All Tags

    GuardDuty

    9 items across 3 sections

    Blog Posts1
    Weekly News4

    Week 26 - June 22-28, 2026

    GuardDuty previews AI-powered investigations, and AWS Sign-In gains resource-based policies plus RCPs that lock console access to expected networks. Researchers deliver a triple hit: Unit 42's universal bucket hijacking, a targeted AWS-console phishing kit that handles MFA, and Wiz's disclosure of an Amazon Q Developer flaw that leaked AWS credentials on repo open.

    2026-06-22 - 2026-06-28

    Week 27 - June 29 - July 5, 2026

    AWS discloses an HTTP/2 body-inspection bypass in WAF rated CVSS 9.8, and a new CitrixBleed-class NetScaler flaw is exploited within 24 hours of its patch. On the launch side: ACM speaks ACME, GuardDuty watches sensitive file modifications, and WAF extends to AgentCore Gateway. Three more toolchain bulletins land on July 1.

    2026-06-29 - 2026-07-05

    Week 29 - July 13-19, 2026

    GuardDuty extends threat detection to Bedrock and SageMaker workloads, Security Hub goes multicloud with Azure support and an AI asset inventory, and Cognito removes the last big migration blocker by importing password hashes. Seven AWS bulletins land in four days, including a prompt-and-response leak in AgentCore telemetry.

    2026-07-13 - 2026-07-19

    Week 30 - July 20-26, 2026

    GuardDuty gets an on-demand investigation agent in public preview, Secrets Manager starts publishing secret-change events to EventBridge, and CloudTrail learns to filter network activity logging by identity. Five more bulletins close out July, including a TLS 1.3 record-drop flaw in s2n-tls and a third AgentCore SDK patch this summer.

    2026-07-20 - 2026-07-26
    Best Practices4

    Need Help with AWS Security?

    Our AWS security experts can help you implement best practices across all these topics.

    Contact Us