12 items across 4 sections
Sever the DynamoDB and S3 endpoints an application quietly depends on, using AWS FIS, and watch whether one dependency outage stays contained or takes the whole app down. Real Terraform, real per-endpoint numbers.
Spin up a local AWS, plant deliberately insecure resources, and run real security scanners against it. No account, no token, no cost, no risk.
How I built a secure, scalable file sharing solution using AWS Lambda, API Gateway, and Cognito with zero infrastructure to manage and 91% cost reduction.
Complete guide to Amazon S3 covering the object model, storage classes, security, encryption, lifecycle policies, replication, performance optimization, and cost management.
Complete guide to AWS cost optimization covering Cost Explorer, Compute Optimizer, Savings Plans, Spot Instances, S3 lifecycle policies, gp2 to gp3 migration, scheduling, budgets, and production best practices.
AWS announces SSE-C will be disabled by default on new general-purpose S3 buckets starting April 2026, closing the Codefinger ransomware vector. Security Hub and Security Agent updates from re:Invent 2025 keep rolling out.
Security Agent extends preview support to GitHub Enterprise Cloud, so your code, IaC, and supply chain now sit on the same scanning surface. Network Firewall picks up GenAI traffic classification. S3 lets you change a bucket's encryption type without re-uploading objects.
AWS issues four security bulletins in a single week, signaling fresh scrutiny on developer tooling and cryptographic libraries. Trivy CI/CD pipelines get backdoored by TeamPCP. Amazon publishes 36-day-old honeypot intel on Interlock ransomware exploiting Cisco Firewall Management Center.
Security Agent and DevOps Agent both ship to general availability after their re:Invent 2025 preview. S3 finally rolls out the SSE-C default-off across 37 Regions, the kill announced back in January. Audit Manager stops onboarding new customers as of April 30.
GuardDuty previews AI-powered investigations, and AWS Sign-In gains resource-based policies plus RCPs that lock console access to expected networks. Researchers deliver a triple hit: Unit 42's universal bucket hijacking, a targeted AWS-console phishing kit that handles MFA, and Wiz's disclosure of an Amazon Q Developer flaw that leaked AWS credentials on repo open.
Our AWS security experts can help you implement best practices across all these topics.
Contact Us