12 items across 2 sections
A CVSS 8.4 command injection in AWS's new Kiro IDE lets a crafted project execute code the moment you open it. Client VPN gets simplified onboarding. AWS is named ISG Leader for Sovereign Cloud for the third year running.
Security Hub Extended Plan reaches GA with 14+ partners on day one, the launch most enterprises have been waiting for. LexisNexis loses 2 GB via a misconfigured AWS environment. Three AWS-LC crypto library CVEs land in one drop. VPC Encryption Controls move from preview to paid.
AWS issues four security bulletins in a single week, signaling fresh scrutiny on developer tooling and cryptographic libraries. Trivy CI/CD pipelines get backdoored by TeamPCP. Amazon publishes 36-day-old honeypot intel on Interlock ransomware exploiting Cisco Firewall Management Center.
OpenAI GPT-5.5, GPT-5.4, and Codex reach general availability on Amazon Bedrock under the same governance controls as the rest of AWS. Amazon Cognito adds near-real-time multi-Region replication of identities and credentials, Bedrock AgentCore Identity integrates Secrets Manager, and two new CVEs hit Kiro IDE and Graph Explorer.
Four AWS bulletins land in a single week, all in the build and agent toolchain: AgentCore CLI code injection, CDK command injection, s2n-quic memory exhaustion, and a heap double-free in the HTTP client under the C++ and Java SDKs. Meanwhile the Klue breach shows again what stolen OAuth integration tokens are worth.
AWS unveils Continuum, a model-agnostic vulnerability lifecycle platform, and at AWS Summit New York pushes Security Agent into threat modeling and pull-request review. AWS WAF starts charging AI bots for content. On the patch side: Kiro IDE, the AgentCore Python SDK, and five containerd CVEs.
GuardDuty previews AI-powered investigations, and AWS Sign-In gains resource-based policies plus RCPs that lock console access to expected networks. Researchers deliver a triple hit: Unit 42's universal bucket hijacking, a targeted AWS-console phishing kit that handles MFA, and Wiz's disclosure of an Amazon Q Developer flaw that leaked AWS credentials on repo open.
AWS discloses an HTTP/2 body-inspection bypass in WAF rated CVSS 9.8, and a new CitrixBleed-class NetScaler flaw is exploited within 24 hours of its patch. On the launch side: ACM speaks ACME, GuardDuty watches sensitive file modifications, and WAF extends to AgentCore Gateway. Three more toolchain bulletins land on July 1.
Sygnia documents a lone actor compromising a global enterprise's AWS estate in under 72 hours with AI-assisted workflows. Wiz finds the same symlink trust flaw in six AI coding assistants. On defense: Security Hub gains internet-facing network scanning and AWS Config adds 191 managed rules.
GuardDuty extends threat detection to Bedrock and SageMaker workloads, Security Hub goes multicloud with Azure support and an AI asset inventory, and Cognito removes the last big migration blocker by importing password hashes. Seven AWS bulletins land in four days, including a prompt-and-response leak in AgentCore telemetry.
GuardDuty gets an on-demand investigation agent in public preview, Secrets Manager starts publishing secret-change events to EventBridge, and CloudTrail learns to filter network activity logging by identity. Five more bulletins close out July, including a TLS 1.3 record-drop flaw in s2n-tls and a third AgentCore SDK patch this summer.
Our AWS security experts can help you implement best practices across all these topics.
Contact Us