All Tags

    Compliance

    19 items across 4 sections

    Comparisons3
    Blog Posts8

    From Findings to Fixed: Lambda Compliance Mapping and Remediation

    Part 3 of 4 in the Lambda Security Series. Map every Lambda security finding to ten compliance frameworks (PCI DSS, HIPAA, SOC 2, ISO 27001, NIST, GDPR), then fix each of the 19 checks with a precise AWS CLI command.

    11 min read · 2026-06-04

    Build a Free AWS Security Lab on Your Laptop with LocalEmu

    Spin up a local AWS, plant deliberately insecure resources, and run real security scanners against it. No account, no token, no cost, no risk.

    9 min read · 2026-06-01

    Fixing EC2 Security Issues: A Practical Remediation Guide

    Part 3 of 3 in the EC2 Security Series. A hands-on remediation guide mapped to the scanner findings: AWS CLI commands, Terraform snippets, and console steps for every category.

    11 min read · 2026-05-19

    Building an EC2 Security Scanner: 46 Checks, 137 Controls, Zero Excuses

    Part 2 of 3 in the EC2 Security Series. One open-source command that scores every EC2 instance 0-100 across 46 checks and maps each finding to 137 controls in 10 compliance frameworks.

    13 min read · 2026-05-17

    Run AI Locally for AWS Security Work: The Complete Ollama Guide

    Stop sending your IAM policies, CloudTrail logs, and infrastructure code to third-party APIs. Run LLMs locally with Ollama on Apple Silicon: private, offline, fast. Complete setup guide with AWS security use cases.

    15 min read · 2026-03-30

    AWS Security Audit Checklist: The Complete 2026 Guide

    A comprehensive AWS security audit checklist covering IAM, S3, networking, logging, and compliance. Follow this step-by-step guide to secure your AWS infrastructure.

    12 min read · 2026-02-10

    AWS Compliance Guide: HIPAA, GDPR, PCI DSS & SOC 2

    Navigate AWS compliance requirements for HIPAA, GDPR, PCI DSS, and SOC 2. Learn which AWS services help you meet regulatory obligations.

    13 min read · 2026-01-20

    Episode 3: Public RDS Detective - Finding Your Exposed Databases Before Attackers Do

    Build automated scanners that identify publicly accessible RDS databases, analyze security groups, check encryption, and generate remediation commands across all AWS regions.

    16 min read · 2025-09-03
    Weekly News6

    Week 3 - Jan 13-19, 2026

    AWS European Sovereign Cloud goes live in Brandenburg, run by EU residents under German law, physically and logically isolated from other Regions. The Sovereign Reference Framework establishes how it is governed.

    2026-01-13 - 2026-01-19

    Week 10 - Mar 3-9, 2026

    Bedrock AgentCore Policy hits GA, mixing LLM authorship with Cedar policy-as-code, the first AWS service to do that at scale. IAM gets a simplified role-creation flow with inline panels. AWS adds DESC 2026 certification for the UAE.

    2026-03-03 - 2026-03-09

    Week 21 - May 18-24, 2026

    Security Hub learns to find identity risk that no one is using: unused IAM permissions, roles, and credentials, measured against 90 days of real activity. The Extended plan grows to 21 partners across 9 categories. Secrets Manager Agent picks up pre-fetching and cross-account role assumption, and Amazon Inspector Classic reaches end of support.

    2026-05-18 - 2026-05-24

    Week 25 - June 15-21, 2026

    AWS unveils Continuum, a model-agnostic vulnerability lifecycle platform, and at AWS Summit New York pushes Security Agent into threat modeling and pull-request review. AWS WAF starts charging AI bots for content. On the patch side: Kiro IDE, the AgentCore Python SDK, and five containerd CVEs.

    2026-06-15 - 2026-06-21

    Week 28 - July 6-12, 2026

    Sygnia documents a lone actor compromising a global enterprise's AWS estate in under 72 hours with AI-assisted workflows. Wiz finds the same symlink trust flaw in six AI coding assistants. On defense: Security Hub gains internet-facing network scanning and AWS Config adds 191 managed rules.

    2026-07-06 - 2026-07-12

    Week 29 - July 13-19, 2026

    GuardDuty extends threat detection to Bedrock and SageMaker workloads, Security Hub goes multicloud with Azure support and an AI asset inventory, and Cognito removes the last big migration blocker by importing password hashes. Seven AWS bulletins land in four days, including a prompt-and-response leak in AgentCore telemetry.

    2026-07-13 - 2026-07-19
    Best Practices2

    Need Help with AWS Security?

    Our AWS security experts can help you implement best practices across all these topics.

    Contact Us