9 items across 2 sections
AWS announces SSE-C will be disabled by default on new general-purpose S3 buckets starting April 2026, closing the Codefinger ransomware vector. Security Hub and Security Agent updates from re:Invent 2025 keep rolling out.
Security Hub Extended Plan reaches GA with 14+ partners on day one, the launch most enterprises have been waiting for. LexisNexis loses 2 GB via a misconfigured AWS environment. Three AWS-LC crypto library CVEs land in one drop. VPC Encryption Controls move from preview to paid.
Security Hub Extended officially expands to AWS, Azure, GCP, OCI, and Kubernetes, the long-anticipated cross-cloud play. European Sovereign Cloud completes SOC 2 Type 2 and BSI C5 audits. IAM Roles Anywhere ships post-quantum signing via ML-DSA. Inspector Classic gets a May 2026 EOL date.
Security Hub learns to find identity risk that no one is using: unused IAM permissions, roles, and credentials, measured against 90 days of real activity. The Extended plan grows to 21 partners across 9 categories. Secrets Manager Agent picks up pre-fetching and cross-account role assumption, and Amazon Inspector Classic reaches end of support.
Sygnia documents a lone actor compromising a global enterprise's AWS estate in under 72 hours with AI-assisted workflows. Wiz finds the same symlink trust flaw in six AI coding assistants. On defense: Security Hub gains internet-facing network scanning and AWS Config adds 191 managed rules.
GuardDuty extends threat detection to Bedrock and SageMaker workloads, Security Hub goes multicloud with Azure support and an AI asset inventory, and Cognito removes the last big migration blocker by importing password hashes. Seven AWS bulletins land in four days, including a prompt-and-response leak in AgentCore telemetry.
Comprehensive guide to securing AWS CloudTrail. Covers organization trails, KMS encryption, log integrity validation, S3 bucket hardening, CloudWatch integration, data events, Network Activity Events, Insights, SCP anti-tampering, CloudTrail Lake, and continuous audit.
Comprehensive guide to securing AWS Secrets Manager. Covers automatic rotation, custom Lambda rotation, KMS encryption, resource policies, VPC endpoints, multi-region replication, batch retrieval, and continuous compliance.
Comprehensive guide to AWS Security Hub for centralized security posture management. Covers central configuration, security standards (FSBP, CIS v5.0), automation rules, cross-region aggregation, custom insights, integrations with GuardDuty, Inspector, and Config, and operational best practices for multi-account environments.
Our AWS security experts can help you implement best practices across all these topics.
Contact Us