AWS News - 2026-09-09

2026-09-09
最終更新: 2026-09-11 06:21:35 JST

AI による概要

32 記事

この日は 32 件と多く、OpenAI モデルの提供、Kiro の学生向け拡大、エージェント基盤の強化、そして数多くのサービス更新が並びました。OpenAI の最新モデル GPT-6 Astra が Amazon Bedrock で一般提供となり、要求の厳しいタスク向けに深い推論と的確な判断を提供します。Kiro は学生向けプログラム Kiro Students を 16 か国の新たな 121 大学へ拡大し、対象の学生は Kiro を 1 年間無料で使え、毎月 1,000 クレジットとプレミアムモデル・Kiro Web が付きます。あわせて Kiro が AWS の ISO/IEC 27001:2022 認証のスコープに含まれ、調達・セキュリティ・ベンダーリスクの各チームが第三者検証済みのエビデンスを利用できるようになりました。Bedrock AgentCore Memory は、短期メモリのイベントとして永続化せずに長期メモリ抽出用のコンテンツを直接投入できる IngestData API を追加しました。Amazon API Gateway はバックエンド統合の相互 TLS (mTLS) に対応し、TLS ハンドシェイク時に ACM 証明書をバックエンドへ提示できるようになったほか、サードパーティや AWS Private CA の独自クライアント証明書を持ち込めるようになりました。セキュリティブログでは、SANS Institute と共同執筆した 2026 Cloud Security Exchange eBook の章として、エージェントのアイデンティティとガバナンス、振る舞いの監視、段階的な自動対応、マルチエージェントエコシステムへの備えを扱う「エージェンティックセキュリティ」が公開されています。SageMaker Feature Store は UpdateRecord API による特徴量単位の書き込みに対応し、レコード全体を読み書きせずに更新できて書き込みレイテンシが下がりました。マネージド MLflow と SageMaker AI Model Registry の同期は、学習メトリクス・評価結果・推論仕様・リネージまで同期し、クロスアカウントのモデルガバナンスへ広げる 2 部構成の解説が出ています。GPU インスタンスの比較検証では、30B の MoE モデル Qwen3-Coder-30B と NVIDIA Nemotron-3-Nano-30B を G5 / G6 / G6e / G7 でベンチマークしています。セキュリティ速報は 1 件で、OpenSearch Dashboards の Vega 式関数バイパスによる格納型 XSS (CVE-2026-84942) が Important として公開されました。サービス更新では、RDS for MariaDB がコミュニティの新しいマイナーバージョン (10.6.28、10.11.19、11.4.13、11.8.9、12.3.3) に対応し、EBS Volume Clones がアカウントをまたいだボリュームのコピーと再暗号化に対応、AWS Transform が GovCloud (US-West) で利用可能に、AWS Private CA の EKS アドオンと AD 向けコネクタが GovCloud (US) で利用可能になりました。ほかに HealthOmics の WDL ワークフローでアクセラレータ種別のフォールバック順序を定義できる機能、Timestream for InfluxDB 3 の独自 Python プラグイン、Entity Resolution の ML マッチングにおけるレコード単位の信頼度スコア、Bedrock Managed Knowledge Base の Confluence Data Center コネクタ、Systems Manager がアンマネージドな EC2 の原因を 6 カテゴリー追加で診断、Connect Customer Profiles のセグメント出入りイベントなどが加わりました。AWS ジャパンのブログでは、DiDi が Bedrock 上に自前のコンタクトセンター QA を構築して意図検証の精度を 38% から 86% へ引き上げた事例、HPE Zerto が顧客環境内のオンプレミスで動くエージェント型トラブルシュートシステムを Bedrock で構築した事例、Oracle Database@AWS のオンボーディング完全ガイド、データ秘匿性を考慮した産業特化型 AI 基盤 CODAS の取り組みが公開されました。

主要トピック
  • モデル: OpenAI GPT-6 Astra が Amazon Bedrock で一般提供

  • 開発ツール: Kiro Students が 16 か国の新たな 121 大学へ拡大 (1 年間無料 / 月 1,000 クレジット)、Kiro が AWS の ISO/IEC 27001:2022 スコープに

  • エージェント: Bedrock AgentCore Memory が長期メモリへの直接投入 API (IngestData) を追加

  • API: API Gateway がバックエンド統合の mTLS に対応、ACM 証明書提示と独自クライアント証明書の持ち込みが可能に

  • セキュリティ論考: SANS Institute と共同のエージェンティックセキュリティ (アイデンティティ・監視・段階的自動対応)

  • 機械学習基盤: SageMaker Feature Store が UpdateRecord で特徴量単位の書き込みに対応、書き込みレイテンシを低減

  • ガバナンス: マネージド MLflow と SageMaker AI Model Registry の同期をクロスアカウントのモデルガバナンスへ拡張 (全 2 部)

  • 脆弱性: OpenSearch Dashboards の Vega 式関数バイパスによる格納型 XSS (CVE-2026-84942)

  • データベース: RDS for MariaDB が新マイナー (10.6.28 ほか) に対応、EBS Volume Clones がクロスアカウントのコピーと再暗号化に対応

  • 規制対応: AWS Transform が GovCloud (US-West) へ、AWS Private CA の EKS アドオンと AD コネクタが GovCloud (US) へ

  • 事例: DiDi が Bedrock で自前のコンタクトセンター QA を構築し意図検証の精度を 38%→86% に、HPE Zerto は顧客環境内で動くエージェント型トラブルシュートを構築

AI (Claude Opus 5) が生成 · 2026-09-11 07:54:56 JST

AWS What's New

Amazon RDS for MariaDB now supports community MariaDB minor versions 10.6.28, 10.11.19, 11.4.13, 11.8.9, and 12.3.3

詳細を表示

Starting today, Amazon Relational Database Service (Amazon RDS) for MariaDB now supports MariaDB minor versions 10.6.28, 10.11.19, 11.4.13, 11.8.9, and 12.3.3, the latest minors released by community MariaDB. In addition to operational improvements, these minor versions introduce support for post-quantum TLS (PQ-TLS) key exchange, providing you with post-quantum cryptography options for encrypting your data in-transit. We recommend upgrading to the newer minor versions to accept fixes for Common Vulnerabilities and Exposures (CVEs) in prior versions of MariaDB and to benefit from bug fixes, performance improvements, and new functionality added by the MariaDB community. Learn more about the enhancements in RDS for MariaDB in the RDS MariaDB release notes.

You can upgrade your database using Amazon RDS Blue/Green Deployments, in-place upgrade, or restore from a snapshot. To simplify operations at scale, enable automatic minor version upgrades and use the AWS Organizations Upgrade Rollout Policy to orchestrate upgrades across your clusters in phases. Learn more about performing version upgrades in the Amazon RDS User Guide. You can also migrate to RDS for MariaDB from external MariaDB sources using AWS Database Migration Service. Learn more about pricing details and regional availability at Amazon RDS for MariaDB

Amazon RDS for MariaDB makes it simple to set up, operate, and scale MariaDB deployments in the cloud. Create or update a fully managed Amazon RDS for MariaDB database in the Amazon RDS Management Console.

Amazon Bedrock AgentCore Memory now supports direct ingestion to long-term memory

Amazon Bedrock AgentCore Memory now lets developers submit content directly for long-term memory extraction without persisting it as a short-term memory event. The new IngestData API accepts content, fans it out to the memory's configured long-term memory strategies, and makes the resulting memory records available through the same retrieval operations used for any other long-term memory records, all without creating a short-term event.

Until now, all content had to be stored as a short-term memory event before extraction strategies could process it into long-term memory records. IngestData removes this requirement, enabling developers to adopt long-term memory independently of short-term memory.

IngestData supports both conversational payloads (messages with USER/ASSISTANT roles) and JSON payloads (behavioral events, activity logs, system events), and accepts optional metadata that feeds the same extraction pipeline as CreateEvent. After processing, developers can verify extraction results with ListMemoryRecords or RetrieveMemoryRecords, stream real-time notifications via Kinesis, and redrive failed extractions with ListMemoryExtractionJobs. To get started, see Direct ingestion to long-term memory in the Amazon Bedrock AgentCore Developer Guide. IngestData is available in all AWS Regions where Amazon Bedrock AgentCore Memory is supported.

AWS HealthOmics introduces resource fallback order for WDL workflows

Today, AWS HealthOmics introduces the resource fallback directive, enabling you to define an ordered list of preferred accelerator types, including an option to fallback to CPU instances, for tasks in your Workflow Description Language (WDL) workflows. Researchers and bioinformaticians can use this directive to reduce time spent diagnosing and resubmitting runs due to accelerator constraints and keep production workflows running. AWS HealthOmics is a HIPAA-eligible service that helps healthcare and life sciences customers accelerate scientific breakthroughs at scale with fully managed bioinformatics workflows. 

With resource fallback, you can prioritize your preferred accelerator for your task. When your preferred accelerator is unavailable, HealthOmics automatically moves through your specified alternatives in the fallback without resubmission. Each accelerator profile has a configurable timeout, giving you control over how long HealthOmics searches for that accelerator before moving to the next. Shorter timeouts help you move quickly through the fallback order, while longer timeouts increase the probability of reserving your preferred accelerator. You can also include a CPU profile as a final fallback to increase the likelihood of your task reserving an instance. 

You can now use resource fallback for WDL workflows in all AWS HealthOmics Regions: US East (N. Virginia, Ohio), US West (Oregon), Europe (Frankfurt, Ireland, London), Israel (Tel Aviv), and Asia Pacific (Seoul, Singapore, Tokyo). To learn more, visit the advanced resource configuration documentation

Amazon API Gateway now supports mutual TLS for backend integrations

You can now configure Amazon API Gateway REST APIs to present an AWS Certificate Manager (ACM) certificate to your backend during the TLS handshake, enabling mutual TLS (mTLS). Previously, API Gateway could present only a self-signed certificate that it generated; now you can use a certificate signed by a certificate authority you trust. Your integration endpoint validates this certificate during the handshake to confirm the connection comes from your API. 

You can import a certificate into ACM from your existing public key infrastructure (PKI), or have ACM issue and manage one for you through AWS Private Certificate Authority. When a certificate is reimported or renewed in ACM, API Gateway propagates the update automatically, with no redeployment and no downtime. Combined with the existing inbound mTLS support for client connections, you can apply mutual authentication across both the client-to-API and API-to-backend connections, which is a common requirement in financial services, healthcare, and other regulated or zero-trust environments.

Mutual TLS for backend integrations is available in all commercial AWS Regions and the AWS GovCloud (US) Regions, where API Gateway REST APIs are available. You can configure it through the API Gateway console, AWS CLI, or AWS CloudFormation. To get started, see Amazon API Gateway documentation and AWS blog post

AWS Transform is now available in AWS GovCloud (US-West)

AWS Transform is now available in the AWS GovCloud (US-West) Region, enabling government agencies and regulated organizations to plan and execute large-scale migrations to AWS. With this launch, customers operating in AWS GovCloud (US) can use the migration capabilities of AWS Transform to automate server migrations within an isolated environment designed to host sensitive data and regulated workloads. AWS Transform in this Region supports migrating servers to both AWS GovCloud (US-East) and AWS GovCloud (US-West) as target Regions.

Organizations migrating VMware, bare metal, Hyper-V, or database workloads can use AWS Transform to automate server replication and cutover, reducing the manual effort and risk involved in large-scale moves. This is particularly valuable for federal agencies, defense contractors, and regulated industries that must operate within the AWS GovCloud (US) boundary. Modernization, custom transformation, and assessment capabilities are not included in this regional launch and remain available in supported commercial Regions.

To get started, see the AWS Transform documentation or visit the AWS Transform product page.

Amazon SageMaker Feature Store now supports individual feature updates to lower write latency

Amazon SageMaker Feature Store is a fully managed capability that makes it easy to compute, store, and retrieve features for training and deploying AI models. SageMaker Feature Store now supports feature-level writes, a new capability for updating individual features in a record. Data scientists can now update one or more feature values in a single request, without rewriting the entire record.

Data scientists can use a single update call to replace the read-modify-write pattern their pipelines run today. Each write updates only the features in the request and leaves every other feature in the record unchanged, which lowers write latency and cost. When multiple pipelines write to the same feature group, each pipeline updates only the features it computes, so a streaming job and a nightly batch job can update the same record independently. This capability enables data scientists to update a single feature at high processing volumes, without building merge logic in their data ingestion pipelines.

This capability is now available in all AWS Regions where Amazon SageMaker Feature Store is available. For more information, see Amazon Feature Store Runtime, Standard V2 documentation and launch blog.

Amazon Timestream for InfluxDB 3 now supports custom plugins

Amazon Timestream for InfluxDB now lets you run your own custom Python plugins on the managed versions of InfluxDB 3 Core and Enterprise editions. You host your plugin code in public or private repositories you control and the engine fetches and runs it in response to triggers, letting you implement logic specific to your workload without standing up separate external infrastructure.

Plugins run on the trigger types the processing engine already supports and with them, you can build custom data transformations, alerting, aggregation, and integrations with your own services, all running close to your data. Plugins execute in a managed Python environment that includes the standard library and Amazon-vetted packages , so you can move workload-specific processing into the database instead of operating a separate pipeline to do it.

To get started, set a plugin repository on a DB parameter group, apply that parameter group to your cluster, and create triggers that reference your plugin using the influxdb3 CLI or HTTP API; private repositories are authenticated with a token stored in AWS Secrets Manager.  Custom plugins are available in all AWS Regions where Amazon Timestream for InfluxDB is available. To get started with Amazon Timestream for InfluxDB 3, visit the Amazon Timestream for InfluxDB console. For more information, see the Amazon Timestream for InfluxDB documentation and pricing page

 
 

OpenAI GPT-6 Astra is now generally available on Amazon Bedrock

Today, AWS announces the general availability of GPT-6 Astra from OpenAI on Amazon Bedrock. The latest and most capable model from OpenAI to date, GPT-6 Astra brings deeper reasoning and judgment, professional-quality writing and design, and advanced computer and browser use to demanding business workflows. It supports a context window of up to 1 million input tokens and can produce output aligned with organizational voice, templates, and standards. The Amazon Bedrock inference engine delivers the performance, security, and scale required for production workloads.

You can call GPT-6 Astra directly through supported Amazon Bedrock APIs or configure ChatGPT Work and Codex to use the model on Amazon Bedrock. Use it to build autonomous agents, analyze extensive document collections, investigate complex software issues, and create applications that require judgment across competing inputs. As part of this launch, OpenAI is also introducing new enterprise plugins for ChatGPT Work that extend Astra’s browser-use capabilities across common business applications. Established AWS controls help you secure workloads, govern access, and audit model invocation activity.

You can get started in the Amazon Bedrock console or programmatically supported Amazon Bedrock APIs. For information about supported AWS Regions, endpoints, APIs, features, inference profiles and pricing, see the Amazon Bedrock documentation. To explore what you can build with GPT-6 Astra, read the blog

AWS Systems Manager now diagnoses more issues that cause EC2 instances to be unmanaged

Today, AWS Systems Manager extends its diagnosis capability to identify six additional categories of issues that can prevent Amazon EC2 instances and hybrid-activated nodes from becoming managed by Systems Manager. An instance must be managed by Systems Manager before you can patch it, run commands, connect with Session Manager, or collect inventory, and when an instance is unmanaged the cause can be difficult to isolate. The diagnosis previously covered network connectivity, and it now also identifies issues with IAM permissions, SSM Agent version, instance status checks, operating system configuration, Default Host Management Configuration, and hybrid activation.

With this broader coverage, more of your instances return a specific, actionable cause instead of an unidentified result, so you can bring your fleet under management faster. You run a diagnosis across your instances in the Systems Manager unified console experience, and Systems Manager reports the specific issues it finds in each category. Every diagnosed issue comes with step-by-step guidance to help you resolve it, and for some issues you can also run an AWS Systems Manager Automation runbook from the console to remediate the issue directly.

AWS Systems Manager diagnosis capability is available in all AWS Regions that are enabled by default. The capability runs as AWS Systems Manager Automation runbooks, so you pay standard Automation usage charges for the runbooks you run; see AWS Systems Manager pricing for details. To learn more, see the AWS Systems Manager User Guide, or visit the AWS Systems Manager product page.

AWS Private CA EKS add-on and Connector for AD now available in AWS GovCloud (US)

AWS Private Certificate Authority (AWS Private CA) announces the availability of the AWS Private CA Connector for Kubernetes as a managed Amazon EKS add-on and the AWS Private CA Connector for Active Directory in AWS GovCloud (US-East) and AWS GovCloud (US-West) Regions. These launches expand certificate automation capabilities available to AWS GovCloud (US) customers managing government workloads.

The AWS Private CA Connector for Kubernetes EKS add-on provides simplified installation, configuration, and lifecycle management through the EKS console, CLI, and API. The connector works with cert-manager to automate certificate requests, distribution to Kubernetes secrets, and renewal, enabling TLS for ingress controllers and securing service-to-service communication in service meshes such as Istio and Linkerd.

The AWS Private CA Connector for Active Directory enables AWS GovCloud (US) customers to use AWS Private CA as their certificate authority for Active Directory-enrolled objects. The connector provides automatic certificate issuance to domain-joined users, computers, and other objects through familiar Microsoft certificate enrollment interfaces, supporting enterprise scenarios including smart card authentication, LDAPS, and network device authentication (802.1x).

AWS Private CA secures private key material using FIPS 140-3 Level 3 hardware security modules (HSMs).

To get started, see the AWS Private CA product page, the Amazon EKS add-ons user guide, and the AWS Private CA Connector for Active Directory documentation.

Amazon Connect Customer Profiles now sends events when customers enter or exit segments

Amazon Connect Customer Profiles now sends segment membership events, providing the ability to receive real-time and scheduled notifications when customer profiles enter or exit a segment, such as high-value customers or low-satisfaction customers. Previously, detecting when customer profiles joined or left a segment required exporting entire segments at regular intervals and running custom scripts to identify differences. This manual process consumed resources, introduced errors, and created multi-hour delays between a customer qualifying for a segment and downstream systems acting on it.

With segment membership events, Customer Profiles automatically evaluates and streams membership changes directly to your Amazon Kinesis Data Stream. For segments built with standard conditions, changes are detected in near real-time as profile attributes update. For enhanced segments (using Spark SQL), periodic snapshots evaluate membership at configurable intervals and notify you of changes. Each event includes the profile ID, segment name, operation type (joined or left), and whether the change detected occurred in real-time or during a scheduled run, giving you everything needed to activate outbound campaigns, personalization workflows, or retention actions within seconds instead of hours.

You can start using segment membership events in all AWS Regions where Amazon Connect Customer Profiles is available. To get started, configure an Amazon Kinesis Data Stream in your domain settings and subscribe your segments. For more information, see our admin guide. For more information about Amazon Connect Customer Profiles, visit our product page.

AWS Entity Resolution adds record-level confidence scores for ML matching

AWS Entity Resolution now provides record-level confidence scores for Machine Learning (ML) based matching workflows, giving you a per-record signal of how confident the model is in each individual identity match. Previously, all records within a match group carried the same group-level confidence score regardless of actual match quality — making it impossible to distinguish a near-certain match from a borderline one. This forced customers to apply a single confidence threshold across all records, limiting the number of resolved identities that could be activated downstream.

With record-level confidence scores, each resolved record now carries its own score reflecting actual match quality. This gives you the precision to qualify more records for activation by applying differentiated thresholds — using higher confidence for automated merges and lower thresholds to include additional records that still meet quality standards. The result is larger addressable audiences and improved lead conversions, while maintaining compliance-grade match transparency with audit-ready evidence for each resolved record. For incremental ML workflows, the existing RecordConfidenceLevel column now reflects the actual per-record score with no schema changes required.

You can start using record-level confidence scores in all AWS Regions where AWS Entity Resolution is available. For more information, see our user guide. For more information about AWS Entity Resolution, visit our product page.

Amazon EBS Volume Clones now supports copying volumes across accounts

Amazon Elastic Block Store (Amazon EBS) Volume Clones now supports copying EBS volumes across AWS accounts with re-encryption. You can copy EBS volumes to any AWS account, re-encrypting with an AWS Key Management Service (AWS KMS) key in the target account. This enables organizations that separate production and development workloads into different accounts to copy data across those account boundaries.

With cross-account copy, you can clone a production database volume into an isolated development account, giving developers a fresh copy of production data to experiment with safely. This capability also supports teams that require encryption key separation across environments, such as maintaining separate KMS keys for production and non-production accounts. Cross-account copy is supported for all volume types, including unencrypted volumes and volumes encrypted with customer managed keys.

To copy a volume across accounts, you first share the volume with the target account using AWS Resource Access Manager (AWS RAM), and then the target account creates a copy of the shared volume in the same Availability Zone. You can access this capability using the AWS Management Console, AWS Command Line Interface (CLI), and AWS SDKs. It is available in all AWS Regions that support Amazon EBS Volume Clones, including all Commercial Regions, the AWS GovCloud (US) Regions, AWS China Regions, and supported Local Zones.

To learn more, visit the Amazon EBS Volume Clones documentation.

Amazon Bedrock Managed Knowledge Base now supports Confluence Data Center as a native data source connector

AWS announces the Confluence Data Center data source connector for Amazon Bedrock Managed Knowledge Base, a fully managed retrieval-augmented generation (RAG) service. Customers running self-hosted Confluence Data Center instances can now crawl blogs and pages from their Confluence spaces directly into their managed knowledge base. Previously, bringing Confluence Data Center content into Bedrock Knowledge Bases required building custom ingestion pipelines—now, you provide your instance credentials, and the connector handles data crawling, metadata extraction, and incremental sync automatically.
The Confluence Data Center connector gives your AI agents access to the institutional knowledge your teams already maintain in Confluence, including wiki pages and blog posts across spaces. You can use filters to scope crawls to specific spaces or content types, ensuring only relevant content is ingested and keeping your knowledge base focused and cost-efficient. This makes it easy to power internal assistants grounded in engineering documentation, runbooks, or team knowledge bases hosted on Confluence Data Center.
To learn more, see Confluence Data Center data source connector in the Amazon Bedrock User Guide. For more information about Amazon Bedrock Managed Knowledge Base, visit the Amazon Bedrock Knowledge Bases product page.

AWS Japan Blog

エージェンティックセキュリティ: マシンスピードでの検出と対応

自律型 AI エージェントの台頭は、セキュリティポスチャにとってクラウドへの移行以来最大の変化です。本記事では、SANS Institute と共同執筆した 2026 Cloud Security Exchange eBook の章から、エージェントのアイデンティティとガバナンス、振る舞いの監視とオブザーバビリティによる検出の進化、段階的な自動対応、マルチエージェントエコシステムへの備えという 4 つの基礎領域を紹介します。Amazon GuardDuty、Amazon Inspector、AWS Security Hub を活用し、マシンスピードでの検出と対応を実現する実践的なフレームワークを解説します。

AI を活用したスキャフォールディングで、フルスタックの AWS アプリケーションを数分で構築する

本記事は「Build full-stack AWS applications in minutes with […]

1 年間無料の Kiro を、世界中の学生へ

新年度の始まりにあたって、私たちは、より多くの学生が本格的なツールを手にしてキャンパスへ戻ることを望んでいます。そこで Kiro Students プログラムを、16 か国にわたる新たな 121 の大学へと拡大します。これら 16 か国の対象となる学生は、いまや同じオファーを受けられます。Kiro を 1 年間無料で利用でき、毎月 1,000 クレジット、そしてプレミアムモデルや Kiro Web といった有料機能にもフルアクセスできます。クレジットカードは不要。トライアルのタイマーもありません。ただ作るだけです。

Kiro が ISO/IEC 27001:2022 のカバレッジに対応

調達・セキュリティ・ベンダーリスクの各チームが、Kiro の採用に関する意思決定を裏付ける、第三者によって独立に検証されたエビデンスを利用できるようになったことをお知らせします。Kiro は、AWS の ISO/IEC 27001:2022 認証の定義された範囲(スコープ)に含まれています。チームは Kiro を、ソースコード、システムアーキテクチャ、社内ドキュメント、その他のプロジェクトコンテキストとともに利用します。こうした情報には、知的財産や、組織のセキュリティポリシーによって管理されるデータが含まれることがあります。開発ツールを承認する前に、組織はそのツールを提供する組織が情報セキュリティリスクをどのように特定し、管理し、レビューしているのかについて、明確なエビデンスを必要とします。

Oracle Database@AWS を始める: オンボーディング完全ガイド

Oracle Database@AWS のオンボーディングを、サービスの選定と調達から OCI テナンシのリンク、AWS と OCI 両側の IAM 設定まで 5 つのステップで解説します。ADB-S と ExaDB-XS のパブリックオファー経路、ExaDB-D と ADB-D のプライベートオファー経路の両方を扱います。購入者アカウントの選び方、ネットワーク計画、SCP の注意点、ジョブの分離まで、プロビジョニング前に押さえておくべきポイントをまとめました。

CODAS によるデータ秘匿性を考慮した産業特化型 AI 基盤の研究開発と実装検証に関する取り組み

はじめに 生成 AI は、いまやあらゆる産業に新たな価値創出の機会をもたらす基盤技術になりつつあります。文章の […]

AWS Security Bulletins

CVE-2026-84942 - Stored Cross-Site Scripting via Vega Expression Function Bypass in OpenSearch Dashboards

Bulletin ID: 2026-102-AWS
Scope: AWS
Content Type: Important (requires attention)
Publication Date: 09/08/2026 12:30 PM PDT

Description:

A stored cross-site scripting (XSS) issue in the Vega expression function implementation in OpenSearch Dashboards allows a remote authenticated actor with dashboard write permissions to execute arbitrary JavaScript in the context of other users' browser sessions by saving a crafted Vega visualization.

Affedted products & versions:

OpenSearch Dashboards (open-source, self-managed):
- Affected: v2.0.0, v2.1.0, v2.2.0, v2.3.0, v2.4.0, v2.5.0, v.2.6.0, v2.7.0, v2.8.0, v2.9.0, v2.10.0, v2.11.0, v2.12.0, v2.13.0, v2.14.0, v2.15.0, v2.16.0, v2.17.0, v2.18.0, v2.19.0, v3.0.0, v3.1.0, v3.2.0, v3.3.0, v3.4.0, v3.5.0
- Fixed: v2.19.5 and v3.6.0

Amazon OpenSearch Service (AWS Managed):
- Affected: v2.3.0, v2.5.0, v2.7.0, v2.9.0, v2.11.0, v2.13.0, v2.15.0, v2.17.0, v2.19.0, v3.1.0, v3.3.0, v3.5.0
- Fixed: v2.3.0, v2.5.0, v2.7.0, v2.9.0, v2.11.0, v2.13.0, v2.15.0, v2.17.0, v2.19.0 and v3.1.0, v3.3.0, v3.5.0

Amazon OpenSearch Serverless:
- Not affected

Please refer to the article below for the most up-to-date and complete information related to this AWS Security Bulletin.

AWS Machine Learning Blog

How DiDi built intelligent contact center QA with Amazon Bedrock

DiDi built a transparent, self-owned contact center quality assurance (QA) system on Amazon Bedrock, replacing an opaque third-party tool. Intent verification accuracy rose from 38% to 86%, compliance scoring topped 90%, and Voice of Customer trend analysis dropped from hours to minutes across Spanish and Portuguese support.

How HPE Zerto built an agentic troubleshooting system with Amazon Bedrock

HPE Zerto built an agentic troubleshooting system powered by Amazon Bedrock that runs on-premises inside the customer environment. This post describes the multi-agent architecture, the on-premises deployment model built with Strands Agents, and the engineering challenges of grounding agents in live disaster recovery data.

Benchmarking small LLM inference on SageMaker AI: G7 vs G5 and G6

Benchmark two 30B Mixture-of-Experts models, Qwen3-Coder-30B and NVIDIA Nemotron-3-Nano-30B, across G5, G6, G6e, and G7 GPU instances on Amazon SageMaker AI. Compare throughput, latency, and cost-per-token, and see how G7's NVIDIA Blackwell GPUs deliver measurable price-performance gains for real-time LLM inference.

Automated agent evaluation with Amazon Bedrock AgentCore and GitHub Actions

Wire Amazon Bedrock AgentCore Evaluations into a GitHub Actions pipeline: deploy an AI agent and an OAuth-protected MCP server to AgentCore runtime, invoke the agent with test prompts, score the responses, and automatically block pull requests when agent behavior regresses.

Govern models with MLflow and Amazon SageMaker AI Model Registry sync: Part 1

Managed MLflow on Amazon SageMaker AI now syncs richer model metadata (training metrics, evaluation results, inference specs, and lineage) into the SageMaker AI Model Registry, with lifecycle stage promotion. Part 1 shows how to govern candidate models in a single account using IAM guardrails.

Govern models with MLflow and Amazon SageMaker AI Model Registry sync: Part 2

Governing models across accounts is the next step after automatic model registration. This post extends managed MLflow and Amazon SageMaker AI Model Registry sync to two cross-account governance topologies: a hub-and-spoke pattern that centralizes governance with AWS RAM, and a hybrid pattern that keeps development accounts isolated.

Amazon SageMaker Feature Store introduces UpdateRecord for feature-level writes

Amazon SageMaker Feature Store now supports feature-level writes. With the new UpdateRecord API, you can update one or more feature values in a single call without reading or rewriting the entire record. It is available for both the Standard (Amazon DynamoDB) and In-Memory (Amazon ElastiCache) online store tiers.

Pathway’s brain-inspired architecture development on Amazon SageMaker HyperPod

Pathway's Baby Dragon Hatchling (BDH) is a brain-inspired, post-transformer architecture that reasons in latent space instead of emitting chain-of-thought tokens. See how Pathway develops and scales BDH on Amazon SageMaker HyperPod, and how BDH-CQ set a new cost-efficiency mark on the ARC-AGI-1 benchmark.

Pathway’s brain-inspired architecture development on Amazon SageMaker HyperPod

Pathway's Baby Dragon Hatchling (BDH) is a brain-inspired, post-transformer architecture that reasons in latent space instead of emitting chain-of-thought tokens. See how Pathway develops and scales BDH on Amazon SageMaker HyperPod, and how BDH-CQ set a new cost-efficiency mark on the ARC-AGI-1 benchmark.

Take on your most ambitious work with GPT-6 Astra on Amazon Bedrock

GPT-6 Astra from OpenAI is now generally available on Amazon Bedrock. It brings deeper reasoning and sharper judgment to your most demanding tasks, running on the Amazon Bedrock inference engine built for high performance, security, and scale.

AWS Compute Blog

Bring your own client certificate for backend mTLS in Amazon API Gateway

Enterprises that use Amazon API Gateway often want to bring their own client certificate for backend mutual TLS (mTLS) authentication. With API Gateway, you can now use a third-party or AWS Private CA-issued client certificate for the outbound mTLS handshake. In this post, you build a REST API with an outbound mTLS connection to an Amazon ECS backend.