AWS News - 2026-09-03
2026-09-03
最終更新: 2026-09-09 05:38:55 JST
AI による概要
この日は OS とセキュリティ運用の基盤、そしてエージェントを実務へ落とし込む事例が中心でした。まず Amazon Linux 2027 (AL2027) がパブリックプレビューとして発表され、AWS 上のクラウドネイティブなワークロード向けに性能とスケールを狙った次世代 OS が姿を見せました。セキュリティブログでは、この 1 年の企業のセキュリティリーダーとの対話を踏まえ、自律型 AI エージェントの台頭がクラウド移行以来もっとも大きなセキュリティ体制の転換であるとして、機械の速度での検知と対応を論じる記事が公開されています。IAM Identity Center の ID ソース移行に関する記事も、Active Directory の移行戦略と許可セットの自動化を含めて 9 月 2 日に再公開されました。セキュリティ速報は 1 件で、Amazon Ion の C 実装である Amazon Ion-C の 1.1.6 より前のバージョンで、Ion リーダーに制御されない再帰がある問題 (CVE-2026-84851) が Important として公開されています。サービス更新は幅広く、AWS Config が Amazon Bedrock、EC2、SageMaker、AWS Organizations を含む 60 の新しいリソースタイプに対応してカバレッジを広げ、AWS CloudFormation は CloudFormation CLI の cfn test コマンドに --v2 フラグで使える contract tests v2 に対応しました。従来は基本的なシナリオしか網羅していなかったコントラクトテストが拡充されています。Amazon Connect Customer では、AI による自己解決体験をノーコードのキャンバスで設計・デプロイできる agentic CX designer が一般提供となり、マレー語での人間と AI エージェントの自動評価にも対応しています。規制対応の要素も多く、第 2 世代の Outposts ラックが GovCloud (US-East / US-West) で利用可能になり、Bedrock の Web Search 組み込みツールが GovCloud (US-West) へ、S3 が FIPS 140-3 の検証済みエンドポイントで PrivateLink に対応、SES が S/MIME による電子メール署名をサポートしました。移行では AWS Transform がブロックストレージの移行先として Amazon FSx for NetApp ONTAP を一般提供で追加しています。機械学習ブログでは、オーストラリアのチームがシドニー・メルボルンの両リージョンからグローバルなクロスリージョン推論で OpenAI GPT-5.6 の Sol / Terra / Luna を使えるようになったことが案内され、障害のある学生の移行計画を支援する対話型 AI ソリューション Trinity を Bedrock 上のサーバーレスなマルチエージェント構成へ拡張した事例、.NET のコードベースを解析してアーキテクチャ図を生成し継続的に維持するパイプラインをグローバルなインターディーラーブローカーが AgentCore 上に構築した事例、インフラ監視がすべて正常でも空白・陳腐化・誤りを示すことがある BI ダッシュボードの内容の破綻を Bedrock で検知する取り組みが公開されました。国内では Aurora DSQL の事例セミナー告知に加え、ウィークリー総まとめと Graviton5 の R9g / R9gd の日本語版が出ています。
主要トピック
OS: Amazon Linux 2027 (AL2027) がパブリックプレビューで登場
セキュリティ論考: 自律型エージェントの台頭を踏まえた、機械の速度での検知と対応
脆弱性: Amazon Ion-C 1.1.6 より前の Ion リーダーに制御されない再帰 (CVE-2026-84851)
ガバナンス: AWS Config が Bedrock・EC2・SageMaker・Organizations を含む 60 の新リソースタイプに対応
IaC: CloudFormation が cfn test の --v2 フラグで contract tests v2 に対応、テストシナリオを拡充
コンタクトセンター: Connect の agentic CX designer が GA、ノーコードで AI 自己解決体験を設計、評価はマレー語にも対応
規制対応: 第 2 世代 Outposts ラックと Bedrock Web Search が GovCloud へ、S3 が FIPS エンドポイントで PrivateLink に対応
メール: SES が S/MIME 署名に対応し、受信者が送信元の真正性を検証可能に
推論: オーストラリア (シドニー・メルボルン) から OpenAI GPT-5.6 Sol / Terra / Luna をグローバルクロスリージョン推論で利用可能に
移行: AWS Transform がブロックストレージの移行先として FSx for NetApp ONTAP を GA で追加
エージェント事例: .NET コードからアーキテクチャ図を生成する文書化パイプライン、BI ダッシュボードの内容破綻を検知する仕組み
AWS What's New
AWS Config now supports 60 new resource types
- Link: https://aws.amazon.com/about-aws/whats-new/2026/09/aws-config-new-resource-types/
- Published: 2026-09-03 00:00:00
- Fetched: 2026-09-03 03:24:47
詳細を表示
AWS Config now supports 60 additional AWS resource types across key services including Amazon Bedrock, Amazon EC2, Amazon SageMaker, and AWS Organizations. This expansion provides greater coverage over your AWS environment, enabling you to more effectively discover, assess, audit, and remediate an even broader range of resources.
With this launch, if you have enabled recording for all resource types, then AWS Config will automatically track these new additions. The newly supported resource types are also available in Config rules and Config aggregators.
You can now use AWS Config to monitor the following newly supported resource types in all AWS Regions where the resources are available:
Resource Types:
| AWS::AppSync::ChannelNamespace | AWS::EC2::RouteServer | AWS::Organizations::Policy |
| AWS::AppSync::SourceApiAssociation | AWS::EC2::RouteServerEndpoint | AWS::Organizations::ResourcePolicy |
| AWS::Bedrock::EnforcedGuardrailConfiguration | AWS::EC2::RouteServerPeer | AWS::QuickSight::RefreshSchedule |
| AWS::Bedrock::Flow | AWS::EKS::PodIdentityAssociation | AWS::RDS::DBProxy |
| AWS::Bedrock::FlowVersion | AWS::ElasticLoadBalancingV2::ListenerRule | AWS::S3Vectors::Index |
| AWS::Bedrock::PromptVersion | AWS::GameLiftStreams::Application | AWS::SageMaker::Action |
| AWS::BedrockAgentCore::OAuth2CredentialProvider | AWS::GameLiftStreams::StreamGroup | AWS::SageMaker::Algorithm |
| AWS::BedrockAgentCore::PaymentManager | AWS::IdentityStore::Group | AWS::SageMaker::App |
| AWS::BedrockAgentCore::Policy | AWS::IoT::TopicRuleDestination | AWS::SageMaker::Context |
| AWS::BedrockAgentCore::PolicyEngine | AWS::Lightsail::Container | AWS::SageMaker::Hub |
| AWS::BedrockAgentCore::TokenVault | AWS::Lightsail::Database | AWS::SageMaker::MlflowApp |
| AWS::Chime::AppInstance | AWS::Lightsail::Distribution | AWS::SageMaker::ModelCard |
| AWS::CloudTrail::ResourcePolicy | AWS::Lightsail::Domain | AWS::SageMaker::ModelPackage |
| AWS::CodePipeline::Webhook | AWS::Lightsail::Instance | AWS::SES::MailManagerArchive |
| AWS::Config::OrganizationConformancePack | AWS::Lightsail::LoadBalancer | AWS::Transfer::WebApp |
| AWS::Connect::AgentStatus | AWS::Logs::ResourcePolicy | AWS::WorkSpacesWeb::TrustStore |
| AWS::Connect::EvaluationForm | AWS::MediaConnect::Bridge | AWS::WorkSpacesWeb::UserAccessLoggingSettings |
| AWS::Connect::View | AWS::NetworkManager::CoreNetwork | AWS::XRay::Group |
| AWS::Connect::ViewVersion | AWS::Organizations::Account | AWS::XRay::ResourcePolicy |
| AWS::EC2::NetworkPerformanceMetricSubscription | AWS::Organizations::Organization | AWS::XRay::SamplingRule |
AWS CloudFormation now supports contract tests v2 for resource types
- Link: https://aws.amazon.com/about-aws/whats-new/2026/09/aws-cloudformation-contract-tests-v2-resource-types/
- Published: 2026-09-03 00:23:00
- Fetched: 2026-09-09 05:38:55
AWS CloudFormation now supports contract tests v2, available through the --v2 flag of the cfn test command in the CloudFormation CLI. Previously, the contract test suite covered only basic scenarios around the CRUD handlers. Contract tests v2 adds deeper test scenarios that exercise your resource type implementation across each handler operation. All new resource types can run contract tests v2 through the test-type API during registry submission, and Java-based resource types can also run them locally with cfn test --v2, requiring only Docker and a built handler package.
Contract tests v2 introduces live-state verification that confirms actual resource state matches the requested state after create, update, and delete operations. Developers also benefit from schema backward-compatibility checks, test input linting that flags hardcoded Regions, account IDs, and partitions, and detailed HTML and JUnit XML reports for local contract test execution. These improvements significantly reduce iteration cycles by surfacing issues before registry submission.
Contract tests v2 is available in all AWS Regions where AWS CloudFormation is available. To learn more, visit the AWS CloudFormation contract tests documentation and the AWS CloudFormation product page.
Amazon Connect Customer announces general availability of agentic CX designer
- Link: https://aws.amazon.com/about-aws/whats-new/2026/09/agentic-cx-designer/
- Published: 2026-09-03 01:00:00
- Fetched: 2026-09-03 03:24:47
Amazon Connect Customer announces the general availability of agentic CX designer, a no-code canvas for designing and deploying AI-powered self-service experiences. You can now build and launch voice and digital experiences that bring agentic and deterministic AI together to transform how you serve customers with the control and reliability enterprises demand. Your business teams users can go from designing conversations and integrating with the systems that run your business, to testing, to launching production-ready experiences in weeks, not months.
Agentic CX designer gives you the clarity of a flowchart with the power of a large language model. On a visual canvas you define the logic, guardrails, and integrations, and the model handles the natural conversation. For outcomes that have to be exact, such as eligibility, approvals, routing, or compliance, you define the workflow and the conversation follows it. You build, test, and deploy in the same place, so the team that designs an experience can validate it and put it into production without writing code or handing the work to engineering.
Second-generation AWS Outposts racks now in the AWS GovCloud (US) Regions
- Link: https://aws.amazon.com/about-aws/whats-new/2026/09/aws-outposts-govcloud-us-regions/
- Published: 2026-09-03 01:00:00
- Fetched: 2026-09-03 06:32:41
Second-generation AWS Outposts racks are now supported in the AWS GovCloud (US-East) and AWS GovCloud (US-West) Regions. Outposts racks extend AWS infrastructure, AWS services, APIs, and tools to virtually any on-premises data center or colocation space for a truly consistent hybrid experience.
Organizations from startups to enterprises and the public sector can now order their Outposts racks connected to the new supported regions, optimizing for their latency and data residency needs. Outposts allows customers to run workloads that need low latency access to on-premises systems locally while connecting back to their home Region for application management. Customers can also use Outposts and AWS services to manage and process data that needs to remain on-premises to meet data residency requirements. This regional expansion provides additional flexibility in the AWS Regions that customers’ Outposts can connect to.
To learn more about second-generation Outposts racks, read this blog post and user guide. For the most updated list of countries and territories and the AWS Regions where second-generation Outposts racks are supported, check out the Outposts rack FAQs page.
Amazon Quick adds new tool settings and Model Context Protocol (MCP) sync support for connectors
- Link: https://aws.amazon.com/about-aws/whats-new/2026/09/amazon-quick-adds-tool-settings-mcp-sync/
- Published: 2026-09-03 01:54:00
- Fetched: 2026-09-03 03:24:47
Amazon Quick connectors let users leverage tools and services such as Outlook, Slack, Salesforce, Jira, and homegrown MCP servers directly into their workflows across chat, agents, apps, flows, and deep research. Today, Amazon Quick introduces new tool settings and MCP sync support that give admins and connector owners more control over how connectors are deployed and kept up to date.
Connector owners and admins can now selectively enable or disable individual tools within a connector to ensure only approved tools are available to end users. Additionally, new tool permission settings let connector owners decide which tools require consent before proceeding or give end users the flexibility to decide for themselves. Lastly, MCP sync keeps connectors current as external MCP servers add new tools, update descriptions, and evolve their capabilities, ensuring users always have the latest information to get their work done.
These features are available in all AWS Regions where Amazon Quick is available. To learn more, visit the Amazon Quick User Guide.
Amazon Connect Customer expands automated performance evaluations to Malay
- Link: https://aws.amazon.com/about-aws/whats-new/2026/09/amazon-connect-customer-automated-evaluations-malay/
- Published: 2026-09-03 02:00:00
- Fetched: 2026-09-03 06:32:41
Amazon Connect Customer now automates evaluations of human and AI agents in Malay using generative AI. Managers define custom evaluation criteria in natural language and receive AI-generated evaluations with justifications in their preferred language. Performance evaluations also supports cross-language evaluation and can complete assessments in English, even when the conversation is in Malay. This enables multilingual contact centers to use a standardized evaluation framework across languages.
This feature is supported in 8 AWS regions including US East (N. Virginia), US West (Oregon), Europe (Frankfurt), Europe (London), Canada (Central), Asia Pacific (Sydney), Asia Pacific (Tokyo), and Asia Pacific (Singapore). For information about Amazon Connect pricing, please visit our pricing page. To learn more, please visit our documentation and our webpage.
Web Search on Amazon Bedrock is now available in AWS GovCloud (US-West)
- Link: https://aws.amazon.com/about-aws/whats-new/2026/09/amazon-bedrock-web-aws-govcloud/
- Published: 2026-09-03 02:52:00
- Fetched: 2026-09-03 06:32:41
詳細を表示
The Web Search built-in server-side tool on Amazon Bedrock is now available in AWS GovCloud (US-West), helping bring grounded web results to compliance-sensitive government and public-sector workloads. Web Search helps supported OpenAI GPT models ground responses with information from the web. Responses include citations to the sources the model used so users can trace each claim back to its web origin. This can be especially valuable whenever an answer depends on information that changes over time or is more recent than a model's training data, such as current events, recent releases or live pricing. Because the tool runs inside Amazon Bedrock, you don't host a search index, manage crawlers, or write the tool-call loop yourself.
Web Search is designed to support the governance and data-handling standards AWS GovCloud (US) customers require. By default, it keeps your request data within the AWS boundary, serving results from a web index and cache maintained by Amazon. As an AWS-native capability governed by AWS Identity and Access Management (IAM), administrators can allow or deny it at the account or organization level and restrict it by Region, giving teams centralized control while keeping request data within the AWS boundary by default. To get started, add a tool of type web_search to the tools array in your OpenAI Responses API request using your existing OpenAI client library with an Amazon Bedrock API key. The model uses the tool only when it determines a request needs current information. At launch, Web Search in AWS GovCloud (US-West) supports GPT-5.4 , GPT-5.6 Terra and Luna models.
Web Search is available in AWS GovCloud (US-West), in addition to US East (N. Virginia), US East (Ohio), and US West (Oregon). To get started, see the Web Search technical blog. For implementation guidance, see the Web Search documentation. For pricing, see the Amazon Bedrock pricing page.
AWS Transform announces general availability of Amazon FSx for NetApp ONTAP support
- Link: https://aws.amazon.com/about-aws/whats-new/2026/09/aws-transform-fsx-netapp-ontap-support/
- Published: 2026-09-03 12:00:00
- Fetched: 2026-09-04 01:53:14
AWS Transform for migrations adds Amazon FSx for NetApp ONTAP as a generally available storage target for block storage workloads, alongside Amazon EBS. With AWS Transform, you can now migrate block storage directly to FSx for ONTAP as part of the same migration wave that handles compute and networks, eliminating the need for intermediate storage platforms and separate migration tools.
Whether migrating from NetApp ONTAP, other block storage platforms, or VMware environments, your data access patterns and operational processes remain unchanged with FSx for ONTAP. Now your workloads run on a fully managed, production-ready shared storage service that combines ONTAP's enterprise capabilities with the scalability and resiliency of AWS. What previously required stitching together multiple tools is now a single migration workflow.
This capability is available in all AWS Transform supported target Regions and where Amazon FSx for NetApp ONTAP is supported. To get started, visit AWS Transform for migrations. To learn more about Amazon FSx for NetApp ONTAP, see the product page.
Amazon S3 now supports PrivateLink for FIPS endpoints
- Link: https://aws.amazon.com/about-aws/whats-new/2026/09/amazon-s3-privatelink-fips-endpoints
- Published: 2026-09-03 13:00:00
- Fetched: 2026-09-04 07:12:38
Amazon S3 now supports AWS PrivateLink for endpoints that have been validated under the Federal Information Processing Standard (FIPS) 140-3 program.
Customers with security and compliance requirements can use FIPS-validated cryptographic modules when connecting to S3 while keeping their traffic within their Virtual Private Cloud (VPC). To get started, create a new or edit an existing interface VPC endpoint for S3 and configure it to use the FIPS S3 endpoint.
AWS PrivateLink support for FIPS S3 endpoints is now available in the AWS US East (N. Virginia), US East (Ohio), US West (N. California), US West (Oregon), Canada (Central), Canada West (Calgary), and AWS GovCloud (US) Regions, at no additional cost. To learn more, visit accessing AWS services through AWS PrivateLink, FIPS 140-3 Compliance, and S3 documentation.
Amazon SES now supports S/MIME email signing
- Link: https://aws.amazon.com/about-aws/whats-new/2026/09/amazon-ses-supports-smime-signing
- Published: 2026-09-03 16:00:00
- Fetched: 2026-09-04 07:12:38
Amazon Simple Email Service (SES) now supports Secure/Multipurpose Internet Mail Extensions (S/MIME) signing, giving you a way to help recipients verify your emails are authentic. An S/MIME signature lets recipients confirm that a message was sent by the holder of the From address and that its content was not altered in transit.
Previously, senders who needed S/MIME had to sign each message themselves before submitting it to SES, adding complexity to their sending. With this feature, you store your signing certificate in AWS Certificate Manager and enable S/MIME signing for your sender identity. SES then signs your messages automatically as you send, so you don't have to sign messages yourself beforehand. Recipients whose email clients don't support S/MIME can still read the message normally. This gives security-conscious senders a simple way to add digital signatures to their email while continuing to use their existing SES setup.
This feature is available in all AWS Regions where Amazon SES is available. To learn more about S/MIME signing in Amazon SES, visit the Amazon SES console or refer to the documentation.
Amazon Linux 2027 is now available in public preview
- Link: https://aws.amazon.com/about-aws/whats-new/2026/09/announcing-amazon-linux-2027/
- Published: 2026-09-03 17:00:00
- Fetched: 2026-09-04 04:36:40
Today, AWS announces the public preview of Amazon Linux 2027 (AL2027), the next version of the Amazon Linux operating system, purpose-built for cloud-native workloads on AWS with performance, scale, and security in mind. Built on AL2023's baseline, AL2027 is designed for customers running web applications, databases, containerized microservices, AI/ML workloads, and large-scale infrastructure who need a secure, stable, and AWS-native operating system.
AL2027 runs on kernel 7.1+, enables SELinux in enforcing mode as default, accelerates cryptographic performance with AWS-LC, and keeps builders current with the latest toolchains and language runtimes. For AI and machine learning workloads, it delivers access to accelerator drivers, including AWS Neuron driver support. The public preview gives customers hands-on access before general availability (GA) to experiment with new features, validate their applications, and provide direct feedback to the Amazon Linux team.
AL2027 Preview AMIs are available through the AWS Management Console across all commercial AWS Regions, with both x86-64 and ARM variants. Container base images are available on Amazon ECR Public Gallery. Customers can submit feedback through the AL2027 GitHub repository. For a full list of changes relative to AL2023, see the AL2027 documentation. To learn more, visit the Amazon Linux product page.
AWS Japan Blog
「どう動く」「どう使う」が理解できる Aurora DSQL 事例セミナー開催
- Link: https://aws.amazon.com/jp/blogs/news/dsql_day_tokyo_2026/
- Published: 2026-09-03 11:54:53
- Fetched: 2026-09-03 16:42:41
AWS ウィークリー総まとめ: DuckLabs のチームへようこそ、エージェント・リソース・ディスカバリー (ARD) など (2026 年 8 月 31 日)
- Link: https://aws.amazon.com/jp/blogs/news/aws-weekly-roundup-welcome-ducklabs-to-the-team-agentic-resource-discovery-ard-and-more-august-31-2026/
- Published: 2026-09-03 17:36:21
- Fetched: 2026-09-03 21:32:08
AWS Graviton5 プロセッサを搭載した Amazon EC2 の R9g インスタンスと R9gd インスタンスが一般公開されました
- Link: https://aws.amazon.com/jp/blogs/news/amazon-ec2-r9g-and-r9gd-instances-powered-by-aws-graviton5-processors-are-now-generally-available/
- Published: 2026-09-03 18:15:06
- Fetched: 2026-09-03 21:32:08
AWS Security Blog
Agentic security: Detection and response at machine speed
- Link: https://aws.amazon.com/blogs/security/agentic-security-detection-and-response-at-machine-speed/
- Published: 2026-09-03 03:36:37
- Fetched: 2026-09-03 06:32:42
Managing identity source transition for AWS IAM Identity Center
- Link: https://aws.amazon.com/blogs/security/managing-identity-source-transition-for-aws-iam-identity-center/
- Published: 2026-09-03 05:36:31
- Fetched: 2026-09-03 06:32:42
AWS Security Bulletins
CVE-2026-84851- Uncontrolled recursion in the Ion reader in Amazon Ion-C before 1.1.6
- Link: https://aws.amazon.com/security/security-bulletins/rss/2026-094-aws/
- Published: 2026-09-03 05:32:01
- Fetched: 2026-09-03 06:32:42
Bulletin ID: 2026-094-AWS
Scope: AWS
Content Type: Important (requires attention)
Publication Date: 09/02/2026 13:30 AM PDT
Description:
Amazon Ion-C (ion-c) is the C implementation of the Amazon Ion data serialization format. It is distributed as an open-source library (amazon-ion/ion-c) that applications embed to read and write Ion text and binary data. We identified CVE-2026-84851, an uncontrolled recursion issue in versions before 1.1.6 that might allow a remote unauthenticated actor to craft Ion data that exhausts the native call stack and crashes the application using the library, resulting in a denial of service.
Impacted versions: < 1.1.6
Please refer to the article below for the most up-to-date and complete information related to this AWS Security Bulletin.
AWS Machine Learning Blog
Trinity: Agentic AI-powered transition planning for students with disabilities
- Link: https://aws.amazon.com/blogs/machine-learning/trinity-agentic-ai-powered-transition-planning-for-students-with-disabilities/
- Published: 2026-09-03 03:14:17
- Fetched: 2026-09-03 03:24:49
From code to diagrams: Agentic architecture documentation with Amazon Bedrock AgentCore
- Link: https://aws.amazon.com/blogs/machine-learning/from-code-to-diagrams-agentic-architecture-documentation-with-amazon-bedrock-agentcore/
- Published: 2026-09-03 03:18:47
- Fetched: 2026-09-03 03:24:49
How an AWS team detects dashboard content failures at scale using Amazon Bedrock
- Link: https://aws.amazon.com/blogs/machine-learning/how-an-aws-team-detects-dashboard-content-failures-at-scale-using-amazon-bedrock/
- Published: 2026-09-03 03:21:20
- Fetched: 2026-09-03 03:24:49
Modernizing and scaling support operations with generative AI on AWS
- Link: https://aws.amazon.com/blogs/machine-learning/modernizing-and-scaling-support-operations-with-generative-ai-on-aws/
- Published: 2026-09-03 03:26:35
- Fetched: 2026-09-03 06:32:43
Accessing OpenAI models on Amazon Bedrock from Australia with global cross-Region inference
- Link: https://aws.amazon.com/blogs/machine-learning/accessing-openai-gpt-5-6-models-on-amazon-bedrock-from-australia-with-global-cross-region-inference/
- Published: 2026-09-03 06:22:05
- Fetched: 2026-09-03 06:32:43