AWS Application and Network Load Balancers now support RFC 9151 compliant security policies

AWS Application Load Balancer (ALB) and Network Load Balancer (NLB) now support new TLS-based security policies that comply with RFC 9151 TLS server requirements for Commercial National Security Algorithm (CNSA) 1.0 suite requirements. These policies implement the cryptographic requirements defined by the US National Security Agency (NSA) for secure communications using TLS 1.2 and TLS 1.3 protocols. Customers who are required to meet CNSA 1.0 TLS security requirements can now use ALB and NLB with RFC 9151 compliant security policies. Broader interoperability policies are also supported, allowing you to implement CNSA by default while maintaining compatibility with non-CNSA clients during their transition to RFC 9151 compliance, minimizing service disruption. This feature is available for ALB and NLB in all AWS Commercial Regions, the AWS GovCloud (US) Regions, and the China region at no additional cost. To use this capability, update your existing ALB HTTPS listeners or NLB TLS listeners to a RFC 9151 compliant security policy, or select a compliant policy when creating new listeners through the AWS Management Console, CLI, API, or SDK. To learn more, visit the ALB User Guide and NLB User Guide documentation. Get started with Elastic Load Balancing.
Quelle: aws.amazon.com

Amazon EC2 C8g instances now available in additional regions

Starting today, Amazon Elastic Compute Cloud (Amazon EC2) C8g instances are available in AWS Europe (Paris), AWS Africa (Cape Town), AWS Israel (Tel Aviv), and AWS Canada West (Calgary) regions. These instances are powered by AWS Graviton4 processors and deliver up to 30% better performance compared to AWS Graviton3-based instances. Amazon EC2 C8g instances are built for compute-intensive workloads, such as high performance computing (HPC), batch processing, gaming, video encoding, scientific modeling, distributed analytics, CPU-based machine learning (ML) inference, and ad serving. These instances are built on the AWS Nitro System, which offloads CPU virtualization, storage, and networking functions to dedicated hardware and software to enhance the performance and security of your workloads.
AWS Graviton4-based Amazon EC2 instances deliver the best performance and energy efficiency for a broad range of workloads running on Amazon EC2. These instances offer larger instance sizes with up to 3x more vCPUs and memory compared to Graviton3-based Amazon C7g instances. AWS Graviton4 processors are up to 40% faster for databases, 30% faster for web applications, and 45% faster for large Java applications than AWS Graviton3 processors. C8g instances are available in 12 different instance sizes, including two bare metal sizes. They offer up to 50 Gbps enhanced networking bandwidth and up to 40 Gbps of bandwidth to the Amazon Elastic Block Store (Amazon EBS).
To learn more, see Amazon EC2 C8g Instances. To get started, see the AWS Management Console.
Quelle: aws.amazon.com

AWS Security Hub Extended adds supply chain security as its 10th category

The AWS Security Hub Extended plan now includes Supply Chain Security as its 10th security category, with Chainguard and Socket as the curated partners. As developers adopt open-source libraries at scale, security teams need confidence that the packages entering their environments are trustworthy and free from malicious code. With this addition, you can detect and block malicious dependencies before they are built into your applications, with the same streamlined activation and pay-as-you-go pricing as every other Extended category. This brings the Extended plan to 23 curated partner solutions. All solutions are on a single AWS bill and no required long-term commitments.
Security Hub Extended is a plan within AWS Security Hub that helps simplify how you procure, deploy, and integrate a full-stack enterprise security solution across endpoint, identity, email, network, data, browser, cloud, AI, security operations, and supply chain. Security findings from all participating solutions are emitted in the Open Cybersecurity Schema Framework (OCSF) and automatically aggregated in AWS Security Hub. With the Extended plan, you can combine AWS and curated partner solutions to quickly identify and respond to risks that span boundaries.
We will continue to expand the Extended plan based on customer feedback. The two new curated partner solutions are available today in all AWS commercial Regions where Security Hub is available. For a list of supported Regions, see the AWS Region table. For more information about pricing, visit the AWS Security Hub pricing page. To get started, visit the AWS Security Hub console or product page.
Quelle: aws.amazon.com

AWS Organizations now provides maximum account quota visibility in Service Quotas

AWS Organizations customers can now view their maximum number of accounts quota and its utilization directly through AWS Service Quotas instead of relying on AWS Support or AWS account teams to determine their current account limit. Customers can now proactively plan account growth with ease by monitoring their current account quota utilization and requesting increases before reaching their limit. They can view this quota by logging into management account and accessing the Service Quotas console or calling the Service Quotas GetServiceQuota API. This quota visibility is available now available in US East (N. Virginia). To learn more, see viewing service quotas in the AWS Service Quotas documentation. For more information about AWS Organizations quotas and service limits, see the AWS Organizations documentation.
Quelle: aws.amazon.com

AWS Resilience Hub now provides recommended resilience tests

AWS Resilience Hub now offers recommended resilience tests that help platform engineering and site reliability teams validate how their services respond to and recover from known failure scenarios. 
Resilience Hub provides pre-configured tests based on your service’s architecture, configuration, and resilience policy. It uses AWS Fault Injection Service (FIS) to inject controlled faults and then evaluates whether your service recovers within your defined recovery objectives. With the AWS-recommended resilience tests, teams can validate readiness for scenarios such as Availability Zone impairment, Regional impairment, and dependency failure. Each test automatically targets resources in the service, injects the required faults, produces a pass or fail outcome based on alarm evaluation and recovery objectives, then generates a detailed test report.
The recommended testing on the next generation of the AWS Resilience Hub is available in the following AWS Regions: US East (N. Virginia), US East (Ohio), US West (Oregon), Canada (Central), Europe (Ireland), Europe (London), Europe (Frankfurt), Europe (Paris), Europe (Stockholm), Asia Pacific (Mumbai), Asia Pacific (Singapore), Asia Pacific (Sydney), Asia Pacific (Tokyo), Asia Pacific (Seoul), and South America (São Paulo).
To get started, visit the AWS console. To learn more about recommended resilience testing see the product page for the next generation of AWS Resilience Hub. 
Quelle: aws.amazon.com

Amazon GameLift Streams now supports sharing streams with stream URLs

Amazon GameLift Streams now offers stream URLs, which give end users temporary, unauthenticated access to a playable stream session in a supported web browser. Recipients need no AWS account, no credentials, and no software install.
To share a playable stream, create a stream URL for a stream group and one of its applications, set how long the stream URL stays valid and how many sessions it can start, and send the link. Each person who opens the link starts an independent stream session, and Amazon GameLift Streams routes them to a nearby streaming location from the locations you selected. No client integration or backend service is required. You can create, monitor, and revoke stream URLs in the Amazon GameLift Streams console or with the new CreateStreamUrl, GetStreamUrl, ListStreamUrls, and RevokeStreamUrl APIs.
There is no additional charge for stream URLs. You are charged for the stream capacity that sessions started from a stream URL consume, as described on the Amazon GameLift Streams pricing page. For a full list of supported Regions, see the AWS Region table.
To get started, see Share stream sessions with stream URLs in the Amazon GameLift Streams Developer Guide and the CreateStreamUrl API Reference. To learn more about the service, see the Amazon GameLift Streams product page. 
Quelle: aws.amazon.com

OpenAI GPT-5.6 Sol, Terra, and Luna now support 1 million token context windows on Amazon Bedrock

GPT-5.6 Sol, Terra, and Luna now support 1 million token context windows on Amazon Bedrock, enabling you to process full codebases, lengthy documents, and multi-turn agent histories in a single request. Models reason over broader context and return more accurate, coherent responses without chunking or information loss.
With a context window size of 1 million tokens, you can analyze entire repositories in a single pass for code review and migration, process long-form legal or regulatory documents end-to-end, and maintain full conversation history in multi-step agentic workflows. Prompt caching with explicit cache breakpoints applies to long context requests, so repeated context is billed at a caching discount. 
GPT-5.6 Sol is available in the following AWS Regions: US East (N. Virginia) and US East (Ohio). GPT-5.6 Terra and Luna are available in US East (N. Virginia), US East (Ohio), and US West (Oregon). Get started with Sol, Terra, and Luna using the Amazon Bedrock Console or the Responses API on the bedrock-mantle endpoint. To learn more, see the Amazon Bedrock documentation and read the launch blog post.
Quelle: aws.amazon.com

AWS Transform continuous modernization is now generally available

AWS Transform continuous modernization is now generally available in all AWS Regions where AWS Transform is supported. This capability helps engineering teams analyze and remediate technical debt across source code repositories at scale. Teams can connect GitHub organizations, GitLab groups, and Bitbucket workspaces, run analyses on demand or on a recurring schedule, and prioritize findings across technical debt, security, agentic readiness, modernization readiness, and custom analysis criteria. With today’s launch, you can connect source code providers, initiate and schedule analyses, review findings, and create remediations directly from the AWS Transform web application. For findings with an associated remediation, continuous modernization creates branches and opens pull requests or merge requests containing validated code changes for review. Analysis and remediation run in your AWS account using your credentials, while your source code remains under your control. You can also use the AWS Transform Kiro Power, agent plugins, or AWS Transform CLI to work from your IDE or terminal, analyze local repositories, organize repositories using labels, and run analyses locally or remotely using Amazon EC2 or AWS Batch. To get started, open the AWS Transform web application or use the AWS Transform Kiro Power and agent plugins. To learn more, see AWS Transform continuous modernization in the AWS Transform User Guide.
Quelle: aws.amazon.com

AWS Transform for full-stack Windows modernization now supports offline schema transformation to Aurora PostgreSQL

Today, AWS Transform for full-stack Windows modernization announced general availability of offline source transformation, enabling customers to modernize Microsoft SQL Server databases to Amazon Aurora PostgreSQL without requiring a live database connection. AWS Transform now converts SQL Server storage objects, powered by AWS DMS, and code objects (stored procedures) using an agentic, interactive experience. Enterprises modernizing legacy .NET applications and their dependent SQL Server databases can now start their modernization by directly uploading the Data Design Language (DDL) source files from their databases.
With offline source transformation, customers upload SQL Server data design language (DDL) files, assess database and stored procedure complexity, and generate a customizable transformation plan. AWS Transform converts tables, schemas and converts code objects such as stored procedures and functions, validates functional equivalence, and deploys the converted schema to Aurora PostgreSQL. The same workflow transforms database dependent .NET applications to be PostgreSQL compatible .NET applications with updated connection strings, ADO.NET and Entity Framework data-access calls. To address remaining conversion issues, customers can iterate directly in the web console or hand off to their preferred IDE using the AWS Transform MCP server. A separate synthetic data workflow populates Aurora PostgreSQL with test data for end-to-end application validation.
AWS Transform for full-stack Windows modernization and offline source transformation is available in US East (N. Virginia). To get started, you can go to AWS Transform product page or see AWS Transform for full-stack Windows documentation.
Quelle: aws.amazon.com

AWS WAF now supports Miggo Security managed rule groups for emerging threats and AI/ML application protection

AWS WAF now supports two new partner managed rule groups from Miggo Security, available through AWS Marketplace: Miggo Rules for AWS WAF – High Emerging Application Threats, and Miggo Rules for AWS WAF – AI/ML Application Protection. These rule groups give AWS WAF customers continuously updated protection against vulnerabilities that are being actively exploited, have public proof-of-concept code, or appear in the CISA Known Exploited Vulnerabilities (KEV) catalog, without writing or maintaining custom rules. The High Emerging Application Threats rule group focuses on vulnerabilities under active exploitation, and the AI/ML Application Protection rule group focuses on generative-AI application stacks such as AI agent frameworks, LLM gateways, and model-serving infrastructure. You can subscribe to either rule group and add it to a web ACL directly in the AWS WAF console through AWS Marketplace, with no additional configuration. Both rule groups support versioning, and pricing is set by Miggo through AWS Marketplace. To get started, visit the AWS WAF console or find the Miggo rule groups in AWS Marketplace. For more information, see the AWS WAF Developer Guide. For a full list of supported Regions, visit the AWS Regional Services page.
Quelle: aws.amazon.com