bartek@aws: ~/news
$ whoami

Bartek Chojnacki

$ AWS Architect · DevOps · Cloud
Thursday, September 3, 2026

Amazon CodeCatalyst Blueprints SDK: OS Command Injection Vulnerability

Amazon CodeCatalyst blueprints SDK versions before 0.3.156 contain a command injection vulnerability (CVE-2026-85012) in the resynthesis framework. An attacker with repository commit access could inject shell metacharacters into the .ownership-file to execute arbitrary commands. Good news: no user action needed—AWS applies server-side validation that blocks this attack on the service side, even for older blueprint versions.

source: [aws/security-bulletin]

AWS Graviton5 Powers New EC2 Instances Across Four Fresh Regions

Amazon EC2 M9g and M9gd instances, built on the new AWS Graviton5 processors, just landed in Ireland, Singapore, Sydney, and Tokyo. These beasts deliver up to 25% better performance than Graviton4 predecessors and feature the Nitro Isolation Engine with mathematically proven security—perfect for memory-intensive workloads like databases and analytics.

source: [aws/whats-new]

also that day:

Wednesday, September 2, 2026

Amazon Ion-C Vulnerability: Update to 1.1.6 Required

Amazon Ion-C before version 1.1.6 has a nasty uncontrolled recursion bug (CVE-2026-84851) that lets attackers crash your app with specially crafted Ion data. If you're using ion-c in your stack, you need to update immediately—this is a denial-of-service vulnerability affecting all versions below 1.1.6. Remote attackers can exploit this without authentication, so don't sleep on this one.

source: [aws/security-bulletin]

Smooth Your AWS IAM Identity Center Migration with Active Directory

AWS just dropped updated guidance on migrating your identity source to IAM Identity Center, including solid strategies for moving from Active Directory and automating permission sets. If you're managing user access across multiple AWS accounts, this post walks you through the practical steps to avoid the usual migration headaches.

source: [aws/security-blog]

also that day:

Tuesday, September 1, 2026

Amazon SageMaker Python SDK: Critical HMAC Key Exposure Vulnerability

Amazon SageMaker Python SDK has a serious security flaw where HMAC signing keys are stored in cleartext in pipeline definitions. Attackers with account access can extract these keys via DescribePipeline API and execute arbitrary code in other users' pipelines. Update immediately: SDK v3 to v3.11.0+ or v2 to v2.256.0+. Action required for all users running affected versions.

source: [aws/security-bulletin]

Claude Fable 5.1 Lands on AWS with Serious Reasoning Chops

Anthropic's Claude Fable 5.1 is now generally available on AWS through Amazon Bedrock and Claude Platform, bringing frontier-level AI to your coding, research, and enterprise workflows. This beast handles multi-hour sessions across entire codebases, admits when it's stuck instead of faking success, and won't ghost you with confident wrong answers—plus Enterprise Frontier Safeguards let you keep your data in your own cloud.

source: [aws/whats-new]

Amazon Quick Now Lets You Build Apps Without Code

Amazon Quick is now generally available, letting you create custom business applications just by describing what you need in plain English—no coding required. The tool connects to your existing systems like Salesforce, Jira, and Microsoft 365, building live apps with real-time data that you can share instantly across your organization.

source: [aws/whats-new]

also that day: