Amazon S3 adds additional policy details to access denied error messages

Amazon S3 now includes the specific AWS Identity and Access Management (IAM) and AWS Organizations policy Amazon Resource Name (ARN) in HTTP 403 Access Denied error messages for same-account and same-organization requests. This helps you quickly identify the exact policy responsible for a denied request and remediate the issue directly.
Previously, S3 access denied error messages included the policy type and reason for denial, but when multiple policies of the same type existed, you still had to manually inspect each one to pinpoint the root cause. Now the error message includes the specific policy ARN for explicit deny cases, covering Service Control Policies (SCPs), Resource Control Policies (RCPs), identity-based policies, session policies, and permission boundaries.
This capability is available in all AWS Regions, including the AWS GovCloud (US) Regions and the AWS China Regions. To learn more about how to troubleshoot access denied errors in Amazon S3, visit the S3 User Guide and the IAM troubleshooting documentation.
Quelle: aws.amazon.com

Daybreak Red and Daybreak Blue from OpenAI are now available to eligible customers on Amazon Bedrock

Security teams can now access Daybreak Red and Daybreak Blue from OpenAI on Amazon Bedrock. Both are part of Daybreak, the cyber defense initiative from OpenAI that gives defenders governed access to frontier AI for cybersecurity work.
Daybreak Blue is the starting point for most security teams across defensive workflows including vulnerability discovery, detection engineering, and incident response. Daybreak Red is designed for advanced, authorized tasks such as vulnerability research, exploit reproduction, and mitigation development. For these tasks, a lower refusal threshold matched by stronger identity verification, monitoring, and access controls improves the speed and depth of an investigation. Both models run on Bedrock’s next-generation inference engine with zero-operator access (ZOA) enforced at the chip. Your inference data is not used for model training, and neither model requires you to opt into sharing your data with OpenAI.
Daybreak Red: GPT-5.6 Cyber and Daybreak Blue: GPT-5.6 Sol are now available to eligible customers on Amazon Bedrock in the following AWS Region: US East (N. Virginia). Access to the models requires enrollment in Daybreak access from OpenAI. To enroll, contact OpenAI or reach out to your AWS account team for guidance on eligibility. Once approved, work with your account team to request access on AWS. To learn more, read the blog.
Quelle: aws.amazon.com

Spot Placement Score now includes Local Zones

Today, AWS announces support for AWS Local Zones in Spot placement score, helping you identify locations where your Spot capacity request is most likely to succeed. Spot placement score evaluates your target capacity and compute requirements and returns scores for AWS Regions or Availability Zones.
Previously, Spot placement scores excluded local zone capacity information when reporting zonal and regional scores. Now, you can optionally request local zones to be included in the zonal and regional score responses giving you a broader view of your Spot capacity options.
You can use Spot placement score through EC2 Spot Console, AWS CLI, or SDK. To learn more about Spot placement score see Spot placement score documentation.
Quelle: aws.amazon.com

Amazon Quick Microsoft 365 extensions are now generally available

Today, Amazon Quick announces the general availability of Microsoft 365 extensions for Excel, PowerPoint, Word, and Outlook. These extensions enable Quick to perform tasks directly within users’ M365 environments, using AI to handle complex local tasks such as redlining documents, building financial models, creating presentation-ready decks, and managing Outlook inboxes.
The Excel extension helps with complex spreadsheet analysis, creating pivot tables and charts, and importing and cleaning data. The PowerPoint extension helps you create and refine presentations from Quick data using organization-defined templates. The Word extension generates formatted documents with Word primitives, makes sweeping edits with track changes enabled, and participates as a reviewer in comments. The Outlook extension performs inbox and calendaring tasks such as prioritizing emails, organizing your inbox, scheduling meetings, and drafting replies using your Quick data and entire inbox context.
These extensions transform daily work across teams. Finance teams can build complex models by describing what they need. Sales teams can draft proposals that automatically pull from CRM data. Marketing teams can create branded presentations without manual formatting. Legal teams can streamline contract reviews. Operations teams can manage email workflows and schedule meetings intelligently, and IT teams can automate routine data analysis that previously required manual effort.
Amazon Quick Microsoft 365 extensions are available in US East (N. Virginia), US West (Oregon), Asia Pacific (Sydney), Europe (Ireland), Asia Pacific (Tokyo), and Europe (Frankfurt). To learn more, see Amazon Quick for Microsoft 365: Agentic AI where you work, and download extensions on the Quick download page.
Quelle: aws.amazon.com

Amazon Quick adds deny by default for custom permissions

Amazon Quick custom permissions now include deny by default, a governance setting that automatically restricts new AI capabilities before they reach users. Previously, new AI capabilities were available to all users on release, requiring administrators to react after the fact. With deny by default, administrators restrict the AI capability category in a custom permissions profile and assign it to users, roles, or the entire account. Quick then denies any new AI capability at launch for those users. Restricting a category also restricts existing capabilities in it. Administrators explicitly allow each capability when ready. The restriction applies only to the profile you configure. Configure deny by default in Manage account in Amazon Quick or through the AWS CLI. To learn more, see Custom permissions deny by default. Deny by default is available in all AWS Regions where Amazon Quick is available.
Quelle: aws.amazon.com

AWS IAM now provides role manager to set up IAM roles automatically

Today, AWS announces the general availability of role manager, a capability in AWS Identity and Access Management (IAM) that automatically sets up the IAM roles your AWS services need. When you set up a supported service in the console, role manager creates a default role on your behalf, or reuses one that already exists in your account if it already matches the required permissions. You can enable or disable role manager at any time, as well as inspect the AWS-managed templates that role manager deploys on your behalf.
Role manager supports 6 AWS service consoles at launch, including AWS Lambda and Amazon EventBridge. For example, when you create an AWS Lambda function, role manager applies the AWS-managed template for that workflow. Roles created via role manager appear in the IAM console as standard IAM roles that you fully control, and you can identify the ones role manager created. When you are ready to tighten permissions, you can disable role manager and use IAM Access Analyzer to refine each role to only the permissions it needs.
Role manager is available in all AWS Regions, except the AWS GovCloud (US) Regions and the China Regions.
To learn more, see How AWS IAM role manager rethinks the starting point for IAM roles on the AWS Security Blog, or Create roles automatically with role manager in the IAM User Guide.
Quelle: aws.amazon.com

AWS Global View now offers an interactive map view for AWS Regions and AWS Local Zones

Today, AWS announces the addition of an interactive map view to AWS Global View in the AWS Management Console, providing a visual way to explore AWS Global Infrastructure.
Previously, customers had to scan through a list of AWS locations in AWS Global View. With this new capability, customers can toggle between the interactive map view and the existing list view, making it easier to visualize their global AWS infrastructure footprint. 
When customers select the map view, they will see all AWS Regions and AWS Local Zones plotted on an interactive map. This capability helps customers make informed infrastructure planning decisions by visualizing already enabled AWS locations and the full range of AWS locations available to them, all in a single glance.
This capability is available across all public AWS Regions. To get started, navigate to the Regions and Zones page in AWS Global View console. For more information, see the AWS Global View documentation.
Quelle: aws.amazon.com

Amazon Quick agentic AI capabilities are now available in AWS GovCloud (US-West)

Today, AWS announces that Amazon Quick’s agentic AI capabilities are now available in AWS GovCloud (US-West), bringing an agentic AI teammate to government and regulated-industry teams within an isolated, FedRAMP Class D (formerly High) authorized environment. Building on the analytics and business intelligence capabilities already available to customers in AWS GovCloud (US), Quick now turns questions into actions, helping teams drive mission-critical decisions faster without switching applications.
With this launch, teams can build custom chat agents tailored to mission-specific workflows — including procurement, ATO compliance, and grants management — while keeping data hosted and processed entirely within the AWS GovCloud (US-West) Region. Spaces enforce least-privilege access by scoping information to the appropriate program office or mission area, ensuring analysts only access mission-relevant data. Quick also integrates with tools teams already rely on, including Microsoft 365, SharePoint, and OneDrive via GCC High connectors, as well as browser extensions.
AWS GovCloud (US) Regions are isolated AWS Regions operated by U.S. citizens on U.S. soil, purpose-built to host sensitive data and regulated workloads. Customers can address the most stringent U.S. government security and compliance requirements, including the FedRAMP Class D (formerly High) baseline, Department of Defense Cloud Computing Security Requirements Guide (DoD SRG) Impact Levels 4 and 5, International Traffic in Arms Regulations (ITAR), Criminal Justice Information Services (CJIS), and Federal Information Processing Standard (FIPS) 140-3. Inference on authorized foundation models is processed within the AWS GovCloud (US-West) Region, and enterprise governance features are available at launch.
With this launch, Amazon Quick’s agentic AI capabilities are available in 8 AWS Regions: US East (N. Virginia), US West (Oregon), Europe (Frankfurt, Ireland, London), Asia Pacific (Sydney, Tokyo), and AWS GovCloud (US-West). 
To learn more, visit the Amazon Quick product page and AWS GovCloud (US) documentation
Quelle: aws.amazon.com

Amazon Connect Customer supports manual assignment of queued agent-first callbacks

Amazon Connect Customer now lets agents view and self-assign queued agent-first callbacks alongside emails, tasks, and chats. This gives agents the option to prioritize work that needs immediate follow-up or for which they already have relevant context. For example, an agent familiar with a customer’s issue can assign the callback to themselves, avoiding another handoff and helping resolve the issue faster.
This feature is available in all AWS Regions where Amazon Connect Customer is available. To learn more about how to use queued callbacks, refer to our documentation Access the Worklist app and Set up queued callbacks. For more information about Amazon Connect Customer, visit our product page.
Quelle: aws.amazon.com

Amazon EKS now supports advanced Kubernetes control plane configuration parameters

Amazon Elastic Kubernetes Service (Amazon EKS) now supports configuring parameters for Kubernetes control plane components including the scheduler, controller manager, and API server. You can tune pod placement strategies to improve resource utilization, adjust how quickly horizontal pod autoscaling responds to changes in demand, set resource lifecycle parameters such as event retention duration, and more. Cluster administrators now have more control over Kubernetes control plane parameters beyond the defaults. For example, you can set the scheduler’s node resource fit strategy parameter to MostAllocated, which packs pods onto nodes that are already well utilized and helps you run the same workloads on fewer nodes. The default LeastAllocated strategy spreads pods across nodes, and you can keep it where headroom matters more than density. You can configure Kubernetes control plane parameters in any AWS Region where Amazon EKS is available. For the full list of configurable parameters and to learn more, see Control plane configuration in the Amazon EKS User Guide.
Quelle: aws.amazon.com