Publicado el Deja un comentario

Amazon EC2 Dedicated Hosts now support AMD SEV-SNP

Amazon EC2 is announcing support for AMD Secure Encrypted Virtualization-Secure Nested Paging (SEV-SNP) on Dedicated Hosts, enabling customers to run their confidential computing workloads on physical servers fully dedicated to their use.

Customers can allocate a Dedicated Host with SEV-SNP enabled and launch SEV-SNP instances on it. This gives customers the benefits of Dedicated Hosts for confidential computing workloads, including control over instance placement, and host affinity that allows customers to deploy instances to the same physical server over time. The physical host is provisioned with AMD security firmware during allocation, ensuring a customer’s confidential computing environment is up to date.

Dedicated Host SEV-SNP is available in all AWS commercial Regions with AMD instances. To learn more, visit our documentation.

 

​Amazon EC2 is announcing support for AMD Secure Encrypted Virtualization-Secure Nested Paging (SEV-SNP) on Dedicated Hosts, enabling customers to run their confidential computing workloads on physical servers fully dedicated to their use. Customers can allocate a Dedicated Host with SEV-SNP enabled and launch SEV-SNP instances on it. This gives customers the benefits of Dedicated Hosts for confidential computing workloads, including control over instance placement, and host affinity that allows customers to deploy instances to the same physical server over time. The physical host is provisioned with AMD security firmware during allocation, ensuring a customer’s confidential computing environment is up to date. Dedicated Host SEV-SNP is available in all AWS commercial Regions with AMD instances. To learn more, visit our documentation.  

Publicado el Deja un comentario

AWS Config now supports 8 new resource types

AWS Config now supports 8 additional AWS resource types across key services including Amazon API Gateway, Amazon EC2, and Amazon S3 Vectors. This expansion provides greater coverage over your AWS environment, enabling you to more effectively discover, assess, audit, and remediate an even broader range of resources.

With this launch, if you have enabled recording for all resource types, then AWS Config will automatically track these new additions. The newly supported resource types are also available in Config rules and Config aggregators.

You can now use AWS Config to monitor the following newly supported resource types in all AWS Regions where the resources are available:

Resource Types:

  • AWS::ApiGateway::DomainNameV2
  • AWS::ApiGatewayV2::VpcLink
  • AWS::EC2::VPCEncryptionControl
  • AWS::NetworkFirewall::ContainerAssociation
  • AWS::OpenSearchServerless::SecurityPolicy
  • AWS::OSIS::Pipeline
  • AWS::S3Vectors::VectorBucket
  • AWS::S3Vectors::VectorBucketPolicy

 

​AWS Config now supports 8 additional AWS resource types across key services including Amazon API Gateway, Amazon EC2, and Amazon S3 Vectors. This expansion provides greater coverage over your AWS environment, enabling you to more effectively discover, assess, audit, and remediate an even broader range of resources.
With this launch, if you have enabled recording for all resource types, then AWS Config will automatically track these new additions. The newly supported resource types are also available in Config rules and Config aggregators.
You can now use AWS Config to monitor the following newly supported resource types in all AWS Regions where the resources are available:
Resource Types:

AWS::ApiGateway::DomainNameV2
AWS::ApiGatewayV2::VpcLink
AWS::EC2::VPCEncryptionControl
AWS::NetworkFirewall::ContainerAssociation
AWS::OpenSearchServerless::SecurityPolicy
AWS::OSIS::Pipeline
AWS::S3Vectors::VectorBucket
AWS::S3Vectors::VectorBucketPolicy  

Publicado el Deja un comentario

Alcanzar el éxito con la IA

Alcanzar el éxito con la IA

Composición abstracta en 3D de formas suaves, en capas y tipo cinta, que se curvan y pliegan en espirales. Está renderizada con gradientes suaves en tonos cálidos de naranja, rosa y púrpura. Las superficies parecen semitranslúcidas, con sutiles texturas acanaladas y una iluminación delicada sobre un fondo neutro gris claro.

Por: Judson Althoff, CEO, Microsoft Commercial Business.

Los dos elementos más importantes en cualquier solución de IA son Inteligencia + Confianza. Hice esta declaración por primera vez en noviembre en nuestra conferencia Ignite y mi convicción se ve reforzada con cada conversación que mantengo con los clientes. A lo largo de mis viajes, se plantean tres temas recurrentes al considerar la adopción de soluciones de IA:

  1. ¿Amplificará la IA la inteligencia de mi organización y los atributos que hacen única a mi empresa dentro de su sector para hacer crecer mi negocio? ¿O usará mi inteligencia para su propio beneficio, para aprender de mis flujos empresariales más importantes y aprovechar mi propiedad intelectual?
  2. ¿Puedo confiar en que los resultados proporcionan un retorno duradero de la inversión y que estas soluciones funcionan dentro de los límites de mis estándares de gobernanza y seguridad?
  3. ¿Cómo consigo la visibilidad, el control, la flexibilidad y la innovación en el modelo de negocio necesarios para gestionar los costes asociados a la IA y maximizar el valor?

Siempre aconsejo a los clientes que deben construir su propio coeficiente intelectual sobre una plataforma de inteligencia que sea diversa en modelos, abierta y heterogénea en cada capa de la pila. Los modelos son una mercancía. Ninguna empresa debería depender de un modelo o del arnés de un solo modelo. Durante el fin de semana, Satya advirtió de un mundo en el que todas las empresas, de todos los sectores, ceden valor a unos pocos modelos que se comen todo lo que ven. La IA destinada al crecimiento debe amplificar la inteligencia de una organización para que se componga desde dentro.

Las empresas también necesitan una plataforma de observabilidad que proporcione gobernanza, gestión, seguridad y operaciones financieras (FinOps, por sus siglas en inglés) para garantizar el retorno de inversión con IA. Esto permite que la IA sea confiable dentro del entorno sobre el que se basa y pone al negocio en control de los resultados.

Inteligencia + Confianza está integrado en Microsoft 365 Copilot, GitHub Copilot y Copilot Studio, donde la diversidad de modelos alinea coste y rendimiento a cada tarea. Microsoft IQ optimiza los flujos de trabajo, para que el contexto se enrute de manera eficiente y reduzca el cálculo innecesario. El Agente 365 es el plano de control para observar, gobernar, gestionar y asegurar agentes. Hemos creado un sistema para gestionar el gasto en IA como una capacidad central de la empresa, no como una idea secundaria. Se entrega a través de proveedores de nube y de modelos, sin limitar a los clientes a un único enfoque.

Gestión de costes a gran escala

A medida que el uso de agentes crece, las organizaciones necesitan un conjunto claro de palancas para gestionar los costes:

Diversidad de modelos. Cualquier modelo de inferencia, harness de modelo o bucle agéntico por sí solo no ayuda a desarrollar el coeficiente intelectual de una organización de maneras que comuniquen su inteligencia. Tanto Microsoft 365 Copilot como GitHub Copilot son diversos en modelos por diseño, sin limitar a los clientes a un solo proveedor. Diferentes modelos — como GPT-5.5 o Claude Opus 4.8 — cumplen funciones distintas con distintas economías. Combinar la inteligencia adecuada para cada tarea optimiza el rendimiento y el coste.

Su coeficiente intelectual. Los agentes tienen dificultades con los datos en bruto. Se dedica un cálculo significativo a interpretar la estructura y el contexto antes de que comience el trabajo útil. La plataforma Microsoft IQ potencia su CI al convertir los datos en bruto en inteligencia útil, a través de construir de manera continua una comprensión semántica de cómo opera su organización en Microsoft 365 y sistemas de línea de negocio. Proporciona a los agentes el contexto que necesitan desde el principio, en lugar de requerirles que lo reconstruyan. El resultado es medible: ejecución más rápida, mayor precisión y menor uso de tokens. Así es como la inteligencia se acumula dentro de su organización.

Operaciones financieras. FinOps se volvió fundamental cuando las empresas pasaron a la nube y requiere aún más atención a medida que la IA pasa de precios fijos a modelos basados en el uso. Con Foundry y Agent 365, ofrecemos herramientas para ayudar a nuestros clientes a optimizar sus costes de IA hoy mismo.

Modelos de negocio Frontier

Los modelos de negocio evolucionan a medida que utilizamos la IA para impulsar los resultados empresariales. La Licencia de Suscripción de Usuario (USL, por sus siglas en inglés) se ha convertido en la base, al proporcionar un paquete de capacidades por una tarifa predecible por usuario y mes. La licencia basada en el uso ha surgido para agentes multitarea de larga trayectoria, donde el coste se alinea de manera directa al trabajo realizado.

Microsoft ofrece a los clientes una combinación única de flexibilidad en el modelo de negocio y experiencias integradas de producto que no tiene igual en el mercado. Microsoft 365 Copilot y GitHub Copilot utilizan ambos modelos — una oferta de USL que no solo ofrece valor y capacidades, sino también un consumo flexible. Hoy anunciamos la disponibilidad general de Copilot Cowork a nivel mundial, que requiere el Microsoft 365 Copilot USL y que por su cuenta se basa en el uso.

Nuestra estrategia diversa en modelos permite a los clientes adquirir capacidad con la flexibilidad de utilizar el modelo adecuado para el trabajo, basándose en las fortalezas del modelo, la economía y las últimas innovaciones. Microsoft Agent Factory ofrece un único modelo de consumo que abarca Microsoft 365 Copilot (incluido Cowork), GitHub Copilot y agentes integrados en Fabric, Foundry y Copilot Studio.

Nuestras experiencias integradas de producto sitúan la IA en el flujo de trabajo tanto para trabajadores del conocimiento como para desarrolladores de software, y gestionan la capacidad de forma fluida entre ambos. A nivel histórico, estas personalidades han sido distintas, pero cada vez más la línea entre ellas se difumina. La programación se convierte en una habilidad habitual para los trabajadores del conocimiento y el chat y el cowork se convierte en modalidades importantes para el desarrollo de software. Con Microsoft 365 y GitHub, ofrecemos herramientas líderes en el mercado para ambos roles y facilitamos la gestión fluida de la capacidad según la disponibilidad y la necesidad.

Agente 365: El plano de control

A medida que las organizaciones adoptan agentes de Microsoft, otro proveedor, o construyen los suyos propios, un plano de control es esencial. Agent 365 ofrece a los líderes de TI y seguridad un único lugar para observar, gobernar, gestionar y proteger a los agentes en toda la organización. Se basa en la pila de Microsoft en la que las empresas confían las empresas: Entra para la identidad, Defender para la protección contra amenazas, Purview para la gobernanza de datos e Intune para la gestión de terminales. Ampliamos Agent 365 para incluir la gestión de costes, de modo que las organizaciones puedan monitorizar y gestionar el gasto de los agentes junto con la seguridad y el cumplimiento. A medida que el modelo operativo de Frontier Firm se consolida, los líderes gestionarán el trabajo humano y el agente como un único sistema, con visibilidad tanto del rendimiento como del coste.

Los dos elementos más esenciales en cualquier solución de IA son la Inteligencia + la Confianza. En Microsoft, esta convicción moldea cómo diseñamos cada capa de nuestra plataforma de IA. Microsoft IQ permite a las organizaciones aprovechar su propio coeficiente intelectual único, para aportar contexto a los datos e integrar la IA directo en el flujo de trabajo para ofrecer resultados más rápidos, precisos y fiables, para proteger activos y la propiedad intelectual. Agent 365 proporciona esa capa de confianza, lo que asegura que cada agente y artefacto de IA sea observado en todo el entorno para que las organizaciones puedan pasar de la experimentación al impacto empresarial con confianza. Como dijo Jay Parikh en Build, la IA por sí sola no cambiará su negocio. El sistema que lo ejecuta lo hará.

Hemos construido este sistema para nuestros clientes y socios, donde la inteligencia se acumula desde dentro y cada agente actúa con control, visibilidad y confianza. Juntos, podemos escalar la ambición humana y definir cómo la IA genera un impacto empresarial medible en todos los roles, organizaciones e industrias.

Judson Althoff es el director ejecutivo del negocio comercial en Microsoft. Es responsable de la estrategia de producto, ventas, servicios, soporte, marketing, operaciones y crecimiento de ingresos del negocio comercial de la empresa, que opera en más de 120 filiales regionales y nacionales a nivel mundial.

The post Alcanzar el éxito con la IA appeared first on Source LATAM.

 

​The post Alcanzar el éxito con la IA appeared first on Source LATAM.  

Publicado el Deja un comentario

ECS Service Connect now supports Zone-Aware routing

Amazon Elastic Container Service (Amazon ECS) introduces zone-aware routing for ECS Service Connect, enabling customers to reduce cross Availability Zone (AZ) data transfer costs and latency by automatically prioritizing service-to-service traffic within the same AZ.

With this launch, ECS Service Connect preferentially routes requests to endpoints in the same AZ as the originating task while dynamically adjusting traffic weights as endpoints scale to maintain balanced load across target services. Previously, as customers distributed their applications across AZs for resiliency, service-to-service traffic led to significant cross-zone data transfer, requiring trade-offs between cost and resilience. Zone-aware routing eliminates this trade-off, and when local endpoints become unhealthy or fall below capacity thresholds, traffic automatically redistributes across healthy AZs to maintain availability without overloading any single zones.

Zone-aware routing is enabled by default for all new and existing services and requires no additional infrastructure or application code changes. Existing services require a one-time redeployment to enable the new routing behavior. You can use Amazon VPC Flow Logs with AZ metadata to monitor cross-AZ traffic patterns and validate routing effectiveness. This feature is available in all AWS commercial and AWS GovCloud (US) Regions, where ECS Service Connect is supported at no additional cost. For more details, refer to our documentation and launch blog post.

 

​Amazon Elastic Container Service (Amazon ECS) introduces zone-aware routing for ECS Service Connect, enabling customers to reduce cross Availability Zone (AZ) data transfer costs and latency by automatically prioritizing service-to-service traffic within the same AZ. With this launch, ECS Service Connect preferentially routes requests to endpoints in the same AZ as the originating task while dynamically adjusting traffic weights as endpoints scale to maintain balanced load across target services. Previously, as customers distributed their applications across AZs for resiliency, service-to-service traffic led to significant cross-zone data transfer, requiring trade-offs between cost and resilience. Zone-aware routing eliminates this trade-off, and when local endpoints become unhealthy or fall below capacity thresholds, traffic automatically redistributes across healthy AZs to maintain availability without overloading any single zones. Zone-aware routing is enabled by default for all new and existing services and requires no additional infrastructure or application code changes. Existing services require a one-time redeployment to enable the new routing behavior. You can use Amazon VPC Flow Logs with AZ metadata to monitor cross-AZ traffic patterns and validate routing effectiveness. This feature is available in all AWS commercial and AWS GovCloud (US) Regions, where ECS Service Connect is supported at no additional cost. For more details, refer to our documentation and launch blog post.  

Publicado el Deja un comentario

Amazon ECS now provides real-time deployment observability in the AWS Management Console

Amazon Elastic Container Service (Amazon ECS) now provides real-time deployment observability in the Amazon ECS Console. With this launch, customers can track deployment progress, monitor deployment health, and diagnose failures directly from the console, and understand exactly what is happening during a deployment, identify issues as they occur, and reduce the time it takes to troubleshoot and resolve deployment failures.

The enhanced deployment observability introduces a live deployment timeline that shows each phase, service events, and task launch and termination progress with automatic refresh. You can monitor deployment health in real time using circuit breaker status with live task failure proximity and threshold tracking, deployment alarm state, and health checks at both the container and load-balancer level. To diagnose deployment failures faster, you can view failed tasks directly in the deployment timeline with diagnostic context and deep links to related services such as AWS CloudTrail, reducing the need to navigate across multiple tools to pinpoint the root cause of a failure.

These capabilities are available at no additional charge in all AWS commercial Regions, and AWS GovCloud (US) Regions for all Amazon ECS services using the rolling update deployment type. To get started, navigate to any Amazon ECS service in the Amazon ECS Console and select the Deployments tab. 

 

​Amazon Elastic Container Service (Amazon ECS) now provides real-time deployment observability in the Amazon ECS Console. With this launch, customers can track deployment progress, monitor deployment health, and diagnose failures directly from the console, and understand exactly what is happening during a deployment, identify issues as they occur, and reduce the time it takes to troubleshoot and resolve deployment failures.
The enhanced deployment observability introduces a live deployment timeline that shows each phase, service events, and task launch and termination progress with automatic refresh. You can monitor deployment health in real time using circuit breaker status with live task failure proximity and threshold tracking, deployment alarm state, and health checks at both the container and load-balancer level. To diagnose deployment failures faster, you can view failed tasks directly in the deployment timeline with diagnostic context and deep links to related services such as AWS CloudTrail, reducing the need to navigate across multiple tools to pinpoint the root cause of a failure.
These capabilities are available at no additional charge in all AWS commercial Regions, and AWS GovCloud (US) Regions for all Amazon ECS services using the rolling update deployment type. To get started, navigate to any Amazon ECS service in the Amazon ECS Console and select the Deployments tab.   

Publicado el Deja un comentario

Amazon CloudWatch supports creating alarms from log queries

Amazon CloudWatch allows you to create alarms on log data using log queries, and get alerted on anomalies without leaving your log analysis workflow.

With today’s launch, you can configure an alarm on log query and specify the alarm threshold directly, thereby eliminating the need to first create metric filters or custom metrics as intermediate steps. This streamlines the path to actively monitoring the data in your logs, and monitoring and alerting on it. For example, you can write a query to count error rates by service, set a threshold, and receive an alarm notification with log context when errors spike – all in a single workflow. Alarms created from log queries support all standard CloudWatch Alarm actions, including Amazon SNS notifications, and Amazon EventBridge integrations.

This feature is available in all commercial AWS Regions except Middle East (UAE), and Middle East (Bahrain). You can create log query-based alarms using the Amazon CloudWatch console, AWS Command Line Interface (AWS CLI), AWS CloudFormation, and AWS SDKs. For pricing details and documentation, see the Amazon CloudWatch pricing and visit the Amazon CloudWatch documentation.

 

​Amazon CloudWatch allows you to create alarms on log data using log queries, and get alerted on anomalies without leaving your log analysis workflow.
With today’s launch, you can configure an alarm on log query and specify the alarm threshold directly, thereby eliminating the need to first create metric filters or custom metrics as intermediate steps. This streamlines the path to actively monitoring the data in your logs, and monitoring and alerting on it. For example, you can write a query to count error rates by service, set a threshold, and receive an alarm notification with log context when errors spike – all in a single workflow. Alarms created from log queries support all standard CloudWatch Alarm actions, including Amazon SNS notifications, and Amazon EventBridge integrations.
This feature is available in all commercial AWS Regions except Middle East (UAE), and Middle East (Bahrain). You can create log query-based alarms using the Amazon CloudWatch console, AWS Command Line Interface (AWS CLI), AWS CloudFormation, and AWS SDKs. For pricing details and documentation, see the Amazon CloudWatch pricing and visit the Amazon CloudWatch documentation.  

Publicado el Deja un comentario

Amazon Bedrock AgentCore increases default runtime quota limits

Amazon Bedrock AgentCore has increased the default runtime quota limits, giving customers greater capacity to scale their agent-based workloads. AgentCore is the platform for developers to build, connect, and optimize AI agents.

The new default limits support up to 5,000 active concurrent sessions in US East (N. Virginia) and US West (Oregon), and 2,500 in all other supported Regions. All AWS Regions where AgentCore is available now support 200 agent interactions per second and 25 new sessions created per second. This means customers can run more AI agents simultaneously while handling high-throughput workloads out of the box.

To learn more, visit the AgentCore product page or see the AgentCore Developer Guide. For all quota limits, see the AgentCore Quotas documentation.

 

 

​Amazon Bedrock AgentCore has increased the default runtime quota limits, giving customers greater capacity to scale their agent-based workloads. AgentCore is the platform for developers to build, connect, and optimize AI agents.
The new default limits support up to 5,000 active concurrent sessions in US East (N. Virginia) and US West (Oregon), and 2,500 in all other supported Regions. All AWS Regions where AgentCore is available now support 200 agent interactions per second and 25 new sessions created per second. This means customers can run more AI agents simultaneously while handling high-throughput workloads out of the box.
To learn more, visit the AgentCore product page or see the AgentCore Developer Guide. For all quota limits, see the AgentCore Quotas documentation.
   

Publicado el Deja un comentario

AWS Artifact now includes Assurance Assistant for compliance inquiries

AWS Artifact now includes Assurance Assistant, an AI-powered capability that generates citation-backed responses to security and compliance questions about AWS services. AWS Artifact is the service through which AWS provides compliance reports, certifications, and agreements to customers. Assurance Assistant helps third-party risk managers, compliance officers, security engineers, and auditors accelerate vendor assessments and due diligence questionnaire (DDQ) completion by providing sourced answers grounded in verified AWS compliance documentation.

Assurance Assistant offers two modes: single-question mode for immediate on-screen responses, and questionnaire upload mode for bulk processing of XLSX files including industry-standard formats such as CAIQ, SIG, and custom DDQs. All responses include citations from AWS compliance documentation — including SOC reports, ISO certifications, and C5 attestation packages — so customers can independently verify information against source materials. Responses can be exported selectively or in full, with or without citations, in the original file format. To control access, two new IAM managed policies are available: AWSArtifactComplianceInquiriesReadOnlyAccess and AWSArtifactComplianceInquiriesFullAccess.

Assurance Assistant is available at no additional charge through the AWS Artifact console in all commercial AWS Regions. AWS Artifact is a globally accessible service; customers do not need to select a specific Region to use Assurance Assistant.

To learn more about Assurance Assistant, see Managing compliance inquiries in the AWS Artifact User Guide. For general information about AWS Artifact, see the AWS Artifact product page.

 

​AWS Artifact now includes Assurance Assistant, an AI-powered capability that generates citation-backed responses to security and compliance questions about AWS services. AWS Artifact is the service through which AWS provides compliance reports, certifications, and agreements to customers. Assurance Assistant helps third-party risk managers, compliance officers, security engineers, and auditors accelerate vendor assessments and due diligence questionnaire (DDQ) completion by providing sourced answers grounded in verified AWS compliance documentation. Assurance Assistant offers two modes: single-question mode for immediate on-screen responses, and questionnaire upload mode for bulk processing of XLSX files including industry-standard formats such as CAIQ, SIG, and custom DDQs. All responses include citations from AWS compliance documentation — including SOC reports, ISO certifications, and C5 attestation packages — so customers can independently verify information against source materials. Responses can be exported selectively or in full, with or without citations, in the original file format. To control access, two new IAM managed policies are available: AWSArtifactComplianceInquiriesReadOnlyAccess and AWSArtifactComplianceInquiriesFullAccess. Assurance Assistant is available at no additional charge through the AWS Artifact console in all commercial AWS Regions. AWS Artifact is a globally accessible service; customers do not need to select a specific Region to use Assurance Assistant. To learn more about Assurance Assistant, see Managing compliance inquiries in the AWS Artifact User Guide. For general information about AWS Artifact, see the AWS Artifact product page.  

Publicado el Deja un comentario

AWS Partner Central now supports AWS Marketplace listings for co-selling

Today, AWS announces that partners can associate one or more AWS Marketplace solutions and product listings from their AWS Marketplace catalog directly to co-sell opportunities in AWS Partner Central. Previously, opportunities required partners to use solutions specially created for co-selling, which meant partners managed their solutions for the AWS Marketplace catalog and solutions for co-selling separately. Partners can now associate their existing AWS Marketplace listings with opportunities to track fulfillment more effectively.

When creating or editing an opportunity in AWS Partner Central in the AWS Console, Partners can select one of the following options: (1) AWS Marketplace solutions and products, (2) AWS Marketplace solutions only, (3) AWS Marketplace products only, or (4) Other. Partners can associate up to 10 AWS Marketplace Solutions and up to 10 AWS Marketplace Products with a single opportunity. This includes AWS Marketplace listings within AWS accounts that have an established subsidiary account connection. The same capability is available programmatically through the AWS Partner Central Selling API. To progress an opportunity to the Committed or Launched stage, an AWS Marketplace Solution, AWS Marketplace Product, or Partner Solution must be associated.

This capability is generally available in AWS Partner Central in the AWS Console. To learn more, review creating an opportunity and attach AWS Marketplace listings to ACE opportunities guides, or explore how to leverage the programmatic implementation option with the AWS Partner Central Selling API.

 

​Today, AWS announces that partners can associate one or more AWS Marketplace solutions and product listings from their AWS Marketplace catalog directly to co-sell opportunities in AWS Partner Central. Previously, opportunities required partners to use solutions specially created for co-selling, which meant partners managed their solutions for the AWS Marketplace catalog and solutions for co-selling separately. Partners can now associate their existing AWS Marketplace listings with opportunities to track fulfillment more effectively.
When creating or editing an opportunity in AWS Partner Central in the AWS Console, Partners can select one of the following options: (1) AWS Marketplace solutions and products, (2) AWS Marketplace solutions only, (3) AWS Marketplace products only, or (4) Other. Partners can associate up to 10 AWS Marketplace Solutions and up to 10 AWS Marketplace Products with a single opportunity. This includes AWS Marketplace listings within AWS accounts that have an established subsidiary account connection. The same capability is available programmatically through the AWS Partner Central Selling API. To progress an opportunity to the Committed or Launched stage, an AWS Marketplace Solution, AWS Marketplace Product, or Partner Solution must be associated.
This capability is generally available in AWS Partner Central in the AWS Console. To learn more, review creating an opportunity and attach AWS Marketplace listings to ACE opportunities guides, or explore how to leverage the programmatic implementation option with the AWS Partner Central Selling API.  

Publicado el Deja un comentario

Amazon GuardDuty adds sensitive file modification threat detections

Amazon GuardDuty Runtime Monitoring now includes three new threat detections that alert security teams when sensitive files are modified on Amazon EC2 instances and container workloads running on Amazon EKS or Amazon ECS. These findings help identify post-compromise attacker activities by monitoring critical system files, including configuration files, authentication settings, and system logs. This capability is designed for security teams, DevSecOps professionals, and cloud security architects who need comprehensive threat visibility across their AWS compute environments.

The new detections—Persistence:Runtime/SensitiveFileModified, PrivilegeEscalation:Runtime/SensitiveFileModified, and DefenseEvasion:Runtime/SensitiveFileModified—help identify attempts to maintain persistent access, escalate privileges, and evade detection after an initial system compromise. By monitoring five specific file operations (open-for-write, rename, symlink, link, and unlink) directly, these findings can detect threats even when attackers use obfuscated techniques that bypass traditional command-line monitoring. The correlation-based analysis distinguishes malicious behavior from legitimate administrative operations, helping reduce false positives while providing actionable intelligence with MITRE ATT&CK® tactics mapping and remediation recommendations.

These sensitive file modification findings are now available to all customers who have enabled GuardDuty Runtime Monitoring for their Amazon EC2, Amazon EKS, or Amazon ECS workloads. A 30-day free trial is available for new users. To learn more, see Amazon GuardDuty Findings. To receive programmatic updates on new Amazon GuardDuty features and threat detections, please subscribe to the Amazon GuardDuty SNS topic.

 

​Amazon GuardDuty Runtime Monitoring now includes three new threat detections that alert security teams when sensitive files are modified on Amazon EC2 instances and container workloads running on Amazon EKS or Amazon ECS. These findings help identify post-compromise attacker activities by monitoring critical system files, including configuration files, authentication settings, and system logs. This capability is designed for security teams, DevSecOps professionals, and cloud security architects who need comprehensive threat visibility across their AWS compute environments. The new detections—Persistence:Runtime/SensitiveFileModified, PrivilegeEscalation:Runtime/SensitiveFileModified, and DefenseEvasion:Runtime/SensitiveFileModified—help identify attempts to maintain persistent access, escalate privileges, and evade detection after an initial system compromise. By monitoring five specific file operations (open-for-write, rename, symlink, link, and unlink) directly, these findings can detect threats even when attackers use obfuscated techniques that bypass traditional command-line monitoring. The correlation-based analysis distinguishes malicious behavior from legitimate administrative operations, helping reduce false positives while providing actionable intelligence with MITRE ATT&CK® tactics mapping and remediation recommendations. These sensitive file modification findings are now available to all customers who have enabled GuardDuty Runtime Monitoring for their Amazon EC2, Amazon EKS, or Amazon ECS workloads. A 30-day free trial is available for new users. To learn more, see Amazon GuardDuty Findings. To receive programmatic updates on new Amazon GuardDuty features and threat detections, please subscribe to the Amazon GuardDuty SNS topic.