The week in one paragraph
79 announcements across five working days, weighted heavily towards security and governance, with Wednesday 30 September carrying 25 of them on its own. Five deep-dives went out, one per news day, and three of them landed on the same failure shape without being chosen for it: a configuration that is absent rather than wrong. S3 Vectors was returning fewer results than asked for because a filter arrived too late. A GuardDuty declarative policy silently drops every feature a Region override forgets to re-list. An ECS linear deployment accepts two values that are individually valid and together exceed a third documented timeout. None of the three produces an error.
The other through-line is that AWS spent the week wiring governance into places it had not reached. GuardDuty got declarative policies, Security Hub got remediation plans and absorbed GuardDuty Runtime Monitoring into its Threat Analytics plan, Secrets Manager got posture recommendations, IAM Identity Center widened its multi-Region footprint, and AWS Health started tracking software version lifecycles. Five separate services, one direction of travel.
Covered in depth
One post per news day. The column that matters is the last one — what the announcement did not say.
| News date | Post | What the announcement left out |
|---|---|---|
| 28 Sep | #42 — The air gap is that they are not in your account | The backups sit in an AWS Backup service-owned account, which CloudTrail reports as shared outside your organization. Always compliance-mode locked, 7-day minimum retention, KMS key immutable after creation, and RAM sharing to individual account IDs only. |
| 29 Sep | #43 — The third agent runtime | Bedrock Agents is now Bedrock Agents Classic and closed to new customers, while AgentCore Harness already offers a managed agent loop that already reaches OpenAI. Three overlapping runtimes, one being retired quietly. |
| 30 Sep | #44 — The filter ran after the search | The cutover is a date, not a flag: buckets created before 30 September 2026 are CLASSIC, and the docs now admit that on a CLASSIC index "queries with filters may return fewer than top K results". The 5x figure is a confession about the old behaviour. |
| 1 Oct | #45 — A Regional override replaces the default | A Region block "fully replaces the default for that Region" rather than extending it, so an override written to disable one feature drops everything it did not re-list. Omitting the default block forfeits automatic coverage of future Regions, and detaching departs from the general declarative-policy rollback rule. |
| 2 Oct | #46 — The most cautious deployment the API accepts cannot finish | stepPercent goes to 3.0 and stepBakeTimeInMinutes to 1440; together they are 33 days against a 30-day overall deployment timeout. CloudFormation caps the whole deployment at 36 hours. And the circuit breaker is rolling-update only, so these strategies roll back on alarms or not at all. |
Two Architecture Series posts this week sit directly against the week's news rather than beside it. #35's seven-gate evaluation order is the permissions counterpart to GuardDuty's declarative policies — one denies API calls, the other enforces configuration — and #71, published this morning on AWS Private CA, is the service behind Friday's AgentCore Gateway private-TLS announcement.
What else shipped, by domain
Security and governance
The densest cluster of the week, and all of it unwritten.
Security Hub remediation plans arrived to "prioritize and fix security exposures", and
separately GuardDuty Runtime Monitoring is now included in the Security Hub Threat Analytics
plan — a packaging change worth reading carefully alongside #45, because
runtime_monitoring is one of the eight keys a GuardDuty declarative policy
governs, so enablement and billing now arrive from two different directions.
Secrets Manager gained actionable posture recommendations in the console.
IAM Identity Center extended multi-Region support to more Regions.
AgentCore Gateway began accepting private TLS certificates for VPC endpoints.
S3 Object Lock variable retention with event holds reached GovCloud (US).
Data and analytics
DynamoDB filtered export to S3 is the notable one — exporting a subset rather than the whole table changes the economics of feeding a lake from an operational store. Redshift gained cross-Region queries for data lakes, Glue Data Catalog added table optimization, statistics and crawlers for Apache Iceberg V3, EMR Serverless got terabyte-scale shuffle on Serverless Storage, and S3 Tables raised the limit to 100 table buckets per Region per account.
Databases
Aurora DSQL partial indexes — an index over a subset of rows, which "improves query performance and lowers index storage cost" — is the most interesting, because DSQL's pricing model makes storage decisions visible in a way provisioned engines do not. DocumentDB had a strong week with retryable writes plus five MongoDB aggregation stages and change stream capabilities in 8.0.2. Aurora and RDS for PostgreSQL shipped the usual minor-version sweep, and Aurora Serverless gained instant 16-ACU scaling.
Compute and containers
EKS and EKS Distro support Kubernetes 1.37, which starts the usual upgrade clock. EC2 future-dated Capacity Reservations can now have their start dates postponed — small, and genuinely useful if you have ever had a reservation activate against a project that slipped.
AI and agents
Besides Bedrock Managed Agents (covered in #43): GPT-6 Astra gained UltraFast mode on Bedrock, GPT-6.1 Sol reached GA, Grok 4.7 and Claude Sonnet 5.5 became available, Claude model availability expanded to India, South Korea and Singapore, and the Well-Architected Agent entered preview. The AWS MCP Server reached six additional Regions.
Operations and cost
AWS Health's version catalog is the sleeper item of the week: "a centralized source of lifecycle information for software versions across AWS services". Anyone who has tried to build an end-of-life inventory across RDS engine versions, EKS versions, Lambda runtimes and managed Kafka by scraping documentation should look at this before building it again. Systems Manager documents can now be shared through AWS RAM, ElastiCache for Valkey gained OpenTelemetry metrics and detailed monitoring, Transfer Family supports custom CloudWatch log groups for managed workflows, and Budgets added email verification for notification subscribers.
Security bulletins
Three on 1 October, of which one is the kind this series keeps finding:
CVE-2026-104002, fail-open error handling in the data masking utility in Powertools for
AWS Lambda (Python) — a masking utility that fails open does not mask. Also
CVE-2026-97662, argument injection in the security-agent-mcp-server
diff scan, and CVE-2026-104020, uncontrolled recursion in the Ion reader in Amazon Ion
Python.
What I would act on
1. Audit existing GuardDuty Region overrides today. This is the only item of the week that can already be configured wrong rather than becoming wrong later. If you piloted declarative policies and wrote a Region block to adjust one feature, that block replaced the default for that Region and silently dropped every feature it did not re-list. Check the account status report, not the policy document — the policy cannot show you a Region it never asserted anything about.
2. Multiply your ECS linear deployment settings. If any service uses the
LINEAR strategy with a small step percent and a long step bake time, compute
steps × bake time and compare it against 36 hours if CloudFormation deploys that
service. Nothing warns you — both values are inside their documented ranges, and the failure is a
timeout that rolls back a revision already serving most of your traffic.
3. Check whether your S3 Vectors buckets are CLASSIC. Every
vector bucket created before 30 September 2026 is, and on a CLASSIC index a
selective filter can return fewer results than you asked for with no error. If you run retrieval over a
filtered corpus, this has been quietly costing you recall. The fix is a new bucket, not a setting.
4. Look at the AWS Health version catalog before your next end-of-life exercise. Low urgency, high leverage. Software lifecycle tracking across AWS services has been a bespoke scraping job in most organisations; a first-party catalogue changes whether that job needs to exist.
One thing I would specifically not rush: GuardDuty Runtime Monitoring moving into the Security Hub Threat Analytics plan. It is a packaging change, the cost question depends on which plan you are already on, and it interacts with declarative-policy enablement in a way worth working out deliberately rather than in the week it shipped.
Complete inventory
All 79 announcements from the AWS What's New feed for 28 September to 2 October 2026, newest first, with AWS's own one-line summary for each. Built from the raw feed rather than summarised, and every link verified to return HTTP 200 at publication.
| Day | Announcements |
|---|---|
| Monday 28 September | 10 |
| Tuesday 29 September | 19 |
| Wednesday 30 September | 25 |
| Thursday 1 October | 16 |
| Friday 2 October | 9 |
| Total | 79 |
Friday 02 October — 9 announcements
- Amazon ECS adds Amazon VPC Lattice support for blue/green, linear, and canary deploymentsAmazon Elastic Container Service (Amazon ECS) now supports built-in blue/green, linear, and canary deployment strategies for ECS services using Amazon VPC Lattice .
- AWS Health introduces the version catalog for software lifecycle managementToday, AWS Health introduces the version catalog which provides a centralized source of lifecycle information for software versions across AWS services.
- Amazon Aurora DSQL now supports partial indexesAmazon Aurora DSQL now lets you build an index over a specific subset of a table, storing only qualifying rows rather than every row in the entire table, which improves query performance and lowers index storage cost.
- Amazon EKS and Amazon EKS Distro now support Kubernetes version 1.37Kubernetes version 1.37 introduced several new features and bug fixes, and AWS is excited to announce that you can now use Amazon Elastic Kubernetes Service (EKS) and Amazon EKS Distro to run Kubernetes version 1.37.
- AWS Brazil automates distribution of non-Brazilian software product licenses to Brazilian customersAWS Brazil now provides an automated distribution workflow through the AWS Brazil 2P Distribution Program.
- The AWS MCP Server is now available in six additional AWS RegionsThe AWS MCP Server is now available in six additional AWS Regions: Asia Pacific (Singapore), Asia Pacific (Sydney), Asia Pacific (Tokyo), Europe (Ireland), Europe (London), and US West (Oregon).
- AgentCore Gateway supports private TLS certificates for VPC endpointsAmazon Bedrock AgentCore Gateway now supports TLS certificates signed by private certificate authorities (CAs) on MCP, OpenAPI, and HTTP proxy targets.
- Amazon ElastiCache for Valkey now supports OpenTelemetry metrics and detailed monitoringAmazon ElastiCache for Valkey now publishes OpenTelemetry metrics to Amazon CloudWatch for your node-based clusters, and each metric carries attributes you can filter and aggregate on with Prometheus Query Language (PromQL) expressions.
- GuardDuty Runtime Monitoring is now included in the AWS Security Hub Threat Analytics planToday, AWS announces that Amazon GuardDuty Runtime Monitoring is now included in the AWS Security Hub Threat Analytics plan.
Thursday 01 October — 16 announcements
- AWS Well-Architected Agent is now available in previewAWS announces the preview of AWS Well-Architected Agent, a AI-powered service that is the next-gen evolution of AWS Trusted Advisor and the AWS Well-Architected Tool.
- Amazon Redshift now supports cross-Region queries for your data lakeAmazon Redshift now supports querying Amazon S3 data lake tables located in a different AWS Region.
- Amazon DynamoDB introduces filtered export to Amazon S3Amazon DynamoDB now supports filtered export for tables.
- Amazon DynamoDB Accelerator (DAX) is now available in additional RegionsToday, AWS announces the availability of Amazon DynamoDB Accelerator (DAX) in 17 additional AWS Regions: Asia Pacific (Hong Kong), Asia Pacific (Hyderabad), Asia Pacific (Jakarta), Asia Pacific…
- Amazon GuardDuty now supports centralized management using AWS Organizations declarative policiesAmazon GuardDuty now supports AWS Organizations declarative policies, enabling you to centrally enable GuardDuty threat detection across every account and Region in your AWS organization.
- Amazon Corretto 8 September 2026 Patch UpdatesOn September 30, 2026, Amazon announced a patch update for the following Amazon Corretto Long-Term Support (LTS) version of OpenJDK: Corretto 8u504 is now available for download .
- Amazon S3 Object Lock variable retention with event holds is now available in AWS GovCloud (US) RegionsAmazon S3 Object Lock support for variable retention with event holds is now available in AWS GovCloud (US-East) and AWS GovCloud (US-West).
- AWS Security Hub introduces remediation plans to prioritize and fix security exposuresAWS Security Hub now offers remediation plans that group related exposure findings sharing a root cause.
- AWS Transfer Family now supports custom CloudWatch log groups for managed workflowsAWS Transfer Family now lets you choose a custom log group in Amazon CloudWatch Logs for managed workflow execution logs.
- AWS Budgets now supports email verification for notification subscribersAWS Budgets lets you set custom cost and usage thresholds and alerts you by email when your spending crosses the threshold.
- AWS Glue Data Catalog now supports table optimization, statistics, and crawlers for Apache Iceberg V3AWS Glue Data Catalog now supports table optimization, statistics, and crawlers for Apache Iceberg Version 3 (V3) tables.
- Serverless Storage on Amazon EMR Serverless now supports terabyte-scale shuffleAmazon EMR Serverless now offers enhanced serverless storage capabilities with support for up to 1TB shuffle operations, raising the previous 200 GB per-job limit.
- Announcing DNS analytics and insights for Route 53 Global Resolver and DNS FirewallRoute 53 Global Resolver and DNS Firewall now provide DNS analytics and insights through native Amazon CloudWatch integration.
- AWS IAM Identity Center extends multi-Region support to more AWS RegionsIAM Identity Center helps you connect your workforce identities to AWS once and streamline access management to AWS accounts and applications.
- Improve your secrets security posture with actionable recommendations in the AWS Secrets Manager consoleAWS Secrets Manager now integrates with the AWS Recommended Actions framework to surface contextual, actionable suggestions for your secrets directly in the Secrets Manager console.
- Amazon S3 Tables now support up to 100 table buckets per AWS Region in an AWS accountAmazon S3 Tables now support up to 100 table buckets per AWS Region in an AWS account, increased from 10.
Wednesday 30 September — 25 announcements
- Amazon WorkSpaces Core Managed Instances adds support for NVIDIA Blackwell GPUAmazon WorkSpaces Core Managed Instances now supports Graphics G7 instances, powered by NVIDIA RTX PRO 4500 Blackwell Server Edition GPUs and Intel Xeon 6 processors.
- Apache Iceberg materialized views now support system-managed write protectionToday, AWS announces system-managed materialized views for Apache Iceberg.
- AWS CLI now supports bulk skill updates and version checks for the Agent Toolkit for AWSToday, AWS expanded the AWS Command Line Interface (CLI) commands for the Agent Toolkit for AWS with two new capabilities that make it easier to keep agent skills up to date.
- Amazon S3 Vectors introduces metadata pre-filtering for up to 5x higher recall on filtered searchAmazon S3 Vectors now supports pre-filtering, which evaluates metadata filters before running similarity search, returning up to 5x more of the matching vectors when your filter is selective.
- Amazon Managed Grafana now supports creating Grafana 13.2 workspacesAmazon Managed Grafana now supports creating new workspaces with Grafana version 13.2.
- OpenAI GPT-6 Astra now supports UltraFast mode on Amazon BedrockToday, AWS announces the availability of UltraFast mode for GPT-6 Astra from OpenAI on Amazon Bedrock.
- AWS Parallel Computing Service now supports scaling logsAWS Parallel Computing Service (AWS PCS) now supports scaling logs, which record how AWS PCS scales the compute node groups in your cluster.
- Amazon Aurora serverless now scales faster to support agentic AI and other bursty workloadsAmazon Aurora serverless now scales in even larger steps, adding up to 16 ACUs to its current capacity within a second and continuing to scale up to 256 ACUs as your workload grows.
- Amazon Aurora and RDS now support AMD-based R8a instancesAmazon Aurora and Amazon RDS now support R8a database instances powered by 5th generation AMD EPYC processors, expanding the choice available for your database workloads.
- Amazon RDS now supports AMD-based M8a instancesAmazon RDS for PostgreSQL, MySQL, and MariaDB now support M8a database instances powered by 5th generation AMD EPYC processors, expanding the choice available for your database workloads.
- Amazon Bedrock expands Claude models in-region support in the UK (London)We're excited to announce in-region support for Anthropic's Claude Opus 5.5 and Claude Sonnet 5 on Amazon Bedrock in the UK (London) Region.
- AWS Continuum for Penetration Testing now available in 6 additional RegionsAWS Continuum for Penetration Testing now available in 6 additional Regions AWS Continuum for Penetration Testing (AWS Security Agent) is a managed security service that enables AWS customers to…
- Aurora PostgreSQL now supports querying of Apache Iceberg and Parquet dataStarting today, you can directly query operational data together with data stored in data lakes in Apache Iceberg and Parquet formats using your existing PostgreSQL applications and tools, without…
- Amazon RDS for MySQL supports MySQL 26.7 in Amazon RDS Database Preview EnvironmentStarting today, Amazon RDS for MySQL 26.7 is available in the Amazon RDS Database Preview Environment , allowing you to evaluate the pre-release of MySQL 26.7 on Amazon RDS for MySQL.
- Uncover blind spots in AWS data plane operations with CloudTrail Event CoverageAWS CloudTrail introduces Event Coverage, a new console experience that gives customers visibility into their data plane operations coverage at the account and organization level.
- Amazon Quick adds Hierarchy Filter for guided dashboard drill-downAmazon Quick now supports the hierarchy filter, a single control that lets readers drill through related dimensions such as Region, Country, and City.
- Amazon Quick now supports live data from your datasets in appsToday, Amazon Quick adds support for building applications that use live data directly from your Quick datasets, so the KPIs, charts, tables, and insights in your application always reflect the latest data.
- Partner Revenue Measurement adds Multi-Partner support to Resource TaggingPartner Revenue Measurement (PRM) provides measurement of AWS consumption driven by Partner solutions.
- AWS accounts now support phone number verificationAWS Accounts now support phone number verification for primary contact phone numbers.
- AWS Transfer Family now automatically approves SFTP connector quota increases up to 1,000AWS Transfer Family now automatically approves requests to increase your SFTP connector quota up to 1,000 connectors per AWS account in each AWS Region.
- AWS IAM Identity Center Identity Store APIs now accept resource ARNs in addition to resource IDsAWS IAM Identity Center's Identity Store APIs now accept the Amazon Resource Name (ARN) for a user, group, group membership, or identity store anywhere the APIs previously accepted the resource ID.
- Amazon Redshift simplifies access to secure logging with federated permissionsAmazon Redshift now makes it easier to troubleshoot and audit queries on data protected by federated permissions with fine-grained access control (FGAC).
- Amazon Kinesis Video Streams now supports VPC endpoints with AWS PrivateLinkAmazon Kinesis Video Streams now supports interface VPC endpoints powered by AWS PrivateLink , providing private connectivity from your Amazon Virtual Private Cloud (Amazon VPC).
- AWS Marketplace launches an AI agent skill for usage-based metering integrationAWS announces the general availability of the AWS Marketplace metering agent skill, an AI-guided experience that helps sellers build, deploy, and validate a usage-based (pay-as-you-go) SaaS metering…
- Amazon S3 Tables now support all Apache Iceberg V3 data typesAmazon S3 Tables add support for geometry, geography, unknown, and nanosecond timestamp data types, along with column default values, as defined in the Apache Iceberg Version 3 (V3) specification.
Tuesday 29 September — 19 announcements
- AWS Deadline Cloud now supports expressions in job templatesAWS Deadline Cloud now supports flexible expressions and rich parameter types in job templates, giving customers a cleaner, more powerful way to fit the service to existing production pipelines.
- Amazon Bedrock Managed Agents, powered by OpenAI, is now available in previewDeveloped jointly by AWS and OpenAI, Bedrock Managed Agents (BMA) is built on a customized version of OpenAI's Agents API engineered to be AWS-native and integrated with AWS resources.
- Amazon RDS now adds full snapshot size information to the Console and APIAmazon RDS now displays the full snapshot size for RDS Snapshots.
- AWS Deadline Cloud now supports ECS containers on Linux Service-Managed FleetsAWS Deadline Cloud now supports running jobs using Docker containers from Amazon Elastic Container Service (ECS) on Linux-based service-managed fleets.
- OpenAI GPT-6.1 Sol is now generally available on Amazon BedrockToday, AWS announces the general availability of GPT-6.1 Sol from OpenAI on Amazon Bedrock.
- Amazon Connect Customer now lets business users manage more reference data to adjust contact center configurations in real timeAmazon Connect Customer now lets administrators store more of the reference data that drives their contact center configurations.
- Amazon WorkSpaces Applications introduces unified graphics imagesToday, Amazon WorkSpaces Applications announces unified graphics images, a single image type that works across all supported graphics instance families, including G4dn, G5, G6, and G7.
- AWS Service Availability UpdatesWe're announcing availability changes to the following AWS services and features.
- Amazon RDS for PostgreSQL announces Extended Support minor versions 13.23-rds.20260514, 12.22-rds.20260514 and 11.22-rds.20260514Amazon Relational Database Service (RDS) for PostgreSQL announces Amazon RDS Extended Support minor versions 13.23-rds.20260514, 12.22-rds.20260514, and 11.22-rds.20260514.
- Amazon Aurora now supports PostgreSQL 18.6, 17.11, 16.15, 15.19, 14.24Amazon Aurora PostgreSQL-Compatible Edition now supports PostgreSQL versions 18.6, 17.11, 16.15, 15.19, and 14.24, which include bug fixes from the PostgreSQL community and Aurora-specific enhancements.
- Amazon Bedrock expands Claude model availability to India, South Korea, and SingaporeWe're excited to announce the availability of Anthropic's Claude Opus 5, Claude Sonnet 5 , and Claude Haiku 4.5 on Amazon Bedrock in India, Claude Opus 5 and Claude Sonnet 5 in South Korea, as well as Claude Sonnet 5 in Singapore.
- AWS Transform now supports Apache Kafka migration assessments for Amazon MSKYou can now use AWS Transform agentic migration assessments to evaluate the migration of on-premises Apache Kafka clusters to Amazon Managed Streaming for Apache Kafka (Amazon MSK) .
- Amazon CloudWatch Logs now automatically indexes frequently queried fieldsAmazon CloudWatch Logs now automatically indexes the fields you query frequently, speeding up CloudWatch Logs Insights queries without requiring any manual setup.
- AWS Systems Manager now supports sharing documents through AWS Resource Access ManagerAWS Systems Manager now lets you share your Systems Manager Documents (SSM Documents) with an entire AWS organization or with specific organizational units (OUs) using AWS Resource Access Manager (AWS RAM).
- AWS DataSync now supports shared VPCsAWS DataSync now supports shared Virtual Private Clouds (VPCs).
- AWS Transfer Family now supports downloading multiple files and folders in web appsAWS Transfer Family now lets web app users download multiple files and folders at once.
- Amazon CloudWatch Logs Insights now lets you estimate bytes scanned before running a queryAmazon CloudWatch Logs Insights now lets you estimate the volume of log data, in bytes, that a query would scan over your selected log groups and time range - without running the query.
- Amazon ElastiCache Serverless for Valkey now supports public endpointsAmazon ElastiCache Serverless for Valkey now supports public endpoints, letting you connect to your cache directly from a laptop, a serverless function, or any application running outside AWS,…
- Amazon Route 53 Resolver DNS Firewall support for Palo Alto Networks Advanced DNS Security is now Generally Available (GA)Amazon Route 53 Resolver DNS Firewall support for Palo Alto Networks (PANW) Advanced DNS Security is now generally available across 32 AWS Regions, allowing security teams to detect and block…
Monday 28 September — 10 announcements
- Amazon EC2 Future-dated Capacity Reservations Now Supports Postponing Start DatesAmazon EC2 Future-dated Capacity Reservations let you secure capacity up to 120 days in advance by specifying the capacity you need, the start date, and a commitment duration.
- Amazon Rekognition Face Liveness now returns Feedback CodesAmazon Rekognition Face Liveness now returns Feedback Codes that help customers understand why a liveness check received a low score and how users could retry successfully.
- Grok 4.7 is now available on Amazon BedrockAmazon Bedrock now supports SpaceXAI Grok 4.7, a frontier model built for coding, agentic tasks, and knowledge work, with US Geo and Global cross-Region inference.
- Claude Sonnet 5.5 now available on AWSAWS now offers Claude Sonnet 5.5, a smarter and more efficient Sonnet that delivers a clear leap forward on coding and knowledge work with at a lower cost per task for most work at faster speed.
- Claude Sonnet 5.5 now available on AWS GovCloud (US)AWS GovCloud (US) now offers Claude Sonnet 5.5, a smarter and more efficient Sonnet that delivers a clear leap forward on coding and knowledge work with at a lower cost per task for most work ag faster speed.
- Amazon Corretto September 2026 Patch UpdatesOn September 25, 2026, Amazon announced a patch update for the following Amazon Corretto Long-Term Support (LTS) and Feature Release (FR) versions of OpenJDK: Corretto 25.0.4.10.1, 21.0.12.11.1,…
- Amazon DocumentDB (with MongoDB compatibility) adds support for 5 MongoDB aggregation stages and change stream capabilities in version 8.0.2Amazon DocumentDB (with MongoDB compatibility) now supports retryable writes, 5 new aggregation stages, and change stream enhancements starting from minor version 8.0.2.
- Amazon DocumentDB (with MongoDB compatibility) now supports retryable writesFor developers building MongoDB-compatible applications, retryable writes improve application resilience during transient errors such as network interruptions or primary failovers.
- Amazon SageMaker Unified Studio now supports two new connection capabilities: Iceberg REST Catalog connections and IAM authentication for Amazon DocumentDBAmazon SageMaker Unified Studio now supports two new connection capabilities: (1) Iceberg REST Catalog (IRC) connections for external Apache Iceberg catalogs, and (2) IAM authentication for Amazon DocumentDB.
- AWS Backup adds logically air-gapped vault support for Amazon FSx for NetApp ONTAPAWS Backup logically air-gapped vault now supports Amazon FSx for NetApp ONTAP.
Official AWS references
- AWS What's New — the announcement feed this inventory is built from
- AWS Security Bulletins — the three bulletins in this window
- GuardDuty centralized management using AWS Organizations declarative policies
- Amazon ECS adds Amazon VPC Lattice support for blue/green, linear, and canary deployments
- Amazon S3 Vectors introduces metadata pre-filtering
- AWS Backup logically air-gapped vault support for FSx for NetApp ONTAP
- Amazon Bedrock Managed Agents, powered by OpenAI, in preview
- AWS Health introduces the version catalog for software lifecycle management
- AWS Security Hub introduces remediation plans
- GuardDuty Runtime Monitoring included in the Security Hub Threat Analytics plan
- AgentCore Gateway supports private TLS certificates for VPC endpoints
- AWS IAM Identity Center extends multi-Region support to more Regions
- Amazon DynamoDB introduces filtered export to Amazon S3
- Amazon Aurora DSQL now supports partial indexes
- Amazon EKS and EKS Distro support Kubernetes 1.37
- Amazon DocumentDB now supports retryable writes
- Secrets security posture recommendations in the AWS Secrets Manager console
- Amazon S3 Tables now support up to 100 table buckets per Region per account
Comments