing support to seven additional AWS Regions

AWS Backup restore testing is now available in seven additional AWS Regions: Asia Pacific (Taipei), Asia Pacific (Malaysia), Asia Pacific (New Zealand), Asia Pacific (Thailand), Israel (Tel Aviv), Mexico (Central), and Canada West (Calgary).

Restore testing helps you automate and periodically run restore tests of supported AWS resources across storage, compute, and database services. You can create restore testing plans that automatically select recovery points, run restores on a schedule, and measure restore job completion time against your recovery time objectives (RTO). This helps you evaluate recovery readiness and meet regulatory and compliance requirements for disaster recovery and business continuity.

To get started, visit the AWS Backup console, AWS Command Line Interface (CLI), or AWS SDKs. For a complete list of supported Regions and features, visit the AWS Backup documentation To learn more about restore testing, visit the feature documentation and pricing page.

AWS Japan Blog

【開催報告】AWS Summit Japan 2026 ― AI で加速する製品イノベーション 〜マルチエージェントで実現する製品開発

はじめに AWS Summit Japan 2026 の流通小売・消費財・飲食ブースにて、私たちは「AI で加 […]

Amazon OpenSearch Service の書き込み可能なウォームストレージでコストと運用負荷を削減

Amazon OpenSearch Service に、書き込み可能なウォームストレージ (writable warm) が加わりました。UltraWarm では履歴データの更新にホットとの往復が必要でしたが、writable warm ならウォームに直接書き込めます。インフラコストは最大 48% 削減でき、更新も数時間ではなく数秒で完了します。

Amazon Bedrock における LLM コストの最適化:請求の帰属から運用テレメトリまで

Amazon Bedrock 上で、基盤モデル (FM) の一種である大規模言語モデル (LLM) の利用が拡 […]

株式会社Diverse が Amazon SageMaker で実現した「温度感」ベースのマッチング体験

はじめに 本ブログは 株式会社Diverse 様と Amazon Web Services Japan 合同会 […]

Amazon RDS for Oracle の追加ストレージボリュームを使ったデータ作成と再編成のベストプラクティス

Amazon RDS for Oracle の追加ストレージボリューム機能を使い、64 TiB を超えるストレージ拡張、アクティブデータと履歴データの分離配置、一時ストレージの確保を行う方法とベストプラクティスを解説します。

Amazon Bedrock と Oracle Database@AWS で生成 AI ユースケースを加速する

Oracle Database@AWS 上の Oracle AI Database 26ai をベクトルストアとして使い、Amazon Bedrock の Amazon Titan 埋め込みモデルと Anthropic Claude LLM を統合した RAG アシスタントアプリケーションの構築手順を解説します。

AIで変える鉄道保全と、「クローズド」を読み解くクラウド設計 — AWS Summit Japan 2026 展示ブース開催報告

2026年6月25日〜26日、幕張メッセで開催された AWS Summit Japan 2026 にて、AWS […]

AWS CloudFormation を使った Oracle Database@AWS スタックのプロビジョニング

AWS CloudFormation テンプレートを使って Oracle Database@AWS の主要コンポーネント (ODB ネットワーク、Exadata インフラストラクチャ、VM クラスター) をプロビジョニングする手順を解説します。

Oracle Database@AWS のバックアップとリカバリオプションを理解する

Oracle Database@AWS (ExaDB-D / ADB-D) で利用できる自動・手動・ユーザー管理・長期バックアップの各オプションと、Amazon S3、OCI Object Storage、Autonomous Recovery Service へのバックアップ先の選択、リストアオプション、ベストプラクティスを解説します。

Oracle Database@AWS の高性能ネットワーキング入門

Oracle Database@AWS の高性能ネットワーキング機能を使い、EC2 上のアプリケーションと ODB@AWS データベース間で安定したサブミリ秒のネットワークレイテンシーを実現する設定手順を解説します。

Oracle Database@AWS のクロスアカウント共有のベストプラクティスとアーキテクチャパターン

AWS RAM によるリソース共有と AWS License Manager によるエンタイトルメント共有を使い、AWS アカウント間で Oracle Database@AWS リソースを共有する 6 つのアーキテクチャパターンとベストプラクティスを解説します。

Oracle Database@AWS を読み解く: Oracle ワークロードに最適な選択肢の見極め方

2025 年 7 月に GA となった Oracle Database@AWS (ODB@AWS) が Oracle ワークロードに適しているかを判断する 5 つの質問と、ビジネス・技術・ライセンス面での利点、Amazon RDS for Oracle や EC2 との使い分けを解説します。

Terraform を使用した Oracle Database@AWS リソースのプロビジョニング

本記事では、Terraform を使用して Oracle Database@AWS の主要コンポーネント(ODB ネットワーク、Exadata インフラストラクチャ、Exadata VM クラスター、Autonomous VM クラスター)をプロビジョニングする方法を説明します。サンプルの Terraform テンプレートとステップバイステップの手順により、Oracle Database@AWS 環境の自動デプロイを実現できます。

Oracle Database@AWS のトラフィック集中検査

Oracle Database@AWS 環境で AWS Transit Gateway の集中検査 VPC または AWS Cloud WAN のサービス挿入を使用して、東西・南北ネットワークトラフィックを集中検査する 2 つのパターンを解説します。

AWS Security Bulletins

CVE-2026-15746 - Credential disclosure in Strands Agents Tools elasticsearch_memory tool

Bulletin ID: 2026-056-AWS
Scope: AWS
Content Type: Important (requires attention)
Publication Date: 07/15/2026 11:30 AM PDT

Description:

Strands Agents is an open-source Python SDK for building and running AI agents. The strands-agents-tools package provides pre-built tools for use with the SDK, including the elasticsearch_memory tool for agent memory storage. We identified CVE-2026-15746, a server-side request forgery (SSRF) issue in the elasticsearch_memory tool. The tool exposed its connection parameters (es_url, cloud_id, api_key) as fields the large language model (LLM) could control through the tool schema. When a caller omitted the api_key parameter, the tool fell back to the operator's ELASTICSEARCH_API_KEY environment variable and sent it to whichever host the LLM specified. A crafted prompt could cause the tool to connect to a threat-actor-controlled server and disclose the operator's Elasticsearch API key in the Authorization header.

Impacted versions: < 0.7.0

Please refer to the article below for the most up-to-date and complete information related to this AWS Security Bulletin.

AWS Architecture Blog

How bitdrift scaled to 121 million concurrent gRPC connections on Amazon CloudFront for live telemetry sporting events

When 121 million mobile devices establish persistent gRPC connections to your origin infrastructure within seconds of a live broadcast, the routing policy behind your DNS records matters far more than it does at normal traffic levels. The wrong policy can concentrate all your connections onto a single origin endpoint, turning a scaling success into an […]

Prioritize your AWS Health alerts using AWS User Notifications

If you run critical workloads on AWS, such as a contact center on Amazon Connect Customer, database workloads on Amazon Relational Database Service (Amazon RDS), or hybrid connectivity through AWS Direct Connect, service health events demand your attention. But not all events are equal. An operational issue, a scheduled maintenance window, and a deprecation notice […]

AWS Machine Learning Blog

Monitor Amazon SageMaker Pipelines cross-account with custom Amazon CloudWatch dashboards

In this post, we present a solution designed to centralize the monitoring of SageMaker Pipelines across AWS accounts and Regions using Amazon CloudWatch custom dashboards. The accompanying GitHub repository provides a customizable AWS Cloud Development Kit (AWS CDK) example of the required infrastructure.

Agentic vision: Building visual intelligence with Amazon Bedrock and MCP servers

In this post, we walk you through the Computer Vision MCP Server, which illustrates this approach, representing how AI systems can process visual information and make intelligent decisions through a single, standardized interface. This convergence transforms what was once a complex integration challenge into a streamlined process, making AI capabilities accessible to a broader range of applications and developers.

Built Technologies builds an AI-powered document intelligence solution on AWS to power agents across real estate finance

Built partnered with the AWS Generative AI Innovation Center (GenAIIC), AWS Partner AND Digital, and AWS account teams to create a scalable, AI-powered document processing engine that can classify, split, extract, evaluate, and reason over complex real estate finance documents. It reduces workflows that previously took days to minutes, supports hundreds of document types, and gives technical teams and industry experts a shared environment for building and improving document processors.

AWS Compute Blog

New: Enhanced AssetState dimension for AWS Outposts capacity metrics on Amazon CloudWatch

Today, we are releasing an expanded format of our Amazon CloudWatch dimensions for AWS Outposts capacity metrics. The existing CloudWatch metrics, AvailableInstanceType_Count, UsedInstanceType_Count, InstanceTypeCapacityAvailability, and InstanceTypeCapacityUtilization for Outposts, can now be grouped using the new AssetState dimension with values: Active, Isolated, or Retiring. In this post, we describe what’s changing and how you can use […]