Posts

Amazon ECS adds Amazon VPC Lattice support for blue/green, linear, and canary deployments - devamazonaws.blogspot.com

Amazon Elastic Container Service (Amazon ECS) now supports built-in blue/green, linear, and canary deployment strategies for ECS services using Amazon VPC Lattice . Applications that use VPC Lattice for service-to-service communication across VPCs and AWS accounts can now take advantage of managed traffic shifting natively from Amazon ECS when rolling out updates. With this launch, ECS customers using VPC Lattice can shift traffic in a controlled manner during deployments, choosing how quickly traffic moves based on their confidence in each release: all at once with blue/green, in equal increments with linear, or starting with a small percentage with canary. Teams can validate new versions with test traffic before shifting production traffic, and run custom validation steps or manual approvals with deployment lifecycle hooks, including Lambda and pause hooks. These services can also use Amazon CloudWatch alarms and the Amazon ECS deployment circuit breaker to automatically roll back ...

AWS Security Hub introduces remediation plans to prioritize and fix security exposures - devamazonaws.blogspot.com

AWS Security Hub now offers remediation plans that group related exposure findings sharing a root cause. Instead of addressing each exposure individually, you can now fix a single underlying resource, such as a misconfigured setting or overly permissive policy, and resolve or reduce the severity of multiple exposures at once. Each remediation plan includes prioritization guidance (Critical, High, Medium, or Low), impact assessment, and detailed step-by-step instructions with examples in multiple formats including AWS CLI, Terraform, CloudFormation, Python, and CDK. Security Hub automatically prioritizes plans so those reducing the most risk appear first, helping you focus remediation efforts where they matter most. AI agents can also programmatically consume remediation plans through the API to automate security fixes across your environment. Remediation plans are available in every AWS Region where AWS Security Hub is available and at no additional cost under AWS Security Hub Essent...

AWS Budgets now supports email verification for notification subscribers - devamazonaws.blogspot.com

AWS Budgets lets you set custom cost and usage thresholds and alerts you by email when your spending crosses the threshold. AWS Budgets now verifies new email subscribers before sending them budget alerts. When you add an email address to a budget notification, AWS Budgets sends a verification email to that address, and the address begins receiving notifications once the recipient confirms it. Verification applies to email addresses added from 9/30/26 onward. Addresses already subscribed on existing budgets are unaffected and need no action. For a new address, the recipient confirms it by following the link in the verification email, which opens the AWS Management Console. The AWS Budgets console shows the verification status of every subscriber, with a resend option for addresses still pending confirmation. AWS Budgets delivers these notifications through AWS User Notifications, and recipients can opt out at any time. AWS Budgets email verification is available in all AWS Regions, ...

AWS Continuum for Penetration Testing now available in 6 additional Regions - devamazonaws.blogspot.com

AWS Continuum for Penetration Testing now available in 6 additional Regions AWS Continuum for Penetration Testing (AWS Security Agent) is a managed security service that enables AWS customers to conduct  penetration testing against their web applications and APIs. Previously limited in geographic reach, the service now addresses the growing need for localized security testing by expanding into six additional AWS Regions: Asia Pacific (Seoul), Canada (Montreal), Europe (London), US East (Columbus), Europe (Paris), and Europe (Stockholm). This expansion helps organizations operating across these geographies meet data residency requirements while maintaining robust security testing programs. With this regional expansion, customers can now run penetration testing workloads closer to their production environments. Security and compliance teams can leverage AWS Continuum for Penetration Testing for critical use cases including vulnerability assessments, compliance validation agai...

Amazon Bedrock expands Claude models in-region support in the UK (London) - devamazonaws.blogspot.com

We're excited to announce in-region support for Anthropic's Claude Opus 5.5 and Claude Sonnet 5 on Amazon Bedrock in the UK (London) Region. Customers who need to process data within the United Kingdom, including those in financial services, healthcare, and the public sector, can now use these models at scale while keeping inference in-country. In the UK, Amazon Bedrock supports Claude Opus 5.5 and Claude Sonnet 5 with in-region inference on the bedrock-runtime endpoint in the London (eu-west-2) Region. Amazon Bedrock processes inference requests and data within the Region you call, and the processing never leaves that Region. For the most current information about model availability in each Region, see Regional availability by models in the Amazon Bedrock User Guide. To get started with Claude models on Amazon Bedrock, visit the Amazon Bedrock console. Post Updated on September 30, 2026 at 06:00PM

[MS] Windows on AArch64 also provides for hot-patching, but it's much simpler than on x86 - devamazonaws.blogspot.com

I have noted in the past that x86-32 and x86-64 versions of Windows are careful to start each function with a patch point. But what about AArch64 (known in Windows as arm64)? Windows also inserts patch points for functions on AArch64, but they are much simpler due to the fixed-length instruction set. You don't have to worry about patching an instruction when the instruction pointer happens to be in the middle of the byte sequence, because the instruction pointer is never in the middle of the byte sequence. The instruction pointer is always on a multiple of 4. Therefore, there is no special restriction on the first instruction of a function. All instructions meet the requirements of being atomically updatable without risk of the instruction pointer being in the middle of the instruction. Before each function is a patch space of 12 bytes, which is exactly enough for a three-instruction trampoline : ; overwrite the patch space with these three instructions adrp xip0, ...

Amazon WorkSpaces Core Managed Instances adds support for NVIDIA Blackwell GPU - devamazonaws.blogspot.com

Amazon WorkSpaces Core Managed Instances now supports Graphics G7 instances, powered by NVIDIA RTX PRO 4500 Blackwell Server Edition GPUs and Intel Xeon 6 processors. G7 instances deliver up to 2.1X better performance for graphics-intensive workloads compared to previous generation G6 instances. With Graphics G7, customers can run demanding professional applications such as CAD/CAM, 3D rendering, scientific visualization, video editing, and AI-assisted design workflows at higher fidelity and frame rates. G7 instances feature 32 GB of GDDR7 GPU memory per GPU and 2.67X faster memory bandwidth, enabling larger, more complex 3D scenes and models. Six instance sizes are available with 1 to 8 GPUs, vCPUs ranging from 8 to 192, and system memory from 32 GB to 768 GB, with support for Linux and Windows, including bring-your-own-license. Graphics G7 instances for WorkSpaces Core Managed Instances are available in US East (N. Virginia), US East (Ohio), US West (Oregon), and Europe (Spain). Ad...