AWS News - 2026-08-14
2026-08-14
最終更新: 2026-08-15 04:44:31 JST
AI による概要
この日は証明書運用の大きな方針転換が告知されました。AWS Certificate Manager が CA/B フォーラムによる業界全体の動きに合わせ、2027 年 9 月 30 日までに E メール検証済みパブリック証明書のサポートを終了します。あわせて既存の証明書について E メール検証から DNS 検証へ切り替える機能も提供開始されました。Amazon Quick は Microsoft 365 拡張機能が一般提供となり、Word・Excel・PowerPoint・Outlook の中から直接エージェンティック AI とデータにアクセスできます。Claude Opus 5 が GovCloud (US) でも利用可能になり、OpenAI のサイバー防御モデル Daybreak Red / Daybreak Blue も対象顧客向けに Bedrock で提供開始となりました。コンピュートブログでは相関するハードウェア障害を防ぐ分散システム設計、Lambda MicroVMs の CPU・メモリメトリクス収集、durable functions のオブザーバビリティのベストプラクティスが解説されています。
主要トピック
証明書: ACM が 2027 年 9 月 30 日までに E メール検証を終了、DNS 検証への切り替え機能も提供
生産性: Amazon Quick の Microsoft 365 拡張 (Word / Excel / PowerPoint / Outlook) が一般提供
GovCloud: Claude Opus 5 が GovCloud (US) で利用可能に
サイバー防御: OpenAI の Daybreak Red / Daybreak Blue が対象顧客向けに Bedrock で提供開始
耐障害設計: 相関するハードウェア障害を防ぐ分散システム設計と実際のインシデント対応パターン
オブザーバビリティ: Lambda MicroVMs のメトリクス収集と durable functions の監視ベストプラクティス
マルチクラウド: AgentCore Observability でオンプレミス・GCP・Azure 上のエージェントも監視
脆弱性: OpenSearch Security Analytics プラグインの入力検証欠落、SQL プラグインの非同期クエリ検証バイパス
AWS What's New
AWS Certificate Manager supports switching from e-mail to DNS validation
- Link: https://aws.amazon.com/about-aws/whats-new/2026/08/AWS-Certificate-Manager-Email-DNS-Switch
- Published: 2026-08-14 00:00:00
- Fetched: 2026-08-14 07:36:42
詳細を表示
AWS Certificate Manager (ACM) now enables you to change the domain validation method on your existing ACM issued public TLS certificates from e-mail to DNS, without reissuing the certificate or changing its existing Amazon Resource Name (ARN). Due to the Certification Authority/Browser (CA/B) Forum's mandated deprecation of email-based domain validation for publicly trusted certificates, effective March 15, 2028, ACM will phase out its support for email validation throughout 2027. ACM will no longer issue email-validated certificates starting March 31 2027, and stop renewing email-validated certificates on September 30 2027. More details on ACM's deprecation of email validation can be found on the AWS Security Blog. By switching to DNS validation now, you can transition ahead of that deadline and enable fully automated renewals through DNS validated certificates.
Your certificate ARN remains unchanged after switching from e-mail to DNS validation, so existing ARN references in your CI/CD pipelines, load balancer configurations, and other AWS service integrations continue to work without modification. To switch the validation method, use the ACM console or the UpdateCertificateOptions API. ACM provides a CNAME record for each domain in the certificate (the same mechanism used when provisioning new certificates with DNS validation) and you have up to 72 hours to add the records to your DNS configuration. You can monitor the validation status of each domain via the console or the ListCertificateDomainValidations API. We recommend DNS validation for new certificates, and HTTP validation for Amazon CloudFront distributions..
This feature is available in all AWS Regions where ACM certificates are available. To get started, refer to Migrating from email to DNS validation in the AWS Certificate Manager User Guide.
Daybreak Red and Daybreak Blue from OpenAI are now available to eligible customers on Amazon Bedrock
- Link: https://aws.amazon.com/about-aws/whats-new/2026/08/openai-daybreak-red-and-blue-on-amazon-bedrock/
- Published: 2026-08-14 01:12:00
- Fetched: 2026-08-14 02:54:17
Security teams can now access Daybreak Red and Daybreak Blue from OpenAI on Amazon Bedrock. Both are part of Daybreak, the cyber defense initiative from OpenAI that gives defenders governed access to frontier AI for cybersecurity work.
Daybreak Blue is the starting point for most security teams across defensive workflows including vulnerability discovery, detection engineering, and incident response. Daybreak Red is designed for advanced, authorized tasks such as vulnerability research, exploit reproduction, and mitigation development. For these tasks, a lower refusal threshold matched by stronger identity verification, monitoring, and access controls improves the speed and depth of an investigation. Both models run on Bedrock's next-generation inference engine with zero-operator access (ZOA) enforced at the chip. Your inference data is not used for model training, and neither model requires you to opt into sharing your data with OpenAI.
Daybreak Red: GPT-5.6 Cyber and Daybreak Blue: GPT-5.6 Sol are now available to eligible customers on Amazon Bedrock in the following AWS Region: US East (N. Virginia). Access to the models requires enrollment in Daybreak access from OpenAI. To enroll, contact OpenAI or reach out to your AWS account team for guidance on eligibility. Once approved, work with your account team to request access on AWS. To learn more, read the blog.
Spot Placement Score now includes Local Zones
- Link: https://aws.amazon.com/about-aws/whats-new/2026/08/spot-placement-score-local-zones/
- Published: 2026-08-14 02:13:00
- Fetched: 2026-08-14 04:55:18
Today, AWS announces support for AWS Local Zones in Spot placement score, helping you identify locations where your Spot capacity request is most likely to succeed. Spot placement score evaluates your target capacity and compute requirements and returns scores for AWS Regions or Availability Zones.
Previously, Spot placement scores excluded local zone capacity information when reporting zonal and regional scores. Now, you can optionally request local zones to be included in the zonal and regional score responses giving you a broader view of your Spot capacity options.
You can use Spot placement score through EC2 Spot Console, AWS CLI, or SDK. To learn more about Spot placement score see Spot placement score documentation.
Amazon Quick Microsoft 365 extensions are now generally available
- Link: https://aws.amazon.com/amazon-quick-microsoft-365-extensions-generally-available
- Published: 2026-08-14 03:00:00
- Fetched: 2026-08-14 05:37:21
Today, Amazon Quick announces the general availability of Microsoft 365 extensions for Excel, PowerPoint, Word, and Outlook. These extensions enable Quick to perform tasks directly within users' M365 environments, using AI to handle complex local tasks such as redlining documents, building financial models, creating presentation-ready decks, and managing Outlook inboxes.
The Excel extension helps with complex spreadsheet analysis, creating pivot tables and charts, and importing and cleaning data. The PowerPoint extension helps you create and refine presentations from Quick data using organization-defined templates. The Word extension generates formatted documents with Word primitives, makes sweeping edits with track changes enabled, and participates as a reviewer in comments. The Outlook extension performs inbox and calendaring tasks such as prioritizing emails, organizing your inbox, scheduling meetings, and drafting replies using your Quick data and entire inbox context.
These extensions transform daily work across teams. Finance teams can build complex models by describing what they need. Sales teams can draft proposals that automatically pull from CRM data. Marketing teams can create branded presentations without manual formatting. Legal teams can streamline contract reviews. Operations teams can manage email workflows and schedule meetings intelligently, and IT teams can automate routine data analysis that previously required manual effort.
Amazon Quick Microsoft 365 extensions are available in US East (N. Virginia), US West (Oregon), Asia Pacific (Sydney), Europe (Ireland), Asia Pacific (Tokyo), and Europe (Frankfurt). To learn more, see Amazon Quick for Microsoft 365: Agentic AI where you work, and download extensions on the Quick download page.
Claude Opus 5 is now available in AWS GovCloud (US)
- Link: https://aws.amazon.com/about-aws/whats-new/2026/07/claude-opus-5-aws-govcloud/
- Published: 2026-08-14 03:23:00
- Fetched: 2026-08-14 06:40:07
AWS GovCloud (US) now offers Claude Opus 5 — the most advanced Opus model yet, and compatible with zero data retention (ZDR) — bringing a step-change in coding, long-running agents, and complex professional work to teams building at the highest level. Claude Opus 5 is available via the bedrock-runtime endpoint in both AWS GovCloud (US) regions, and available via the bedrock-mantle endpoint in AWS GovCloud (US-West)
Claude Opus 5 delivers advances in coding, understanding and navigating codebases like an experienced engineer and writing production-quality code while adapting its strategy as it works. It powers dependable agents that run for hours and even overnight, finding paths around obstacles, recovering from errors, and reaching their objectives. And it brings deeper reasoning to long documents and higher accuracy to complex analysis, with the largest gains on document-heavy enterprise work.
Amazon Bedrock offers Claude Opus 5 with zero data retention (ZDR) enabled by default, giving you Opus' top-tier intelligence while meeting your data governance requirements. It keeps your data within AWS infrastructure with regional data residency and provides access through a unified service with AWS-managed features like Guardrails and Knowledge Bases. To learn more, see the Amazon Bedrock documentation and regional availability.
Amazon Redshift adds rg.large and rg.12xlarge instance sizes in AWS GovCloud (US) Regions
- Link: https://aws.amazon.com/about-aws/whats-new/2026/08/amazon-redshift-adds-rg-large-12xlarge-aws-govcloud-regions/
- Published: 2026-08-14 04:34:00
- Fetched: 2026-08-15 01:48:51
Amazon Redshift now offers rg.large and rg.12xlarge instance sizes for RG instances in the AWS GovCloud (US-West) and AWS GovCloud (US-East) Regions. RG instances deliver better performance, running data warehouse and data lake workloads up to 2.4x as fast as previous generation RA3 instances, at 30% lower price per vCPU. RG instances include Redshift's custom-built vectorized data lake query engine that processes Apache Iceberg and Parquet data on your cluster nodes, enabling you to run SQL analytics across your data warehouse and data lake using a single engine.
rg.large and rg.12xlarge instance sizes are available on patch version P202 and later. Customers can resize existing RG or RA3 clusters to these new instance sizes using Elastic Resize or Classic Resize. Customers with existing RA3 clusters can also upgrade to RG using Snapshot & Restore.
RG instances are available in four instance sizes: rg.large, rg.xlarge, rg.4xlarge, and rg.12xlarge. RG instances are available with flexible pricing options, including On-Demand, and 1-year and 3-year Reserved Instances with All Upfront, Partial Upfront, and No Upfront payment options. For pricing details, visit the Amazon Redshift pricing page .
To get started, refer to the following resources:
AWS Client VPN now supports CLI, administration controls, and faster connections
- Link: https://aws.amazon.com/about-aws/whats-new/2026/08/aws-client-vpn-cli/
- Published: 2026-08-14 05:49:00
- Fetched: 2026-08-14 07:36:42
詳細を表示
AWS Client VPN introduces a rebuilt AWS VPN Client v6.0.x which offers new features like command-line interface (CLI) support, enterprise administrative controls, and faster connection establishment time, making it easier you to automate VPN connectivity and centralize device management across your organization.
The AWS VPN Client CLI provides full feature parity with the GUI. You can now script VPN connections into your automation workflows and infrastructure-as-code deployments. Previously, integrating VPN connectivity into automated environments required third-party tooling or manual intervention. This feature eliminates that by supporting background CLI operations. Previously, you had to distribute VPN profiles among all users in your organization, which could be managed by any user without permissions. Now, with administration controls on AWS client, you can centralize VPN policy enforcement by scoping profiles to specific users, manage global profiles available to all users on a device, and enforce approved VPN configurations across your organization.
The client is rebuilt with OpenVPN3, delivering faster connection establishment across all supported operating systems. You can use both the GUI and CLI together as both run concurrently and VPN connections persist independently of either interface. The rebuilt client v6.0 onwards maintains full backward compatibility with existing AWS Client VPN endpoints, so no endpoint changes are required. The updated AWS VPN Client is available today for Windows (x64/ARM), macOS (x64/ARM), and Linux (x64). There are no additional charges beyond standard pricing of AWS Client VPN. Download the latest client version 6.0.x for macOS, Windows and Linux to start using it.
To learn more about Client VPN, visit the AWS Client VPN product page or read the documentation.
AWS Billing and Cost Management introduces Managed Dashboards
- Link: https://aws.amazon.com/about-aws/whats-new/2026/08/aws-billing-and-cost-management-managed-dashboards/
- Published: 2026-08-14 11:00:00
- Fetched: 2026-08-14 13:03:37
AWS Billing and Cost Management (BCM) Dashboards now include Managed Dashboards. These are a collection of preconfigured and read-only dashboards located in your dashboard list. They deliver actionable cost insights with your account data pre-populated without setup.
There are five curated dashboards. Cost Overview & Trends tracks your spending patterns across services, accounts, and regions over 12 months with forward-looking forecasts. Compute and Database dashboards show your spend pattern within each service category, pairing cost breakdowns with relevant commitment coverage and utilization metrics in a single view. Reservations and Savings Plans dashboards show how well your purchased commitments are performing across all eligible services, quantifying gaps and underutilization in monetary terms.
All managed dashboards are read-only and maintained by AWS. You can duplicate any dashboard to create a fully editable custom copy, add individual widgets to your existing dashboards, and export via PDF or CSV. Whether you are starting your FinOps journey or looking for a standardized baseline across accounts, Managed Dashboards give you cost visibility without setup so you can focus on analysis and action rather than configuration.
AWS Managed Dashboards are available in all commercial AWS Regions at no additional cost. To get started, navigate to Dashboards in the AWS Billing and Cost Management console or view the user guide.
Amazon SES click tracking now supports custom URL paths for mobile app deep linking
- Link: https://aws.amazon.com/about-aws/whats-new/2026/08/amazon-ses-supports-customurl-deeplinking
- Published: 2026-08-14 16:00:00
- Fetched: 2026-08-15 04:44:31
Amazon Simple Email Service (SES) now makes it easier to support mobile deep linking with the new ses:custom-path HTML attribute. When you add this attribute to an <a> tag, SES carries your path segment through to the tracking URL, so mobile operating systems can match it to your app's Universal Links (iOS) or App Links (Android) configuration. This enables you to use mobile deep linking without disabling engagement tracking.
This feature is available in all AWS Regions where Amazon SES is available. To use this feature, you need a custom redirect domain for click tracking with an Apple App Site Association (AASA) or Digital Asset Links verification file hosted on that domain. Then, add the ses:custom-path attribute to links in your HTML emails.
To learn more, see Configuring custom domains to handle open and click tracking and the Amazon SES email sending metrics FAQs in the Amazon SES Developer Guide.
AWS Japan Blog
Amazon EKS Auto Mode 上で Agones を安定稼働させる設計のポイント
- Link: https://aws.amazon.com/jp/blogs/news/agones-on-eks-automode-practice/
- Published: 2026-08-14 10:33:03
- Fetched: 2026-08-14 10:38:08
「聞くだけで、必要な情報が集まる」航空オペレーション基盤を Kiro で実現する
- Link: https://aws.amazon.com/jp/blogs/news/building-aviation-ai-operations-platform-with-bedrock-and-kiro/
- Published: 2026-08-14 16:13:05
- Fetched: 2026-08-14 17:11:44
AWS Security Blog
AWS Certificate Manager will discontinue email validation to prove domain validation for certificates
- Link: https://aws.amazon.com/blogs/security/aws-certificate-manager-will-discontinue-email-validation-to-prove-domain-validation-for-certificates/
- Published: 2026-08-14 06:23:00
- Fetched: 2026-08-14 06:40:08
AWS Security Bulletins
CVE-2026-18952 - Missing Input Validation in OpenSearch Security Analytics Plugin
- Link: https://aws.amazon.com/security/security-bulletins/rss/2026-079-aws/
- Published: 2026-08-14 02:43:27
- Fetched: 2026-08-14 02:54:19
Bulletin ID: 2026-079-AWS
Scope: AWS
Content Type: Important (requires attention)
Publication Date: 08/12/2026 11:45 AM PDT
Description:
OpenSearch is a community-driven, open-source search and analytics suite. We identified CVE-2026-18952, a missing input validation issue in the threat intelligence feed parser of the OpenSearch Security Analytics plugin. This issue may allow an authenticated user with the security_analytics_full_access role to perform server-side request forgery (SSRF) and read local files via a crafted URL parameter to the threat intel source configuration endpoint.
Impacted Versions:
OpenSearch Security Analytics Plugin (open-source, self-managed):
- Affected: >= 2.15.0
- Fixed: >= 3.5.0
Amazon OpenSearch Service (AWS Managed):
- Affected: Domains running engine versions >= 2.15.0
- Fixed: Addressed via service software update for engine version 3.5. The affected functionality is not enabled in the default service configuration.
Please refer to the article below for the most up-to-date and complete information related to this AWS Security Bulletin.
CVE-2026-18428 - OpenSearch SQL Plugin - Async Query Validation Bypass
- Link: https://aws.amazon.com/security/security-bulletins/rss/2026-081-aws/
- Published: 2026-08-14 02:46:21
- Fetched: 2026-08-14 02:54:19
Bulletin ID: 2026-081-AWS
Scope: AWS
Content Type: Important (requires attention)
Publication Date: 08/13/2026 10:30 AM PDT
Description:
OpenSearch SQL plugin is a plugin that enables SQL and PPL query capabilities on OpenSearch clusters, including direct query integration with external data sources via Apache Spark. An issue exists where the Flint extension query handler validates SQL queries without sufficient restrictions, allowing a user with async query access to bypass the SQL grammar deny list via the direct query endpoint.
Affected Products & Versions:
OpenSearch SQL Plugin (open-source, self-managed):
- Affected: v2.13 to v3.6
- Fixed: versions 3.7 and 2.19.6
Amazon OpenSearch Service (AWS Managed):
- Affected: v2.13 to v3.5
- Fixed: v2.13 to v3.5 (via service software update)
Please refer to the article below for the most up-to-date and complete information related to this AWS Security Bulletin.
AWS Architecture Blog
Track generative AI costs with Amazon Bedrock inference profiles
- Link: https://aws.amazon.com/blogs/architecture/track-generative-ai-costs-with-amazon-bedrock-inference-profiles/
- Published: 2026-08-14 00:59:39
- Fetched: 2026-08-14 01:52:54
Serverless vehicle tracking at scale: Bosch L.OS on AWS
- Link: https://aws.amazon.com/blogs/architecture/serverless-vehicle-tracking-at-scale-bosch-l-os-on-aws/
- Published: 2026-08-14 19:02:13
- Fetched: 2026-08-14 19:55:24
AWS Machine Learning Blog
Amazon Quick for Microsoft 365: Agentic AI where you work
- Link: https://aws.amazon.com/blogs/machine-learning/amazon-quick-for-microsoft-365-agentic-ai-where-you-work/
- Published: 2026-08-14 00:48:15
- Fetched: 2026-08-14 00:55:27
Accelerating M&A due diligence with Amazon Bedrock AgentCore
- Link: https://aws.amazon.com/blogs/machine-learning/accelerating-ma-due-diligence-with-amazon-bedrock-agentcore/
- Published: 2026-08-14 00:52:44
- Fetched: 2026-08-14 00:55:27
Automate legacy web applications with Amazon Bedrock AgentCore Browser Tool
- Link: https://aws.amazon.com/blogs/machine-learning/automate-legacy-web-applications-with-amazon-bedrock-agentcore-browser-tool/
- Published: 2026-08-14 00:56:07
- Fetched: 2026-08-14 01:52:55
Monitor on-premises and multi-cloud AI agents with AgentCore Observability
- Link: https://aws.amazon.com/blogs/machine-learning/monitor-on-premises-and-multi-cloud-ai-agents-with-agentcore-observability/
- Published: 2026-08-14 01:02:10
- Fetched: 2026-08-14 01:52:55
AWS Compute Blog
Designing for failure: Building resilient systems on AWS
- Link: https://aws.amazon.com/blogs/compute/designing-for-failure-building-resilient-systems-on-aws/
- Published: 2026-08-14 05:03:28
- Fetched: 2026-08-14 05:37:23
Collecting CPU and memory metrics for AWS Lambda MicroVMs
- Link: https://aws.amazon.com/blogs/compute/collecting-cpu-and-memory-metrics-for-aws-lambda-microvms/
- Published: 2026-08-14 20:11:55
- Fetched: 2026-08-14 20:40:51
Observability best practices for Lambda durable functions
- Link: https://aws.amazon.com/blogs/compute/observability-best-practices-for-lambda-durable-functions-2/
- Published: 2026-08-14 21:49:49
- Fetched: 2026-08-14 21:56:26