AWS News - 2026-08-05

2026-08-05
最終更新: 2026-08-06 01:28:43 JST

AI による概要

21 記事

この日は検索とベクトルの基盤強化が目立ちました。Amazon DynamoDB がネイティブのベクトル検索に対応し、数兆ベクトル規模でも 99% 以上の再現率を 1 桁ミリ秒のレイテンシで提供します。Amazon Bedrock には Web Search がサーバーサイドの組み込みツールとして一般提供され、モデル応答を Web 上の情報にグラウンディングできるようになりました (OpenAI GPT モデルでも利用可能)。Kiro では 3 つに分かれていた IDE / CLI / Web のエージェントを標準化された Agent Client Protocol ベースの単一ハーネスへ統合した経緯が解説され、あわせて仕事を代行する Kiro Crew が紹介されています。セキュリティでは Security Hub Extended に 10 番目のカテゴリとしてサプライチェーンセキュリティが追加され、Chainguard と Socket がキュレーションパートナーとなりました。Network Firewall は明示的なフォワードプロキシとして利用できる機能がプレビューで再導入されています。

主要トピック
  • ベクトル検索: DynamoDB がネイティブのベクトル検索に対応、数兆ベクトル規模で 1 桁ミリ秒・再現率 99% 以上

  • グラウンディング: Amazon Bedrock の Web Search が一般提供、サーバーサイド組み込みツールとして応答を Web 情報に接地

  • 開発ツール: Kiro が IDE / CLI / Web の 3 エージェントを Agent Client Protocol ベースの単一ハーネスに統合

  • エージェント: 仕事を代行する Kiro Crew を発表

  • サプライチェーン: Security Hub Extended が 10 番目のカテゴリとしてサプライチェーンセキュリティを追加 (Chainguard / Socket)

  • ネットワーク: Network Firewall を明示的なフォワードプロキシとして使う機能をプレビュー再導入

  • 脆弱性: AgentCore harness の入力検証不足、Kiro IDE / CLI の Windows における信頼できないディレクトリからの実行ファイル解決

AI (Claude Opus 5) が生成 · 2026-08-28 09:28:28 JST

AWS What's New

Amazon EC2 I8g instances now available in AWS Europe (Paris), Asia Pacific (Jakarta) regions

詳細を表示

AWS announces the general availability of Amazon EC2 Storage Optimized I8g instances in AWS Europe (Paris) and Asia Pacific (Jakarta) regions. I8g instances are powered by AWS Graviton4 processors and offer the best compute performance in Amazon EC2 for storage-intensive workloads. I8g instances use the third generation AWS Nitro SSDs, local NVMe storage that deliver up to 65% better real-time storage performance per TB while offering up to 50% lower storage I/O latency and up to 60% lower storage I/O latency variability compared to I4g instances. These instances are built on the AWS Nitro System, which offloads CPU virtualization, storage, and networking functions to dedicated hardware and software enhancing the performance and security for your workloads.


Amazon EC2 I8g instances are designed for I/O intensive workloads that require rapid data access and real-time latency from storage. These instances excel at handling transactional, real-time, distributed databases, including MySQL, PostgreSQL, Hbase and NoSQL solutions like Aerospike, MongoDB, ClickHouse, and Apache Druid. They're also optimized for real-time analytics platforms such as Apache Spark, data lakehouse and AI LLM pre-processing for training. I8g instances are available in eleven different sizes including two metal sizes, 1.5 TiB of memory, and 45 TB local instance storage. They deliver up to 100 Gbps of network performance bandwidth, and 60 Gbps of dedicated bandwidth for Amazon Elastic Block Store (EBS).


To learn more, visit Amazon EC2 I8g instances. To begin your Graviton journey, visit the Level up your compute with AWS Graviton page. To get started, see AWS Management Console, AWS Command Line Interface (AWS CLI), and AWS SDKs.

Amazon Connect Customer now supports capacity planning in 15 or 30 minute intervals

Amazon Connect Customer now lets you generate capacity plans at the interval level (15-minute or 30-minute intervals), giving workforce planners visibility into more granular staffing requirements across Voice, Chat, Task, and Email channels. Interval-level plans capture how demand shifts throughout the day — such as a lunchtime surge in chat contacts or an end-of-day change in call volume — so you can align agent capacity with demand as it changes and staff precisely for each part of the day. You can also provide shrinkage assumptions and available headcount at the interval level for more accurate plans. Together, these capabilities improve planning accuracy and help you reduce over- and under-staffing, improving service levels and operational efficiency.

This feature is available in all AWS Regions where Amazon Connect Customer agent scheduling is available. To learn more about Amazon Connect Customer agent scheduling, click here.

Amazon S3 Vectors is now available in the AWS European Sovereign Cloud (Germany) Region

Amazon S3 Vectors is now available in the AWS European Sovereign Cloud (Germany) Region. Amazon S3 Vectors is purpose-built vector storage for AI agents, inference, Retrieval Augmented Generation (RAG), and semantic search at billion-vector scale. S3 Vectors is designed to provide the same elasticity, durability, and availability as Amazon S3, with a dedicated set of APIs that let you store, access, and query vectors without provisioning any infrastructure.

For a full list of AWS Regions where Amazon S3 Vectors is available, see AWS Regions and endpoints. To learn more, visit the product page, documentation, and the Amazon S3 pricing page.

AWS Application and Network Load Balancers now support RFC 9151 compliant security policies

AWS Application Load Balancer (ALB) and Network Load Balancer (NLB) now support new TLS-based security policies that comply with RFC 9151 TLS server requirements for Commercial National Security Algorithm (CNSA) 1.0 suite requirements. These policies implement the cryptographic requirements defined by the US National Security Agency (NSA) for secure communications using TLS 1.2 and TLS 1.3 protocols.

Customers who are required to meet CNSA 1.0 TLS security requirements can now use ALB and NLB with RFC 9151 compliant security policies. Broader interoperability policies are also supported, allowing you to implement CNSA by default while maintaining compatibility with non-CNSA clients during their transition to RFC 9151 compliance, minimizing service disruption.

This feature is available for ALB and NLB in all AWS Commercial Regions, the AWS GovCloud (US) Regions, and the China region at no additional cost. To use this capability, update your existing ALB HTTPS listeners or NLB TLS listeners to a RFC 9151 compliant security policy, or select a compliant policy when creating new listeners through the AWS Management Console, CLI, API, or SDK.

To learn more, visit the ALB User Guide and NLB User Guide documentation. Get started with Elastic Load Balancing.

Amazon EC2 C8g instances now available in additional regions

Starting today, Amazon Elastic Compute Cloud (Amazon EC2) C8g instances are available in AWS Europe (Paris), AWS Africa (Cape Town), AWS Israel (Tel Aviv), and AWS Canada West (Calgary) regions. These instances are powered by AWS Graviton4 processors and deliver up to 30% better performance compared to AWS Graviton3-based instances. Amazon EC2 C8g instances are built for compute-intensive workloads, such as high performance computing (HPC), batch processing, gaming, video encoding, scientific modeling, distributed analytics, CPU-based machine learning (ML) inference, and ad serving. These instances are built on the AWS Nitro System, which offloads CPU virtualization, storage, and networking functions to dedicated hardware and software to enhance the performance and security of your workloads.

AWS Graviton4-based Amazon EC2 instances deliver the best performance and energy efficiency for a broad range of workloads running on Amazon EC2. These instances offer larger instance sizes with up to 3x more vCPUs and memory compared to Graviton3-based Amazon C7g instances. AWS Graviton4 processors are up to 40% faster for databases, 30% faster for web applications, and 45% faster for large Java applications than AWS Graviton3 processors. C8g instances are available in 12 different instance sizes, including two bare metal sizes. They offer up to 50 Gbps enhanced networking bandwidth and up to 40 Gbps of bandwidth to the Amazon Elastic Block Store (Amazon EBS).

To learn more, see Amazon EC2 C8g Instances. To get started, see the AWS Management Console.

AWS Security Hub Extended adds supply chain security as its 10th category

詳細を表示

The AWS Security Hub Extended plan now includes Supply Chain Security as its 10th security category, with Chainguard and Socket as the curated partners. As developers adopt open-source libraries at scale, security teams need confidence that the packages entering their environments are trustworthy and free from malicious code. With this addition, you can detect and block malicious dependencies before they are built into your applications, with the same streamlined activation and pay-as-you-go pricing as every other Extended category. This brings the Extended plan to 23 curated partner solutions. All solutions are on a single AWS bill and no required long-term commitments.

Security Hub Extended is a plan within AWS Security Hub that helps simplify how you procure, deploy, and integrate a full-stack enterprise security solution across endpoint, identity, email, network, data, browser, cloud, AI, security operations, and supply chain. Security findings from all participating solutions are emitted in the Open Cybersecurity Schema Framework (OCSF) and automatically aggregated in AWS Security Hub. With the Extended plan, you can combine AWS and curated partner solutions to quickly identify and respond to risks that span boundaries.

We will continue to expand the Extended plan based on customer feedback. The two new curated partner solutions are available today in all AWS commercial Regions where Security Hub is available. For a list of supported Regions, see the AWS Region table. For more information about pricing, visit the AWS Security Hub pricing page. To get started, visit the AWS Security Hub console or product page.

Run interactive workloads on Amazon EMR on EC2 with Spark Connect

詳細を表示

Amazon EMR on EC2 now supports interactive Apache Spark sessions with Spark Connect. Data engineers and data scientists can develop and debug Apache Spark applications interactively from managed notebooks in Amazon SageMaker Unified Studio and their own IDEs, such as Jupyter and Visual Studio Code, with each session running on dedicated EMR on EC2 clusters. You can also monitor and debug active and completed sessions in the EMR console.

 

An interactive session provides a persistent Spark context that spans across cells and scripts, letting you blend local Python code execution with remote Spark operations. Spark Connect's client-server architecture decouples your application client from the Spark driver and allows you to maintain your preferred development environment and tooling while Spark infrastructure runs on the cluster. This architecture supports workflows including ad hoc data exploration, iterative step-by-step debugging, and incremental PySpark job development before deploying to production. For observability, you get real-time session monitoring via the Spark UI, history tracking through the Spark History Server, and session management from the EMR console or API/CLI/SDK.

 

Interactive Sessions is available on Amazon EMR on EC2 with AWS runtime for Apache Spark (emr-spark-8.0) and later, in all AWS Regions where Amazon EMR is available, except the AWS GovCloud Regions and the China Regions. The Amazon SageMaker Unified Studio experience is available in supported regions. To get started, visit the Interactive sessions with Spark Connect guide or the Amazon SageMaker Unified Studio Getting Started guide.

Amazon Bedrock launches Web Search for OpenAI GPT models

詳細を表示

Today, we are announcing the general availability of Web Search on Amazon Bedrock, a built-in server side tool that performs web search entirely within AWS, enabling OpenAI models (GPT-5.4, GPT-5.5, and GPT-5.6 Sol/Terra/Luna) to ground responses with current web knowledge while maintaining data residency within your secured AWS environment with zero data egress. Previously, adding web grounding required onboarding a third-party search provider, managing separate API keys and billing, building custom orchestration, and conducting additional compliance reviews for each external vendor. Web Search removes this heavy lifting by enable grounding with a single parameter in an existing API call, with no vendor onboarding, no external APIs to orchestrate, and no additional vendor security reviews to conduct.

Web Search is built by Amazon, informed by years of experience across Alexa+, Amazon Quick and Kiro. It combines a web index operated by Amazon, spanning tens of billions of documents refreshed continually, with a built-in knowledge graph that provides verified facts. Rather than returning raw pages, Web Search performs semantic snippet extraction, delivering context-efficient results optimized for the model's context window with low latency. Web Search integrates through a standardized tool-use interface, compatible with the OpenAI Responses API. Simply add the web search tool to your API call, and Bedrock handles the entire search lifecycle server-side; a single API call returns a grounded response with citations.

Web Search on Amazon Bedrock is generally available today in US East (N. Virginia), US East (Ohio), and US West (Oregon). To get started, read our blog post Introducing Web Search on Amazon Bedrock for foundation model grounding, review the Web Search section in the Amazon Bedrock User Guide for technical documentation, and visit the Amazon Bedrock pricing page for cost details.

Amazon Connect Customer now lets you export cases to CSV from the agent workspace

Amazon Connect Customer now supports exporting cases to a CSV file directly from the agent workspace, making it easier to share case data with internal teams and external stakeholders such as vendors, legal teams, or business partners. Agents can filter and select cases and choose which case fields to include in the export. Admins can control access using a security profile permission.

Cases is available in the following AWS regions: US East (N. Virginia), US West (Oregon), Canada (Central), Europe (Frankfurt), Europe (London), Asia Pacific (Seoul), Asia Pacific (Singapore), Asia Pacific (Sydney), Asia Pacific (Tokyo), and Africa (Cape Town). To learn more and get started, visit the Cases webpage and documentation.

[Preview Announcement] Re-introducing Forward Proxy as AWS Network Firewall Functionality

You can now use your Network Firewall with all its existing filtering capabilities and features as an explicit forward proxy.

On Nov 25, 2025, AWS introduced Network Firewall proxy in public preview to help customers exert centralized security controls against data exfiltration and malware injection. At the time, the Network Firewall proxy was introduced as a standalone product, separate from Network Firewall transparent firewall and used its own separate proxy security policy. Customers who tested it in preview shared that they want the Network Firewall proxy to maintain parity with Network Firewall’s existing set of capabilities and use the same security policy across the two functionalities. In keeping with customer feedback, we are reintroducing explicit proxy as a functionality of Network Firewall. With this launch, you can configure Network Firewall with your existing Firewall policy in a new no-source-preservation deployment where it can be used as an explicit proxy with all its existing features including managed rule groups, active threat defense, Geo-IP filtering, URL and domain category filtering, container attribute-based rules for Amazon EKS and Amazon ECS, etc. You can create a single security policy and use it for both explicit proxy and transparent firewall functionalities.

Try out AWS Network Firewall in no-source-preservation deployment with proxy functionality in your test environment today in US East (Ohio) region. no-source-preservation Network Firewall is available for free during public preview. For more information, check no-source-preservation Network Firewall documentation.

AWS News Blog

Amazon DynamoDB now supports real-time vector search at any scale

DynamoDB now supports native vector search with single-digit millisecond latency at 99%+ recall. It is designed for any scale, even trillions of vectors and requires zero infrastructure management.

AWS Japan Blog

AWS 認定の上位・下位関係を理解して効率的に認定を更新しましょう

AWS 認定には Professional → Associate → Foundational の上位・下位関係があり、上位の認定を取得または更新すると、取得済みの下位認定も自動的に更新されます。複数の認定を保持している方は、この関係を活用して効率的に再認定を進めることができます。本記事では具体的な上位・下位の紐づきを図で整理し、効率的な再認定の方法と注意点を解説します。

1 つのエージェントで、あらゆるクライアントに: Kiro エージェントハーネスをどう構築したか

Kiro IDE、CLI、Web に別々に存在した 3 つのエージェントを、単一の Kiro エージェントハーネスに統合した過程を解説します。標準化された Agent Client Protocol (ACP) を採用し、独自の WebSocket トランスポートと Kiro-ACP 拡張、Cedar ベースのケイパビリティ権限モデルを組み合わせることで、仕様駆動開発、カスタムエージェント、フックをすべてのクライアントで一貫して提供します。IDE 1.0、CLI v3、Web、iOS 版で今すぐ試せます。

Kiro Crew の紹介

Kiro Crew は、その仕事を代わりに引き受けます。Crew にメッセージを 1 通投げれば、前回どう対応したかを探し出し、まとめ、同僚に送るところまでを、あなたが再び手を入れることなく進めてくれます。あなたはその日の仕事を終えて外に出て、「問題は解決しました」というチームからのメモを目にするだけです。チケットのキューを渡せば、Kiro Crew はトリアージして振り分け、オーナーを特定し、あなたの判断が必要なものにフラグを立てます。複数リポジトリにまたがるインシデントを指し示せば、あなたが修正に集中している間に調査を進めます。マイグレーションを開始すれば、あなたが会議中でも眠っている間でも、チェックポイントとリトライを通じて前進し続けます。すでにあなたが使っているツールをつなぎ、セッションをまたいで作業を調整するので、戻ってきたときに待っているのは「やり直すべきワークフロー」ではなく「進んだ結果」です。

KNFSD ファイルキャッシュのご紹介: NFS ストレージをクラウドに拡張

本記事では、KNFSD File Cache (KNFSD) の仕組みと、オンプレミスのファイラー、サードパーティ、Amazon FSx などの AWS サービスを問わず、NFS 準拠のストレージとどのように連携するかを説明します。また、単一の Terraform モジュールを使って本番環境向けのオートスケーリングクラスターをデプロイする方法も紹介します。このクラスターは、100 Gb 毎秒あたり時間 6 ドル未満で集約スループットを実現します。

AWS Weekly のまとめ: Bedrock の GPT モデルの値下げ、Prometheus メトリクス向けの CloudWatch マネージドコレクターなど (2026年8月3日)

2026 年 7 月 27 日週、7 歳の息子と一緒に Amazon の「子供を仕事に連れて行く日」に参加でき […]

AWS Security Blog

Spring 2026 PCI DSS and PCI 3DS compliance packages for AWS now available

Amazon Web Services (AWS) is pleased to announce the successful completion of our Payment Card Industry (PCI) Data Security Standard (DSS) and Three Domain Secure (3DS) certifications. As part of this renewal, we have expanded the scope to include three additional AWS services and one additional AWS Region: Newly added AWS services: Amazon Bedrock AgentCore […]

AWS Security Bulletins

CVE-2026-18830 - Issue with Amazon Bedrock AgentCore harness – Insufficient Input Validation

Bulletin ID: 2026-073-AWS
Scope: AWS
Content Type: Important (requires attention)
Publication Date: 08/04/2026 10:00 AM PDT

Description:

We have identified CVE-2026-18830 in the Amazon Bedrock AgentCore harness InvokeHarness API. This issue could allow an authenticated user to execute configured tools while bypassing model invocation and associated security controls. When the most recent message in an InvokeHarness request contained a tool-use content block, the agent event loop could dispatch the named tool directly, without model mediation.

Please note that potential impact was limited to the tools configured on a given harness. A harness with no configured tools could not execute any tool, and a harness with a restricted tool set was limited to that set.

Impacted versions:

Amazon Bedrock AgentCore harness InvokeHarness API prior to July 31, 2026.

Please refer to the article below for the most up-to-date and complete information related to this AWS Security Bulletin.

CVE-2026-18656 & CVE-2026-18657 - Issue with Kiro IDE and CLI - Executable Resolution from Untrusted Project Directory on Windows

Bulletin ID: 2026-074-AWS
Scope: AWS
Content Type: Important (requires attention)
Publication Date: 08/04/2026 12:30 PM PDT

Description:

Kiro is an agentic IDE and command-line interface users install on their desktop. We identified CVE-2026-18656 and CVE-2026-18657, an issue where an uncontrolled search path element on Windows might allow an actor to execute arbitrary code via a maliciously crafted project directory containing a planted executable that is resolved before the system PATH when a local user opens the directory.

Impacted versions:
- Kiro IDE for Windows between versions 1.0.0 through 1.0.212
- Kiro CLI for Windows prior to v2.10.0

Please refer to the article below for the most up-to-date and complete information related to this AWS Security Bulletin.

AWS Machine Learning Blog

Automated web insight extraction with Amazon Bedrock AgentCore

Extracting insights from dozens of websites by hand quickly becomes overwhelming. This post shows how to build an automated web insight extraction solution with Amazon Bedrock AgentCore Browser, Amazon Bedrock, Amazon OpenSearch Serverless, and AWS Lambda that monitors RSS feeds, renders pages reliably, and makes AI-extracted insights searchable.

Introducing Web Search on Amazon Bedrock for foundation model grounding

Today, we are introducing the general availability of Web Search on Amazon Bedrock. It is a server-side built-in tool that grounds model responses in current web knowledge. With Web Search, grounding becomes a native capability of Amazon Bedrock, with no third-party vendors to onboard, no external APIs to orchestrate, and no additional third party vendor security reviews to conduct. In this post, we walk through what Web Search on Amazon Bedrock is, why it matters, how to enable it using the OpenAI Responses API, and how to get started with the tool.