AWS News - 2026-08-01
2026-08-01
最終更新: 2026-08-04 07:04:53 JST
AI による概要
この日は月初で件数が少なく、エージェント運用とコンプライアンスが中心でした。Amazon Bedrock AgentCore Observability を使い、プロトタイプから本番に移行した AI エージェントを高速かつ効率的に保つための最適化手法が解説されています。Amazon Quick には Agentic Catalog Experience が導入され、データキュレーターが自然言語で上流のカタログ資産を発見できるようになりました。セキュリティブログでは HIPAA セキュリティ規則の技術的セーフガードについて、対象事業者とビジネスアソシエイト向けの実装・準備ガイダンスが公開されています。セキュリティ速報は 4 件と多く、smithy-rs 生成サーバーの未知キースキップ経路における制御されない再帰、OpenSearch Dashboards TSVB プラグインのプロトタイプ汚染による RCE、Strands Agents Tools の http_request における認可不備、@aws-amplify/codegen-ui-react の修正不完全が報告されました。
主要トピック
エージェント運用: AgentCore Observability による本番エージェントの速度・効率の最適化
データカタログ: Amazon Quick の Agentic Catalog Experience で自然言語による上流資産の発見
コンプライアンス: HIPAA セキュリティ規則の技術的セーフガード実装・準備ガイダンスを公開
脆弱性: OpenSearch Dashboards TSVB プラグインのプロトタイプ汚染によるリモートコード実行 (CVE-2026-18420)
脆弱性: Strands Agents Tools の http_request における認可不備、smithy-rs の制御されない再帰による DoS
データベース: Aurora DSQL のマルチリージョンクラスターが 4 リージョン追加、RDS for Oracle に R8i / M8i のリザーブドインスタンス
AWS What's New
Amazon RDS for Oracle now offers Reserved Instances for R8i and M8i instances
- Link: https://aws.amazon.com/about-aws/whats-new/2026/07/amazon-rds-oracle-r8i-m8i/
- Published: 2026-08-01 00:00:00
- Fetched: 2026-08-01 08:58:20
Amazon RDS for Oracle now offers 1-year and 3-year Reserved Instances for R8i and M8i instances with up to 53% cost savings compared to On-Demand prices. These instances are powered by custom Intel Xeon 6 processors, available only on AWS, delivering the highest performance and fastest memory bandwidth among comparable Intel processors in the cloud. R8i and M8i instances offer up to 15% better price-performance and 2.5x more memory bandwidth compared to previous generation Intel-based instances.
Reserved Instance benefits apply to both Multi-AZ and Single-AZ configurations. This means that customers can move freely between configurations within the same database instance class type, making them ideal for varying production workloads. Amazon RDS for Oracle Reserved Instances also provide size flexibility for the Oracle database engine under the Bring Your Own License (BYOL) licensing model. With size flexibility, the discounted rate for Reserved Instances will automatically apply to usage of any size in the same instance family.
Customers can now purchase Reserved Instances for Amazon RDS for Oracle in all AWS regions where R8i and M8i instances are available except the South America (São Paulo) Region. For information on specific Oracle database editions and licensing options that support these database instance types, refer to the Amazon RDS user guide.
To get started, purchase Reserved Instances through the AWS Management Console, AWS CLI, or AWS SDK. For detailed pricing information and purchase options visit Amazon RDS for Oracle Pricing.
Amazon Aurora DSQL adds multi-Region cluster support in four more Regions
- Link: https://aws.amazon.com/about-aws/whats-new/2026/07/amazon-aurora-dsql-adds-multi-region-clusters-four-more-regions/
- Published: 2026-08-01 03:00:00
- Fetched: 2026-08-01 05:16:28
Starting today, Amazon Aurora DSQL supports multi-Region clusters in four additional AWS Regions: Europe (Stockholm), Europe (Spain), Asia Pacific (Mumbai), and Asia Pacific (Singapore). Aurora DSQL is the fastest serverless, distributed SQL database, with active-active high availability and multi-Region strong consistency. Each multi-Region cluster provides a writable endpoint in both peered Regions, presenting a single logical database that remains available even if one Region becomes unavailable.
With this launch, Aurora DSQL multi-Region clusters are available in the following AWS Regions: US East (N. Virginia), US East (Ohio), US West (Oregon), Asia Pacific (Mumbai), Asia Pacific (Osaka), Asia Pacific (Seoul), Asia Pacific (Singapore), Asia Pacific (Tokyo), Canada (Central), Canada West (Calgary), Europe (Frankfurt), Europe (Ireland), Europe (London), Europe (Paris), Europe (Spain), and Europe (Stockholm). Aurora DSQL single-Region clusters are available in all of these Regions and in Asia Pacific (Hong Kong), Asia Pacific (Melbourne), Asia Pacific (Sydney), and South America (São Paulo).
Get started with Aurora DSQL for free with the AWS Free Tier. To learn more, visit the Aurora DSQL webpage and documentation.
Amazon SageMaker Unified Studio now supports Teradata Vantage
- Link: https://aws.amazon.com/about-aws/whats-new/2026/07/amazon-sagemaker-unified-teradata
- Published: 2026-08-01 05:19:00
- Fetched: 2026-08-04 07:04:53
Amazon SageMaker Unified Studio now supports Teradata Vantage as a data source, enabling you to query and analyze your enterprise data warehouse data directly alongside your other data assets. With this new connection, you can combine business-critical data stored in Teradata with data from sources like Amazon Redshift, Amazon S3, and relational databases — all within a single, governed environment.
This integration is particularly valuable when you need to correlate data across analytical and operational workloads. For example, you can join historical enterprise data and business metrics stored in Teradata with real-time datasets to gain deeper insights into customer behavior, financial performance, and operational trends. Data engineers and analysts can build data pipelines that bring together enterprise data warehouse assets with cloud-native datasets, streamlining cross-source workflows without switching between tools. To get started, add a Teradata Vantage connection under your project’s data section. Your Teradata data now appears in the data explorer alongside your other project data. From there, you can query it directly using the query editor, explore it in notebooks, or incorporate it into a visual ETL job, all without leaving the studio.
Support for Teradata Vantage connections is available in all AWS Regions where Amazon SageMaker Unified Studio is available.
To get started, see connecting to a new data source in the Amazon SageMaker Unified Studio User Guide.
AWS Security Blog
HIPAA Security Rule on AWS – Technical Safeguards Implementation and Readiness Guidance
- Link: https://aws.amazon.com/blogs/security/hipaa-security-rule-on-aws-technical-safeguards-implementation-and-readiness-guidance/
- Published: 2026-08-01 04:44:25
- Fetched: 2026-08-01 05:16:29
AWS Security Bulletins
CVE-2026-18140 - Uncontrolled recursion in the aws-smithy-json unknown-key skip path allows unauthenticated remote denial of service in smithy-rs generated servers
- Link: https://aws.amazon.com/security/security-bulletins/rss/2026-067-aws/
- Published: 2026-08-01 01:27:39
- Fetched: 2026-08-01 03:16:23
Please refer to the article below for the most up-to-date and complete information related to this AWS Security Bulletin.
Incomplete fix for CVE-2025-4318 code injection in Amazon @aws-amplify/codegen-ui-react
- Link: https://aws.amazon.com/security/security-bulletins/rss/2026-066-aws/
- Published: 2026-08-01 02:20:33
- Fetched: 2026-08-01 03:16:23
Please refer to the article below for the most up-to-date and complete information related to this AWS Security Bulletin.
CVE-2026-18420 - Remote Code Execution via Prototype Pollution in OpenSearch Dashboards TSVB Plugin
- Link: https://aws.amazon.com/security/security-bulletins/rss/2026-068-aws/
- Published: 2026-08-01 03:22:09
- Fetched: 2026-08-01 05:16:29
Bulletin ID: 2026-068-AWS
Publication Date: 07/31/2026 11:00 AM PDT
Please refer to the article below for the most up-to-date and complete information related to this AWS Security Bulletin.
CVE-2026-18394 - Incorrect authorization in Strands Agents Tools http_request tool
- Link: https://aws.amazon.com/security/security-bulletins/rss/2026-069-aws/
- Published: 2026-08-01 04:41:06
- Fetched: 2026-08-01 05:16:29
Bulletin ID: 2026-069-AWS
Scope: AWS
Content Type: Important (requires attention)
Publication Date: 07/31/2026 12:30 PM PDT
Description:
Strands Agents is an open-source SDK for building AI agents. The strands-agents-tools package provides pre-built tools for use with the SDK, including the http_request tool for making HTTP API requests.
We identified CVE-2026-18394, an incorrect authorization issue in the http_request tool. Operators can use the HTTP_REQUEST_TOKEN_CONFIG allowlist to bind a credential to a set of approved hostnames so it is sent only to those hosts. The tool also exposed a proxies parameter in the input schema that the large language model (LLM) could control. A crafted prompt, for example one delivered through untrusted web content the agent reads (indirect prompt injection), could set proxies to an actor-controlled endpoint. The hostname allowlist check still passes on the request URL, the credential is attached, and the request is routed through the actor's proxy on the first hop, disclosing the credential in cleartext in the Authorization header.
Impacted versions: < 0.8.2
Please refer to the article below for the most up-to-date and complete information related to this AWS Security Bulletin.
AWS Machine Learning Blog
Optimizing production agents with Amazon Bedrock AgentCore Observability
- Link: https://aws.amazon.com/blogs/machine-learning/optimizing-production-agents-with-amazon-bedrock-agentcore-observability/
- Published: 2026-08-01 00:33:11
- Fetched: 2026-08-01 01:00:41
Announcing the Agentic Catalog Experience in Amazon Quick
- Link: https://aws.amazon.com/blogs/machine-learning/announcing-the-agentic-catalog-experience-in-amazon-quick/
- Published: 2026-08-01 04:53:04
- Fetched: 2026-08-01 05:16:30