Home› Blog› AWS Weekly Intelligence #10 - 5-9 October 2026
AWS Weekly Intelligence AWS

AWS Weekly Intelligence #10 - 5-9 October 2026

Verified against current vendor documentation on 10 October 2026. Pricing, limits and API behaviour were checked against the official docs on that date. Cloud services change fast — if you are reading this much later, treat the specifics as a starting point and re-check the linked sources.

36 announcements across five working days — a markedly quieter week than the last, and one where the volume sat in model availability while the substance sat in security.

The week in one paragraph

Thirty-six announcements, against seventy-nine the week before. The drop is real rather than a feed artefact, and it changed the shape of the week: Monday carried twelve items and Friday eleven, while Tuesday produced two. Roughly a quarter of everything was model or AI-tooling availability — Claude Haiku 5.5 on AWS and in GovCloud, GLM 5.3, TwelveLabs Pegasus 1.5, Nova 2.5 Sonic, OpenAI reasoning summaries, an Ultrafast mode — which is now the steady background rate rather than news in itself.

The security items were where the week had weight, and they arrived at both ends of it. Monday brought network access controls for the IAM Identity Center Identity Store, device posture assessment for Client VPN, detailed issuance logging for Private CA, and continuous penetration testing in a pipeline. Friday closed with Security Hub exporting findings to S3. In between, GuardDuty learned to detect data exfiltration and destruction inside Aurora and RDS — the single most consequential thing AWS shipped this week and the one least likely to be noticed, because it arrives as a capability inside a service most people enabled years ago.

A quieter theme worth naming: sovereignty. Two EC2 instance families landed in the AWS European Sovereign Cloud (Germany) Region, S3 Vectors pre-filtering reached GovCloud, Claude models reached GovCloud twice, and the Architecture blog published a Digital Sovereignty Lens for the Well-Architected Framework. None of those is a headline on its own. Together they are a week of steady work on a partition-shaped problem.

Covered in depth

Five news days, five deep-dives — the first week in this series where every day of the window produced a daily post. Each links below, with the detail the announcement itself left out.

News dateAnnouncementPostWhat the announcement did not say
5 Oct AWS Private CA detailed certificate issuance logs #47 The new CloudTrail event records successful issuance. The failures were the part that was not logged — and the event also carries cross-account delivery and algorithm-migration tracking that the announcement does not mention.
6 Oct ACM ACME issuance through AWS PrivateLink #48 Private DNS resolves the existing directory URL, so client config is identical on both paths — which means nothing on the client records which path a certificate took. And an endpoint created without private DNS leaves clients on the public path, successfully and silently.
7 Oct AWS Config supports 77 new resource types #49 If you record all resource types, Config tracks the additions automatically — so coverage and cost both moved with no action on your side, while a selected-list account gained nothing.
8 Oct Bedrock product attributes in Cost Explorer, Budgets and Dashboards #50 Cost Explorer and Dashboards can group and filter; Budgets can only filter. So per-model alerting is one budget per model, and a model adopted later sits outside all of them while they keep passing.
9 Oct Security Hub exports findings to S3 in CSV or JSON #51 An export inherits the filters from the page you start it on, the default CSV is nine columns, and nothing in the file records which filters produced it — for an artefact AWS positions as audit evidence.

The architecture series ran alongside it, and two of those posts bear directly on this week's news: #75 on why a Security Hub control can pass because nothing was in scope, and #77 on which of the five scores on an Inspector finding knows anything about your environment. Both are the background to reading an exported findings file.

What else shipped, by domain

Security and identity

GuardDuty RDS Protection now detects data exfiltration and destruction in Aurora and RDS. The week's most important item. This is a new detection class rather than a new service, which is exactly why it will be missed — nothing changes in your console until something fires. It also lands next to #74's finding that a suppression rule quietly reduces what GuardDuty reports: new detection types are worth checking against existing suppression rules, because a rule written broadly a year ago can silence a finding type that did not exist when it was written.

IAM Identity Center network access controls for Identity Store. Carried in this backlog since Monday as the strongest unwritten item, and still is. Restricting access to the Identity Store by network is a control on the directory itself rather than on what the directory authorises — a different layer from the permission sets, and one that has had no equivalent until now.

Client VPN device posture assessment. Posture as an input to network admission. Worth pairing mentally with the Identity Center item: both are this week's answer to "the credential was valid and the device should not have been there".

AWS Continuum for Penetration Testing in CI/CD. Continuous penetration testing integrated into a pipeline. The interesting question, unanswered by the announcement, is what a failing result does to a deployment — a security gate that blocks and a security gate that reports are very different engineering commitments.

Network Firewall wildcard support for container attribute filters. A small, welcome reduction in rule maintenance for anyone writing firewall rules against container metadata that changes with every deployment.

Governance, cost and operations

Control Tower AFT plan-only customization runs. A dry run for account customisations. For anyone who has watched AFT apply something unintended across an OU, this is the feature that was missing.

AWS Capabilities by Region adds availability notifications for individual features, plus advanced filters. Underrated. Regional feature availability is the thing that quietly invalidates an architecture diagram, and until now the answer was to check manually and remember to check again. A notification per feature turns that into a subscription.

Batch publishes job metrics to CloudWatch, and separately Batch supports EKS access entry authentication. The metrics item has been in this backlog since Tuesday; the access-entry one moves Batch onto the EKS authentication mechanism that replaced the aws-auth ConfigMap, which is the direction everything on EKS is going.

Data and databases

Redshift creates and refreshes Apache Iceberg materialized views. The strongest non-security item of the week, and a genuine capability rather than a convenience — a materialised view maintained by Redshift over Iceberg tables changes where the refresh logic lives.

RDS for Oracle minor version upgrade prechecks, with a new RDS event. A precheck that tells you an upgrade will fail before the maintenance window rather than during it. The new event is the part to wire up.

Lambda OAuth authentication for self-managed Apache Kafka event sources. Removes a long-standing awkwardness for anyone connecting Lambda to a Kafka cluster they run themselves.

Compute, and the sovereignty thread

EC2 R8gd and R8g in the AWS European Sovereign Cloud (Germany) Region, and C8gb and Hpc8a in additional Regions. Instance-family expansion is routine; the European Sovereign Cloud destination is what makes two of these worth noting together. S3 Vectors metadata pre-filtering in GovCloud and Claude models reaching GovCloud twice belong to the same thread.

EC2 shared tags for Amazon Machine Images. Tags on a shared AMI, visible to the accounts it is shared with. Small, and it fixes a real gap in AMI governance across an organisation.

GameLift Servers CPU burstability for container fleets. Narrow but material if you run game servers in containers.

AI, models and tooling

Nine or so items, most of them availability. Claude Haiku 5.5 on AWS and in GovCloud; Claude Sonnet 5.5 and Opus 5.5 on Kiro in GovCloud; GLM 5.3 and TwelveLabs Pegasus 1.5 on Bedrock; Nova 2.5 Sonic for voice agents; OpenAI GPT-6.1 Sol Ultrafast mode.

Two are mechanism rather than catalogue. Bedrock reasoning summaries for OpenAI models adds a reasoning.summary parameter — a request-level option, so it is a code change rather than a model switch. And SageMaker Unified Studio custom Tooling blueprints is the kind of extensibility item that decides whether a platform team can standardise on Unified Studio at all.

Amazon Quick brand templates and Connect automated checks for evaluation forms round out the week. The AWS Advanced Ruby Driver Wrapper reached GA, which matters to a small audience a great deal.

What I would act on

1. Check whether GuardDuty RDS Protection is enabled, then check your suppression rules against the new finding types. Data exfiltration and destruction detection inside Aurora and RDS is the week's biggest security gain, and it is worth nothing if RDS Protection was never turned on, or if a broadly written suppression rule catches the new types. Both are five-minute checks with a large downside if skipped.

2. Look at IAM Identity Center network access controls for the Identity Store. Five days old and still the strongest item nobody has written up. If you have ever been asked "can we restrict who can read the directory, by network?", the answer changed on Monday.

3. If you record all AWS Config resource types, look at this month's configuration item count. Seventy-seven types were added and, per #49, an all-types recorder picked them up automatically. The cost moved without a change request, and a rule scoped to all supported types now evaluates a wider population — so a compliance percentage can fall without anything being misconfigured.

4. Take one Security Hub findings export now, in JSON (OCSF), before you need it. Doing it once in advance tells you whether the bucket policy, the KMS key policy and the IAM permissions are right, which is not information you want to be gathering the week an auditor asks. Name it yourself rather than accepting the suggested page-and-timestamp default.

And one to read rather than do: the Digital Sovereignty Lens for the Well-Architected Framework, published this week in the Architecture blog. If sovereignty is on your roadmap it is a structured set of questions, and if it is not, it is a useful preview of the ones you will be asked.

Complete inventory — 36 announcements

Every What's New announcement in the 5–9 October window, grouped by day, with AWS's own one-line summary. Built from the raw feeds by build_weekly_inventory.py; all 36 links were validated and returned 200.

Friday 09 October — 11 announcements

Thursday 08 October — 6 announcements

Wednesday 07 October — 5 announcements

Tuesday 06 October — 2 announcements

Monday 05 October — 12 announcements

Official AWS references

Every announcement above links to its own AWS page. The items this roundup makes a specific claim about:

Looking for one service rather than a whole week?

Every AWS, Azure and Google Cloud announcement is browsable by service and date, each linked to the vendor’s own page — and the other weekly roundups are collected in one place.

Browse announcements →

Comments

How was your experience?
Your feedback helps improve this site.
PoorExcellent