Publicado el — Deja un comentario

Amazon WorkSpaces Applications now publishes enhanced observability metrics

Amazon WorkSpaces Applications now publishes additional performance and session health metrics to Amazon CloudWatch, enabling IT administrators to gain deeper visibility into their application streaming workloads. These new metrics span network performance, compute resource utilization, and session lifecycle events — all available at no additional cost.

With these metrics, administrators can proactively identify and troubleshoot issues that impact end-user experience. For example, metrics such as TCP retransmission rate and congestion window help pinpoint network degradation, while GPU utilization and memory page hard faults surface resource bottlenecks before they affect session quality. Session lifecycle metrics like connection failures and connection duration enable teams to set CloudWatch alarms for rapid detection of connectivity issues, build custom dashboards for fleet-wide visibility, and reduce mean time to resolution.

These metrics are available in all AWS Regions where Amazon WorkSpaces Applications is supported.

To get started, navigate to the Amazon CloudWatch console and observe these metrics or update your WorkSpaces Applications custom dashboards. You can also monitor these metrics through WorkSpaces Applications automatic dashboard. To learn more about metric availability by operating system, visit the Amazon WorkSpaces Applications documentation and the CloudWatch metrics reference.

 

​Amazon WorkSpaces Applications now publishes additional performance and session health metrics to Amazon CloudWatch, enabling IT administrators to gain deeper visibility into their application streaming workloads. These new metrics span network performance, compute resource utilization, and session lifecycle events — all available at no additional cost. With these metrics, administrators can proactively identify and troubleshoot issues that impact end-user experience. For example, metrics such as TCP retransmission rate and congestion window help pinpoint network degradation, while GPU utilization and memory page hard faults surface resource bottlenecks before they affect session quality. Session lifecycle metrics like connection failures and connection duration enable teams to set CloudWatch alarms for rapid detection of connectivity issues, build custom dashboards for fleet-wide visibility, and reduce mean time to resolution. These metrics are available in all AWS Regions where Amazon WorkSpaces Applications is supported. To get started, navigate to the Amazon CloudWatch console and observe these metrics or update your WorkSpaces Applications custom dashboards. You can also monitor these metrics through WorkSpaces Applications automatic dashboard. To learn more about metric availability by operating system, visit the Amazon WorkSpaces Applications documentation and the CloudWatch metrics reference.  

Publicado el — Deja un comentario

Una mejor seguridad empieza con mejores preguntas

Una mejor seguridad empieza con mejores preguntas

Esta imagen muestra cómo las soluciones de seguridad protegen contra amenazas. Incluye elementos visuales que representan la detección y prevención de amenazas.

Por: Aarti Borkar, vicepresidenta corporativa de Microsoft Security

A medida que las organizaciones superan la experimentación con IA, el éxito dependerá de lo eficaz que combinen inteligencia y confianza. Los mismos sistemas que amplifican el conocimiento, aceleran decisiones y desbloquean nuevos resultados también deben proteger los datos, gobernar la IA y fomentar la resiliencia. En esta nueva fase de la transformación, la seguridad no está separada de la innovación: es un facilitador que ayuda a hacer posible la innovación responsable a un ritmo más rápido. Eso empieza por hacer mejores preguntas—de esas que ayudan a las organizaciones a convertir la inteligencia en acción y la confianza en una base para el progreso.

La IA ha comenzado a cambiar la manera en que se toman las decisiones de seguridad. Los defensores ahora tienen acceso a más señales, conocimientos y poder analítico que nunca. Pero una mejor seguridad no empieza con más información. Empieza por hacer las preguntas adecuadas: ¿Qué intentamos proteger? ¿Qué riesgos importan más? ¿Qué condiciones deben cumplirse? ¿Y qué decisiones debemos tomar con confianza?

Esa claridad importa porque la seguridad está moldeada por algo más que la tecnología. Los desafíos a los que se enfrentan las organizaciones rara vez existen de forma aislada. Surgen en personas, procesos, tecnología, datos, identidades y gobernanza. Comprender esas conexiones es lo que permite a los equipos de seguridad utilizar plataformas, IA y automatización para tomar mejores decisiones en condiciones reales.

Conéctense con Microsoft Security en Black Hat USA 2026

La seguridad como desafío de sistemas

La seguridad nunca ha sido un reto de una sola capa. Las vulnerabilidades pueden surgir en código, datos, identidades e integraciones, mientras que la exposición suele crearse en las intersecciones entre ellas. Diseñar para la seguridad requiere una mentalidad de sistemas: entender cómo funcionan estos elementos juntos, dónde puede ocurrir un fallo y qué salvaguardas son necesarias para que ninguna capa soporte la carga por sí sola. Por eso la defensa en profundidad es todavía esencial: los controles en capas, la monitorización continua, las mitigaciones y la gestión de riesgos a lo largo del ciclo de vida de la IA ayudan a las organizaciones a reducir la exposición mientras continúan adaptándose.

Esto es en especial importante a medida que la IA se integra más en el funcionamiento de las organizaciones. La IA puede ayudar a los equipos a analizar grandes cantidades de información, identificar patrones y presentar recomendaciones a una escala que antes era impensable. Esos resultados de IA aun requieren de supervisión, gobernanza y juicio humano, con una clara responsabilidad sobre cómo se validan y utilizan los conocimientos generados por IA. Pero la visión solo crea valor cuando está fundamentada en el contexto adecuado y conectada con la acción.

Los conocimientos generados por IA aún requieren validación, supervisión y planificación de la resiliencia porque los sistemas de IA pueden producir resultados incompletos o inexactos.

La claridad genera mejores decisiones

Las decisiones de seguridad más importantes comienzan con una visión clara del riesgo, el nivel de control o visibilidad requerido y el resultado para el que está diseñado el sistema. Cuando optimizamos la capacidad en lugar del contexto, perdemos cómo se toman en realidad las decisiones de seguridad: a través de señales, experiencia, validación y juicio. Esto se vuelve aún más importante a medida que la IA amplía lo posible. Un mejor análisis puede aportar más perspectivas, pero las mejores decisiones todavía dependen de entender qué es lo que más importa y aplicar el contexto adecuado. Eso importa de manera especial cuando las condiciones cambian con rapidez y los equipos deben actuar antes de que cada respuesta sea segura.

La inteligencia de amenazas ofrece un ejemplo útil. Los defensores operan en entornos definidos por la ambigüedad, la información incompleta y condiciones que cambian con rapidez. El éxito rara vez proviene de una sola fuente o señal. Proviene de combinar múltiples formas de inteligencia, aplicar experiencia, validar suposiciones y conectar ideas de manera que fortalezcan la garantía.  

La lección va más allá de la inteligencia de amenazas. Diferentes objetivos de seguridad requieren distintas combinaciones de señales, análisis y juicio humano. Las decisiones resilientes surgen de reunir esos elementos de forma reflexiva, en lugar de depender de una única fuente de verdad o asumir que solo la tecnología puede proporcionar la respuesta.

Diseñar para obtener mejores resultados

A medida que la IA se integra más en las operaciones de seguridad, la calidad de nuestros resultados depende de la claridad con la que definimos los objetivos que queremos alcanzar. Los líderes de seguridad generan más valor cuando identifican los riesgos que más importan, las condiciones que deben cumplirse y los sistemas necesarios para apoyar mejores decisiones.

Luego diseñamos para esos resultados mediante la combinación adecuada de controles, salvaguardas y procesos de toma de decisiones. Esto se refleja no solo en la arquitectura, sino en cómo los equipos establecen barreras de seguridad, validan suposiciones y responden a lo inesperado. El objetivo no es dificultar la seguridad para los defensores. Es para facilitar la ejecución del trabajo, apoyado por plataformas, herramientas e IA que ayudan a ofrecer mayor velocidad, precisión y confianza.

Los sistemas que construimos hoy no existen de manera aislada. Interactúan con las personas, moldean decisiones y operan a una escala que puede amplificar tanto fortalezas como debilidades. Nuestra responsabilidad va más allá de las elecciones tecnológicas. Tenemos que ayudar a las organizaciones a diseñar sistemas que puedan entender, gobernar y en los que confiar con confianza a medida que crece la complejidad.

La confianza no es algo que podamos dar por sentado, y eso no cambia en la era de la IA. Se construye a través de decisiones deliberadas: los controles que establecemos, la visibilidad que creamos, las suposiciones que validamos y las salvaguardas que establecemos. A medida que la IA se integra más en el funcionamiento de las organizaciones, los líderes de seguridad tienen la responsabilidad de ayudar a generar confianza en los sistemas de los que la gente confía cada día.

Construir sistemas de IA fiables requiere gobernanza, seguridad, protecciones de privacidad, transparencia y responsabilidad en toda la pila tecnológica, alineados con principios y estándares responsables de IA.

El riesgo no es tan solo que escojamos la herramienta, modelo o plataforma equivocados. El mayor riesgo es creer que una sola respuesta puede resolver un problema complejo y en evolución. La IA puede ayudar a los equipos a entender la complejidad, pero no elimina la necesidad de juzgar. Si acaso, pone de manifiesto la importancia de definir los resultados adecuados y diseñar sistemas que faciliten la toma de las acciones correctas.

Una mejor seguridad comienza con mejores preguntas y con la claridad para actuar en consecuencia. Las organizaciones que tengan éxito aplicarán la IA de manera reflexiva, definirán los resultados con claridad y combinarán el poder analítico con la experiencia, el juicio y la adaptabilidad necesarios para construir sistemas más resilientes en la era de la IA.

Exploren las soluciones de seguridad de Microsoft

Para saber más sobre las soluciones de seguridad de Microsoft, visiten nuestra página web. Agreguen a Favoritos el blog de Seguridad para estar al día con nuestra cobertura experta sobre temas de seguridad. Además, síganos en LinkedIn (Microsoft Security) y X (@MSFTSecurity) para las últimas noticias y actualizaciones sobre ciberseguridad.

The post Una mejor seguridad empieza con mejores preguntas appeared first on Source LATAM.

 

​The post Una mejor seguridad empieza con mejores preguntas appeared first on Source LATAM.  

Publicado el — Deja un comentario

Amazon RDS now provides visibility into storage volume initialization status

Amazon RDS now provides visibility into the initialization status of database storage volumes created from snapshots. You can use this status to determine when your storage is fully initialized after a restore and is ready to support latency-sensitive database workloads at fully provisioned performance.

When you restore a database instance to a point-in-time, or create a read replica creation, or convert from Single-AZ to Multi-AZ conversion, Amazon RDS creates storage volumes from a snapshot. These volumes undergo initialization, during which storage blocks are downloaded from Amazon S3 and written to the volume before they can be accessed. The initialization rate varies depending on the workload and which blocks are accessed and during this period you may notice increased I/O latency. Previously, Amazon RDS reported the instance as available throughout initialization, giving you no direct signal for when performance would stabilize. The new StorageOperationStatus and StorageOperationPercentProgress fields on the RDS Console and DescribeDBInstances API let you monitor your storage initialization progress in real time, so you can validate when all blocks have been written. You can use the information to time your workloads to align with its completion. The fields also report storage optimization progress so you can plan for full provisioned performance after a storage modification.

Storage volume initialization status is accessible by default for all Amazon RDS database instances in all commercial AWS Regions and US GovCloud Regions. You can start using it today through the Amazon RDS Management Console, the AWS Command Line Interface (CLI), or the AWS SDKs. To learn more, see Amazon RDS storage in the Amazon RDS User Guide.

 

​Amazon RDS now provides visibility into the initialization status of database storage volumes created from snapshots. You can use this status to determine when your storage is fully initialized after a restore and is ready to support latency-sensitive database workloads at fully provisioned performance. When you restore a database instance to a point-in-time, or create a read replica creation, or convert from Single-AZ to Multi-AZ conversion, Amazon RDS creates storage volumes from a snapshot. These volumes undergo initialization, during which storage blocks are downloaded from Amazon S3 and written to the volume before they can be accessed. The initialization rate varies depending on the workload and which blocks are accessed and during this period you may notice increased I/O latency. Previously, Amazon RDS reported the instance as available throughout initialization, giving you no direct signal for when performance would stabilize. The new StorageOperationStatus and StorageOperationPercentProgress fields on the RDS Console and DescribeDBInstances API let you monitor your storage initialization progress in real time, so you can validate when all blocks have been written. You can use the information to time your workloads to align with its completion. The fields also report storage optimization progress so you can plan for full provisioned performance after a storage modification. Storage volume initialization status is accessible by default for all Amazon RDS database instances in all commercial AWS Regions and US GovCloud Regions. You can start using it today through the Amazon RDS Management Console, the AWS Command Line Interface (CLI), or the AWS SDKs. To learn more, see Amazon RDS storage in the Amazon RDS User Guide.  

Publicado el — Deja un comentario

Announcing temporal policies and rate limiting in Amazon Bedrock AgentCore

Amazon Bedrock AgentCore announces two new controls: temporal policies for stateful agent authorization and rate limiting for AI traffic.

Temporal policies let you define stateful authorization rules that evaluate each request in the context of an agent’s prior actions within a session, because a single tool call can be safe in isolation yet harmful given what preceded it. With temporal policies you can enforce workflow sequencing, require that a tool argument exactly matches the output of a prior call, require human approval before taking privileged actions, and enforce data freshness.

Rate limiting enables per-user or per-group controls over how much traffic flows to the tools, models, and agents connected to your gateway. Using rules scoped by OAuth or AWS IAM, you can set rate limits on requests across all target types, tokens for inference targets, and concurrent connections to cap long-lived concurrent sessions, aiding downstream service availability and enforcing fair limit distribution. 

For regional availability and to learn more, see the documentation, read the announcement blog, and explore the Dogwood reference implementation. 

 

​Amazon Bedrock AgentCore announces two new controls: temporal policies for stateful agent authorization and rate limiting for AI traffic.
Temporal policies let you define stateful authorization rules that evaluate each request in the context of an agent’s prior actions within a session, because a single tool call can be safe in isolation yet harmful given what preceded it. With temporal policies you can enforce workflow sequencing, require that a tool argument exactly matches the output of a prior call, require human approval before taking privileged actions, and enforce data freshness.
Rate limiting enables per-user or per-group controls over how much traffic flows to the tools, models, and agents connected to your gateway. Using rules scoped by OAuth or AWS IAM, you can set rate limits on requests across all target types, tokens for inference targets, and concurrent connections to cap long-lived concurrent sessions, aiding downstream service availability and enforcing fair limit distribution. 
For regional availability and to learn more, see the documentation, read the announcement blog, and explore the Dogwood reference implementation.   

Publicado el — Deja un comentario

AWS Glue Data Quality makes ETL anomaly detection free and improves anomaly predictions

AWS Glue Data Quality now offers improved anomaly detection with a new observation mode that reduces detection of false anomalies and removes pricing for anomaly detection in ETL jobs. Customers using notebook-based or exploratory workflows now benefit from smarter anomaly detection that gracefully handles irregular data arrival intervals. This new capability avoids over-extrapolating trends by using a constant baseline instead of a linear trend, delivering more accurate alerts and reducing noise so teams can focus on genuine anomalies.

The new anomaly detection observation mode is particularly useful for exploratory data analysis, datasets with flat or random patterns, workloads without predictable trends and cases where you run data quality checks on varying schedules or in interactive environments like notebooks. Additionally, anomaly detection for AWS Glue ETL jobs is now available at no additional cost, so you can monitor data quality anomalies across all your Glue pipelines without worrying about pricing.

These improvements are available in all AWS commercial regions and AWS GovCloud (US) regions.

To get started, visit the AWS Glue Data Quality documentation. To learn more about pricing, see the AWS Glue pricing page.

 

​AWS Glue Data Quality now offers improved anomaly detection with a new observation mode that reduces detection of false anomalies and removes pricing for anomaly detection in ETL jobs. Customers using notebook-based or exploratory workflows now benefit from smarter anomaly detection that gracefully handles irregular data arrival intervals. This new capability avoids over-extrapolating trends by using a constant baseline instead of a linear trend, delivering more accurate alerts and reducing noise so teams can focus on genuine anomalies. The new anomaly detection observation mode is particularly useful for exploratory data analysis, datasets with flat or random patterns, workloads without predictable trends and cases where you run data quality checks on varying schedules or in interactive environments like notebooks. Additionally, anomaly detection for AWS Glue ETL jobs is now available at no additional cost, so you can monitor data quality anomalies across all your Glue pipelines without worrying about pricing. These improvements are available in all AWS commercial regions and AWS GovCloud (US) regions. To get started, visit the AWS Glue Data Quality documentation. To learn more about pricing, see the AWS Glue pricing page.  

Publicado el — Deja un comentario

AWS Lambda announces scalable network bandwidth up to 3,000 Mbps for functions outside a VPC

AWS Lambda now supports scalable network bandwidth for Lambda functions, enabling faster data transfer to and from your execution environment for latency-sensitive workloads. This feature enables functions outside a VPC configured with 2 GB of memory or more to access network bandwidth that scales proportionally, from 625 Mbps at 2 GB up to 3,000 Mbps at 10 GB.

Customers use Lambda to build latency-sensitive data processing workloads, which need to transfer large volumes of data – up to several terabytes – from external data sources into the function’s execution environment for processing. As data volume and performance requirements grow, the existing limit of 625 Mbps can constrain data transfer speeds to and from an execution environment. With this launch, network throughput increases proportionally from 625 Mbps at 2 GB up to 3,000 Mbps at 10 GB, helping reduce function execution times and per-invocation costs while improving end-user experience.

To get started, submit a request through AWS Service Quotas under the Network bandwidth per execution environment quota to enable scalable network bandwidth on your account. Once enabled, bandwidth will scale automatically based on your function’s memory configuration for all functions outside a VPC in your account.

Scalable network bandwidth for functions outside a VPC is available at no additional charge in all commercial AWS Regions. To learn more, visit the Lambda quotas page. 

 

​AWS Lambda now supports scalable network bandwidth for Lambda functions, enabling faster data transfer to and from your execution environment for latency-sensitive workloads. This feature enables functions outside a VPC configured with 2 GB of memory or more to access network bandwidth that scales proportionally, from 625 Mbps at 2 GB up to 3,000 Mbps at 10 GB. Customers use Lambda to build latency-sensitive data processing workloads, which need to transfer large volumes of data – up to several terabytes – from external data sources into the function’s execution environment for processing. As data volume and performance requirements grow, the existing limit of 625 Mbps can constrain data transfer speeds to and from an execution environment. With this launch, network throughput increases proportionally from 625 Mbps at 2 GB up to 3,000 Mbps at 10 GB, helping reduce function execution times and per-invocation costs while improving end-user experience. To get started, submit a request through AWS Service Quotas under the Network bandwidth per execution environment quota to enable scalable network bandwidth on your account. Once enabled, bandwidth will scale automatically based on your function’s memory configuration for all functions outside a VPC in your account. Scalable network bandwidth for functions outside a VPC is available at no additional charge in all commercial AWS Regions. To learn more, visit the Lambda quotas page.   

Publicado el — Deja un comentario

Amazon Keyspaces (for Apache Cassandra) is now available in the Canada West (Calgary) Region (ca-west-1)

Amazon Keyspaces (for Apache Cassandra) is now available in the Canada West (Calgary) Region (ca-west-1), allowing customers in the Canada West Region to build Cassandra-compatible applications with lower latency while keeping their data within the Region to meet data residency requirements. 

Amazon Keyspaces (for Apache Cassandra) is a scalable, highly available, and managed Apache Cassandra–compatible database service. Amazon Keyspaces is serverless, so you pay for only the resources that you use and you can build applications that serve thousands of requests per second with virtually unlimited throughput and storage. 

This regional expansion enables organizations in Canada to build highly scalable, low-latency applications using familiar Cassandra Query Language (CQL) without the operational burden of managing Cassandra clusters.

To learn more about on Keyspaces, visit the Amazon Keyspaces documentation.

 

​Amazon Keyspaces (for Apache Cassandra) is now available in the Canada West (Calgary) Region (ca-west-1), allowing customers in the Canada West Region to build Cassandra-compatible applications with lower latency while keeping their data within the Region to meet data residency requirements. 
Amazon Keyspaces (for Apache Cassandra) is a scalable, highly available, and managed Apache Cassandra–compatible database service. Amazon Keyspaces is serverless, so you pay for only the resources that you use and you can build applications that serve thousands of requests per second with virtually unlimited throughput and storage. 
This regional expansion enables organizations in Canada to build highly scalable, low-latency applications using familiar Cassandra Query Language (CQL) without the operational burden of managing Cassandra clusters.
To learn more about on Keyspaces, visit the Amazon Keyspaces documentation.  

Publicado el — Deja un comentario

AWS IAM Identity Center makes managment of AWS account access optional for new organization instances

AWS IAM Identity Center now lets you decide whether to enable management of AWS account access when you create a new organization instance. This allows you to use IAM Identity Center to manage access to AWS applications only, without the need to manage access to AWS accounts. This feature is available at the time of initial configuration of an IAM Identity Center instance and does not affect existing IAM Identity Center instances.

IAM Identity Center enables you to connect your workforce identities to AWS once and offer AWS application owners across your organization streamlined access management. Application end users benefit from single sign-on, user awareness, and consistent authentication experience across AWS applications. Previously, this meant you also needed to manage access to AWS accounts. With this release, account management is now optional. When you choose not to enable management of AWS accounts, IAM Identity Center does not provision its service-linked role into your member accounts, which reduces the access surface in your environment. You can enable account management permissions later through instance settings or the UpdateInstance API. 

This capability is available in all AWS Regions where IAM Identity Center is available. To get started, see Configure instance settings in the IAM Identity Center User Guide.

 

​AWS IAM Identity Center now lets you decide whether to enable management of AWS account access when you create a new organization instance. This allows you to use IAM Identity Center to manage access to AWS applications only, without the need to manage access to AWS accounts. This feature is available at the time of initial configuration of an IAM Identity Center instance and does not affect existing IAM Identity Center instances.
IAM Identity Center enables you to connect your workforce identities to AWS once and offer AWS application owners across your organization streamlined access management. Application end users benefit from single sign-on, user awareness, and consistent authentication experience across AWS applications. Previously, this meant you also needed to manage access to AWS accounts. With this release, account management is now optional. When you choose not to enable management of AWS accounts, IAM Identity Center does not provision its service-linked role into your member accounts, which reduces the access surface in your environment. You can enable account management permissions later through instance settings or the UpdateInstance API. 
This capability is available in all AWS Regions where IAM Identity Center is available. To get started, see Configure instance settings in the IAM Identity Center User Guide.  

Publicado el — Deja un comentario

AWS Marketplace adds AI Insights so buyers can understand pricing before they buy

You can now understand how a product’s pricing works before you buy it. Available in the pricing section of the listing in AWS Marketplace, AI Insights explains each product’s pricing in plain language: what a pricing unit maps to, how your bill changes as usage scales, how multiple pricing dimensions combine into one cost, and what is and isn’t included. Answering these questions used to mean having to visit multiple websites and piecing together pricing details on your own. Now the context sits on the listing, so you can evaluate pricing and move to purchase without switching tabs.

AI Insights cites sources so you can see where the explanations come from. AI Insights draws from the pricing the seller publishes on the Marketplace listing, and additional pricing context on the seller’s public website.

AI Insights is live today on most listings where external pricing context is available. It is available in all commercial AWS Regions where AWS Marketplace is available. To see it, open any product listing on the AWS Marketplace website and scroll to the pricing section. Sellers can review what appears on their listing and request edits at any time through the Contact Us form linked in the AI Insights page on the AWS Marketplace Seller Guide.

 

​You can now understand how a product’s pricing works before you buy it. Available in the pricing section of the listing in AWS Marketplace, AI Insights explains each product’s pricing in plain language: what a pricing unit maps to, how your bill changes as usage scales, how multiple pricing dimensions combine into one cost, and what is and isn’t included. Answering these questions used to mean having to visit multiple websites and piecing together pricing details on your own. Now the context sits on the listing, so you can evaluate pricing and move to purchase without switching tabs.
AI Insights cites sources so you can see where the explanations come from. AI Insights draws from the pricing the seller publishes on the Marketplace listing, and additional pricing context on the seller’s public website.
AI Insights is live today on most listings where external pricing context is available. It is available in all commercial AWS Regions where AWS Marketplace is available. To see it, open any product listing on the AWS Marketplace website and scroll to the pricing section. Sellers can review what appears on their listing and request edits at any time through the Contact Us form linked in the AI Insights page on the AWS Marketplace Seller Guide.  

Publicado el — Deja un comentario

Amazon DynamoDB now supports real-time vector search

Today, AWS announces the general availability of vector search for Amazon DynamoDB, a new feature to index and search vectors in real time. As vector datasets grow into the billions or trillions, vector search at scale traditionally trades off search speed, scale, and accuracy: latency climbs with vector count unless you accept lower recall or throughput. DynamoDB now supports native vector search with single-digit millisecond latency at 99%+ recall and is designed for any scale, even trillions of vectors.

With DynamoDB vector search, you store vector embeddings alongside your other attributes and generate them using a model of your choice, including models available on Amazon Bedrock. You create a vector index and run approximate nearest neighbor searches, pick the vector index partition key to scale, and filter on attributes to scope results. You get the same serverless benefits you rely on today: zero infrastructure management, zero downtime, zero maintenance windows, and pay for only what you use. You can already use DynamoDB to store memory for AI agents, and with vector search you can now add semantic retrieval over that memory for agentic grounding, along with product similarity search, personalized advertising, retrieval augmented generation, and recommendation systems, with predictable performance.

To learn more, visit the AWS News Blog, Amazon DynamoDB product page, and Amazon DynamoDB Developer Guide.

 

​Today, AWS announces the general availability of vector search for Amazon DynamoDB, a new feature to index and search vectors in real time. As vector datasets grow into the billions or trillions, vector search at scale traditionally trades off search speed, scale, and accuracy: latency climbs with vector count unless you accept lower recall or throughput. DynamoDB now supports native vector search with single-digit millisecond latency at 99%+ recall and is designed for any scale, even trillions of vectors. With DynamoDB vector search, you store vector embeddings alongside your other attributes and generate them using a model of your choice, including models available on Amazon Bedrock. You create a vector index and run approximate nearest neighbor searches, pick the vector index partition key to scale, and filter on attributes to scope results. You get the same serverless benefits you rely on today: zero infrastructure management, zero downtime, zero maintenance windows, and pay for only what you use. You can already use DynamoDB to store memory for AI agents, and with vector search you can now add semantic retrieval over that memory for agentic grounding, along with product similarity search, personalized advertising, retrieval augmented generation, and recommendation systems, with predictable performance. To learn more, visit the AWS News Blog, Amazon DynamoDB product page, and Amazon DynamoDB Developer Guide.