6 items across 1 section
AWS announces SSE-C will be disabled by default on new general-purpose S3 buckets starting April 2026, closing the Codefinger ransomware vector. Security Hub and Security Agent updates from re:Invent 2025 keep rolling out.
Security Agent extends preview support to GitHub Enterprise Cloud, so your code, IaC, and supply chain now sit on the same scanning surface. Network Firewall picks up GenAI traffic classification. S3 lets you change a bucket's encryption type without re-uploading objects.
Security Groups finally show a "Related Resources" tab listing every dependent resource, a quality-of-life win years overdue. Security Agent now scopes shared VPCs. Claude Opus 4.6 lands in Amazon Bedrock.
Security Agent and DevOps Agent both ship to general availability after their re:Invent 2025 preview. S3 finally rolls out the SSE-C default-off across 37 Regions, the kill announced back in January. Audit Manager stops onboarding new customers as of April 30.
AWS publishes bulletin 2026-030-AWS, a single rolling document for the Copy.fail / DirtyFrag Linux kernel privilege-escalation class. If you run Amazon Linux, Bottlerocket, ECS, EKS, EMR, Fargate, or SageMaker, this is the bulletin you bookmark. Security Agent meanwhile learns to read whole repositories.
AWS unveils Continuum, a model-agnostic vulnerability lifecycle platform, and at AWS Summit New York pushes Security Agent into threat modeling and pull-request review. AWS WAF starts charging AI bots for content. On the patch side: Kiro IDE, the AgentCore Python SDK, and five containerd CVEs.
Our AWS security experts can help you implement best practices across all these topics.
Contact Us