Amazon Bedrock launches Web Search for OpenAI GPT models

Today, we are announcing the general availability of Web Search on Amazon Bedrock, a built-in server side tool that performs web search entirely within AWS, enabling OpenAI models (GPT-5.4, GPT-5.5, and GPT-5.6 Sol/Terra/Luna) to ground responses with current web knowledge while maintaining data residency within your secured AWS environment with zero data egress. Previously, adding web grounding required onboarding a third-party search provider, managing separate API keys and billing, building custom orchestration, and conducting additional compliance reviews for each external vendor. Web Search removes this heavy lifting by enable grounding with a single parameter in an existing API call, with no vendor onboarding, no external APIs to orchestrate, and no additional vendor security reviews to conduct. Web Search is built by Amazon, informed by years of experience across Alexa+, Amazon Quick and Kiro. It combines a web index operated by Amazon, spanning tens of billions of documents refreshed continually, with a built-in knowledge graph that provides verified facts. Rather than returning raw pages, Web Search performs semantic snippet extraction, delivering context-efficient results optimized for the model’s context window with low latency. Web Search integrates through a standardized tool-use interface, compatible with the OpenAI Responses API. Simply add the web search tool to your API call, and Bedrock handles the entire search lifecycle server-side; a single API call returns a grounded response with citations. Web Search on Amazon Bedrock is generally available today in US East (N. Virginia), US East (Ohio), and US West (Oregon). To get started, read our blog post Introducing Web Search on Amazon Bedrock for foundation model grounding, review the Web Search section in the Amazon Bedrock User Guide for technical documentation, and visit the Amazon Bedrock pricing page for cost details.
Quelle: aws.amazon.com

Amazon Connect Customer now lets you export cases to CSV from the agent workspace

Amazon Connect Customer now supports exporting cases to a CSV file directly from the agent workspace, making it easier to share case data with internal teams and external stakeholders such as vendors, legal teams, or business partners. Agents can filter and select cases and choose which case fields to include in the export. Admins can control access using a security profile permission. Cases is available in the following AWS regions: US East (N. Virginia), US West (Oregon), Canada (Central), Europe (Frankfurt), Europe (London), Asia Pacific (Seoul), Asia Pacific (Singapore), Asia Pacific (Sydney), Asia Pacific (Tokyo), and Africa (Cape Town). To learn more and get started, visit the Cases webpage and documentation.
Quelle: aws.amazon.com

[Preview Announcement] Re-introducing Forward Proxy as AWS Network Firewall Functionality

You can now use your Network Firewall with all its existing filtering capabilities and features as an explicit forward proxy. On Nov 25, 2025, AWS introduced Network Firewall proxy in public preview to help customers exert centralized security controls against data exfiltration and malware injection. At the time, the Network Firewall proxy was introduced as a standalone product, separate from Network Firewall transparent firewall and used its own separate proxy security policy. Customers who tested it in preview shared that they want the Network Firewall proxy to maintain parity with Network Firewall’s existing set of capabilities and use the same security policy across the two functionalities. In keeping with customer feedback, we are reintroducing explicit proxy as a functionality of Network Firewall. With this launch, you can configure Network Firewall with your existing Firewall policy in a new no-source-preservation deployment where it can be used as an explicit proxy with all its existing features including managed rule groups, active threat defense, Geo-IP filtering, URL and domain category filtering, container attribute-based rules for Amazon EKS and Amazon ECS, etc. You can create a single security policy and use it for both explicit proxy and transparent firewall functionalities. Try out AWS Network Firewall in no-source-preservation deployment with proxy functionality in your test environment today in US East (Ohio) region. no-source-preservation Network Firewall is available for free during public preview. For more information, check no-source-preservation Network Firewall documentation.
Quelle: aws.amazon.com

Amazon RDS for SQL Server now support BYOM in additional commercial regions

Amazon Relational Database Service (Amazon RDS) for SQL Server now supports Bring Your Own Media (BYOM) in 10 additional AWS Regions: Asia Pacific (Taipei, Hyderabad, Jakarta, Malaysia, Melbourne, New Zealand, Thailand), Europe (Milan, Spain), and Mexico (Central). With BYOM, you can adopt Amazon RDS as a managed database service and reuse your existing Microsoft SQL Server licenses with active Software Assurance, through Microsoft’s License Mobility program. BYOM is supported on SQL Server 2019, 2022, and 2025. Amazon RDS for SQL Server BYOM is integrated with AWS License Manager so you can track license usage across your AWS environment for compliance. To learn more, see Bring Your Own Media (BYOM) for RDS for SQL Server. For pricing and regional availability, see Amazon RDS for SQL Server Pricing.
Quelle: aws.amazon.com

Amazon EC2 I8g instances now available in AWS Europe (Paris), Asia Pacific (Jakarta) regions

AWS announces the general availability of Amazon EC2 Storage Optimized I8g instances in AWS Europe (Paris) and Asia Pacific (Jakarta) regions. I8g instances are powered by AWS Graviton4 processors and offer the best compute performance in Amazon EC2 for storage-intensive workloads. I8g instances use the third generation AWS Nitro SSDs, local NVMe storage that deliver up to 65% better real-time storage performance per TB while offering up to 50% lower storage I/O latency and up to 60% lower storage I/O latency variability compared to I4g instances. These instances are built on the AWS Nitro System, which offloads CPU virtualization, storage, and networking functions to dedicated hardware and software enhancing the performance and security for your workloads.
Amazon EC2 I8g instances are designed for I/O intensive workloads that require rapid data access and real-time latency from storage. These instances excel at handling transactional, real-time, distributed databases, including MySQL, PostgreSQL, Hbase and NoSQL solutions like Aerospike, MongoDB, ClickHouse, and Apache Druid. They’re also optimized for real-time analytics platforms such as Apache Spark, data lakehouse and AI LLM pre-processing for training. I8g instances are available in eleven different sizes including two metal sizes, 1.5 TiB of memory, and 45 TB local instance storage. They deliver up to 100 Gbps of network performance bandwidth, and 60 Gbps of dedicated bandwidth for Amazon Elastic Block Store (EBS).
To learn more, visit Amazon EC2 I8g instances. To begin your Graviton journey, visit the Level up your compute with AWS Graviton page. To get started, see AWS Management Console, AWS Command Line Interface (AWS CLI), and AWS SDKs.
Quelle: aws.amazon.com

AWS Application and Network Load Balancers now support RFC 9151 compliant security policies

AWS Application Load Balancer (ALB) and Network Load Balancer (NLB) now support new TLS-based security policies that comply with RFC 9151 TLS server requirements for Commercial National Security Algorithm (CNSA) 1.0 suite requirements. These policies implement the cryptographic requirements defined by the US National Security Agency (NSA) for secure communications using TLS 1.2 and TLS 1.3 protocols. Customers who are required to meet CNSA 1.0 TLS security requirements can now use ALB and NLB with RFC 9151 compliant security policies. Broader interoperability policies are also supported, allowing you to implement CNSA by default while maintaining compatibility with non-CNSA clients during their transition to RFC 9151 compliance, minimizing service disruption. This feature is available for ALB and NLB in all AWS Commercial Regions, the AWS GovCloud (US) Regions, and the China region at no additional cost. To use this capability, update your existing ALB HTTPS listeners or NLB TLS listeners to a RFC 9151 compliant security policy, or select a compliant policy when creating new listeners through the AWS Management Console, CLI, API, or SDK. To learn more, visit the ALB User Guide and NLB User Guide documentation. Get started with Elastic Load Balancing.
Quelle: aws.amazon.com

Amazon EC2 C8g instances now available in additional regions

Starting today, Amazon Elastic Compute Cloud (Amazon EC2) C8g instances are available in AWS Europe (Paris), AWS Africa (Cape Town), AWS Israel (Tel Aviv), and AWS Canada West (Calgary) regions. These instances are powered by AWS Graviton4 processors and deliver up to 30% better performance compared to AWS Graviton3-based instances. Amazon EC2 C8g instances are built for compute-intensive workloads, such as high performance computing (HPC), batch processing, gaming, video encoding, scientific modeling, distributed analytics, CPU-based machine learning (ML) inference, and ad serving. These instances are built on the AWS Nitro System, which offloads CPU virtualization, storage, and networking functions to dedicated hardware and software to enhance the performance and security of your workloads.
AWS Graviton4-based Amazon EC2 instances deliver the best performance and energy efficiency for a broad range of workloads running on Amazon EC2. These instances offer larger instance sizes with up to 3x more vCPUs and memory compared to Graviton3-based Amazon C7g instances. AWS Graviton4 processors are up to 40% faster for databases, 30% faster for web applications, and 45% faster for large Java applications than AWS Graviton3 processors. C8g instances are available in 12 different instance sizes, including two bare metal sizes. They offer up to 50 Gbps enhanced networking bandwidth and up to 40 Gbps of bandwidth to the Amazon Elastic Block Store (Amazon EBS).
To learn more, see Amazon EC2 C8g Instances. To get started, see the AWS Management Console.
Quelle: aws.amazon.com

AWS Security Hub Extended adds supply chain security as its 10th category

The AWS Security Hub Extended plan now includes Supply Chain Security as its 10th security category, with Chainguard and Socket as the curated partners. As developers adopt open-source libraries at scale, security teams need confidence that the packages entering their environments are trustworthy and free from malicious code. With this addition, you can detect and block malicious dependencies before they are built into your applications, with the same streamlined activation and pay-as-you-go pricing as every other Extended category. This brings the Extended plan to 23 curated partner solutions. All solutions are on a single AWS bill and no required long-term commitments.
Security Hub Extended is a plan within AWS Security Hub that helps simplify how you procure, deploy, and integrate a full-stack enterprise security solution across endpoint, identity, email, network, data, browser, cloud, AI, security operations, and supply chain. Security findings from all participating solutions are emitted in the Open Cybersecurity Schema Framework (OCSF) and automatically aggregated in AWS Security Hub. With the Extended plan, you can combine AWS and curated partner solutions to quickly identify and respond to risks that span boundaries.
We will continue to expand the Extended plan based on customer feedback. The two new curated partner solutions are available today in all AWS commercial Regions where Security Hub is available. For a list of supported Regions, see the AWS Region table. For more information about pricing, visit the AWS Security Hub pricing page. To get started, visit the AWS Security Hub console or product page.
Quelle: aws.amazon.com

AWS Organizations now provides maximum account quota visibility in Service Quotas

AWS Organizations customers can now view their maximum number of accounts quota and its utilization directly through AWS Service Quotas instead of relying on AWS Support or AWS account teams to determine their current account limit. Customers can now proactively plan account growth with ease by monitoring their current account quota utilization and requesting increases before reaching their limit. They can view this quota by logging into management account and accessing the Service Quotas console or calling the Service Quotas GetServiceQuota API. This quota visibility is available now available in US East (N. Virginia). To learn more, see viewing service quotas in the AWS Service Quotas documentation. For more information about AWS Organizations quotas and service limits, see the AWS Organizations documentation.
Quelle: aws.amazon.com

AWS Resilience Hub now provides recommended resilience tests

AWS Resilience Hub now offers recommended resilience tests that help platform engineering and site reliability teams validate how their services respond to and recover from known failure scenarios. 
Resilience Hub provides pre-configured tests based on your service’s architecture, configuration, and resilience policy. It uses AWS Fault Injection Service (FIS) to inject controlled faults and then evaluates whether your service recovers within your defined recovery objectives. With the AWS-recommended resilience tests, teams can validate readiness for scenarios such as Availability Zone impairment, Regional impairment, and dependency failure. Each test automatically targets resources in the service, injects the required faults, produces a pass or fail outcome based on alarm evaluation and recovery objectives, then generates a detailed test report.
The recommended testing on the next generation of the AWS Resilience Hub is available in the following AWS Regions: US East (N. Virginia), US East (Ohio), US West (Oregon), Canada (Central), Europe (Ireland), Europe (London), Europe (Frankfurt), Europe (Paris), Europe (Stockholm), Asia Pacific (Mumbai), Asia Pacific (Singapore), Asia Pacific (Sydney), Asia Pacific (Tokyo), Asia Pacific (Seoul), and South America (São Paulo).
To get started, visit the AWS console. To learn more about recommended resilience testing see the product page for the next generation of AWS Resilience Hub. 
Quelle: aws.amazon.com