AWS News - 2026-08-14

2026-08-14
最終更新: 2026-08-15 04:44:31 JST

AI による概要

23 記事

この日は証明書運用の大きな方針転換が告知されました。AWS Certificate Manager が CA/B フォーラムによる業界全体の動きに合わせ、2027 年 9 月 30 日までに E メール検証済みパブリック証明書のサポートを終了します。あわせて既存の証明書について E メール検証から DNS 検証へ切り替える機能も提供開始されました。Amazon Quick は Microsoft 365 拡張機能が一般提供となり、Word・Excel・PowerPoint・Outlook の中から直接エージェンティック AI とデータにアクセスできます。Claude Opus 5 が GovCloud (US) でも利用可能になり、OpenAI のサイバー防御モデル Daybreak Red / Daybreak Blue も対象顧客向けに Bedrock で提供開始となりました。コンピュートブログでは相関するハードウェア障害を防ぐ分散システム設計、Lambda MicroVMs の CPU・メモリメトリクス収集、durable functions のオブザーバビリティのベストプラクティスが解説されています。

主要トピック
  • 証明書: ACM が 2027 年 9 月 30 日までに E メール検証を終了、DNS 検証への切り替え機能も提供

  • 生産性: Amazon Quick の Microsoft 365 拡張 (Word / Excel / PowerPoint / Outlook) が一般提供

  • GovCloud: Claude Opus 5 が GovCloud (US) で利用可能に

  • サイバー防御: OpenAI の Daybreak Red / Daybreak Blue が対象顧客向けに Bedrock で提供開始

  • 耐障害設計: 相関するハードウェア障害を防ぐ分散システム設計と実際のインシデント対応パターン

  • オブザーバビリティ: Lambda MicroVMs のメトリクス収集と durable functions の監視ベストプラクティス

  • マルチクラウド: AgentCore Observability でオンプレミス・GCP・Azure 上のエージェントも監視

  • 脆弱性: OpenSearch Security Analytics プラグインの入力検証欠落、SQL プラグインの非同期クエリ検証バイパス

AI (Claude Opus 5) が生成 · 2026-08-28 09:31:16 JST

AWS What's New

AWS Certificate Manager supports switching from e-mail to DNS validation

詳細を表示

AWS Certificate Manager (ACM) now enables you to change the domain validation method on your existing ACM issued public TLS certificates from e-mail to DNS, without reissuing the certificate or changing its existing Amazon Resource Name (ARN). Due to the Certification Authority/Browser (CA/B) Forum's mandated deprecation of email-based domain validation for publicly trusted certificates, effective March 15, 2028, ACM will phase out its support for email validation throughout 2027. ACM will no longer issue email-validated certificates starting March 31 2027, and stop renewing email-validated certificates on September 30 2027. More details on ACM's deprecation of email validation can be found on the AWS Security Blog. By switching to DNS validation now, you can transition ahead of that deadline and enable fully automated renewals through DNS validated certificates.

Your certificate ARN remains unchanged after switching from e-mail to DNS validation, so existing ARN references in your CI/CD pipelines, load balancer configurations, and other AWS service integrations continue to work without modification. To switch the validation method, use the ACM console or the  UpdateCertificateOptions API. ACM provides a CNAME record for each domain in the certificate (the same mechanism used when provisioning new certificates with DNS validation) and you have up to 72 hours to add the records to your DNS configuration. You can monitor the validation status of each domain via the console or the ListCertificateDomainValidations API. We recommend DNS validation for new certificates, and HTTP validation for Amazon CloudFront distributions..

This feature is available in all AWS Regions where ACM certificates are available. To get started, refer to  Migrating from email to DNS validation in the AWS Certificate Manager User Guide.

Daybreak Red and Daybreak Blue from OpenAI are now available to eligible customers on Amazon Bedrock

Security teams can now access Daybreak Red and Daybreak Blue from OpenAI on Amazon Bedrock. Both are part of Daybreak, the cyber defense initiative from OpenAI that gives defenders governed access to frontier AI for cybersecurity work.

Daybreak Blue is the starting point for most security teams across defensive workflows including vulnerability discovery, detection engineering, and incident response. Daybreak Red is designed for advanced, authorized tasks such as vulnerability research, exploit reproduction, and mitigation development. For these tasks, a lower refusal threshold matched by stronger identity verification, monitoring, and access controls improves the speed and depth of an investigation. Both models run on Bedrock's next-generation inference engine with zero-operator access (ZOA) enforced at the chip. Your inference data is not used for model training, and neither model requires you to opt into sharing your data with OpenAI.

Daybreak Red: GPT-5.6 Cyber and Daybreak Blue: GPT-5.6 Sol are now available to eligible customers on Amazon Bedrock in the following AWS Region: US East (N. Virginia). Access to the models requires enrollment in Daybreak access from OpenAI. To enroll, contact OpenAI or reach out to your AWS account team for guidance on eligibility. Once approved, work with your account team to request access on AWS. To learn more, read the blog.

Spot Placement Score now includes Local Zones

Today, AWS announces support for AWS Local Zones in Spot placement score, helping you identify locations where your Spot capacity request is most likely to succeed. Spot placement score evaluates your target capacity and compute requirements and returns scores for AWS Regions or Availability Zones.

Previously, Spot placement scores excluded local zone capacity information when reporting zonal and regional scores. Now, you can optionally request local zones to be included in the zonal and regional score responses giving you a broader view of your Spot capacity options.

You can use Spot placement score through EC2 Spot Console, AWS CLI, or SDK. To learn more about Spot placement score see Spot placement score documentation.

Amazon Quick Microsoft 365 extensions are now generally available

Today, Amazon Quick announces the general availability of Microsoft 365 extensions for Excel, PowerPoint, Word, and Outlook. These extensions enable Quick to perform tasks directly within users' M365 environments, using AI to handle complex local tasks such as redlining documents, building financial models, creating presentation-ready decks, and managing Outlook inboxes.

The Excel extension helps with complex spreadsheet analysis, creating pivot tables and charts, and importing and cleaning data. The PowerPoint extension helps you create and refine presentations from Quick data using organization-defined templates. The Word extension generates formatted documents with Word primitives, makes sweeping edits with track changes enabled, and participates as a reviewer in comments. The Outlook extension performs inbox and calendaring tasks such as prioritizing emails, organizing your inbox, scheduling meetings, and drafting replies using your Quick data and entire inbox context.

These extensions transform daily work across teams. Finance teams can build complex models by describing what they need. Sales teams can draft proposals that automatically pull from CRM data. Marketing teams can create branded presentations without manual formatting. Legal teams can streamline contract reviews. Operations teams can manage email workflows and schedule meetings intelligently, and IT teams can automate routine data analysis that previously required manual effort.

Amazon Quick Microsoft 365 extensions are available in US East (N. Virginia), US West (Oregon), Asia Pacific (Sydney), Europe (Ireland), Asia Pacific (Tokyo), and Europe (Frankfurt). To learn more, see Amazon Quick for Microsoft 365: Agentic AI where you work, and download extensions on the Quick download page.

Claude Opus 5 is now available in AWS GovCloud (US)

AWS GovCloud (US) now offers Claude Opus 5 — the most advanced Opus model yet, and compatible with zero data retention (ZDR) — bringing a step-change in coding, long-running agents, and complex professional work to teams building at the highest level. Claude Opus 5 is available via the bedrock-runtime endpoint in both AWS GovCloud (US) regions, and available via the bedrock-mantle endpoint in AWS GovCloud (US-West)

Claude Opus 5 delivers advances in coding, understanding and navigating codebases like an experienced engineer and writing production-quality code while adapting its strategy as it works. It powers dependable agents that run for hours and even overnight, finding paths around obstacles, recovering from errors, and reaching their objectives. And it brings deeper reasoning to long documents and higher accuracy to complex analysis, with the largest gains on document-heavy enterprise work. 

Amazon Bedrock offers Claude Opus 5 with zero data retention (ZDR) enabled by default, giving you Opus' top-tier intelligence while meeting your data governance requirements. It keeps your data within AWS infrastructure with regional data residency and provides access through a unified service with AWS-managed features like Guardrails and Knowledge Bases. To learn more, see the Amazon Bedrock documentation and regional availability.

Amazon Redshift adds rg.large and rg.12xlarge instance sizes in AWS GovCloud (US) Regions

Amazon Redshift now offers rg.large and rg.12xlarge instance sizes for RG instances in the AWS GovCloud (US-West) and AWS GovCloud (US-East) Regions. RG instances deliver better performance, running data warehouse and data lake workloads up to 2.4x as fast as previous generation RA3 instances, at 30% lower price per vCPU. RG instances include Redshift's custom-built vectorized data lake query engine that processes Apache Iceberg and Parquet data on your cluster nodes, enabling you to run SQL analytics across your data warehouse and data lake using a single engine.

rg.large and rg.12xlarge instance sizes are available on patch version P202 and later. Customers can resize existing RG or RA3 clusters to these new instance sizes using Elastic Resize or Classic Resize. Customers with existing RA3 clusters can also upgrade to RG using Snapshot & Restore.

RG instances are available in four instance sizes: rg.large, rg.xlarge, rg.4xlarge, and rg.12xlarge. RG instances are available with flexible pricing options, including On-Demand, and 1-year and 3-year Reserved Instances with All Upfront, Partial Upfront, and No Upfront payment options. For pricing details, visit the  Amazon Redshift pricing page .

 

To get started, refer to the following resources:

AWS Client VPN now supports CLI, administration controls, and faster connections

詳細を表示

AWS Client VPN introduces a rebuilt AWS VPN Client v6.0.x which offers new features like command-line interface (CLI) support, enterprise administrative controls, and faster connection establishment time, making it easier you to automate VPN connectivity and centralize device management across your organization.

The AWS VPN Client CLI provides full feature parity with the GUI. You can now script VPN connections into your automation workflows and infrastructure-as-code deployments. Previously, integrating VPN connectivity into automated environments required third-party tooling or manual intervention. This feature eliminates that by supporting background CLI operations. Previously, you had to distribute VPN profiles among all users in your organization, which could be managed by any user without permissions. Now, with administration controls on AWS client, you can centralize VPN policy enforcement by scoping profiles to specific users, manage global profiles available to all users on a device, and enforce approved VPN configurations across your organization.

The client is rebuilt with OpenVPN3, delivering faster connection establishment across all supported operating systems. You can use both the GUI and CLI together as both run concurrently and VPN connections persist independently of either interface. The rebuilt client v6.0 onwards maintains full backward compatibility with existing AWS Client VPN endpoints, so no endpoint changes are required. The updated AWS VPN Client is available today for Windows (x64/ARM), macOS (x64/ARM), and Linux (x64). There are no additional charges beyond standard pricing of AWS Client VPN. Download the latest client version 6.0.x for macOS, Windows and Linux to start using it. 

To learn more about Client VPN, visit the AWS Client VPN product page or read the documentation.

AWS Billing and Cost Management introduces Managed Dashboards

AWS Billing and Cost Management (BCM) Dashboards now include Managed Dashboards. These are a collection of preconfigured and read-only dashboards located in your dashboard list. They deliver actionable cost insights with your account data pre-populated without setup. 

There are five curated dashboards. Cost Overview & Trends tracks your spending patterns across services, accounts, and regions over 12 months with forward-looking forecasts. Compute and Database dashboards show your spend pattern within each service category, pairing cost breakdowns with relevant commitment coverage and utilization metrics in a single view. Reservations and Savings Plans dashboards show how well your purchased commitments are performing across all eligible services, quantifying gaps and underutilization in monetary terms. 

All managed dashboards are read-only and maintained by AWS. You can duplicate any dashboard to create a fully editable custom copy, add individual widgets to your existing dashboards, and export via PDF or CSV. Whether you are starting your FinOps journey or looking for a standardized baseline across accounts, Managed Dashboards give you cost visibility without setup so you can focus on analysis and action rather than configuration. 

AWS Managed Dashboards are available in all commercial AWS Regions at no additional cost. To get started, navigate to Dashboards in the AWS Billing and Cost Management console or view the user guide

Amazon SES click tracking now supports custom URL paths for mobile app deep linking

Amazon Simple Email Service (SES) now makes it easier to support mobile deep linking with the new ses:custom-path HTML attribute. When you add this attribute to an <a> tag, SES carries your path segment through to the tracking URL, so mobile operating systems can match it to your app's Universal Links (iOS) or App Links (Android) configuration. This enables you to use mobile deep linking without disabling engagement tracking.

This feature is available in all AWS Regions where Amazon SES is available. To use this feature, you need a custom redirect domain for click tracking with an Apple App Site Association (AASA) or Digital Asset Links verification file hosted on that domain. Then, add the ses:custom-path attribute to links in your HTML emails.

To learn more, see Configuring custom domains to handle open and click tracking and the Amazon SES email sending metrics FAQs in the Amazon SES Developer Guide.

AWS Japan Blog

Amazon EKS Auto Mode 上で Agones を安定稼働させる設計のポイント

リアルタイム性の高いマルチプレイヤーゲームでは専用ゲームサーバー方式が広く使われており、マッチメイキングやサーバーの割り当て・回収といったライフサイクル管理のオーケストレーション基盤の設計が重要なテーマとなります。AWS で専用ゲームサーバーをホストする主な選択肢は、マネージドの Amazon GameLift Servers を使うか、EC2 / ECS / EKS 上でセルフホストするかの2つです。より柔軟な制御が必要な場合は、EKS 上にデプロイできる OSS の Agones が選択肢になりますが、Kubernetes 基盤の運用負荷は避けられませんでした。2024 年 12 月に GA した Amazon EKS Auto Mode は Kubernetes の構築・運用負担を軽減する機能で、Agones の基盤 EKS クラスタと組み合わせることで柔軟さと簡素さを両立できます。ただし EKS Auto Mode にはいくつかの制約もあります。本記事では、EKS Auto Mode の制約が Agones の特性を阻害しないための設計方針を紹介します。

「聞くだけで、必要な情報が集まる」航空オペレーション基盤を Kiro で実現する

航空業界では、散在するデータの横断的な活用が長年の課題でした。本ブログでは、 Amazon S3 を中心とした […]

AWS Security Blog

AWS Certificate Manager will discontinue email validation to prove domain validation for certificates

Today, we’re announcing that AWS Certificate Manager (ACM) will discontinue support for email-validated public certificates by September 30, 2027. If you use email validation for your ACM public certificates, you need to migrate to DNS validation before that date. This change aligns with the Certification Authority/Browser (CA/B) Forum’s industry-wide deprecation of email-based domain validation and […]

AWS Security Bulletins

CVE-2026-18952 - Missing Input Validation in OpenSearch Security Analytics Plugin

Bulletin ID: 2026-079-AWS
Scope: AWS
Content Type: Important (requires attention)
Publication Date: 08/12/2026 11:45 AM PDT

Description:

OpenSearch is a community-driven, open-source search and analytics suite. We identified CVE-2026-18952, a missing input validation issue in the threat intelligence feed parser of the OpenSearch Security Analytics plugin. This issue may allow an authenticated user with the security_analytics_full_access role to perform server-side request forgery (SSRF) and read local files via a crafted URL parameter to the threat intel source configuration endpoint.

Impacted Versions:

OpenSearch Security Analytics Plugin (open-source, self-managed):
- Affected: >= 2.15.0
- Fixed: >= 3.5.0

Amazon OpenSearch Service (AWS Managed):
- Affected: Domains running engine versions >= 2.15.0
- Fixed: Addressed via service software update for engine version 3.5. The affected functionality is not enabled in the default service configuration.

Please refer to the article below for the most up-to-date and complete information related to this AWS Security Bulletin.

CVE-2026-18428 - OpenSearch SQL Plugin - Async Query Validation Bypass

Bulletin ID: 2026-081-AWS
Scope: AWS
Content Type: Important (requires attention)
Publication Date: 08/13/2026 10:30 AM PDT

Description:

OpenSearch SQL plugin is a plugin that enables SQL and PPL query capabilities on OpenSearch clusters, including direct query integration with external data sources via Apache Spark. An issue exists where the Flint extension query handler validates SQL queries without sufficient restrictions, allowing a user with async query access to bypass the SQL grammar deny list via the direct query endpoint.

Affected Products & Versions:

OpenSearch SQL Plugin (open-source, self-managed):
- Affected: v2.13 to v3.6
- Fixed: versions 3.7 and 2.19.6

Amazon OpenSearch Service (AWS Managed):
- Affected: v2.13 to v3.5
- Fixed: v2.13 to v3.5 (via service software update)

Please refer to the article below for the most up-to-date and complete information related to this AWS Security Bulletin.

AWS Architecture Blog

Track generative AI costs with Amazon Bedrock inference profiles

Learn how to track generative AI costs by department using Amazon Bedrock application inference profiles and AWS cost allocation tags. Create tagged profiles for each team and view per-department cost breakdowns in AWS Cost Explorer.

Serverless vehicle tracking at scale: Bosch L.OS on AWS

Learn how Bosch Mobility Platform Solutions built L.OS, a serverless vehicle tracking platform on AWS that unifies India's fragmented spot logistics market into a single real-time visibility layer using Amazon ECS, AWS Lambda, and Amazon MSK.

AWS Machine Learning Blog

Amazon Quick for Microsoft 365: Agentic AI where you work

Amazon Quick is now available directly inside Microsoft Word, Excel, PowerPoint, and Outlook. These extensions bring connected data access and agentic document editing into the Microsoft 365 apps your teams already use, so you can analyze data, draft content, and reach enterprise knowledge without switching applications.

Accelerating M&A due diligence with Amazon Bedrock AgentCore

Learn how to build a multi-agent M&A due diligence system on Amazon Bedrock AgentCore. This post walks through a reference architecture that combines agent orchestration, knowledge retrieval, and governance controls, then deploys a complete sample you can run in your own AWS account.

Automate legacy web applications with Amazon Bedrock AgentCore Browser Tool

Learn how to automate legacy web applications that need human-like interaction using Amazon Bedrock AgentCore Browser Tool and Strands Agents. This walkthrough covers a reference architecture for an AI-powered digital worker that drives legacy interfaces through secure, isolated browser sessions while preserving human oversight and full audit trails.

Monitor on-premises and multi-cloud AI agents with AgentCore Observability

Set up Amazon Bedrock AgentCore Observability for AI agents running outside AWS: on-premises, on GCP, on Azure, or on developer machines. This walkthrough uses the AWS Distro for OpenTelemetry (ADOT) and IAM credentials to route session traces, span metrics, and token usage to the same AgentCore Observability dashboard.

AWS Compute Blog

Designing for failure: Building resilient systems on AWS

Learn how to prevent correlated hardware failures in distributed systems on Amazon EC2. This post walks through real incident response patterns, including Partition Placement Groups, composite alarms, automated recovery with Auto Scaling, and observability best practices.

Collecting CPU and memory metrics for AWS Lambda MicroVMs

Learn how to collect CPU and memory metrics for AWS Lambda MicroVMs using the Amazon CloudWatch agent. This post walks through configuring Telegraf and OpenTelemetry pipelines inside a MicroVM image, and explains how in-guest metrics differ from your bill.

Observability best practices for Lambda durable functions

Learn observability best practices for AWS Lambda durable functions, including CloudWatch metrics, custom alarms, structured logging, and X-Ray tracing for debugging callback timeouts end-to-end.