Amazon Connect Customer now provides routing step data in the analytics data lake, making it easier for customers to generate insights from routing decisions. Using the data lake, customers can leverage Amazon Athena and Amazon Quick to analyze trends, such as contacts queued and contacts joined at each routing step, without complex data pipelines. For example, an analyst can now report on how contacts progressed through each routing step, identify where agent matching criteria were relaxed, and measure the impact of routing step configurations on wait times and agent utilization.
Amazon Connect Customer now provides routing step data in the analytics data lake, making it easier for customers to generate insights from routing decisions. Using the data lake, customers can leverage Amazon Athena and Amazon Quick to analyze trends, such as contacts queued and contacts joined at each routing step, without complex data pipelines. For example, an analyst can now report on how contacts progressed through each routing step, identify where agent matching criteria were relaxed, and measure the impact of routing step configurations on wait times and agent utilization.
Routing step data is available in all AWS regions where Amazon Connect Customer data lake is offered. To learn more about Amazon Connect Customer data lake, see the Amazon Connect Customer Administrator Guide. To learn more about Amazon Connect Customer, visit the Amazon Connect Customer website.
Reimaginar el SOC para la era agéntica en Microsoft Defender
5 minutos
Por: Rob Lefferts, vicepresidente corporativo de Microsoft Threat Protection.
La física de la ciberseguridad ha comenzado a cambiar. También debe hacerlo el Centro de Operaciones de Seguridad (SOC).
Los ciberatacantes utilizan agentes para automatizar la ejecución a una escala sin precedentes. Lo que antes requería equipos enteros ahora requiere un solo operador y un marco de agentes.
Ese cambio ha dejado a la luz una dura realidad: la seguridad no puede operar a velocidad de IA cuando la protección y las operaciones se construyen como sistemas separados. Cada traspaso, integración y límite ralentiza a los defensores. Los agentes heredan esa complejidad.
Para que la seguridad agéntica funcione, la industria necesita un modelo diferente. Necesita una pila cibernética moderna con la amplitud para ver a través del entorno y la profundidad para investigar y actuar. Las operaciones de seguridad y la protección nativa deben funcionar como un solo sistema. Este es el Centro Integrado de Operaciones de Seguridad (ISOC, por sus siglas en inglés).
Hoy anunciamos ISOC en Microsoft Defender: una base construida para la seguridad agéntica que reúne soluciones líderes para la gestión de información y eventos de seguridad (SIEM, por sus siglas en inglés) y la protección contra amenazas. Ofrece a personas y agentes una base compartida para ver, entender y actuar en todo el entorno, sin la complejidad de operar sistemas separados.
En julio de 2026, introdujimos la pila cibernética de extremo a extremo junto con Project Perception, con el objetivo de ofrecer los modelos adecuados, un arnés y agentes especializados para ayudar a los defensores a percibir, razonar y actuar a velocidad de máquina. Pero ahora innovamos en cada capa de la pila, porque la inteligencia y la orquestación por sí solas no son suficientes. Los agentes dependen de que el resto de la pila trabaje como uno solo.
Necesitan señales y sensores que proporcionen visibilidad, contexto que convierta esas señales en comprensión y actuadores que traduzcan las decisiones en protección. Con ISOC, estas capas trabajan en conjunto, para que los agentes puedan ir más allá de tareas aisladas y ayudar a operar un SOC agéntico.
Las señales y sensores proporcionan conciencia del sistema.
El contexto convierte esas señales en comprensión.
Los actuadores convierten las percepciones en acción protectora.
ISOC reúne estas capacidades como base, para que humanos y agentes puedan operar como un solo sistema, donde cada uno aporta lo que mejor sabe hacer. Los agentes proporcionan la velocidad y la escala para ejecutar de manera continua, mientras que las personas establecen prioridades, aplican juicio y definen los resultados que importan. Juntos, empoderan a los defensores para mantenerse al día con los actores amenazantes impulsados por IA y lograr mejores resultados de seguridad.
Bucle de protección integrado
Con ISOC que permite que señales, contexto y controles funcionen como uno solo, este rompe el patrón de flujos de trabajo lineales de seguridad. El resultado es un bucle de protección integrado que convierte de manera continua lo que los defensores aprenden en una protección previa a la brecha más fuerte.
La interrupción de ataques en Microsoft Defender muestra lo que esto hace posible. La telemetría y los controles ricos permiten al sistema detectar, predecir y adaptarse a un atacante mientras el ataque aún está en desarrollo. Interrumpe las amenazas en curso y anticipa hacia dónde pueden moverse los atacantes a continuación. Es un bucle de protección que utiliza información de exposición para reforzar la protección casi en tiempo real, con la inteligencia de amenazas que centra el bucle en las amenazas que más importan.
ISOC reúne las capacidades necesarias para hacer que este bucle sea nativo, lo que elimina la carga de montarlo, ajustarlo y mantenerlo ustedes mismos. Y a medida que avanza la protección, nuevas capacidades pueden formar parte de ese ciclo. El resultado es una protección más fuerte y una manera diferente de trabajar, donde los profesionales dedican menos tiempo a perseguir señales individuales y más tiempo en aplicar juicios, para establecer prioridades e impulsar resultados de seguridad.
Diseñado para el practicante
Durante demasiado tiempo, los profesionales han tenido que compensar los límites en su arquitectura de seguridad, a través de unir señales, reconstruir el contexto y moviéndose entre herramientas solo para obtener la información y los controles necesarios para actuar.
ISOC cambia su punto de partida. Las capacidades que los profesionales necesitan para investigar, buscar, automatizar, gestionar incidentes, comprender amenazas y actuar se reúnen y están disponibles por defecto. En lugar de organizar su trabajo en torno a los límites entre herramientas, los equipos pueden organizarse en torno al resultado de seguridad que intentan lograr.
Y esa base se vuelve más poderosa a medida que crece la autonomía. El bucle de protección integrado puede asumir más del trabajo continuo de detección y defensa contra amenazas, mientras que los agentes ayudan a los profesionales a investigar, razonar y actuar a través del mismo contexto y controles que ya disponen.
No hay una capa agéntica separada que ensamblar, ni un nuevo modelo operativo que unir. Los profesionales pueden multiplicar su experiencia donde ya trabajan, para desplazar más tiempo de operar la pila de seguridad para dirigir la defensa.
El camino por seguir
La seguridad siempre ha sido una carrera entre atacantes y defensores. La IA cambia la velocidad, la escala y la economía de esa carrera. El próximo SOC no se definirá por cuántas características de IA tiene, sino por si las personas y agentes pueden percibir, razonar y actuar en un entorno como un solo sistema.
Para saber más sobre las soluciones de Microsoft Security, visiten nuestra página web. Guarden el blog de Seguridad en Favoritos para estar al día con nuestra cobertura experta sobre temas de seguridad. Además, síganos en LinkedIn (Microsoft Security) y X (@MSFTSecurity) para las últimas noticias y actualizaciones sobre ciberseguridad.
AWS announces the general availability of Amazon CloudWatch Omni, an evolution of Amazon CloudWatch. Omni is an AI-powered observability experience organized around your teams and the applications they run, so that you can observe and troubleshoot your applications and agents in one place. It combines the interoperability of OpenTelemetry with the scale and reliability of CloudWatch. And it meets you wherever you work: a standalone web experience with single sign-on (SSO) for your team, or a local IDE extension for getting hands-on with your agents.
With CloudWatch Omni, you create spaces in your central accounts to see telemetry across your AWS accounts and Regions, as well as other clouds, including Azure workloads. Omni automatically discovers services, maps dependencies, and surfaces golden metrics to help streamline your operational workflows. Using Omni, you can interact with telemetry however you prefer: via chat, through a guided point-and-click path in the console, or directly from a tool of your choice leveraging Agent Toolkit for AWS. Ask a question in natural language and Omni finds the relevant telemetry, builds dynamic views of the signals you care about, and helps you get to root cause powered by AWS DevOps Agent. Prefer to drive yourself? Point and click through the signals that matter most, whether you’re investigating a degrading application or diving deep into a trace or evaluation.
Omni also features a dedicated agent observability experience with an evaluation-driven development workflow for AI workloads across frameworks including LangGraph, CrewAI, OpenAI Agents SDK, Vercel AI SDK, and Strands. For every prompt, model call, and tool invocation, Omni helps you evaluate quality and run experiments to validate fixes before you ship.
To get started, create your Omni space from the CloudWatch console, configure SSO, and sign in to the standalone web experience. Agent developers can install the free CloudWatch Omni extension for VS Code, Cursor, and Kiro to instrument, debug, and evaluate agents locally (no AWS account required). CloudWatch Omni is generally available in US East (N. Virginia), US West (Oregon) and Europe (Ireland). To learn more, see the Amazon CloudWatch Omni product page and documentation. For pricing, see the CloudWatch Omni pricing page.
AWS announces the general availability of Amazon CloudWatch Omni, an evolution of Amazon CloudWatch. Omni is an AI-powered observability experience organized around your teams and the applications they run, so that you can observe and troubleshoot your applications and agents in one place. It combines the interoperability of OpenTelemetry with the scale and reliability of CloudWatch. And it meets you wherever you work: a standalone web experience with single sign-on (SSO) for your team, or a local IDE extension for getting hands-on with your agents.
With CloudWatch Omni, you create spaces in your central accounts to see telemetry across your AWS accounts and Regions, as well as other clouds, including Azure workloads. Omni automatically discovers services, maps dependencies, and surfaces golden metrics to help streamline your operational workflows. Using Omni, you can interact with telemetry however you prefer: via chat, through a guided point-and-click path in the console, or directly from a tool of your choice leveraging Agent Toolkit for AWS. Ask a question in natural language and Omni finds the relevant telemetry, builds dynamic views of the signals you care about, and helps you get to root cause powered by AWS DevOps Agent. Prefer to drive yourself? Point and click through the signals that matter most, whether you’re investigating a degrading application or diving deep into a trace or evaluation.
Omni also features a dedicated agent observability experience with an evaluation-driven development workflow for AI workloads across frameworks including LangGraph, CrewAI, OpenAI Agents SDK, Vercel AI SDK, and Strands. For every prompt, model call, and tool invocation, Omni helps you evaluate quality and run experiments to validate fixes before you ship.
To get started, create your Omni space from the CloudWatch console, configure SSO, and sign in to the standalone web experience. Agent developers can install the free CloudWatch Omni extension for VS Code, Cursor, and Kiro to instrument, debug, and evaluate agents locally (no AWS account required). CloudWatch Omni is generally available in US East (N. Virginia), US West (Oregon) and Europe (Ireland). To learn more, see the Amazon CloudWatch Omni product page and documentation. For pricing, see the CloudWatch Omni pricing page.
Amazon EMR 7.14 is now available with new features across Amazon EMR on EC2, Amazon EMR on EKS, and Amazon EMR Serverless, along with version upgrades for additional applications. This release also upgrades Apache Spark to 3.5.8 and Apache Iceberg to 1.10.1.
Apache Iceberg materialized views now refresh faster on tables with updates and deletes, using change data capture to read only the data files affected by a change. On Amazon EMR on EKS, clusters now support Spark Connect endpoints for interactive Spark sessions with token-based authentication, and can run workloads on IPv6 Amazon EKS clusters. On Amazon EMR Serverless, the storage limit for Spark jobs increases from 200 GiB to 1 TiB, giving more room for shuffle data.
Amazon EMR 7.14 is available in all AWS Regions where Amazon EMR is available.
Amazon EMR 7.14 is now available with new features across Amazon EMR on EC2, Amazon EMR on EKS, and Amazon EMR Serverless, along with version upgrades for additional applications. This release also upgrades Apache Spark to 3.5.8 and Apache Iceberg to 1.10.1.
Apache Iceberg materialized views now refresh faster on tables with updates and deletes, using change data capture to read only the data files affected by a change. On Amazon EMR on EKS, clusters now support Spark Connect endpoints for interactive Spark sessions with token-based authentication, and can run workloads on IPv6 Amazon EKS clusters. On Amazon EMR Serverless, the storage limit for Spark jobs increases from 200 GiB to 1 TiB, giving more room for shuffle data.
Amazon EMR 7.14 is available in all AWS Regions where Amazon EMR is available.
To learn more, visit the Amazon EMR 7.14 Release Guide, or get started by creating a cluster from the Amazon EMR console.
AWS Billing Transfer users can now enable the Auto-Billing Transfer Billing Group Creation, a new AWS Billing Conductor preference that eliminates the manual billing group configuration in two-level billing transfer arrangements. Designed for AWS Distributors managing billing for downstream seller Partners and their end customers, this feature automatically creates billing groups when an end customer accepts a billing transfer from a downstream seller Partner, ensuring pro forma cost data is immediately available to the Partner, with no extra manual configuration.
Auto-Billing Transfer Billing Group Creation is a one-time preference configuration per inbound transfer relationship, enabling you to request the creation of a billing group for any new indirect transfer coming through your Partners’ account, as well as being able to specify an AWS Billing Conductor pricing plan for the billing groups created automatically.
The preference is accessible through two new API operations and through the AWS Management Console in the Billing Transfer details page.
To learn more about Auto-Billing Transfer Billing Group Creation and how to configure your billing transfer preferences, visit the AWS Billing Conductor documentation.
AWS Billing Transfer users can now enable the Auto-Billing Transfer Billing Group Creation, a new AWS Billing Conductor preference that eliminates the manual billing group configuration in two-level billing transfer arrangements. Designed for AWS Distributors managing billing for downstream seller Partners and their end customers, this feature automatically creates billing groups when an end customer accepts a billing transfer from a downstream seller Partner, ensuring pro forma cost data is immediately available to the Partner, with no extra manual configuration.
Auto-Billing Transfer Billing Group Creation is a one-time preference configuration per inbound transfer relationship, enabling you to request the creation of a billing group for any new indirect transfer coming through your Partners’ account, as well as being able to specify an AWS Billing Conductor pricing plan for the billing groups created automatically.
The preference is accessible through two new API operations and through the AWS Management Console in the Billing Transfer details page.
To learn more about Auto-Billing Transfer Billing Group Creation and how to configure your billing transfer preferences, visit the AWS Billing Conductor documentation.
AWS Glue Data Quality now generates data quality rules in seconds, reducing the time to establish data quality checks for your tables in the AWS Glue Data Catalog. You get a ready-to-use set of rules with full coverage across every column, with no manual setup—so you can move from raw data to trusted data faster while authoring pipelines.
This is delivered through a new Advanced mode for rule recommendations, in which AWS Glue Data Quality uses generative AI to detect the intent behind your data and proposes business-relevant rules that reflect how your data is used. You can use this Advanced mode to bootstrap rules for a newly onboarded dataset or establish baseline checks across a large data lake without hand-writing each rule. You review the recommended rules, adjust as needed, and save them as a ruleset to begin monitoring immediately.
Advanced mode is available in the following AWS Regions: Asia Pacific (Melbourne, Osaka, Sydney, Tokyo), Canada (Central), Europe (Frankfurt, Ireland, London, Milan, Paris, Spain, Stockholm, Zurich), US East (N. Virginia, Ohio), and US West (N. California, Oregon).
AWS Glue Data Quality now generates data quality rules in seconds, reducing the time to establish data quality checks for your tables in the AWS Glue Data Catalog. You get a ready-to-use set of rules with full coverage across every column, with no manual setup—so you can move from raw data to trusted data faster while authoring pipelines.
This is delivered through a new Advanced mode for rule recommendations, in which AWS Glue Data Quality uses generative AI to detect the intent behind your data and proposes business-relevant rules that reflect how your data is used. You can use this Advanced mode to bootstrap rules for a newly onboarded dataset or establish baseline checks across a large data lake without hand-writing each rule. You review the recommended rules, adjust as needed, and save them as a ruleset to begin monitoring immediately.
Advanced mode is available in the following AWS Regions: Asia Pacific (Melbourne, Osaka, Sydney, Tokyo), Canada (Central), Europe (Frankfurt, Ireland, London, Milan, Paris, Spain, Stockholm, Zurich), US East (N. Virginia, Ohio), and US West (N. California, Oregon).
To get started, see the AWS Glue Data Quality documentation.
Today, AWS announces the general availability of GPT-6 Sol and GPT-6 Luna from OpenAI on Amazon Bedrock. Expanding the GPT-6 family alongside Astra, these two models give teams more ways to balance intelligence, speed, and cost across every workload. Sol is the daily model for recurring complex tasks and software development. On an internal OpenAI factuality evaluation, it makes roughly half as many mistakes as GPT-5.6 Sol. Luna is the family’s most efficient model for focused, high-volume tasks such as summarization, extraction, classification, and routing. Both models support up to 1M tokens of context. The Amazon Bedrock inference engine delivers the performance, security, and scale required for production workloads.
GPT-6 Sol can implement features, debug issues, review and refactor code, analyze data, and complete multistep workflows across tools. Improvements in coding and computer use help it carry tasks from investigation through validation. GPT-6 Luna handles high-volume workloads like extraction, summarization, classification, and routing, with adjustable reasoning effort to balance quality, speed, and cost per request. Established AWS controls help you secure workloads, govern access, and audit model invocation activity.
Today, AWS announces the general availability of GPT-6 Sol and GPT-6 Luna from OpenAI on Amazon Bedrock. Expanding the GPT-6 family alongside Astra, these two models give teams more ways to balance intelligence, speed, and cost across every workload. Sol is the daily model for recurring complex tasks and software development. On an internal OpenAI factuality evaluation, it makes roughly half as many mistakes as GPT-5.6 Sol. Luna is the family’s most efficient model for focused, high-volume tasks such as summarization, extraction, classification, and routing. Both models support up to 1M tokens of context. The Amazon Bedrock inference engine delivers the performance, security, and scale required for production workloads.
GPT-6 Sol can implement features, debug issues, review and refactor code, analyze data, and complete multistep workflows across tools. Improvements in coding and computer use help it carry tasks from investigation through validation. GPT-6 Luna handles high-volume workloads like extraction, summarization, classification, and routing, with adjustable reasoning effort to balance quality, speed, and cost per request. Established AWS controls help you secure workloads, govern access, and audit model invocation activity.
You can get started with GPT-6 Sol and GPT-6 Luna in the Amazon Bedrock console or programmatically through supported Amazon Bedrock APIs. For information about supported AWS Regions, endpoints, APIs, features, inference profiles and pricing, see the Amazon Bedrock documentation. To learn more, read the blog.
AWS Security Hub AI Inventory now supports discovering and cataloging AI assets running on self-hosted instances in Microsoft Azure. This expansion extends Security Hub’s existing self-hosted discovery capabilities beyond AWS, enabling central security teams to gain a continuously updated, organization-wide view of AI assets and their security posture across multi-cloud environments.
Security Hub leverages the software bill of materials (SBOM) analysis from Amazon Inspector, which has been enhanced to identify inference endpoints, models, and AI agents installed on Azure virtual machines, including frameworks such as Ollama, vLLM, Hugging Face TGI, and others. Each discovered AI asset is mapped to its underlying infrastructure and correlated with security findings, enabling teams to filter, group, and query their AI inventory across both AWS and Azure environments.
This capability is included with Security Hub Essentials at no additional cost. It is available in all AWS commercial Regions where Security Hub is offered. To learn more, see the AWS Security Hub User Guide and the AWS Security Hub product page.
AWS Security Hub AI Inventory now supports discovering and cataloging AI assets running on self-hosted instances in Microsoft Azure. This expansion extends Security Hub’s existing self-hosted discovery capabilities beyond AWS, enabling central security teams to gain a continuously updated, organization-wide view of AI assets and their security posture across multi-cloud environments.
Security Hub leverages the software bill of materials (SBOM) analysis from Amazon Inspector, which has been enhanced to identify inference endpoints, models, and AI agents installed on Azure virtual machines, including frameworks such as Ollama, vLLM, Hugging Face TGI, and others. Each discovered AI asset is mapped to its underlying infrastructure and correlated with security findings, enabling teams to filter, group, and query their AI inventory across both AWS and Azure environments.
This capability is included with Security Hub Essentials at no additional cost. It is available in all AWS commercial Regions where Security Hub is offered. To learn more, see the AWS Security Hub User Guide and the AWS Security Hub product page.
AWS GovCloud (US) now offers Claude Opus 5.5, Anthropic’s most capable Opus model yet and, the first of the Claude 5.5 model family, a better collaborator that handles long-running coding and knowledge work, reporting back clearly on what it did, what it found, and what it needs next.
According to Anthropic, Claude Opus 5.5 completes tasks using fewer tokens than Claude Opus 5, at a lower price per token, with cheaper cache reads stacking on top of the efficiency gain. Claude Opus 5.5 is the enterprise workhorse, a clear step up from Opus 5 on the work teams count on Opus to do. It handles long-running coding and knowledge work, and reports back like a good teammate, surfacing what it did, what it found, and what it needs from you. It thinks adaptively on every request, deciding how much effort each task needs.
Amazon Bedrock gives you Opus 5.5’s advanced capabilities with zero data retention (ZDR) support by default. It keeps your data within AWS infrastructure with regional data residency and provides access through a unified service with AWS-managed features like Guardrails and Knowledge Bases. To learn more, see the Amazon Bedrock documentation and regional availability.
AWS GovCloud (US) now offers Claude Opus 5.5, Anthropic’s most capable Opus model yet and, the first of the Claude 5.5 model family, a better collaborator that handles long-running coding and knowledge work, reporting back clearly on what it did, what it found, and what it needs next.
According to Anthropic, Claude Opus 5.5 completes tasks using fewer tokens than Claude Opus 5, at a lower price per token, with cheaper cache reads stacking on top of the efficiency gain. Claude Opus 5.5 is the enterprise workhorse, a clear step up from Opus 5 on the work teams count on Opus to do. It handles long-running coding and knowledge work, and reports back like a good teammate, surfacing what it did, what it found, and what it needs from you. It thinks adaptively on every request, deciding how much effort each task needs.
Amazon Bedrock gives you Opus 5.5’s advanced capabilities with zero data retention (ZDR) support by default. It keeps your data within AWS infrastructure with regional data residency and provides access through a unified service with AWS-managed features like Guardrails and Knowledge Bases. To learn more, see the Amazon Bedrock documentation and regional availability.
AWS now offers Claude Opus 5.5, Anthropic’s most capable Opus model yet and, the first of the Claude 5.5 model family, a better collaborator that handles long-running coding and knowledge work, reporting back clearly on what it did, what it found, and what it needs next.
According to Anthropic, Claude Opus 5.5 completes tasks using fewer tokens than Claude Opus 5, at a lower price per token, with cheaper cache reads stacking on top of the efficiency gain. Claude Opus 5.5 is the enterprise workhorse, a clear step up from Opus 5 on the work teams count on Opus to do. It handles long-running coding and knowledge work, and reports back like a good teammate, surfacing what it did, what it found, and what it needs from you. It thinks adaptively on every request, deciding how much effort each task needs.
Customers have two ways to access Claude Opus 5.5: Amazon Bedrock and Claude Platform on AWS: Amazon Bedrock gives you Opus 5.5’s advanced capabilities with zero data retention (ZDR) support by default. It keeps your data within AWS infrastructure with regional data residency and provides access through a unified service with AWS-managed features like Guardrails and Knowledge Bases. To learn more, see the Amazon Bedrock documentation and regional availability.
Claude Platform on AWS gives you direct access to Anthropic’s native platform experience and capabilities via the AWS Console. Build, test, and deploy with the same APIs, features, and console experience you’d get working with Anthropic directly, unified with AWS billing and authentication. To get started, see the Claude Platform on AWS documentation.
AWS now offers Claude Opus 5.5, Anthropic’s most capable Opus model yet and, the first of the Claude 5.5 model family, a better collaborator that handles long-running coding and knowledge work, reporting back clearly on what it did, what it found, and what it needs next.
According to Anthropic, Claude Opus 5.5 completes tasks using fewer tokens than Claude Opus 5, at a lower price per token, with cheaper cache reads stacking on top of the efficiency gain. Claude Opus 5.5 is the enterprise workhorse, a clear step up from Opus 5 on the work teams count on Opus to do. It handles long-running coding and knowledge work, and reports back like a good teammate, surfacing what it did, what it found, and what it needs from you. It thinks adaptively on every request, deciding how much effort each task needs.
Customers have two ways to access Claude Opus 5.5: Amazon Bedrock and Claude Platform on AWS: Amazon Bedrock gives you Opus 5.5’s advanced capabilities with zero data retention (ZDR) support by default. It keeps your data within AWS infrastructure with regional data residency and provides access through a unified service with AWS-managed features like Guardrails and Knowledge Bases. To learn more, see the Amazon Bedrock documentation and regional availability.
Claude Platform on AWS gives you direct access to Anthropic’s native platform experience and capabilities via the AWS Console. Build, test, and deploy with the same APIs, features, and console experience you’d get working with Anthropic directly, unified with AWS billing and authentication. To get started, see the Claude Platform on AWS documentation.