AWS News - 2026-09-10

2026-09-10
最終更新: 2026-09-12 04:24:47 JST

AI による概要

概要 37 記事 / 一覧 38 記事

この日は 37 件と今週で最も多く、Amazon Quick の大型アップデート、Lambda の実行時間拡張、Shield Advanced の既定変更、AWS Elemental のメディア機能群が目立ちました。Amazon Quick はデスクトップアプリが macOS と Windows で一般提供となり、アクティビティフィードが iOS / Android のモバイルアプリでも使えるようになったほか、常時稼働エージェント・より見やすいフィード・組織横断のエンタープライズ制御が加わりました。AWS Lambda は Lambda Managed Instances 上の非同期およびイベントソースマッピング呼び出しについて関数タイムアウトを 90 分へ拡張し (従来の 15 分から 6 倍)、Graviton5 を搭載した C9g / C9gd / M9g / M9gd インスタンスにも対応しました。AWS Shield Advanced は、アプリケーションレイヤー (L7) DDoS 保護の既定として AWS WAF Anti-DDoS マネージドルールグループを採用し、2026 年 7 月 27 日から対象のウェブ ACL への Count モードでの追加が始まります。AWS Transform の .NET モダナイゼーションが CLI から 1 行のコマンドで実行できる形で一般提供となり、第 2 世代の単一ラック AWS Outposts (自己完結型の 42U ラック) も一般提供になりました。AWS Elemental では、MediaLive の A/B フォレンジック電子透かし、MediaTailor の Yield Optimization (Amazon Ads の需要で未使用の広告枠を自動収益化)、ライブ映像からリアルタイムに文脈メタデータを生成する Elemental Inference、MediaPackage の Dynamic Multiview、MediaTailor の低遅延 HLS 広告挿入が追加されました。認定資格では MLA・SAP・DVA の 3 試験が更新され、MLA-C02 のベータ登録が開始、SAP-C03 と DVA-C03 は 2026 年 10 月 27 日から登録開始です。AWS AI Security Framework の解説も出て、多層防御を「インフラストラクチャ」「アイデンティティとデータ」「AI アプリケーション」の 3 レイヤーに整理し、Foundational / Enhanced / Advanced のコントロールを対応づけています。このほか Amazon EVS が大阪・台北・スペイン・テルアビブへ拡大、Storage Gateway の S3 File Gateway が PrivateLink 経由の FIPS 140-3 検証済みエンドポイントに対応、CloudWatch Network Monitor が Transit Gateway のリージョン間ピアリング経路にネットワークヘルスインジケーターを提供、Bedrock Managed Knowledge Base が文書単位のアクセス制御をデバッグする API を追加しました。セキュリティ速報は 3 件で、awslabs.mysql-mcp-server の問題 (CVE-2026-85788)、CVE-2026-87911、そして aws-agents-for-devsecops と MCP Server 向けの AWS Security Agent プラグインで S3 バケットの所有権検証が欠けている問題 (CVE-2026-87912、CVE-2026-87913) が公開されました。アーキテクチャブログでは、AWS FIS を使った Terraform Enterprise のマルチリージョン DR 検証 (HashiCorp・Athenahealth と共同) や、SQS キューへの段階的なカオス実験が扱われています。機械学習ブログでは、メンテナンス終了となった TorchServe の代替となるサポート付きコンテナ Ray Serve DLC、AgentCore 上に構築した Heurist Finance の投資ワークベンチ、8 月の AI 向けアップデートの振り返り、2.4 兆パラメータの Qwen3.8-2.4T-A95B を HyperPod と vLLM でデプロイする手順 (NVFP4 量子化) が公開されました。国内では、Umios (旧マルハニチロ) が時系列基盤モデル Chronos-2 で販売計画 AI を実現し作業 4,200 時間を削減した事例が出ています。

主要トピック
  • AI アシスタント: Amazon Quick のデスクトップアプリが macOS / Windows で GA、モバイルにアクティビティフィード、常時稼働エージェントとエンタープライズ制御を追加

  • コンピューティング: Lambda Managed Instances の関数タイムアウトが 90 分へ (15 分から 6 倍)、Graviton5 の C9g / M9g 系にも対応

  • DDoS 対策: Shield Advanced が L7 DDoS 保護の既定に AWS WAF Anti-DDoS マネージドルールグループを採用 (2026-07-27 から Count モード追加開始)

  • 移行: AWS Transform の .NET モダナイゼーションが CLI 1 行で GA、第 2 世代の単一ラック AWS Outposts も GA

  • メディア: AWS Elemental が A/B フォレンジック電子透かし、MediaTailor の Yield Optimization、ライブ映像からの文脈メタデータ生成などを追加

  • 認定資格: MLA / SAP / DVA を更新、MLA-C02 ベータ登録開始、SAP-C03・DVA-C03 は 2026-10-27 登録開始

  • セキュリティ指針: AWS AI Security Framework が多層防御を 3 レイヤー × Foundational / Enhanced / Advanced で整理

  • 脆弱性: AWS Security Agent プラグインで S3 バケットの所有権検証が欠落 (CVE-2026-87912 / CVE-2026-87913)、mysql-mcp-server の問題 (CVE-2026-85788)

  • リージョン / 接続: EVS が大阪・台北・スペイン・テルアビブへ、S3 File Gateway が PrivateLink 経由の FIPS エンドポイントに対応

  • レジリエンス: AWS FIS による Terraform Enterprise のマルチリージョン DR 検証、SQS への段階的カオス実験

  • 事例: Umios (旧マルハニチロ) が時系列基盤モデル Chronos-2 で販売計画 AI を構築し作業 4,200 時間を削減

AI (Claude Opus 5) が生成 · 2026-09-11 07:54:56 JST

AWS What's New

Amazon Quick desktop app is now generally available on macOS and Windows

The Amazon Quick desktop app is now generally available on macOS and Windows. The desktop app brings the full power of Amazon Quick to your computer, working directly with your local files and staying connected to your calendar, email, and business apps in the background. Quick keeps your conversations, context, and agents synchronized across the desktop and mobile applications, so work you start on one surface carries over to the other, enabling you to work wherever you want. 

Additionally, with this release, Amazon Quick agents run continuously in the background, even after you close your computer, so long-running work keeps making progress while you're away. Start an agent before you leave the office, provide additional inputs from the mobile app during your commute home, and then review the final output when you arrive. Quick offers production-grade stability, maintains AWS SLA commitments, and offers the governance and administrative controls for deployments at enterprise scale. 

The Amazon Quick desktop app is available in 7 regions, US East (N. Virginia), Asia Pacific (Sydney), US West (Oregon), Europe (Ireland), Europe (London), Asia Pacific (Tokyo), and Europe (Frankfurt) 

Existing Quick users can download the desktop app from here. The Quick mobile application is available for free from the Apple App Store and Google Play Store.

Amazon Quick activity feed now available on iOS and Android mobile devices

詳細を表示

The Amazon Quick activity feed is now available on the Amazon Quick mobile app for iOS and Android, keeping you connected to your most important work from anywhere. 

The activity feed is your single, prioritized view of everything that needs your attention across your enterprise communications and tools, so you don't have to check each one separately. Items requiring your attention populate the top of your feed, and instead of switching between apps, you can take action directly from within Quick.  Never miss something time-sensitive, even when you're away from your desk. Your decide which notifications are important and which are noise. Over time, Quick learns your priorities and surfaces only the things that matter. 

You can also ask Quick to post anything to your feed through a routine, pulling from any connected data source. For example, you can tell Quick “every morning at 7:30, tell me which customer meetings I have that day and give me 3 bullet points to prep”.  

Additionally, as part of today's announcement, Amazon Quick retains context across the desktop and mobile applications. Any work you do on one surface carries over to the other, so you can start a chat or assign a task to an agent on your desktop, then review progress and continue the chat from your mobile device, picking up right where you left off when you're back at your computer. 

The Amazon Quick mobile app is included with your existing Amazon Quick access at no additional cost. 

Existing Quick customers can download the Quick mobile application for iOS from the Apple App Store, and Android from the Google Play Store. If you're new to Quick, visit the Quick Product Page to create an account for free in minutes. 

Amazon Quick adds always-on agents, a sharper feed, and enterprise controls

Today, Amazon Quick offers new capabilities that make it easier to organize your work, govern it across an organization, and trust the answers it produces. These capabilities build on Amazon Quick across desktop and mobile, bringing enterprise-grade management, richer collaboration, and always-on intelligence to teams wherever they work. 

Your agents no longer stop when you step away. Scheduled tasks and monitoring agents run in the cloud and deliver results to your feed even when your laptop is closed. A sharper activity feed adds top-level filters, an improved catch-up view, a daily briefing that refreshes three times a day, and search across up to seven days of feed data, so you see what needs you first. Administrators gain mobile device management support, custom per-user permissions, and Microsoft Purview data loss prevention integration. Teams can share files and publish agents and skills for others to discover and install, and browse a catalog of official skills. Quick spaces and Quick apps now run natively on the desktop, any indexed local folder can become a searchable space, and inline citations let you verify every answer against its source. Additionally, every Quick subscriber now gets more agent hours each month — Professional grows from 4 to 8 and Enterprise from 8 to 18 — combined into a single, simpler allotment. 

New users can create an account for free and start using Quick in minutes.Or to learn more,  visit the Amazon Quick product page.

Amazon Bedrock Managed Knowledge Base adds APIs and console support for debugging document-level access control

AWS announces the CheckIngestedDocumentAcl and GetIngestedDocumentAcl APIs for Amazon Bedrock Managed Knowledge Base, giving customers a self-service way to debug document access issues and audit document-level permissions. When a user doesn't see an expected document in retrieval results for ACL-enabled data sources, it can be difficult to determine whether the cause is an access control misconfiguration or something else entirely. These new APIs and the accompanying console experience close that gap, enabling you to quickly diagnose and resolve permission issues without opening a support case.

CheckIngestedDocumentAcl lets you verify whether a specific user has access to a given ingested document, while GetIngestedDocumentAcl returns the full ACL attached to a document so you can audit exactly what permissions are configured and catch misconfigurations. The console also introduces a new Document Access Control section on the data source details page, where you can check access by entering a document ID and user email or retrieve a document's full ACL by document ID. Together, these capabilities give administrators the visibility they need to manage access control at scale across enterprise knowledge bases.

To learn more, see CheckIngestedDocumentAcl and GetIngestedDocumentAcl in the Amazon Bedrock API Reference. For more information about Amazon Bedrock Managed Knowledge Base, visit the Amazon Bedrock Knowledge Bases product page.

AWS Lambda now supports Graviton5-powered EC2 instances on Lambda Managed Instances

詳細を表示

AWS Lambda now supports AWS Graviton5-powered C9g, C9gd, M9g, and M9gd instances on Lambda Managed Instances. You can now run your Lambda functions on the latest generation of Graviton processors, delivering up to 25% better compute performance compared to Graviton4-powered instances.

AWS Lambda Managed Instances lets you run Lambda functions on your AWS EC2 instances while maintaining Lambda's operational simplicity. With Lambda Managed Instances, you can access specialized compute configurations and drive cost efficiency through EC2 pricing advantages, without managing infrastructure. Lambda Managed Instances fully manages all infrastructure tasks, including instance lifecycle, OS and runtime patching, built-in routing, load balancing, and auto-scaling based on configurable parameters - so you can focus on writing code. Starting today, you can leverage Lambda Managed Instances with the latest Graviton5-powered instances, which deliver up to 25% better compute performance compared to the previous generation Graviton4-powered instances.

To get started, you can specify the desired Graviton5 instance type (C9g, C9gd, M9g, or M9gd) when you create a capacity provider. When you set the instance type to default, Lambda automatically includes Graviton5 instances in the list of instances it chooses from, based on your function’s configured architecture, memory size, and memory-to-vCPU ratio.

AWS Lambda Managed Instances supports C9g, C9gd, M9g, and M9gd instance types in all AWS Regions where both Lambda Managed Instances and these EC2 instances are available. To learn more, visit the Lambda Managed Instances documentation and AWS Lambda pricing

AWS Lambda now supports 90-minute function timeout on Lambda Managed Instances

詳細を表示

AWS Lambda now supports a 90-minute function timeout for asynchronous and event source mapping (ESM) invocations on Lambda Managed Instances (LMI), a 6x increase from the previous 15-minute limit. You can now run data processing, media transcoding, financial calculations, AI inference, and batch workloads on Lambda for jobs that require longer continuous execution, without re-architecting your applications.

Customers use Lambda to build serverless applications like event-driven processors, API backends, and data processing pipelines. For data-intensive workloads like media transcoding, financial calculations (such as Monte Carlo simulations), and AI inference that need longer continuous execution, Lambda's 15-minute function timeout limit required customers to adopt architectural workarounds. With today's launch, you can configure a function timeout of up to 90 minutes for asynchronous and ESM invocations on Lambda Managed Instances. Lambda Managed Instances lets you process multiple concurrent requests per instance, access specialized compute configurations, and drive cost efficiency through EC2 pricing advantages, without managing infrastructure. The increased function timeout also applies to invocations within Lambda durable functions, which allow you to checkpoint and replay steps for longer-running invocations. When invoked asynchronously, a multi-step durable execution can run for up to 1 year.

You can configure up to a 90-minute function timeout for asynchronous and ESM invocations via the AWS Lambda Console, AWS CLI, Lambda APIs, Infrastructure as Code tooling, or the Agent Toolkit for AWS. Synchronous invocations retain the existing 15-minute maximum timeout. This feature is available in all AWS Regions where Lambda Managed Instances is available.

To learn more about configuring the 90-minute function timeout, see the Lambda developer guide. For combining extended timeouts with checkpoint-and-replay resilience, see the durable functions documentation. For pricing details, see AWS Lambda Pricing. To learn more about AWS Lambda, visit aws.amazon.com/lambda

AWS Transform for .NET modernization is now generally available via CLI

Today, AWS announced the general availability of an AWS-managed transformation for .NET modernization in AWS Transform custom that you can trigger with a single one-line CLI command. You can run this transformation interactively, or script it into any existing pipeline or workflow to run autonomously. The CLI experience complements the existing AWS Transform for .NET experiences: the web application, Visual Studio IDE, Kiro Power, and MCP agents.

AWS Transform custom enables organizations to modernize and transform code at scale using AWS-managed and custom transformations. You can upgrade language versions, migrate frameworks, optimize performance, and analyze code bases using transformations that are ready to use or can be customized to meet your organization's specific requirements. These transformations benefit from continuous improvement, learning from each engagement to deliver more accurate and efficient results.

AWS Transform custom and AWS Transform for .NET are available in eight AWS Regions: US East (N. Virginia), Asia Pacific (Mumbai, Tokyo, Seoul, Sydney), Canada (Central), and Europe (Frankfurt, London).

The .NET modernization transformation includes 50,000 free agent minutes per month. View AWS Transform Pricing for pricing details and examples. To learn more, see AWS-Managed Transformations in the AWS Transform User Guide.

Amazon Connect Customer now lets you set specific capacity limits for different types of Tasks and Emails

Amazon Connect Customer now gives contact center managers the ability to set specific capacity limits for different kinds of work. Previously, concurrency settings were applied at the channel level so all contacts within a channel were treated the same regardless of complexity or effort required. With this launch, managers can classify Task and Email contacts into workload types based on complexity, priority, or business function, each with its own concurrency and interruption rules. For example, a manager can configure agents to handle up to 3 simple, low-effort Tasks concurrently while limiting complex, high-attention Tasks to 1 at a time.

Specific capacity limits for Task and Email channels are available in all AWS commercial and AWS GovCloud (US-West) regions where Amazon Connect Customer is offered. To learn more, see the Amazon Connect Customer Administrator Guide. To learn more about Amazon Connect Customer, visit the Amazon Connect Customer website.

AWS Marketplace sellers now receive qualified demo and private offer requests in minutes

AWS Marketplace sellers that activated the request demo or request private offer call-to-action buttons on their listings can now act on customer requests within minutes of submission, while customers are still actively evaluating their products. This happens automatically, with no changes required to their listings or workflows.

When a customer submits a request, they can now provide details about their use case, and AWS Marketplace uses an agentic workflow to evaluate those details and create an opportunity for the seller: an active prospect with a defined use case. Each opportunity arrives in AWS Partner Central with the customer's contact details and use case, so sellers can reach out directly. Previously, an AWS representative contacted the customer to qualify every request before sharing it, adding days of delay. Now sellers receive every active lead the moment it comes in, without waiting for AWS to manually qualify it first. Even when a customer provides only their contact information without additional information, the seller still receives their details as a lead to follow up on for additional qualification, and can enrich it through AWS lead prospecting workflows.

Sellers who have not yet added the request a demo or request private offer buttons to their listings can turn them on by following the steps in the AWS Marketplace Seller Guide. Enabling these buttons lets customers request demos and private offers directly from a seller's product listing page, accelerating product evaluations and reducing procurement cycle times.

Amazon EVS is now available in more regions

Today, we're announcing that Amazon Elastic VMware Service (Amazon EVS) is now available in the Asia Pacific (Osaka), Asia Pacific (Taipei), Europe (Spain), and Israel (Tel Aviv) Regions. This expansion provides more options to leverage the scale and flexibility of AWS for running your VMware workloads in the cloud.

Amazon EVS lets you run VMware Cloud Foundation (VCF) directly within your Amazon Virtual Private Cloud (VPC) on EC2 bare-metal instances, powered by AWS Nitro. You can set up a complete VCF environment in just a few hours, enabling rapid workload migration to AWS to help you eliminate aging infrastructure, reduce operational risks, and meet critical timelines for exiting your data center. This launch supports all existing Amazon EVS features, including VCF 9.0 and 9.1 support to take advantage of the latest VMware features, such as memory tiering.

The added availability in these Regions gives your VMware workloads lower latency through closer proximity to your end users, compliance with data residency or sovereignty requirements, and additional high availability and resiliency options for your enhanced redundancy strategy.

To get started, visit the Amazon EVS product detail page and user guide

AWS Elemental MediaLive adds support for A/B forensic watermarking

AWS Elemental MediaLive now supports A/B forensic watermarking, enabling content owners to trace the source of unauthorized redistribution of live video content. A single MediaLive channel produces two synchronized output variants, each carrying a distinct visually transparent watermark that persists through re-encoding and screen capture. Downstream packaging and CDN infrastructure assembles these variants into unique per-session sequences that identify the origin of leaked content.

Forensic watermarking follows the DASH Industry Forum (DASH-IF) specification for A/B watermarking (European Telecommunications Standards Institute (ETSI) TS 104 002), ensuring interoperability with standards-compliant packagers and CDN infrastructure. Customers can configure watermarking on Common Media Application Format (CMAF) Ingest output groups through the MediaLive API or console. MediaLive delivers watermarked A and B variants via CMAF ingest to AWS Elemental MediaPackage or third-party packagers, enabling downstream per-session watermark assembly through compatible CDN infrastructure including Amazon CloudFront.

To learn more, visit the AWS Elemental MediaLive User Guide.

A/B forensic watermarking is available in all AWS Regions where AWS Elemental MediaLive is available.

AWS Elemental MediaTailor now offers Yield Optimization to automatically fill ad breaks with Amazon Ads demand

AWS Elemental MediaTailor now offers Yield Optimization, a new capability that automatically monetizes unused ad inventory with Amazon Ads demand during server-side ad insertion (SSAI) for livestreams. Available exclusively to publishers in the Amazon Publisher Services (APS) Streaming TV program, yield optimization turns unfilled ad breaks into monetized impressions at zero cost to enable and with no additional infrastructure required.

Because ads are stitched directly into the stream before reaching the viewer, they play seamlessly on every device. Key highlights:

- Built for scale: yield optimization is designed for large-scale live events such as professional league championships, with low latency and fast response times to maximize ad fill during peak viewership.

- Brand safe: demand is filtered by category to avoid competitive conflicts within the same ad break. publishers set their own price floors and category rules to maintain full control over which ads run in their streams.

- Simple to enable: configure yield optimization through the MediaTailor API or Console. No additional infrastructure or client-side changes are required.

- Performance visibility: monitor ad fill rate improvements using MediaTailor metrics in Amazon CloudWatch. Track revenue and earnings through the APS Publisher portal.

AWS Elemental MediaTailor yield optimization is available at no additional cost in all AWS Regions where MediaTailor is available, including US East (Ohio), US East (N. Virginia), US West (Oregon); Africa (Cape Town); Asia Pacific (Hyderabad, Malaysia, Melbourne, Mumbai, Osaka, Seoul, Singapore, Sydney, Tokyo); Canada (Central); Europe (Frankfurt, Ireland, London, Paris, Stockholm); Middle East (UAE); and South America (São Paulo). To learn more, visit the AWS Elemental MediaTailor documentation.

AWS Elemental Inference now generates contextual metadata from live video in real time

AWS Elemental Inference now generates contextual metadata from live video streams in real time, using AI to produce scene-level intelligence without custom machine learning infrastructure. The new capability analyzes live video in parallel with encoding to extract Interactive Advertising Bureau (IAB) content taxonomy categories, Global Alliance for Responsible Media (GARM) brand suitability signals, detected objects and actions, and shot and scene-level descriptions. Broadcasters and content platforms can now power contextual ad decisioning, media asset enrichment, and content discovery workflows using serverless, fully managed AI.

For contextual advertising, AWS Elemental MediaLive embeds the Elemental Inference feed ID into (Society of Cable Telecommunications Engineers) SCTE-35 ad markers in the live stream. At each ad break, AWS Elemental MediaTailor uses a Monetization Function to retrieve the scene-level signals for that feed ID and translate them into the targeting parameters ad servers expect. This enables context-aware ad decision-making without custom integration work, supporting use cases like contextual deal curation and brand suitability scores, resulting in improved monetization outcomes for publishers. For media asset management, detecting objects and actions, and shot and scene-level descriptions, provide automatic structured metadata generation for every scene and shot, building richer archives that power contextual content discovery, assisted editing workflows, and personalized content recommendations without manual logging or post-production metadata entry.

Contextual metadata is available today in the AWS Elemental MediaLive console in all AWS Regions where AWS Elemental Inference is available.

AWS Elemental introduces Dynamic Multiview for live video

AWS Elemental MediaPackage now offers Dynamic Multiview, a server-side capability that composes multiple live video sources into viewer-selected tiled layouts on demand. Content providers can deliver multi-angle, multi-game, and personalized viewing experiences as standard HLS (HTTP Live Streaming) and DASH (Dynamic Adaptive Streaming over HTTP) streams playable on most modern consumer devices, televisions, and set top boxes without custom player development.

Dynamic Multiview operates entirely in the compressed domain, combining individually encoded sources without re-encoding or compositing. Customers encode each source once through AWS Elemental MediaLive, and MediaPackage assembles compositions on demand - only when viewers request them, eliminating the need to pre-encode combinations. Because the output is standard HLS and DASH, it plays natively on existing devices and players with no app changes or SDK integration required. The feature supports AVC and HEVC codecs, DRM encryption, SCTE-35 ad marker passthrough, and full-screen ad replacement.

To learn more, visit the Elemental Dynamic Multiview Reference Guide.

Dynamic Multiview is available in all AWS Regions where AWS Elemental MediaPackage and MediaLive are available.

AWS Elemental MediaTailor now supports Low-Latency HLS ad insertion

AWS Elemental MediaTailor now supports Low-Latency HTTP Live Streaming (LL-HLS) ad insertion using HLS Interstitials. MediaTailor is a channel assembly and personalized ad insertion service for video providers that monetizes live streams, linear channels, and video-on-demand content. With this launch, video providers can insert ads into low-latency live streams while holding the reduced latency their viewers expect.

LL-HLS reduces live latency by delivering partial segments and letting players hold a playlist request open until the next segment part is ready, which requires media playlists to be cacheable at the content delivery network (CDN) edge. MediaTailor supports this using HLS Interstitials, which reference ads as a separate playlist instead of stitching them into each viewer's media playlist. Every viewer receives the same cacheable playlist, so MediaTailor sustains low-latency playback at scale and moves the ad decision server call off the manifest request path. This capability has been proven in production on live sporting events with multi-million views, and is ideal for live sports, news, betting and wagering, watch-party, and interactive live formats where latency is a product requirement.

Low-Latency HLS ad insertion is available in all AWS Regions where AWS Elemental MediaTailor is available. To learn more, visit the AWS Elemental MediaTailor product page and the MediaTailor server-guided ad insertion documentation. To get started, sign in to the MediaTailor console..

AWS Storage Gateway now supports FIPS-compliant private connectivity for Amazon S3 File Gateway

AWS Storage Gateway now supports FIPS 140-3 validated endpoints over AWS PrivateLink for Amazon S3 File Gateway. Previously, FIPS endpoints for File Gateway were available only over the public internet. Now you can keep FIPS-compliant traffic on the private AWS network, making it easier to use Storage Gateway for regulated workloads.

With this launch, your File Gateway can reach the Storage Gateway service endpoints privately through a FIPS interface VPC endpoint in your VPC. You can also create NFS and SMB file shares that reach Amazon S3 through an S3 FIPS interface endpoint, enabling FIPS-compliant private connectivity for your end-to-end file transfer workloads. To get started, create FIPS interface endpoints for Storage Gateway and Amazon S3 in your VPC, then choose the FIPS VPC endpoint option when activating your gateway and configuring your file shares. To activate a gateway with a FIPS PrivateLink endpoint, your gateway must be running software version 3.2.7 or later.

This launch is available in the eight AWS Regions where Storage Gateway offers FIPS endpoints: US East (N. Virginia), US East (Ohio), US West (N. California), US West (Oregon), Canada (Central), Canada West (Calgary), AWS GovCloud (US-East), and AWS GovCloud (US-West). To learn more, visit the AWS Storage Gateway User Guide or the product page.

CloudWatch Network Monitor now provides NHI for Transit Gateway peering

Today, AWS announces that Amazon CloudWatch Network Monitor synthetic monitoring now provides its network health indicator (NHI) for paths that reach a destination across an AWS Transit Gateway inter-Region peering connection. Amazon CloudWatch Network Monitor is a fully managed service that measures packet loss and latency for the hybrid network paths connecting your AWS-hosted applications to your destinations. The NHI helps network operators and application developers rapidly determine whether an observed degradation is within the AWS network.

Previously, the NHI covered only paths that connect through AWS Direct Connect. With this launch, hybrid architectures that route across Transit Gateway inter-Region peering receive the same rapid diagnosis, reducing the time you spend isolating the source of an issue. For these paths, the NHI reflects the health of the AWS network path up to the Transit Gateway peering connection, and Amazon CloudWatch receives the metric so you can build dashboards and set alarms.

To learn more, see How Network Synthetic Monitor works in the Amazon CloudWatch User Guide.

Amazon CloudWatch now supports network health indicator for TGW inter-Region peering using synthetic monitors

With synthetic monitors in Amazon CloudWatch Network Monitoring, you can now determine whether a network performance issue on a path that crosses an AWS Transit Gateway inter-Region peering connection is caused by the AWS network. This helps network operators and application developers cut the time spent isolating the source of degradation on these paths.

Previously, for synthetic monitors, the network health indicator (NHI) covered only paths that connect through AWS Direct Connect. With this release, synthetic monitors extend it to paths that reach a destination in a peered Region over Transit Gateway inter-Region peering. For these paths, the indicator reflects the health of the AWS network path up to the Transit Gateway peering connection, and is published to your Amazon CloudWatch account so you can build dashboards and set alarms.

For the full list of AWS Regions where Network Monitoring for AWS workloads is available, visit the Regions list. To learn more, visit the Amazon CloudWatch Network Monitoring documentation.

AWS News Blog

Introducing Amazon EBS Volume Clones across AWS accounts

AWS introduces Amazon EBS Volume Clones with cross-account copy, so you can create copies of your EBS volumes into other AWS accounts and optionally re-encrypt them with an AWS Key Management Service (AWS KMS) key in the target account.

AWS Japan Blog

AWS 認定資格 (MLA、SAP、DVA) に関するアップデート: 2026 年 9 月

AWS が 3 つの認定試験を更新します。MLA-C02 のベータ登録はすでに開始しており、SAP-C03 と DVA-C03 は 2026 年 10 月 27 日より登録開始予定です。生成 AI・エージェンティック AI への対応や AI 支援開発など、今日のクラウドエンジニアに求められるスキルを反映した各試験の変更内容と重要な日程をお伝えします。

AWS Shield Advanced が AWS WAF Anti-DDoS マネージドルールグループを採用: 変更点と準備方法

AWS Shield Advanced は、アプリケーションレイヤー (L7) DDoS 保護のデフォルトとして AWS WAF Anti-DDoS マネージドルールグループを採用し、将来的には唯一の保護機能とします。2026 年 7 月 27 日から、対象のウェブ ACL への Count モードでのルールグループの追加が始まります。既存の L7 自動緩和と並行して動作するため、トラフィックへの影響はありません。この記事では、Anti-DDoS マネージドルールグループの機能、2027 年 1 月 1 日の Shield Advanced アプリケーションレイヤー自動緩和の終了までの 5 つのフェーズ、請求、モニタリングとメトリクスの変更点、IaC や AWS Firewall Manager ポリシーの更新など、移行に向けた準備方法を解説します。

【開催報告】Girls Meet STEM in AWS 2026 を開催しました

2026 年 8 月 21 日、AWS は中高生女子向けプログラム「Girls Meet STEM」に参加し、麻布台ヒルズの新オフィスにて生成 AI 体験ワークショップ、オフィスツアー、パネルディスカッションを開催しました。

Umios(旧マルハニチロ) が時系列基盤モデル Chronos-2 で実現する販売計画 AI – 作業4,200時間削減への裏側

本ブログは Umios 株式会社様と Amazon Web Services Japan が共同で執筆いたしま […]

AWS AI セキュリティフレームワーク: レイヤーとフェーズに応じた適切なセキュリティコントロール

AWS AI Security Framework は、適切なコントロールを適切なユースケース・レイヤー・フェーズに対応づけ、AI をプロトタイプから本番、そしてスケールまで安全に進めるための体系的なモデルです。多層防御を「インフラストラクチャ」「アイデンティティとデータ」「AI アプリケーション」の 3 レイヤーに整理し、Foundational / Enhanced / Advanced の 3 フェーズで段階的にセキュリティを強化する方法を解説します。

AWS Security Blog

The state of AI for security: Measuring what matters most for building trust

Security teams are starting to actively use AI for security work, including vulnerability triage, penetration testing, threat modeling, incident response, and code review. The promise is speed, but a security tool that moves fast and raises too many false alarms doesn’t save time. Engineers spend time on false alarms, on-call is noisier, and teams distrust […]

AWS Security Bulletins

CVE-2026-85788 - Issue with awslabs mysql-mcp-server

Bulletin ID: 2026-103-AWS
Scope: AWS
Content Type: Important (requires attention)
Publication Date: 09/09/2026 09:30 AM PDT

Description:

We identified an issue in awslabs.mysql-mcp-server (an open-source, self-hosted Model Context Protocol server distributed via github.com/awslabs/mcp and PyPI). In affected versions, under certain conditions the read-only enforcement could be circumvented via SQL inline comments, allowing a statement to run that the read-only check was expected to block. The read-only mode provided by the server is a best-effort safeguard and is not a substitute for correctly scoped database permissions; the effective boundary is the permissions of the configured MySQL user.

This issue does not affect the confidentiality or integrity of any AWS service. awslabs.mysql-mcp-server is a client-side, self-managed package; customers control installation and the privileges of the database credentials they configure.

Impacted versions: awslabs.mysql-mcp-server <= 1.0.21

Please refer to the article below for the most up-to-date and complete information related to this AWS Security Bulletin.

CVE-2026-87911

Please refer to the article below for the most up-to-date and complete information related to this AWS Security Bulletin.

CVE-2026-87912 and CVE-2026-87913: Missing S3 bucket ownership verification in the AWS Security Agent plugin for aws-agents-for-devsecops and MCP Server

Bulletin ID: 2026-105-AWS
Scope: AWS
Content Type: Important (requires attention)
Publication Date: 09/10/2026 08:30 AM PDT

Description:

AWS Security Agent is a managed AWS service that provides AI-powered code security reviews, threat modeling, and penetration testing.

We identified CVE-2026-87912, where a missing S3 bucket ownership verification in the AWS Security Agent plugin in Amazon aws-agents-for-devsecops before version 1.1.0 might allow remote attackers to obtain the private source archive of a scanned workspace, including credentials and infrastructure state contained in that archive, via a pre-registered storage bucket whose name is derived from a publicly known account identifier.

We identified CVE-2026-87913, where a missing S3 bucket ownership verification in the AWS Security Agent MCP server before 0.2.0 might allow remote attackers to obtain the private source archive of a scanned workspace, including credentials and infrastructure state contained in that archive, via a pre-registered storage bucket whose name is derived from a publicly known account identifier.

Impacted versions:
- <=1.0.0
- >=0.1.0 AND <=0.1.5

Please refer to the article below for the most up-to-date and complete information related to this AWS Security Bulletin.

AWS Architecture Blog

Validating multi-Region DR for Terraform Enterprise with AWS FIS

Learn how AWS, HashiCorp, and Athenahealth designed and chaos-tested a multi-Region disaster recovery strategy for Terraform Enterprise on AWS. This post walks through three-phase AWS Fault Injection Service experiments across Amazon EC2, Aurora, and Amazon S3, the 12-14 minute recovery times achieved, and the state file dependency pitfall to avoid.

Testing application resilience with Amazon SQS and AWS Fault Injection Service

Learn how to use AWS Fault Injection Service and AWS Systems Manager Automation to run progressive chaos experiments against Amazon SQS queues. Validate that your retry logic, circuit breakers, and dead-letter queues actually work under failure before a real outage hits production.

AWS Machine Learning Blog

Automate user-level custom permissions for Amazon Quick

Amazon Quick custom permissions let you enforce least-privilege access by toggling features per user. This post walks through four patterns to automate custom permissions across the user lifecycle: a RegisterUser API parameter, account and role defaults, event-driven Amazon EventBridge and AWS Lambda automation, and a retroactive batch update script.

Simplify and support your TorchServe workloads using Ray Serve Deep Learning Containers

TorchServe is no longer maintained, leaving teams to own the entire GPU inference stack. The AWS Ray Serve Deep Learning Container is a supported, pre-tested container with the framework, GPU drivers, and serving layer already assembled. This post walks through deploying a vision-language model on Amazon EKS using the Ray Serve DLC on a single GPU node.

How Heurist Finance built an AI-native investment workbench on Amazon Bedrock AgentCore

Learn how Heurist built Heurist Finance, a conversational AI investment workbench, on Amazon Bedrock AgentCore. This customer story shows how AgentCore payments, Identity, Memory, Code Interpreter, and Observability let a small team buy premium market data per query, isolate analysis in a sandbox, and keep every action auditable.

ICYMI: What landed for AI builders in August 2026

A recap of August 2026 launches for AI builders across Amazon Bedrock, Amazon Bedrock AgentCore, and Strands: million-token context for OpenAI models, cross-Region inference, agents that run for up to 14 days on dedicated compute, expanded AWS GovCloud availability, and Strands Robots for physical deployment.

Deploying Qwen3.8-2.4T-A95B on Amazon SageMaker HyperPod with vLLM

Learn how to deploy Qwen3.8-2.4T-A95B, a 2.4-trillion-parameter open-weight model, on Amazon SageMaker HyperPod with vLLM. This walkthrough covers cluster provisioning, NVFP4 quantization, and an OpenAI-compatible endpoint with built-in reasoning, tool calling, and native MTP speculative decoding.

AWS Compute Blog

Announcing 90-minute function timeout on AWS Lambda Managed Instances

AWS Lambda now supports a 90-minute function timeout for asynchronous and event source mapping (ESM) invocations on Lambda Managed Instances, a 6x increase from the previous 15-minute limit. Data processing, media transcoding, AI inference, and batch workloads can now run on Lambda without re-architecting.

Architecting SASE solutions using AWS Local Zones

Organizations with geographically distributed workforces face a trade-off between security and low-latency access. This post explores how to use AWS Local Zones and Secure Access Service Edge (SASE) solutions to deploy virtual security appliances closer to end users, covering key design principles, capacity planning, and traffic routing.

Customize Amazon API Gateway destinations for execution logs

Amazon API Gateway execution logs help you trace request processing step by step through your REST API stages. They capture authorization results, integration latency, mapping template output, and error details that are otherwise invisible at the API surface. When a production request fails in a way the access log cannot explain, the execution log is […]