bartek@aws: ~/news
$ whoami

Bartek Chojnacki

$ AWS Architect · DevOps · Cloud
Thursday, August 20, 2026

AWS CDK Command Injection Vulnerability Requires Immediate Update

AWS CDK (aws-cdk-lib) versions before 2.245.0 (2.246.0 on Windows) contain a nasty OS command injection flaw in the NodejsFunction bundling pipeline. If someone controls bundling properties like externalModules or esbuildArgs, they can execute arbitrary commands on your build machine—yikes! Update immediately if you're using affected versions and let untrusted code near your CDK configs.

source: [aws/security-bulletin]

Critical Heap Double-Free Vulnerability in AWS Common Runtime aws-c-http

AWS Common Runtime aws-c-http has a nasty heap double-free bug (CVE-2026-12043) that lets remote servers trigger memory corruption and potentially execute arbitrary code on your client. If you're using aws-c-http versions 0.4.22 through 0.10.15, or aws-sdk-cpp/aws-sdk-java-v2 within the affected ranges, you need to update immediately. This one's serious—patch ASAP.

source: [aws/security-bulletin]

Amazon Bedrock Expands OpenAI GPT-5.6 Models Across 25+ Regions with Cross-Region Inference

Amazon Bedrock now distributes OpenAI's GPT-5.6 models (Sol, Terra, and Luna) globally with cross-Region inference, letting you route requests through geographic and global profiles for better throughput. You'll learn how to integrate these models using OpenAI and Converse APIs, plus configure IAM, quotas, and monitoring for your ML workloads.

source: [aws/machine-learning-blog]

also that day:

Wednesday, August 19, 2026

AWS Cost Anomaly Detection Now Tracks Third-Party AI Models on Bedrock

AWS Cost Anomaly Detection now automatically monitors spending on third-party foundation models like Anthropic Claude running on Amazon Bedrock, with zero setup required. When your generative AI costs spike unexpectedly, you'll get instant alerts with a breakdown showing exactly which service, account, region, or usage type caused the jump—available across all AWS commercial regions except GovCloud and China.

source: [aws/whats-new]

Keep Your AI Agents From Leaking Secrets: Authorization Context in Amazon Bedrock

Your AI agents pulling from DynamoDB, SaaS platforms, and internal knowledge bases need to know *who's asking*—otherwise they'll happily serve confidential data to anyone. Learn how to propagate user authorization context through Amazon Bedrock AgentCore so your agents respect access boundaries and don't become a data leak waiting to happen.

source: [aws/security-blog]

Amazon Bedrock Adds SpaceXAI Grok 4.6 for Complex Agent Work

Amazon Bedrock now supports SpaceXAI Grok 4.6, a flagship model with a massive 500K context window and configurable reasoning levels, perfect for long-running agents tackling complex multi-step tasks like code analysis and research. You can access it across all AWS Regions with enterprise-grade security, monitoring, and cross-Region inference capabilities.

source: [aws/whats-new]

also that day:

Tuesday, August 18, 2026

Amazon ion-java Memory Denial of Service – Update Required

Amazon ion-java (Java library for Ion data format) has two critical memory-amplification DoS vulnerabilities: CVE-2026-75935 via declared-length preallocation and CVE-2026-75936 via compressed data expansion. Versions below 1.12.0 are affected and require immediate patching. If you're using ion-java in production, update now to protect against potential service disruptions.

source: [aws/security-bulletin]

OpenSearch Dashboards DoS Vulnerability Needs Your Attention

OpenSearch Dashboards has a nasty input validation bug (CVE-2026-75897) that lets attackers hammer your system with oversized requests, causing denial of service. If you're running versions 1.3.0 through 3.7.0, you need to patch immediately—upgrade to 3.8.0 or apply the latest AWS service software update. AWS-managed OpenSearch users should grab the patched release available now.

source: [aws/security-bulletin]

AWS Unleashes AgentCore Payments: Your AI Agents Can Now Handle Transactions

AWS just dropped general availability for AgentCore payments in Amazon Bedrock AgentCore, letting your AI agents autonomously discover, access, and pay for APIs, MCPs, and content with minimal code. It's got enterprise-grade security, payment limits, and full observability—plus integrations with Coinbase and Stripe Privy wallets for microtransactions across multiple regions.

source: [aws/whats-new]

also that day: