AWS News - 2026-08-13
2026-08-13
最終更新: 2026-08-18 02:22:10 JST
AI による概要
この日は IAM ロール作成の出発点を見直す role manager の一般提供が目を引きました。新しいアプリケーションを構築する際に必要な IAM ロールを自動的にセットアップし、権限設計に費やす時間を削減します。Amazon Quick にはガバナンス機能がまとまって追加され、Microsoft Purview 連携によるデータ損失防止、新しい AI 機能を利用者に届く前に既定で制限する deny by default、ユーザー単位のインデックスストレージとエージェント時間の上限、共有の承認ポリシーが揃いました。ライフサイエンス領域では Kiro を 24 分野・100 以上のデータベースを横断する統合研究インターフェースへ拡張する Kiro power パッケージ、HealthOmics 上での PacBio 全ゲノムシーケンシングのベンチマークが公開されています。アーキテクチャブログでは Adobe Firefly が Amazon Managed Service for Prometheus への移行で GPU メトリクスのクエリを 28 倍高速化した事例、パラメータ化クエリテンプレートによる Text2SQL のレイテンシ 80% 削減が解説されました。
主要トピック
IAM: role manager が一般提供、必要な IAM ロールを自動的にセットアップ
データガバナンス: Amazon Quick が Microsoft Purview 連携の DLP、deny by default、ユーザー単位の上限、共有承認ポリシーを追加
ライフサイエンス: Kiro を 24 分野・100 以上のデータベース横断の研究インターフェースへ拡張する Kiro power パッケージ
ゲノミクス: HealthOmics 上での PacBio 全ゲノムシーケンシング解析パイプラインのベンチマーク
監視: Adobe Firefly が Amazon Managed Service for Prometheus 移行で GPU メトリクスのクエリを 28 倍高速化
性能: パラメータ化クエリテンプレートで Text2SQL のレイテンシを 80%、トークン消費を 50% 以上削減
トラブルシュート: S3 のアクセス拒否エラーに該当する IAM / Organizations ポリシーの ARN を含めるように改善
脆弱性: OpenSearch Alerting プラグインの認可欠落、AWS SDK for C++ の Base64 デコーダのメモリ安全性問題
AWS What's New
AWS Deadline Cloud Now Supports EBS Persistent Volume Cost Tracking
- Link: https://aws.amazon.com/about-aws/whats-new/2026/08/aws-deadline-cloud-now-supports-ebs-persistent-volume-cost-tracking/
- Published: 2026-08-13 01:00:00
- Fetched: 2026-08-18 02:22:10
AWS Deadline Cloud now surfaces costs related to Amazon Elastic Block Store (Amazon EBS) persistent volumes in the Usage Explorer in the Deadline Cloud Monitor app. AWS Deadline Cloud is a fully managed service that helps teams run compute-intensive workloads in the cloud for visual effects, animation, product design, simulation, and gaming.
Customers have historically been able to see compute and license costs related to Deadline Cloud. With the recent release of support for persistent EBS volumes, customers needed a way to see storage costs as well. Now, Deadline Cloud tracks the cost for each EBS volume from creation until deletion, independent of any job or session. These costs appear as a new persistent volume usage type in Usage Explorer and the statistics APIs. These are attributed to the fleet that owns the volume so customers can aggregate spend by fleet, farm, or time period. This helps customers spot idle volumes and decide whether to adjust a time-to-live or let it expire. Cost tracking is enabled automatically, so no action is required.
Persistent volume cost tracking is available in all AWS Regions where Deadline Cloud is offered. Cost tracking introduces no additional charges. To learn more, visit the AWS Deadline Cloud product page or our user guide.
Amazon Quick now supports data loss prevention with Microsoft Purview
- Link: https://aws.amazon.com/whats-new/2026/08/amazon-quick-dlp-purview/
- Published: 2026-08-13 02:09:00
- Fetched: 2026-08-13 08:36:08
Amazon Quick now integrates with Microsoft Purview to enforce data loss prevention (DLP) policies across your Quick environment. Organizations need to ensure that sensitive files aren't shared outside approved channels. With this integration, IT administrators and security teams can apply their existing Purview sensitivity labels to automatically control how files are handled in Quick capabilities such as chat, spaces, and knowledge bases.
Administrators can configure enforcement actions (block, warn, or allow) for each sensitivity label, giving organizations granular control over sensitive file sharing across Quick. For example, a financial services company can block files labeled "Highly Confidential" from being uploaded to shared spaces while allowing "Internal" files with a warning notification. With this integration, customers can extend their existing Microsoft Purview governance policies into Quick without additional tools.
This feature is available in all AWS Regions where Amazon Quick agentic capabilities are supported. For more information, see the AWS Region table. To learn more, see Data loss prevention in the Amazon Quick User Guide.
Amazon Connect Customer supports manual assignment of queued agent-first callbacks
- Link: https://aws.amazon.com/about-aws/whats-new/2026/08/amazon-connect-agent-callbacks/
- Published: 2026-08-13 02:15:00
- Fetched: 2026-08-13 05:53:54
Amazon Connect Customer now lets agents view and self-assign queued agent-first callbacks alongside emails, tasks, and chats. This gives agents the option to prioritize work that needs immediate follow-up or for which they already have relevant context. For example, an agent familiar with a customer’s issue can assign the callback to themselves, avoiding another handoff and helping resolve the issue faster.
This feature is available in all AWS Regions where Amazon Connect Customer is available. To learn more about how to use queued callbacks, refer to our documentation Access the Worklist app and Set up queued callbacks. For more information about Amazon Connect Customer, visit our product page.
Amazon Quick adds deny by default for custom permissions
- Link: https://aws.amazon.com/whats-new/2026/08/amazon-quick-deny-by-default-permissions/
- Published: 2026-08-13 02:15:00
- Fetched: 2026-08-13 08:36:08
Amazon Quick custom permissions now include deny by default, a governance setting that automatically restricts new AI capabilities before they reach users.
Previously, new AI capabilities were available to all users on release, requiring administrators to react after the fact. With deny by default, administrators restrict the AI capability category in a custom permissions profile and assign it to users, roles, or the entire account. Quick then denies any new AI capability at launch for those users. Restricting a category also restricts existing capabilities in it. Administrators explicitly allow each capability when ready. The restriction applies only to the profile you configure.
Configure deny by default in Manage account in Amazon Quick or through the AWS CLI. To learn more, see Custom permissions deny by default. Deny by default is available in all AWS Regions where Amazon Quick is available.
Amazon EKS now supports advanced Kubernetes control plane configuration parameters
- Link: https://aws.amazon.com/about-aws/whats-new/2026/08/amazon-eks-control-plane-configuration-parameters
- Published: 2026-08-13 03:00:00
- Fetched: 2026-08-13 05:53:54
Amazon Elastic Kubernetes Service (Amazon EKS) now supports configuring parameters for Kubernetes control plane components including the scheduler, controller manager, and API server. You can tune pod placement strategies to improve resource utilization, adjust how quickly horizontal pod autoscaling responds to changes in demand, set resource lifecycle parameters such as event retention duration, and more.
Cluster administrators now have more control over Kubernetes control plane parameters beyond the defaults. For example, you can set the scheduler's node resource fit strategy parameter to MostAllocated, which packs pods onto nodes that are already well utilized and helps you run the same workloads on fewer nodes. The default LeastAllocated strategy spreads pods across nodes, and you can keep it where headroom matters more than density.
You can configure Kubernetes control plane parameters in any AWS Region where Amazon EKS is available. For the full list of configurable parameters and to learn more, see Control plane configuration in the Amazon EKS User Guide.
AWS IAM now provides role manager to set up IAM roles automatically
- Link: https://aws.amazon.com/about-aws/whats-new/2026/08/aws-iam-role-manager
- Published: 2026-08-13 03:00:00
- Fetched: 2026-08-13 10:39:45
Today, AWS announces the general availability of role manager, a capability in AWS Identity and Access Management (IAM) that automatically sets up the IAM roles your AWS services need. When you set up a supported service in the console, role manager creates a default role on your behalf, or reuses one that already exists in your account if it already matches the required permissions. You can enable or disable role manager at any time, as well as inspect the AWS-managed templates that role manager deploys on your behalf.
Role manager supports 6 AWS service consoles at launch, including AWS Lambda and Amazon EventBridge. For example, when you create an AWS Lambda function, role manager applies the AWS-managed template for that workflow. Roles created via role manager appear in the IAM console as standard IAM roles that you fully control, and you can identify the ones role manager created. When you are ready to tighten permissions, you can disable role manager and use IAM Access Analyzer to refine each role to only the permissions it needs.
Role manager is available in all AWS Regions, except the AWS GovCloud (US) Regions and the China Regions.
To learn more, see How AWS IAM role manager rethinks the starting point for IAM roles on the AWS Security Blog, or Create roles automatically with role manager in the IAM User Guide.
AWS Global View now offers an interactive map view for AWS Regions and AWS Local Zones
- Link: https://aws.amazon.com/about-aws/whats-new/2026/08/aws-global-view-map-view/
- Published: 2026-08-13 07:00:00
- Fetched: 2026-08-13 08:36:08
Today, AWS announces the addition of an interactive map view to AWS Global View in the AWS Management Console, providing a visual way to explore AWS Global Infrastructure.
Previously, customers had to scan through a list of AWS locations in AWS Global View. With this new capability, customers can toggle between the interactive map view and the existing list view, making it easier to visualize their global AWS infrastructure footprint.
When customers select the map view, they will see all AWS Regions and AWS Local Zones plotted on an interactive map. This capability helps customers make informed infrastructure planning decisions by visualizing already enabled AWS locations and the full range of AWS locations available to them, all in a single glance.
This capability is available across all public AWS Regions. To get started, navigate to the Regions and Zones page in AWS Global View console. For more information, see the AWS Global View documentation.
Amazon Quick now supports per-user resource limits
- Link: https://aws.amazon.com/whats-new/2026/08/amazon-quick-per-user-resource-limits/
- Published: 2026-08-13 07:17:00
- Fetched: 2026-08-14 07:36:42
Amazon Quick now enables administrators to set per-user limits on index storage and agent hours, giving them direct control over subscription costs. With limits management, administrators can create limit profiles that cap per-user consumption, helping prevent unexpected overage charges and ensuring subscription entitlements are used efficiently across their organization.
For example, an organization deploying Quick enterprise-wide to thousands of users can set account-level limit profiles to establish cost-predictable baselines, then assign higher limits to specific roles that require more agent hours. Administrators can create and assign limit profiles at the user, role, or account level, with a priority hierarchy that ensures the right users get the right capacity. When a user reaches their limit, new consumption is blocked while existing content is preserved.
This feature is available for Professional and Enterprise plans, in all AWS Regions where Amazon Quick agentic capabilities are supported. For more information, see the AWS Region table.
Learn more about Amazon Quick by visiting the Quick website. To learn more about limit profiles, see Limits management in the Amazon Quick User Guide.
Amazon Quick now supports approval policies for sharing
- Link: https://aws.amazon.com/whats-new/2026/08/amazon-quick-approval-policies-sharing/
- Published: 2026-08-13 07:22:00
- Fetched: 2026-08-14 07:36:42
Amazon Quick now offers approval policies, giving administrators governance controls over how assets are shared within their organization. With approval policies, administrators can require designated approvers to review and approve share requests before access is granted, helping organizations ensure that sharing of sensitive assets is deliberate, compliant, and auditable.
Administrators can create approval policies scoped to specific asset types, including knowledge bases, spaces, and custom chat agents. When a user submits a share request for an asset covered by a policy, it is routed to the assigned approver group for review. Approvers can evaluate the asset directly before approving or denying the request, and all workflow events are captured in AWS CloudTrail for full auditability. For custom chat agents, approvers can review and act on the entire dependency package in a single request.
This feature is available for Professional and Enterprise plans, in all AWS Regions where Amazon Quick agentic capabilities are supported. For more information, see the AWS Region table.
Learn more about Amazon Quick by visiting the Quick website. To learn more about approval policies, see Approval policies in the Amazon Quick User Guide.
AWS Clean Rooms supports minimum aggregation thresholds in custom analysis rules
- Link: https://aws.amazon.com/about-aws/whats-new/2026/08/aws-clean-rooms-minimum-aggregation-custom-analysis-rules
- Published: 2026-08-13 21:00:00
- Fetched: 2026-08-14 10:38:07
詳細を表示
AWS Clean Rooms now supports minimum aggregation thresholds for the Custom analysis rule type. Minimum aggregation helps protect the privacy of individual data subjects by preventing queries from returning results about individuals or small groups. With this launch, organizations can enforce minimum aggregation on custom SQL queries, ensuring that every row a query outputs represents at least the specified number of distinct values (e.g., user IDs). Data providers in a collaboration can specify their identity column and a minimum identity count to enforce on a query’s output, with the option to set a higher threshold for specific columns.
Previously, enforcing minimum aggregation thresholds on custom SQL required data providers to rely on pre-approved analysis templates and manual code reviews before queries could run. Now, data providers can configure the minimum aggregation threshold for custom SQL using the Custom analysis rule type, without using pre-structured queries or manual approval processes. Additionally, data providers can specify which columns can be filtered or joined across datasets. For example, a publisher collaborating with an advertiser for media planning use cases can enable ad-hoc queries to run on their data—and small, rural zip codes with fewer than 1,000 common users can be automatically filtered out from the result to help protect user privacy.
AWS Clean Rooms helps companies and their partners easily analyze and collaborate on their collective datasets without revealing or copying one another’s underlying data. For more information about the AWS Regions where AWS Clean Rooms is available, see the AWS Regions table. To learn more about collaborating with AWS Clean Rooms, visit AWS Clean Rooms.
Amazon S3 adds additional policy details to access denied error messages
- Link: https://aws.amazon.com/about-aws/whats-new/2026/08/s3-additional-policy-details-access-denied-error-messages/
- Published: 2026-08-13 22:00:00
- Fetched: 2026-08-14 02:54:17
Amazon S3 now includes the specific AWS Identity and Access Management (IAM) and AWS Organizations policy Amazon Resource Name (ARN) in HTTP 403 Access Denied error messages for same-account and same-organization requests. This helps you quickly identify the exact policy responsible for a denied request and remediate the issue directly.
Previously, S3 access denied error messages included the policy type and reason for denial, but when multiple policies of the same type existed, you still had to manually inspect each one to pinpoint the root cause. Now the error message includes the specific policy ARN for explicit deny cases, covering Service Control Policies (SCPs), Resource Control Policies (RCPs), identity-based policies, session policies, and permission boundaries.
This capability is available in all AWS Regions, including the AWS GovCloud (US) Regions and the AWS China Regions. To learn more about how to troubleshoot access denied errors in Amazon S3, visit the S3 User Guide and the IAM troubleshooting documentation.
AWS Japan Blog
Oracle AI Database@AWS で Oracle Exadata on Exascale が利用可能に
- Link: https://aws.amazon.com/jp/blogs/news/introducing-oracle-exadata-on-exascale-for-oracle-ai-databaseaws/
- Published: 2026-08-13 10:06:23
- Fetched: 2026-08-13 10:39:46
AWS ウィークリーまとめ:AWS ヒーローズサミット、Amazon Bedrock、Dogwood、Kiro Crew のウェブサーチなど (2026年8月10 日)
- Link: https://aws.amazon.com/jp/blogs/news/aws-weekly-roundup-aws-heroes-summit-web-search-on-amazon-bedrock-dogwood-kiro-crew-and-more-august-10-2026/
- Published: 2026-08-13 10:26:32
- Fetched: 2026-08-13 10:39:46
【開催報告】ISV SaaS 事業者向け 8 社合同 AI-DLC Unicorn Gym
- Link: https://aws.amazon.com/jp/blogs/news/joint-ai-dlc-unicorn-gym-isv-202607/
- Published: 2026-08-13 11:58:30
- Fetched: 2026-08-13 13:07:09
Kiro でライフサイエンス研究を加速する: 100 以上のオープンソースデータベースへの統合 AI インターフェース
- Link: https://aws.amazon.com/jp/blogs/news/accelerating-life-sciences-research-with-kiro-a-unified-ai-interface-to-100-open-source-databases/
- Published: 2026-08-13 15:19:49
- Fetched: 2026-08-13 17:16:46
AWS HealthOmics ワークフローで PacBio 全ゲノムシーケンシングのバリアント解析パイプラインをベンチマークする
- Link: https://aws.amazon.com/jp/blogs/news/publicsector-benchmarking-pacbio-whole-genome-sequencing-variant-pipeline-analysis-with-aws-healthomics-workflows/
- Published: 2026-08-13 15:19:52
- Fetched: 2026-08-13 17:16:46
MGI、Sentieon、AWS で強化するゲノムデータストレージとワークフロー
- Link: https://aws.amazon.com/jp/blogs/news/enhanced-genomic-data-storage-and-workflows-with-mgi-sentieon-and-aws/
- Published: 2026-08-13 16:17:16
- Fetched: 2026-08-13 17:16:46
AWS Security Blog
How AWS IAM role manager rethinks the starting point for IAM roles
- Link: https://aws.amazon.com/blogs/security/how-aws-iam-role-manager-rethinks-the-starting-point-for-iam-roles/
- Published: 2026-08-13 07:16:55
- Fetched: 2026-08-13 07:35:41
AWS Security Bulletins
CVE-2026-19311- Missing Authorization in OpenSearch Alerting Plugin
- Link: https://aws.amazon.com/security/security-bulletins/rss/2026-078-aws/
- Published: 2026-08-13 03:46:36
- Fetched: 2026-08-13 03:56:20
Bulletin ID: 2026-078-AWS
Scope: AWS
Content Type: Important (requires attention)
Publication Date: 08/12/2026 11:30 AM PDT
Description:
OpenSearch is a community-driven, open-source search and analytics suite. We identified CVE-2026-19311, a missing authorization issue in the Execute Monitor API of the OpenSearch Alerting plugin. This issue may allow an authenticated user with the alerting_full_access role to read, modify, or delete arbitrary index data via a crafted inline monitor request with unintentional data source and input index parameters.
Impacted Versions:
OpenSearch Alerting Plugin (open-source, self-managed):
- Affected: 2.4.0 through 2.19.5, 3.0.0 through 3.7.0
- Fixed: 2.19.6, 3.8.0
Amazon OpenSearch Service (AWS Managed):
- Affected: All domains running engine versions 2.4 through 3.5
- Fixed: Service software R20260428-P3
Please refer to the article below for the most up-to-date and complete information related to this AWS Security Bulletin.
CVE-2026-19642 & CVE-2026-19643 - Memory-safety issues in the Base64 decoder in the AWS SDK for C++
- Link: https://aws.amazon.com/security/security-bulletins/rss/2026-080-aws/
- Published: 2026-08-13 04:52:23
- Fetched: 2026-08-13 04:59:26
Bulletin ID: 2026-080-AWS
Scope: AWS
Content Type: Important (requires attention)
Publication Date: 08/12/2026 12:30 PM PDT
Description:
The AWS SDK for C++ is an open-source library that provides C++ developers with APIs for AWS services. Its core library includes a Base64 codec used by the generated service clients for a variety of features.We identified the following CVEs:
- CVE-2026-19642 - Out-of-bounds write in the Base64 decoder in the AWS SDK for C++
- CVE-2026-19643 - Out-of-bounds read in the Base64 decoder in the AWS SDK for C++
For CVE-2026-19642, certain inputs to the Base64 decoder might cause the decoder to write past the end of its heap-allocated output buffer, which might crash or corrupt memory in the process performing the decode. Remote code execution has not been demonstrated.
For CVE-2026-19643, certain inputs to the Base64 decoder, on some platforms, might cause the decoder to read outside the bounds of its decode table, which might crash the process performing the decode.
For both issues, impact is confined to the process of the application performing the decode.
Impacted Versions: AWS SDK for C++: <= 1.11.861
Please refer to the article below for the most up-to-date and complete information related to this AWS Security Bulletin.
AWS Architecture Blog
Adobe Firefly: Simplified observability with Amazon Managed Prometheus
- Link: https://aws.amazon.com/blogs/architecture/adobe-firefly-simplified-observability-with-amazon-managed-prometheus/
- Published: 2026-08-13 09:14:19
- Fetched: 2026-08-13 10:39:46
Reducing Text2SQL latency with parameterized query templates
- Link: https://aws.amazon.com/blogs/architecture/reducing-text2sql-latency-with-parameterized-query-templates/
- Published: 2026-08-13 09:40:32
- Fetched: 2026-08-13 10:39:46
Recovery strategies to meet data residency requirements
- Link: https://aws.amazon.com/blogs/architecture/recovery-strategies-to-meet-data-residency-requirements/
- Published: 2026-08-13 23:05:39
- Fetched: 2026-08-13 23:24:24
AWS Machine Learning Blog
Part 2: Amazon Bedrock cost attribution with Amazon Athena and CUDOS
- Link: https://aws.amazon.com/blogs/machine-learning/part-2-amazon-bedrock-cost-attribution-with-amazon-athena-and-cudos/
- Published: 2026-08-13 02:45:20
- Fetched: 2026-08-13 02:54:45
AWS Compute Blog
Burst to Region: Overflow AWS Outposts workloads to Amazon EC2
- Link: https://aws.amazon.com/blogs/compute/burst-to-region-overflow-aws-outposts-workloads-to-amazon-ec2/
- Published: 2026-08-13 02:06:54
- Fetched: 2026-08-13 02:54:45