AWS News - 2026-09-04
2026-09-04
最終更新: 2026-09-05 06:11:39 JST
AI による概要
この日はデータベースのレプリケーション強化と、インシデント対応・脆弱性というセキュリティの実務、そして Graviton5 世代のリージョン拡大が目立ちました。Aurora MySQL に 2 つのレプリケーション機能が加わり、1 つのクラスターが複数のソースからレプリケーションを受けられるマルチソースレプリケーションと、意図的に遅延させて反映する遅延レプリケーションが使えるようになりました。誤操作からの復旧やデータ統合の幅が広がります。あわせて Aurora MySQL 8.4.8 (MySQL 8.4.8 互換) が一般提供となり、Redshift では Graviton ベースの rg.large インスタンスがシングルノードクラスターに対応しました (P204 以降のパッチバージョン)。インスタンスのリージョン展開はこの日だけで 5 件あり、Graviton5 の M9g / M9gd がアイルランドとシンガポール・シドニー・東京へ、C9g / C9gd が東京へ、C8g が台北・ニュージーランド・GovCloud (US-East) へ広がり、NVIDIA Blackwell Ultra を積む P6-B300 がジャカルタ、P6-B200 がハイデラバードで利用可能になりました。セキュリティブログでは CloudTrail を使ったインシデント調査のガイドが前後編で公開され、クロスアカウントでの S3 データ削除とランサムウェアの懸念、暗号通貨マイニングの展開という 2 つのシナリオを題材に、どのフィールドが重要でどう解釈するかが整理されています。セキュリティ速報は 2 件で、再利用可能なプロジェクトテンプレートである Amazon CodeCatalyst blueprints SDK の OS コマンドインジェクション (CVE-2026-85012)、AWS FPGA 開発キットで安全でない権限のディレクトリに一時ファイルを作成する問題 (CVE-2026-85028) が、いずれも Important として公開されました。エージェント関連の記事も厚く、ノートブックで動くエージェントは本番のエージェントではないとして、LangGraph のカスタマーサポートエージェントを Runtime と Gateway へ載せる 2 段階で AgentCore へ移行する手順や、AI-DLC を採用したチームが概念を動くコードへ落とし込めない課題に対する AgentCore 上の 2 つのリファレンス実装が紹介されています。Amazon Quick まわりでは、Quick Automate による本番品質のエージェント型業務自動化のベストプラクティス、Outlook との連携によるメール管理・カレンダー調整の自動化、Cognito 認証を使った QuickSight ビジュアルの React アプリへの埋め込みが公開され、利用量の多いユーザー向けに Plus の 5 倍の利用量とストレージを持つ Quick Max プランが登場しました。このほか MWAA がマネジメントコンソールに組み込みのモニタリングを追加、SageMaker Unified Studio Workflows が PythonOperator と BashOperator に対応、SageMaker AI の Batch Transform が G6e インスタンスに対応、ECS のマネージドデーモンを非クリティカルとして構成できるようになり、Transfer Family の SFTP コネクタが認証情報のローテーション中もファイル転送を継続できるようになりました。国内では、20 週間の実装で RTO を 30 分超からほぼ瞬時まで縮めた NatWest のアクティブ-アクティブなマルチリージョンコンタクトセンター、ICD-705 準拠の SCIF 要件を満たし TS/SCI レベルを扱える AWS Modular Data Center の発注から設置までの 6 ステージ、agentic CX designer で会話とビジネスルールを 1 つのキャンバスに載せる方法、Amazon EVS 上の VMware ワークロードの災害復旧、8 月 4 日に開催された製薬企業向け Claude Code on AWS ワークショップの報告が公開されています。
主要トピック
データベース: Aurora MySQL がマルチソースレプリケーションと遅延レプリケーションに対応、8.4.8 も GA
インスタンス: Graviton5 の M9g / M9gd・C9g / C9gd、C8g、P6-B300 / P6-B200 が計 5 件のリージョン拡大 (東京を含む)
インシデント対応: CloudTrail 調査ガイドを前後編で公開 (S3 のクロスアカウント削除とランサムウェア、暗号通貨マイニング)
脆弱性: CodeCatalyst blueprints SDK に OS コマンドインジェクション (CVE-2026-85012)
脆弱性: AWS FPGA 開発キットが安全でない権限のディレクトリに一時ファイルを作成 (CVE-2026-85028)
エージェント移行: LangGraph のサポートエージェントを Runtime と Gateway の 2 段階で AgentCore へ移行する手順
業務自動化: Quick Automate のベストプラクティスと Outlook 連携、Plus の 5 倍を使える Quick Max プラン
コンテナ: ECS のマネージドデーモンを非クリティカルとして構成し、基幹アプリへの影響を回避
ネットワーク: Gateway Load Balancer が TCP Reset の送信に対応し、障害時の復旧を高速化
国内事例: NatWest が 20 週間でアクティブ-アクティブ化し RTO を 30 分超からほぼ瞬時へ短縮
国内: TS/SCI を扱える AWS Modular Data Center の展開手順、製薬企業向け Claude Code on AWS ワークショップの報告
AWS What's New
Amazon MWAA adds built-in monitoring with Amazon CloudWatch
- Link: https://aws.amazon.com/about-aws/whats-new/2026/09/amazon-mwaa-cloudwatch-monitoring/
- Published: 2026-09-04 00:00:00
- Fetched: 2026-09-04 04:36:40
Amazon Managed Workflows for Apache Airflow (MWAA) now includes a built-in monitoring experience on the environment detail page in the AWS Management Console. A new metrics dashboard displays key Amazon CloudWatch metrics for your environment in one place, and each graph includes an optional toggle to overlay suggested warning ranges, helping you quickly identify conditions that may affect your environment's health and performance.
The environment detail page also now shows an alarms table that lists all Amazon CloudWatch alarms associated with your MWAA environment. You can use the one-click Create Recommended Alarms action to provision a curated set of alarms from an AWS-managed template, so you can start monitoring critical metrics without having to configure each alarm manually. This feature is available for Amazon MWAA Provisioned environments in all regions where Amazon MWAA is available. Standard Amazon CloudWatch pricing applies for metric queries and alarms.
To get started, open the AWS Management Console, review the Amazon MWAA supported regions, or visit the Amazon MWAA documentation to learn more.
Amazon SageMaker Unified Studio Workflows support Python and Bash operators
- Link: https://aws.amazon.com/about-aws/whats-new/2026/09/sagemaker-workflows-python-bash/
- Published: 2026-09-04 00:00:00
- Fetched: 2026-09-04 07:12:38
Amazon SageMaker Unified Studio Workflows now supports PythonOperator and BashOperator, enabling you to run custom Python functions and shell commands directly in your serverless workflows without provisioning separate compute resources. This eliminates the need to offload custom logic to Lambda or ECS for tasks like data transformations or shell script execution.
To get started, open a serverless visual workflow in your SageMaker Unified Studio project, search for PythonOperator or BashOperator in the task panel, and drag the node onto your canvas. Provide your Python or shell script files through the workflow settings, then point each operator to the function or command in your scripts. For example, configure PythonOperator to call a data transformation function or set BashOperator to run a shell command, all without leaving the visual canvas.
This feature is available in all AWS Regions where Amazon SageMaker Unified Studio is available. For more information, see Supported Regions for Amazon SageMaker Unified Studio.
To learn more, see Supported operators for Amazon MWAA Serverless workflows. To get started, see Serverless visual workflows in the Amazon SageMaker Unified Studio User Guide.
Amazon Aurora MySQL now supports multi-source replication and delayed replication
- Link: https://aws.amazon.com/about-aws/whats-new/2026/09/amazon-aurora-mysql-multisourcerep-delayedrep/
- Published: 2026-09-04 01:00:00
- Fetched: 2026-09-04 07:12:38
詳細を表示
Starting today, Amazon Aurora MySQL supports two new replication capabilities: multi-source replication and delayed replication. Multi-source replication lets a single Aurora MySQL cluster replicate from multiple source databases at the same time, making it easier to consolidate data from separate MySQL databases. This enables critical use-cases, such as merging shards or aggregating data from separate databases (e.g. regional or departmental instances) into a central location for operational workflows, such as reporting and backups. To learn more, please refer to the MySQL multi-source replication documentation.
Delayed replication lets you configure a binlog replica to intentionally lag behind its source by a set period of time, giving you a simple safeguard against human error and logical data corruption. If a harmful change is made on the source, you can recover quickly by stopping replication to the replica before the change is applied and promoting it, without performing a full database restore. A delayed replica also provides a convenient fallback during upgrades and a way to inspect an earlier state of your data. To learn more, please refer to the MySQL delayed replication documentation.
Together, these capabilities give you greater flexibility and stronger data protection when replicating into Aurora MySQL. Multi-source replication and Delayed replication are supported on Aurora MySQL version 8.4.8 and higher, in all AWS Regions where Aurora MySQL is available. For additional information on Aurora MySQL disaster recovery, see the guidance from our solutions library. To learn more, please refer to Aurora MySQL 8.4 release notes.
Amazon Aurora is designed for high performance and availability at global scale with full MySQL compatibility. It provides scale-to-zero serverless compute, Aurora Global Database for multi-Region resilience, Aurora I/O-Optimized for improved price performance on I/O-intensive workloads, and built-in security and continuous backups. To get started, take a look at Aurora’s getting started page.
Amazon Aurora MySQL 8.4.8 (compatible with MySQL 8.4.8) is now generally available
- Link: https://aws.amazon.com/about-aws/whats-new/2026/09/amazon-aurora-mysql-848-available/
- Published: 2026-09-04 01:01:00
- Fetched: 2026-09-04 07:12:38
詳細を表示
Starting today, Amazon Aurora MySQL-Compatible Edition 8.4 will support MySQL 8.4.8. In addition to several security enhancements and bug fixes, Aurora MySQL 8.4.8 includes several improvements, such as support for post-quantum TLS (PQ-TLS) key exchange, transaction timeout, multi-source replication, and delayed replication. PQ-TLS provides you with post-quantum cryptography options for encrypting your data in-transit. Transaction timeout helps prevent performance issues caused by long-running transactions blocking innoDB purge.
Multi-source replication allows consolidation of data from multiple sources into a single replica to enable critical use-cases, such as merging shards, reporting, and backups. Delayed replication lets you set a configurable replication lag to protect against accidental data loss. To learn more about these replication features, please refer to the launch announcement. For more details, refer to the Aurora MySQL 8.4 and MySQL 8.4.8 release notes.
You can upgrade your databases during scheduled maintenance windows using automatic minor version upgrades. To simplify operations at scale, enable automatic minor version upgrades and use the AWS Organizations Upgrade Rollout Policy to orchestrate upgrades across your clusters in phases. You can perform minor version upgrades in-place or via snapshot restore. This release is supported in all AWS Regions where Aurora MySQL is available.
Amazon Aurora is designed for high performance and availability at global scale with full MySQL compatibility. It provides scale-to-zero serverless compute, Aurora Global Database for multi-Region resilience, Aurora I/O-Optimized for improved price performance on I/O-intensive workloads, and built-in security and continuous backups. To get started, take a look at Aurora’s getting started page.
Amazon Redshift rg.large instances now support single-node clusters
- Link: https://aws.amazon.com/about-aws/whats-new/2026/09/redshift-rg-large-single-node
- Published: 2026-09-04 01:03:00
- Fetched: 2026-09-04 07:12:38
Amazon Redshift rg.large instances, powered by AWS Graviton processors, now support single-node clusters. Single-node support for rg.large clusters is available on P204 or later patch versions. Customers can now create a single-node rg.large cluster for smaller workloads that do not require high availability, offering a cost-effective option to conduct proofs of concept and tests quickly.
RG instances deliver up to 2.4x faster performance running data warehouse and data lake workloads when compared to previous generation RA3 instances, at 30% lower price per vCPU. RG instances include Redshift's custom-built vectorized data lake query engine that processes Apache Iceberg and Parquet data on your cluster nodes, turning on SQL analytics across your data warehouse and data lake using a single engine.
These RG instances are available in the following AWS Regions: Africa (Cape Town), Asia Pacific (Hong Kong), Asia Pacific (Tokyo), Asia Pacific (Seoul), Asia Pacific (Osaka), Asia Pacific (Mumbai), Asia Pacific (Hyderabad), Asia Pacific (Singapore), Asia Pacific (Sydney), Asia Pacific (Jakarta), Asia Pacific (Melbourne), Asia Pacific (Malaysia), Asia Pacific (Taipei), Asia Pacific (Thailand), Canada (Central), Europe (Frankfurt), Europe (Stockholm), Europe (Spain), Europe (Ireland), Europe (London), Europe (Paris), South America (São Paulo), US East (N. Virginia), US East (Ohio), US West (N. California), US West (Oregon), AWS GovCloud (US-East), AWS GovCloud (US-West) and Mexico (Central).
To learn more, visit the Amazon Redshift RG Instance Documentation, the RA3 to RG Upgrade Guide, and the Amazon Redshift pricing page.
Amazon WorkSpaces Applications adds support for NVIDIA Blackwell GPU instances
- Link: https://aws.amazon.com/about-aws/whats-new/2026/09/amazon-workspaces-applications-nvidia-blackwell-gpu-instances/
- Published: 2026-09-04 02:00:00
- Fetched: 2026-09-04 04:36:40
Amazon WorkSpaces Applications now supports Graphics G7 instances, powered by NVIDIA RTX PRO 4500 Blackwell Server Edition GPUs and Intel Xeon Scalable (6th Gen) processors. G7 instances deliver up to 2.1× better performance for graphics-intensive workloads compared to previous generation G6 instances.
With Graphics G7, customers can stream demanding professional applications such as CAD/CAM, 3D rendering, scientific visualization, video editing, and AI-assisted design workflows at higher fidelity and frame rates. G7 instances feature 32 GB of GDDR7 GPU memory per GPU and 2.67× faster memory bandwidth, enabling streaming of larger, more complex 3D scenes and models. Six instance sizes are available, with 1 to 8 GPUs, vCPUs ranging from 8 to 192, and system memory from 32 GB to 768 GB.
Graphics G7 instances are available in US East (N. Virginia), US East (Ohio), and US West (Oregon). Additional regions will be added as availability expands.
To get started, select a Graphics G7 instance when launching an image builder or creating a new fleet in the Amazon WorkSpaces Applications console. For more information on available instance types, see WorkSpaces Applications Instance Families. To learn more about G7 GPU capabilities, visit the EC2 G7 Instance Types page. For pricing details, see Amazon WorkSpaces Applications Pricing.
AWS Gateway Load Balancer now supports TCP Reset for faster failure recovery
- Link: https://aws.amazon.com/about-aws/whats-new/2026/09/aws-gateway-load-balancer-tcp-reset/
- Published: 2026-09-04 02:00:00
- Fetched: 2026-09-04 07:12:38
AWS Gateway Load Balancer (GWLB) now supports sending TCP Reset (RST) packets when a target becomes unhealthy, is deregistered, or when a flow's idle timeout expires. This feature helps reduce traffic interruptions from minutes to seconds by enabling TCP endpoints to quickly detect failed connections and establish new TCP flows through healthy targets.
Previously, when a GWLB target failed, existing TCP connections would continue to be forwarded to the unhealthy target (aka fail-open behavior). Client and server applications could experience interruptions lasting several minutes due to TCP retry and exponential back-off mechanisms built in the TCP stacks of clients or servers. When this capability is enabled, GWLB sends TCP Resets in response to the incoming traffic, indicating to the sender that a TCP connection is no longer viable. This allows TCP endpoints to recover in quickly.
TCP Reset is not enabled by default to ensure backward compatibility. You can enable it per target group using the AWS Management Console, AWS CLI, or API. Three triggers are supported independently for generating TCP Reset: target becomes unhealthy, target deregistration (after connection draining), and TCP idle timeout expiry.
This feature is available for all new and existing Gateway Load Balancers in all AWS Regions where GWLB is available. There is no additional charge for using this feature.
To learn more, visit this AWS blog, and GWLB User Guide here and here.
Introducing Amazon Quick Max: 5x the usage for power users who want the most out of Quick
- Link: https://aws.amazon.com/about-aws/whats-new/2026/09/amazon-quick-max-5x-usage-power-users/
- Published: 2026-09-04 02:17:00
- Fetched: 2026-09-04 04:36:40
Amazon Quick now offers Quick Max, a new plan for power users who want to get the absolute most out of Quick. With 5x the usage and 5x the storage of Plus, Max gives you the room to do more: more agents, more workflows, more of whatever makes Quick yours.
With Max, you can run large, concurrent workloads without interruption—all month long. It delivers more value per dollar the more you use it and is available with both monthly and annual billing options.
New to Amazon Quick? You can sign up for free in minutes. Already on Plus? Click your name at the bottom of the left navigation bar, then select "Upgrade plan" to switch to Max. To compare all available plans—Free, Plus, and Max—visit the Amazon Quick pricing page.
Amazon CloudFront announces API support for flat-rate pricing plans
- Link: https://aws.amazon.com/about-aws/whats-new/2026/09/cloudfront-flat-rate-pricing-plans-api/
- Published: 2026-09-04 03:00:00
- Fetched: 2026-09-04 04:36:40
Starting today, customers can subscribe and manage flat-rate pricing plans programmatically using the AWS CLI, AWS SDKs, CloudFormation, CDK, or the PricingPlanManager API.
CloudFront flat-rate plans give you one monthly price covering global content delivery, WAF, DDoS, DNS, logging, and edge compute, with no usage-based overage charges regardless of traffic spikes or attacks. Previously, customers could only subscribe to flat-rate pricing plans using the console, which required manual steps when using the API or infrastructure as code (IaC) like CloudFormation to create and manage distributions. Now, customers can programmatically subscribe, upgrade, downgrade, and cancel flat-rate pricing plans using the API or IaC tools.
Paid plans support an optional two-phase activation flow: you first create the plan, then approve it to begin billing. This prevents you from being committed to charges before you confirm, and makes the API well-suited for automated workflows and agents that provision infrastructure on your behalf. Free plans activate immediately and don’t require approval. To learn more, refer to the Getting started with the PricingPlanManager API. There are no additional fees for using the API to manage flat-rate pricing plans.
Amazon EC2 P6-B300 instances are now available in the AWS Asia Pacific (Jakarta) Region
- Link: https://aws.amazon.com/about-aws/whats-new/2026/09/amazon-ec2-p6-b300-instances-available-asia-pacific-jakarta
- Published: 2026-09-04 04:03:00
- Fetched: 2026-09-04 14:25:18
Starting today, Amazon Elastic Cloud Compute (Amazon EC2) P6-B300 instances are available in the AWS Asia Pacific (Jakarta) Region. P6-B300 instances provide 8xNVIDIA Blackwell Ultra GPUs with 2.1 TB high bandwidth GPU memory, 6.4 Tbps EFA networking, 300 Gbps dedicated ENA throughput, and 4 TB of system memory.
P6-B300 instances deliver 2x networking bandwidth, 1.5x GPU memory size, and 1.5x GPU TFLOPS (at FP4, without sparsity) compared to P6-B200 instances, making them well suited to train and deploy large trillion-parameter foundation models (FMs) including large language models (LLMs) with sophisticated techniques. The higher networking and larger memory deliver faster training times and more token throughput for AI workloads.
P6-B300 instances are now available in p6-b300.48xlarge size in the following AWS Regions: US West (Oregon), AWS GovCloud (US-East), US East (N. Virginia), Asia Pacific (Hyderabad, Jakarta, Seoul), and South America (Sao Paulo) Regions. To learn more about P6-B300 instances, visit Amazon EC2 P6 instances.
Amazon EC2 P6-B200 instances are now available in the AWS Asia Pacific (Hyderabad) Region
- Link: https://aws.amazon.com/about-aws/whats-new/2026/09/amazon-ec2-p6-b200-instances-available-asia-pacific-hyderabad
- Published: 2026-09-04 04:14:00
- Fetched: 2026-09-04 14:25:18
Starting today, Amazon Elastic Compute Cloud (Amazon EC2) P6-B200 instances accelerated by NVIDIA Blackwell GPUs are available in the AWS Asia Pacific (Hyderabad) Region. These instances offer up to 2x performance compared to P5en instances for AI training and inference.
P6-B200 instances feature 8 Blackwell GPUs with 1440 GB of high-bandwidth GPU memory and a 60% increase in GPU memory bandwidth compared to P5en, 5th Generation Intel Xeon processors (Emerald Rapids), and up to 3.2 terabits per second of Elastic Fabric Adapter (EFAv4) networking. P6-B200 instances are powered by the AWS Nitro System, so you can reliably and securely scale AI workloads within Amazon EC2 UltraClusters to tens of thousands of GPUs.
P6-B200 instances are now available in p6-b200.48xlarge size in the following AWS Regions: US West (Oregon), US East (N. Virginia, Ohio), AWS GovCloud (US-West, US-East), and Asia Pacific (Hyderabad, Mumbai) Regions. To learn more about P6-B200 instances, visit Amazon EC2 P6 instances.
Amazon EC2 M9g and M9gd instances are now available in four additional regions
- Link: https://aws.amazon.com/about-aws/whats-new/2026/09/ec2-m9g-m9gd-four-regions/
- Published: 2026-09-04 06:00:00
- Fetched: 2026-09-05 03:01:53
Starting today, Amazon Elastic Compute Cloud (Amazon EC2) M9g and M9gd instances, powered by AWS Graviton5 processors, are available in Europe (Ireland) and Asia Pacific (Singapore, Sydney, Tokyo) regions. AWS Graviton5 processors are the fifth generation of custom-designed CPUs, delivering the best price performance for memory-intensive workloads running on Amazon EC2.
M9g and M9gd instances deliver up to 25% better performance compared to AWS Graviton4-based M8g and M8gd instances. They are up to 30% faster for databases. These instances are built on the sixth-generation AWS Nitro System and are the first to feature the Nitro Isolation Engine, harnessing formal verification to provide mathematical assurance that customer workloads are isolated from each other and AWS operators, pioneering a new standard for mathematically proven cloud security.
M9g instances are ideal for workloads such as open-source databases, in-memory caches, big data analytics, and memory-intensive applications. M9gd instances offer local NVMe-based SSD block-level storage for customers running memory-intensive workloads that also require high-speed, low-latency local storage for scratch space, temporary files, and caches.
M9g and M9gd instances are available for purchase in these four regions via Savings Plans, On-Demand, Spot instances, Dedicated instances, or Dedicated hosts. Level up your compute with AWS Graviton and get started today.
Amazon ECS Managed Daemons now support non-critical daemons
- Link: https://aws.amazon.com/about-aws/whats-new/2026/09/ecs-managed-daemons-non-critical/
- Published: 2026-09-04 07:01:00
- Fetched: 2026-09-04 09:41:43
Amazon Elastic Container Service (Amazon ECS) now support non-critical Managed Daemons for ECS Managed Instances. You can configure a daemon as non-critical so that your mission-critical application tasks continue running uninterrupted, even when a daemon fails, stops, or becomes unhealthy.
Amazon ECS Managed Daemons lets you centrally deploy and manage software agents independently of application deployments to ensure consistent coverage and compliance across your container infrastructure. For some mission-critical applications, uninterrupted execution of application tasks may matter more than auxiliary daemon functionality like logging or metrics collection. With this launch, you can now configure a managed daemon as non-critical so that its failure does not cause your application tasks to churn. When a non-critical daemon task fails, stops, or becomes unhealthy, the container instance remains active, your existing application tasks continue running uninterrupted, ECS continues placing new application tasks on it, and instance registration is never blocked, so your tasks launch immediately even when the daemon fails to start. Amazon ECS emits an EventBridge event when a daemon task fails to start and records service action logs for both critical and non-critical daemons, giving you full observability into daemon health.
To get started, you can use AWS Console, CLI, CloudFormation, or AWS SDKs to create a non-critical daemon by setting the critical parameter to false when creating or updating a daemon. Non-critical daemons are available in all AWS Regions where Amazon ECS Managed Daemons are supported. To learn more, refer to our documentation page.
Amazon EC2 C9g and C9gd instances are now available in Asia Pacific (Tokyo) region
- Link: https://aws.amazon.com/about-aws/whats-new/2026/09/ec2-c9g-c9gd-asia-pacific-tokyo/
- Published: 2026-09-04 08:00:00
- Fetched: 2026-09-05 03:01:53
詳細を表示
Starting today, Amazon Elastic Compute Cloud (Amazon EC2) C9g and C9gd instances, powered by AWS Graviton5 processors, are available in the Asia Pacific (Tokyo) region. AWS Graviton5 processors are the fifth generation of custom-designed CPUs, delivering the best price performance for compute-intensive workloads running on Amazon EC2.
C9g and C9gd instances deliver up to 25% better compute performance compared to AWS Graviton4-based C8g and C8gd instances. They are up to 30% faster for databases, up to 35% faster for web applications, and up to 35% faster for machine learning. These instances are built on the sixth-generation AWS Nitro System and are the first to feature the Nitro Isolation Engine, harnessing formal verification to provide mathematical assurance that customer workloads are isolated from each other and AWS operators, pioneering a new standard for mathematically proven cloud security.
C9g instances are ideal for workloads such as high-performance computing (HPC), batch processing, gaming, video encoding, scientific modeling, distributed analytics, CPU-based machine learning (ML) inference, real time analytics, and ad serving. C9gd instances offer local NVMe-based SSD block-level storage for customers running compute-intensive workloads that also require high-speed, low-latency local storage for scratch space, temporary files, and caches.
C9g and C9gd instances are available for purchase in Asia Pacific (Tokyo) via Savings Plans, On-Demand, Spot instances, Dedicated instances, or Dedicated hosts. Level up your compute with AWS Graviton and get started today.
AWS Transfer Family SFTP Connectors now support continuing file transfers during credential rotation
- Link: https://aws.amazon.com/about-aws/whats-new/2026/09/transfer-family-sftp-credential-rotation/
- Published: 2026-09-04 17:00:00
- Fetched: 2026-09-05 03:01:53
AWS Transfer Family SFTP Connectors now continue running file transfers while you rotate the credentials used to authenticate with remote SFTP servers. You no longer need to update the connector to point to a new secret version each time a credential rotates, removing a manual step and helping avoid failed transfers during the rotation window.
Connectors can now retrieve credentials from an ordered list of AWS Secrets Manager version stages, such as the current and previous versions, during authentication. The connector automatically tries each version in the order you specify and proceeds with the first that succeeds, so transfers continue uninterrupted as credentials are rotated on either side. You configure this when you create or update a connector, and the connector's credentials must be stored in AWS Secrets Manager.
Support for continuing transfers during credential rotation is available in all AWS Regions where AWS Transfer Family SFTP Connectors are supported. To learn more, visit the AWS Transfer Family User Guide. Get started with AWS Transfer Family in the AWS Transfer Family console.
Amazon SageMaker AI Batch Transform now supports G6e instances
- Link: https://aws.amazon.com/about-aws/whats-new/2026/09/sagemaker-batch-transform-g6e-instances/
- Published: 2026-09-04 17:00:00
- Fetched: 2026-09-05 06:11:39
Amazon SageMaker AI now supports Amazon EC2 G6e instances for batch transform. Batch Transform enables you to run predictions on datasets stored in Amazon S3 and is suited for large datasets that do not require a persistent inference endpoint.
Amazon EC2 G6e instances are powered by up to eight NVIDIA L40S Tensor Core GPUs with 48 GB of memory per GPU and third-generation AMD EPYC processors. G6e instances deliver improved performance for GPU-intensive workloads. With this launch, you can use G6e instances for GPU-intensive offline inference workloads, including large language models and diffusion models that generate images, video, and audio. To get started, select a supported ml.g6e instance type when creating a Batch Transform job through AWS SDKs, AWS CLI, or the CreateTransformJob API.
G6e support for Batch Transform is available in US East (N. Virginia), US East (Ohio), US West (Oregon), Asia Pacific (Mumbai), and Asia Pacific (Hyderabad). To learn more, visit the Amazon SageMaker AI product page and see the Batch Transform documentation. For pricing information on these instances, please visit our pricing page.
Amazon EC2 C8g instances now available in additional regions
- Link: https://aws.amazon.com/about-aws/whats-new/2026/09/amazon-ec2-c8g-instances-additional-regions/
- Published: 2026-09-04 23:06:00
- Fetched: 2026-09-05 03:01:53
Starting today, Amazon Elastic Compute Cloud (Amazon EC2) C8g instances are available in AWS Asia Pacific (Taipei, New Zealand), and AWS GovCloud (US-East) regions. These instances are powered by AWS Graviton4 processors and deliver up to 30% better performance compared to AWS Graviton3-based instances. Amazon EC2 C8g instances are built for compute-intensive workloads, such as high performance computing (HPC), batch processing, gaming, video encoding, scientific modeling, distributed analytics, CPU-based machine learning (ML) inference, and ad serving. These instances are built on the AWS Nitro System, which offloads CPU virtualization, storage, and networking functions to dedicated hardware and software to enhance the performance and security of your workloads.
AWS Graviton4-based Amazon EC2 instances deliver the best performance and energy efficiency for a broad range of workloads running on Amazon EC2. These instances offer larger instance sizes with up to 3x more vCPUs and memory compared to Graviton3-based Amazon C7g instances. AWS Graviton4 processors are up to 40% faster for databases, 30% faster for web applications, and 45% faster for large Java applications than AWS Graviton3 processors. C8g instances are available in 12 different instance sizes, including two bare metal sizes. They offer up to 50 Gbps enhanced networking bandwidth and up to 40 Gbps of bandwidth to the Amazon Elastic Block Store (Amazon EBS).
To learn more, see Amazon EC2 C8g Instances. To explore how to migrate your workloads to Graviton-based instances, see AWS Graviton Fast Start program and Porting Advisor for Graviton. To get started, see the AWS Management Console.
AWS Japan Blog
【開催報告】AI エージェントは創薬研究をどう変えるか: 製薬企業向け Claude Code on AWS ワークショップ
- Link: https://aws.amazon.com/jp/blogs/news/claude-code-for-pharma-tokyo/
- Published: 2026-09-04 09:58:42
- Fetched: 2026-09-04 14:25:19
AWS Modular Data Center のデプロイ: 発注から配送、設置まで
- Link: https://aws.amazon.com/jp/blogs/news/deploying-aws-modular-data-center-from-ordering-to-delivery-and-installation-jp/
- Published: 2026-09-04 15:55:13
- Fetched: 2026-09-04 19:29:45
構造化されたビジネスロジックとエージェンティック AI を組み合わせ、心地よい会話体験を届ける
- Link: https://aws.amazon.com/jp/blogs/news/blend-structured-business-logic-with-agentic-ai/
- Published: 2026-09-04 15:59:27
- Fetched: 2026-09-04 19:29:45
NatWest が Amazon Connect Customer で実現したマルチリージョンレジリエンス
- Link: https://aws.amazon.com/jp/blogs/news/how-natwest-built-multi-region-resilience-with-amazon-connect-customer/
- Published: 2026-09-04 16:33:09
- Fetched: 2026-09-04 19:29:45
Amazon EVS 上の VMware ワークロードの災害復旧
- Link: https://aws.amazon.com/jp/blogs/news/disaster-recovery-for-vmware-workloads-on-amazon-evs/
- Published: 2026-09-04 19:47:27
- Fetched: 2026-09-04 23:44:24
AWS Security Blog
Incident response guide for AWS CloudTrail investigations – Part 1
- Link: https://aws.amazon.com/blogs/security/incident-response-guide-for-aws-cloudtrail-investigations-part-1/
- Published: 2026-09-04 06:15:39
- Fetched: 2026-09-04 07:12:39
Incident response guide for AWS CloudTrail investigations – Part 2
- Link: https://aws.amazon.com/blogs/security/incident-response-guide-for-aws-cloudtrail-investigations-part-2/
- Published: 2026-09-04 06:15:53
- Fetched: 2026-09-04 07:12:39
AWS Security Bulletins
CVE-2026-85012 - OS command injection in the Amazon CodeCatalyst blueprints SDK
- Link: https://aws.amazon.com/security/security-bulletins/rss/2026-095-aws/
- Published: 2026-09-04 02:22:43
- Fetched: 2026-09-04 04:36:41
Bulletin ID: 2026-095-AWS
Scope: AWS
Content Type: Important (requires attention)
Publication Date: 09/03/2026 10:00 AM PDT
Description:
Amazon CodeCatalyst blueprints are reusable project templates that generate a software project. The @amazon-codecatalyst/blueprints.blueprint npm package is the open source framework that blueprint authors build on, published from github.com/aws/codecatalyst-blueprints.
We identified CVE-2026-85012 in the blueprint resynthesis framework. During resynthesis, the framework reads the .ownership-file from the existing project to determine which files a blueprint may modify. In versions before 0.3.156, the owner field of a [local] merge strategy entry in the .ownership-file was passed to an operating system command through a shell without validation. A user with permission to commit to a repository in the project could place shell metacharacters in that field and execute arbitrary commands in the environment performing resynthesis, with the privileges and credentials available to that environment.
No action is required for use of the Amazon CodeCatalyst service. Resynthesis runs in an isolated per-project environment with scoped credentials, and the service applies server-side validation there that rejects [local] merge strategy commands outside a restricted allowlisted form, including for blueprint versions published before 0.3.156.
Impacted versions: <= 0.3.155
Please refer to the article below for the most up-to-date and complete information related to this AWS Security Bulletin.
CVE-2026-85028: Creation of Temporary File in Directory with Insecure Permissions in AWS FPGA Development Kit
- Link: https://aws.amazon.com/security/security-bulletins/rss/2026-096-aws/
- Published: 2026-09-04 03:20:07
- Fetched: 2026-09-04 04:36:41
Bulletin ID: 2026-096-AWS
Scope: AWS
Content Type: Important (requires attention)
Publication Date: 09/03/2026 11:00 AM PDT
Description:
The AWS FPGA Developer Kit is a hardware-software development kit that enables developers to create accelerators for the high-performance accelerator cards on EC2 F2 instances. We identified CVE-2026-85028, where a creation of a temporary file in a directory with insecure permissions in the FPGA management tool installation component in AWS FPGA Development Kit (aws-fpga) before 2.3.4 might allow local users to execute arbitrary code with root privileges via crafted shell content placed at a predictable path in a world-writable temporary directory, which the installation step reads after elevating its own privileges.
Impacted versions: < 2.3.4
Please refer to the article below for the most up-to-date and complete information related to this AWS Security Bulletin.
AWS Machine Learning Blog
Embed Quick Sight visuals using Cognito user authentication
- Link: https://aws.amazon.com/blogs/machine-learning/embed-quick-sight-visuals-using-cognito-user-authentication/
- Published: 2026-09-04 01:01:56
- Fetched: 2026-09-04 01:53:17
Best practices for building agentic automations with Amazon Quick Automate
- Link: https://aws.amazon.com/blogs/machine-learning/best-practices-for-building-agentic-automations-with-amazon-quick-automate/
- Published: 2026-09-04 01:08:28
- Fetched: 2026-09-04 01:53:17
Set up OpenAI ChatGPT Codex with LiteLLM on Amazon ECS and Amazon Bedrock
- Link: https://aws.amazon.com/blogs/machine-learning/set-up-openai-chatgpt-codex-with-litellm-on-amazon-ecs-and-amazon-bedrock/
- Published: 2026-09-04 01:10:39
- Fetched: 2026-09-04 01:53:17
Integrating Outlook with Amazon Quick for AI-powered email automation
- Link: https://aws.amazon.com/blogs/machine-learning/integrating-outlook-with-amazon-quick-for-ai-powered-email-automation/
- Published: 2026-09-04 01:11:57
- Fetched: 2026-09-04 01:53:17
Migrate agentic workloads to Amazon Bedrock AgentCore
- Link: https://aws.amazon.com/blogs/machine-learning/migrate-agentic-workloads-to-amazon-bedrock-agentcore/
- Published: 2026-09-04 01:14:12
- Fetched: 2026-09-04 01:53:17
AI-driven development lifecycle using Amazon Bedrock AgentCore
- Link: https://aws.amazon.com/blogs/machine-learning/ai-driven-development-lifecycle-using-amazon-bedrock-agentcore/
- Published: 2026-09-04 01:16:28
- Fetched: 2026-09-04 01:53:17