36 announcements across five working days — a markedly quieter week than the last, and one where the volume sat in model availability while the substance sat in security.
The week in one paragraph
Thirty-six announcements, against seventy-nine the week before. The drop is real rather than a feed artefact, and it changed the shape of the week: Monday carried twelve items and Friday eleven, while Tuesday produced two. Roughly a quarter of everything was model or AI-tooling availability — Claude Haiku 5.5 on AWS and in GovCloud, GLM 5.3, TwelveLabs Pegasus 1.5, Nova 2.5 Sonic, OpenAI reasoning summaries, an Ultrafast mode — which is now the steady background rate rather than news in itself.
The security items were where the week had weight, and they arrived at both ends of it. Monday brought network access controls for the IAM Identity Center Identity Store, device posture assessment for Client VPN, detailed issuance logging for Private CA, and continuous penetration testing in a pipeline. Friday closed with Security Hub exporting findings to S3. In between, GuardDuty learned to detect data exfiltration and destruction inside Aurora and RDS — the single most consequential thing AWS shipped this week and the one least likely to be noticed, because it arrives as a capability inside a service most people enabled years ago.
A quieter theme worth naming: sovereignty. Two EC2 instance families landed in the AWS European Sovereign Cloud (Germany) Region, S3 Vectors pre-filtering reached GovCloud, Claude models reached GovCloud twice, and the Architecture blog published a Digital Sovereignty Lens for the Well-Architected Framework. None of those is a headline on its own. Together they are a week of steady work on a partition-shaped problem.
Covered in depth
Five news days, five deep-dives — the first week in this series where every day of the window produced a daily post. Each links below, with the detail the announcement itself left out.
| News date | Announcement | Post | What the announcement did not say |
|---|---|---|---|
| 5 Oct | AWS Private CA detailed certificate issuance logs | #47 | The new CloudTrail event records successful issuance. The failures were the part that was not logged — and the event also carries cross-account delivery and algorithm-migration tracking that the announcement does not mention. |
| 6 Oct | ACM ACME issuance through AWS PrivateLink | #48 | Private DNS resolves the existing directory URL, so client config is identical on both paths — which means nothing on the client records which path a certificate took. And an endpoint created without private DNS leaves clients on the public path, successfully and silently. |
| 7 Oct | AWS Config supports 77 new resource types | #49 | If you record all resource types, Config tracks the additions automatically — so coverage and cost both moved with no action on your side, while a selected-list account gained nothing. |
| 8 Oct | Bedrock product attributes in Cost Explorer, Budgets and Dashboards | #50 | Cost Explorer and Dashboards can group and filter; Budgets can only filter. So per-model alerting is one budget per model, and a model adopted later sits outside all of them while they keep passing. |
| 9 Oct | Security Hub exports findings to S3 in CSV or JSON | #51 | An export inherits the filters from the page you start it on, the default CSV is nine columns, and nothing in the file records which filters produced it — for an artefact AWS positions as audit evidence. |
The architecture series ran alongside it, and two of those posts bear directly on this week's news: #75 on why a Security Hub control can pass because nothing was in scope, and #77 on which of the five scores on an Inspector finding knows anything about your environment. Both are the background to reading an exported findings file.
What else shipped, by domain
Security and identity
GuardDuty RDS Protection now detects data exfiltration and destruction in Aurora and RDS. The week's most important item. This is a new detection class rather than a new service, which is exactly why it will be missed — nothing changes in your console until something fires. It also lands next to #74's finding that a suppression rule quietly reduces what GuardDuty reports: new detection types are worth checking against existing suppression rules, because a rule written broadly a year ago can silence a finding type that did not exist when it was written.
IAM Identity Center network access controls for Identity Store. Carried in this backlog since Monday as the strongest unwritten item, and still is. Restricting access to the Identity Store by network is a control on the directory itself rather than on what the directory authorises — a different layer from the permission sets, and one that has had no equivalent until now.
Client VPN device posture assessment. Posture as an input to network admission. Worth pairing mentally with the Identity Center item: both are this week's answer to "the credential was valid and the device should not have been there".
AWS Continuum for Penetration Testing in CI/CD. Continuous penetration testing integrated into a pipeline. The interesting question, unanswered by the announcement, is what a failing result does to a deployment — a security gate that blocks and a security gate that reports are very different engineering commitments.
Network Firewall wildcard support for container attribute filters. A small, welcome reduction in rule maintenance for anyone writing firewall rules against container metadata that changes with every deployment.
Governance, cost and operations
Control Tower AFT plan-only customization runs. A dry run for account customisations. For anyone who has watched AFT apply something unintended across an OU, this is the feature that was missing.
AWS Capabilities by Region adds availability notifications for individual features, plus advanced filters. Underrated. Regional feature availability is the thing that quietly invalidates an architecture diagram, and until now the answer was to check manually and remember to check again. A notification per feature turns that into a subscription.
Batch publishes job metrics to CloudWatch, and separately Batch supports EKS access
entry authentication. The metrics item has been in this backlog since Tuesday; the access-entry one
moves Batch onto the EKS authentication mechanism that replaced the aws-auth ConfigMap, which
is the direction everything on EKS is going.
Data and databases
Redshift creates and refreshes Apache Iceberg materialized views. The strongest non-security item of the week, and a genuine capability rather than a convenience — a materialised view maintained by Redshift over Iceberg tables changes where the refresh logic lives.
RDS for Oracle minor version upgrade prechecks, with a new RDS event. A precheck that tells you an upgrade will fail before the maintenance window rather than during it. The new event is the part to wire up.
Lambda OAuth authentication for self-managed Apache Kafka event sources. Removes a long-standing awkwardness for anyone connecting Lambda to a Kafka cluster they run themselves.
Compute, and the sovereignty thread
EC2 R8gd and R8g in the AWS European Sovereign Cloud (Germany) Region, and C8gb and Hpc8a in additional Regions. Instance-family expansion is routine; the European Sovereign Cloud destination is what makes two of these worth noting together. S3 Vectors metadata pre-filtering in GovCloud and Claude models reaching GovCloud twice belong to the same thread.
EC2 shared tags for Amazon Machine Images. Tags on a shared AMI, visible to the accounts it is shared with. Small, and it fixes a real gap in AMI governance across an organisation.
GameLift Servers CPU burstability for container fleets. Narrow but material if you run game servers in containers.
AI, models and tooling
Nine or so items, most of them availability. Claude Haiku 5.5 on AWS and in GovCloud; Claude Sonnet 5.5 and Opus 5.5 on Kiro in GovCloud; GLM 5.3 and TwelveLabs Pegasus 1.5 on Bedrock; Nova 2.5 Sonic for voice agents; OpenAI GPT-6.1 Sol Ultrafast mode.
Two are mechanism rather than catalogue. Bedrock reasoning summaries for OpenAI models adds
a reasoning.summary parameter — a request-level option, so it is a code change rather
than a model switch. And SageMaker Unified Studio custom Tooling blueprints is the kind of
extensibility item that decides whether a platform team can standardise on Unified Studio at all.
Amazon Quick brand templates and Connect automated checks for evaluation forms round out the week. The AWS Advanced Ruby Driver Wrapper reached GA, which matters to a small audience a great deal.
What I would act on
1. Check whether GuardDuty RDS Protection is enabled, then check your suppression rules against the new finding types. Data exfiltration and destruction detection inside Aurora and RDS is the week's biggest security gain, and it is worth nothing if RDS Protection was never turned on, or if a broadly written suppression rule catches the new types. Both are five-minute checks with a large downside if skipped.
2. Look at IAM Identity Center network access controls for the Identity Store. Five days old and still the strongest item nobody has written up. If you have ever been asked "can we restrict who can read the directory, by network?", the answer changed on Monday.
3. If you record all AWS Config resource types, look at this month's configuration item count. Seventy-seven types were added and, per #49, an all-types recorder picked them up automatically. The cost moved without a change request, and a rule scoped to all supported types now evaluates a wider population — so a compliance percentage can fall without anything being misconfigured.
4. Take one Security Hub findings export now, in JSON (OCSF), before you need it. Doing it once in advance tells you whether the bucket policy, the KMS key policy and the IAM permissions are right, which is not information you want to be gathering the week an auditor asks. Name it yourself rather than accepting the suggested page-and-timestamp default.
And one to read rather than do: the Digital Sovereignty Lens for the Well-Architected Framework, published this week in the Architecture blog. If sovereignty is on your roadmap it is a structured set of questions, and if it is not, it is a useful preview of the ones you will be asked.
Complete inventory — 36 announcements
Every What's New announcement in the 5–9 October window, grouped by day, with AWS's own one-line
summary. Built from the raw feeds by build_weekly_inventory.py; all 36 links were validated and
returned 200.
Friday 09 October — 11 announcements
- AWS Security Hub now exports findings to S3 in CSV or JSON formatToday, AWS Security Hub announces support for exporting findings to Amazon S3 in CSV or JSON (OCSF) format.
- Amazon EC2 R8gd instances are now available in additional regionsAmazon Elastic Compute Cloud (Amazon EC2) R8gd instances are available in AWS European Sovereign Cloud (Germany) region.
- Amazon EC2 R8g instances now available in additional regionsStarting today, Amazon Elastic Compute Cloud (Amazon EC2) R8g instances are available in the AWS European Sovereign Cloud (Germany) region.
- Amazon Bedrock now supports reasoning summaries for OpenAI modelsAmazon Bedrock now supports the reasoning.summary parameter for OpenAI models through the Responses API.
- Anthropic Claude Sonnet 5.5 and Claude Opus 5.5 are now available on Kiro in AWS GovCloud (US)Two new Anthropic models are now available in the Kiro IDE and CLI for the AWS GovCloud (US) Regions.
- Amazon Connect Customer now provides automated checks to improve performance evaluation formsAmazon Connect Customer now suggests changes to performance evaluation forms that improve the accuracy of evaluations automatically filled by AI.
- Amazon S3 Vectors metadata pre-filtering is now available in AWS GovCloud (US) RegionsAmazon S3 Vectors metadata pre-filtering is now available in the AWS GovCloud (US-East) and AWS GovCloud (US-West) Regions.
- AWS Lambda supports OAuth authentication for self-managed Apache Kafka event sourcesAWS Lambda now supports OAuth authentication for self-managed Apache Kafka event source mappings (ESM), including Kafka clusters that customers run themselves and managed offerings such as Confluent Cloud, Aiven, and Redpanda.
- Amazon Quick now supports brand templates for on-brand presentations and documentsStarting today, you can upload brand templates in Amazon Quick, allowing you to create presentations and documents that match your approved visual identity.
- Amazon SageMaker Unified Studio now supports custom Tooling blueprintsAmazon SageMaker Unified Studio now supports custom Tooling blueprints, giving domain administrators the ability to define the foundation of every project by using their own AWS CloudFormation templates.
- TwelveLabs Pegasus 1.5 model now available on Amazon BedrockAmazon Bedrock now supports TwelveLabs Pegasus 1.5, a video-to-text model that generates structured, time-coded metadata from video.
Thursday 08 October — 6 announcements
- OpenAI GPT-6.1 Sol now supports Ultrafast mode on Amazon BedrockToday, AWS announces the availability of Ultrafast mode for GPT-6.1 Sol from OpenAI on Amazon Bedrock.
- AWS Cost Explorer, Budgets, and Dashboards now support Amazon Bedrock product attributesAWS Cost Explorer, AWS Budgets, and AWS Cost Management Dashboards now let you analyze Amazon Bedrock costs by product attributes, a new dimension that breaks down Bedrock cost by model, model provider, inference type, and feature.
- Amazon RDS for Oracle now supports minor version upgrade prechecks and a new RDS event to help reduce patching downtimeAmazon Relational Database Service (Amazon RDS) for Oracle now lets you run a minor version upgrade precheck yourself, before you start an upgrade or before your scheduled maintenance window.
- AWS Network Firewall adds wildcard support for container attribute filtersAWS Network Firewall now supports wildcard matching in container attribute-based inspection filters for Amazon Elastic Kubernetes Service (Amazon EKS) and Amazon Elastic Container Service (Amazon ECS).
- Amazon GameLift Servers adds CPU burstability for container fleetsAmazon GameLift Servers now supports CPU burstability for container fleets, giving game developers greater flexibility in how compute resources are allocated and consumed at runtime.
- Amazon GuardDuty RDS Protection now detects data exfiltration and destruction in Aurora and RDS databasesAmazon GuardDuty announces an expansion of RDS Protection that extends threat detection beyond login anomalies to identify data exfiltration and data destruction attacks targeting Amazon Aurora…
Wednesday 07 October — 5 announcements
- Amazon EC2 C8gb instances now generally available in additional regionsStarting today, Amazon Elastic Compute Cloud (Amazon EC2) C8gb instances, powered by the latest-generation AWS Graviton4 processors, are available in the US East (Ohio), US West (N.
- AWS Capabilities by Region now offers availability notifications for individual features and advanced filtersToday, AWS announces feature-level availability notifications and advanced filters for AWS Capabilities by Region in AWS Builder Center.
- AWS Config now supports 77 new resource typesAWS Config now supports 77 additional AWS resource types across key services including Amazon EC2, Amazon S3 Files, and Amazon Q Business.
- Claude Haiku 5.5 is now available on AWSAWS now offers Claude Haiku 5.5, the fastest and most efficient model in the Claude 5.5 family, built for subagents and high-volume, cost-sensitive work.
- Claude Haiku 5.5 is now available on AWS GovCloud (US)AWS GovCloud (US) now offers Claude Haiku 5.5, the fastest and most efficient model in the Claude 5.5 family, built for subagents and high-volume, cost-sensitive work.
Tuesday 06 October — 2 announcements
- AWS Batch now publishes job metrics to Amazon CloudWatchAWS Batch now publishes job metrics to Amazon CloudWatch, providing native observability for batch workloads.
- AWS Certificate Manager now supports ACME issuance through AWS PrivateLinkAWS Certificate Manager (ACM) now supports AWS PrivateLink for ACME public certificate issuance, allowing you to request and renew public TLS certificates over a private network path that stays within the AWS network.
Monday 05 October — 12 announcements
- Amazon Redshift adds support for creating and refreshing Apache Iceberg materialized viewsAmazon Redshift now supports the creation and refresh of Apache Iceberg materialized views.
- GLM 5.3 by Z.ai is now generally available on Amazon BedrockAmazon Bedrock now supports GLM 5.3 from Z.ai, giving you a powerful new option for agentic coding and long-horizon software engineering work.
- AWS IAM Identity Center now supports network access controls for Identity StoreAWS IAM Identity Center helps you configure the single sign-on experience for your workforce to AWS accounts and applications.
- Amazon EC2 Hpc8a instances are now available in Asia Pacific (Singapore)Starting today, Amazon EC2 Hpc8a instances are available in Asia Pacific (Singapore) region.
- AWS Control Tower AFT now supports plan-only customization runsAWS Control Tower Account Factory for Terraform (AFT) now supports plan-only customization runs, giving administrators the ability to preview Terraform changes before applying them across their managed accounts.
- AWS Continuum for Penetration Testing now supports continuous penetration testing integrated directly into your CI/CD pipelineAWS Continuum for Penetration Testing now integrates continuous penetration testing directly into your CI/CD pipeline (public preview) AWS Continuum for Penetration Testing (formerly AWS Security…
- Amazon EC2 introduces shared tags for Amazon Machine ImagesAmazon EC2 now supports AMI tag sharing, a new feature that lets AMI owners make selected tags visible to all AWS accounts an AMI is shared with.
- AWS Client VPN now supports device posture assessmentAWS Client VPN now supports device posture assessment, allowing you to verify that connecting user devices meet your security and compliance requirements before granting network access.
- AWS Advanced Ruby Driver Wrapper is generally availableThe Amazon Web Services (AWS) Advanced Ruby Driver Wrapper is now generally available for use with Amazon RDS and Amazon Aurora PostgreSQL and MySQL-compatible databases.
- AWS Batch now supports Amazon EKS access entry authenticationAWS Batch now supports Amazon EKS access entry authentication for compute environments.
- AWS Private CA now provides detailed certificate issuance logsAWS Private CA announces detailed certificate issuance logs, a new AWS CloudTrail service event that records the complete certificate content, issuing CA information, requester identity, and signing status for every issuance.
- Announcing Amazon Nova 2.5 Sonic with improved reasoning for voice agentsToday, we announce the general availability of Amazon Nova 2.5 Sonic, our latest speech-to-speech model for natural, real-time voice agents.
Official AWS references
Every announcement above links to its own AWS page. The items this roundup makes a specific claim about:
- Amazon GuardDuty RDS Protection detects data exfiltration and destruction in Aurora and RDS
- AWS IAM Identity Center network access controls for Identity Store
- AWS Client VPN device posture assessment
- AWS Security Hub findings export to S3 in CSV or JSON
- AWS Config support for 77 additional resource types
- Amazon Bedrock product attributes in Cost Explorer, Budgets and Dashboards
- AWS Private CA detailed certificate issuance logs
- AWS Certificate Manager ACME issuance through AWS PrivateLink
- AWS Network Firewall wildcard support for container attribute filters
- AWS Continuum for Penetration Testing in CI/CD
- AWS Control Tower AFT plan-only customization runs
- AWS Capabilities by Region availability notifications and advanced filters
- Amazon EC2 shared tags for Amazon Machine Images
- AWS Batch support for Amazon EKS access entry authentication
- AWS Batch job metrics to Amazon CloudWatch
- Amazon Redshift Apache Iceberg materialized views
- Amazon RDS for Oracle minor version upgrade prechecks and new RDS event
- AWS Lambda OAuth authentication for self-managed Apache Kafka event sources
- Amazon EC2 R8gd instances in the AWS European Sovereign Cloud (Germany) Region
- Amazon EC2 R8g instances in the AWS European Sovereign Cloud (Germany) Region
- Claude Haiku 5.5 on AWS
- Amazon Bedrock reasoning summaries for OpenAI models
- Amazon S3 Vectors metadata pre-filtering in AWS GovCloud (US) Regions
- Amazon GameLift Servers CPU burstability for container fleets
Comments