All Tags

    S3

    12 items across 4 sections

    Playbooks1
    Blog Posts5
    Weekly News5

    Week 1 - Jan 1-5, 2026

    AWS announces SSE-C will be disabled by default on new general-purpose S3 buckets starting April 2026, closing the Codefinger ransomware vector. Security Hub and Security Agent updates from re:Invent 2025 keep rolling out.

    2026-01-01 - 2026-01-05

    Week 4 - Jan 20-26, 2026

    Security Agent extends preview support to GitHub Enterprise Cloud, so your code, IaC, and supply chain now sit on the same scanning surface. Network Firewall picks up GenAI traffic classification. S3 lets you change a bucket's encryption type without re-uploading objects.

    2026-01-20 - 2026-01-26

    Week 12 - Mar 16-22, 2026

    AWS issues four security bulletins in a single week, signaling fresh scrutiny on developer tooling and cryptographic libraries. Trivy CI/CD pipelines get backdoored by TeamPCP. Amazon publishes 36-day-old honeypot intel on Interlock ransomware exploiting Cisco Firewall Management Center.

    2026-03-16 - 2026-03-22

    Week 14 - Mar 31 - Apr 6, 2026

    Security Agent and DevOps Agent both ship to general availability after their re:Invent 2025 preview. S3 finally rolls out the SSE-C default-off across 37 Regions, the kill announced back in January. Audit Manager stops onboarding new customers as of April 30.

    2026-03-31 - 2026-04-06

    Week 26 - June 22-28, 2026

    GuardDuty previews AI-powered investigations, and AWS Sign-In gains resource-based policies plus RCPs that lock console access to expected networks. Researchers deliver a triple hit: Unit 42's universal bucket hijacking, a targeted AWS-console phishing kit that handles MFA, and Wiz's disclosure of an Amazon Q Developer flaw that leaked AWS credentials on repo open.

    2026-06-22 - 2026-06-28
    Best Practices1

    Need Help with AWS Security?

    Our AWS security experts can help you implement best practices across all these topics.

    Contact Us