bartek@aws: ~/news
$ whoami

Bartek Chojnacki

$ AWS Architect · DevOps · Cloud
Monday, August 31, 2026

OpenSearch SQL Plugin: Critical Deserialization Flaw Lets Attackers Execute Code

OpenSearch SQL Plugin has a nasty vulnerability (CVE-2026-83497) that lets authenticated users with basic read permissions run arbitrary code via a crafted cursor parameter. If you're running v2.8–v3.6 (self-managed) or v2.9–v3.5 (AWS managed), you need to patch immediately. Update to v3.7, v2.19.6, or apply the AWS service software update to stay safe.

source: [aws/security-bulletin]

Redshift Gets IAM Identity Center Auth with Private Network Routing

Amazon Redshift now lets you authenticate using AWS IAM Identity Center while keeping all traffic inside your VPC through enhanced VPC routing—perfect if your compliance rules demand zero public internet exposure. This works for both provisioned clusters and serverless workgroups across all AWS Regions, and even supports multi-Region Identity Center setups.

source: [aws/whats-new]

also that day:

Saturday, August 29, 2026

Kinesis Data Streams Gets Serverless Iceberg Delivery—No Pipeline Coding Required

Amazon Kinesis Data Streams now streams data directly to Apache Iceberg tables on S3 Tables without you building custom pipelines, cutting delivery costs by up to 50% and query costs by 30%. The fully serverless streaming tables handle scaling, compaction, and reliability automatically across all AWS regions, including GovCloud and China.

source: [aws/whats-new]

AWS Graviton4-Powered EC2 C8gn Instances Land in Paris

Amazon EC2 C8gn instances, featuring the new Graviton4 processors, are now live in the Paris region alongside 20+ other global locations. These beasts deliver 30% better performance than their Graviton3 predecessors, pack up to 600 Gbps network bandwidth, and support instance sizes up to 48xlarge—perfect for crushing network-intensive workloads like AI/ML inference and data analytics without breaking the bank.

source: [aws/whats-new]

Friday, August 28, 2026

Critical Path Traversal in amazon-ssm-agent Requires Immediate Update

amazon-ssm-agent versions before 3.3.4515.0 have a path traversal vulnerability in the aws:downloadContent plugin that lets authenticated users write arbitrary files as root. This could lead to remote code execution if sensitive files get overwritten. Yes, you need to act: upgrade to 3.3.4515.0 or later ASAP if you're running affected versions (2.0.767.0 to 3.3.4364.0).

source: [aws/security-bulletin]

Amazon Bedrock AgentCore Memory Gets Fine-Grained Access Control

Amazon Bedrock AgentCore Memory now supports fine-grained access control (FGAC), letting you enforce per-user and per-tenant memory isolation through AgentCore Gateway without writing custom auth logic. You can attach Cedar policies to restrict memory access based on user identity, namespace claims, and specific operations—moving access control from your app code straight to the infrastructure layer.

source: [aws/whats-new]

AWS Management Console Now Works Without Internet—Here's Why That Matters

AWS just dropped Private Access for the Management Console, letting you keep your data perimeter fully isolated even when managing your cloud infrastructure. If you're running regulated workloads in finance, healthcare, or defense, you can now ditch the internet connectivity requirement for console access while staying locked down to your corporate network.

source: [aws/security-blog]

also that day: