9 items across 3 sections
GuardDuty previews AI-powered investigations, and AWS Sign-In gains resource-based policies plus RCPs that lock console access to expected networks. Researchers deliver a triple hit: Unit 42's universal bucket hijacking, a targeted AWS-console phishing kit that handles MFA, and Wiz's disclosure of an Amazon Q Developer flaw that leaked AWS credentials on repo open.
AWS discloses an HTTP/2 body-inspection bypass in WAF rated CVSS 9.8, and a new CitrixBleed-class NetScaler flaw is exploited within 24 hours of its patch. On the launch side: ACM speaks ACME, GuardDuty watches sensitive file modifications, and WAF extends to AgentCore Gateway. Three more toolchain bulletins land on July 1.
GuardDuty extends threat detection to Bedrock and SageMaker workloads, Security Hub goes multicloud with Azure support and an AI asset inventory, and Cognito removes the last big migration blocker by importing password hashes. Seven AWS bulletins land in four days, including a prompt-and-response leak in AgentCore telemetry.
GuardDuty gets an on-demand investigation agent in public preview, Secrets Manager starts publishing secret-change events to EventBridge, and CloudTrail learns to filter network activity logging by identity. Five more bulletins close out July, including a TLS 1.3 record-drop flaw in s2n-tls and a third AgentCore SDK patch this summer.
Comprehensive guide to securing Amazon Elastic Container Service. Covers task role separation, non-root containers, ECR image scanning, secrets management, GuardDuty runtime monitoring, network isolation, ECScape mitigation, and container image signing.
Comprehensive guide to securing AWS Virtual Private Cloud. Covers Security Groups, NACLs, VPC Flow Logs, VPC Endpoints, Block Public Access, Encryption Controls, Network Firewall, Transit Gateway, and GuardDuty threat detection.
Comprehensive guide to AWS GuardDuty threat detection. Covers Extended Threat Detection, Runtime Monitoring for ECS/EKS/EC2, Malware Protection, S3 and RDS Protection, automated response, multi-account management, and SIEM integration.
Comprehensive guide to securing Amazon Elastic Kubernetes Service. Covers Pod Identity, RBAC least privilege, Pod Security Standards, network policies, secrets encryption, GuardDuty EKS protection, EKS Auto Mode, and CIS EKS Benchmark compliance.
Our AWS security experts can help you implement best practices across all these topics.
Contact Us