7/30/2026, 12:00:00 AM ~ 7/31/2026, 12:00:00 AM (UTC)
Recent Announcements
AWS Direct Connect now supports BGP route visibility on Virtual Interfaces
AWS Direct Connect now provides Border Gateway Protocol (BGP) route visibility, allowing you to view the routes exchanged between AWS and your on-premises routers across your private, transit, and public virtual interfaces (VIFs). You can now see which routes AWS accepted from your router and which routes AWS is advertising to your router, along with their AS path and BGP community values. This visibility helps network administrators troubleshoot routing issues, verify route propagation, and monitor their hybrid network connectivity.\n With this feature, you can view accepted routes (routes AWS received from your router) and advertised routes (routes AWS sends to your router) directly in the Direct Connect console or programmatically using the ListVirtualInterfaceRoutes API action. Each route displays its prefix, address family, AS path, community values, and installation timestamp, giving you comprehensive insight into your routing topology. You can filter routes by prefix, AS path, community, or address family to quickly identify specific routing behaviors. This capability is particularly valuable when managing complex multi-region architectures, validating BGP policy configurations, or diagnosing unexpected traffic patterns.
This feature is available in all AWS commercial Regions and the AWS China Regions (Beijing, operated by Sinnet, and Ningxia, operated by NWCD).
To learn more about BGP route visibility, visit the AWS Direct Connect documentation or access the feature through the Direct Connect console.
Amazon Redshift RG large and 12xlarge instances now available on the trailing track
Amazon Redshift now supports Graviton-based RG instances on the trailing track. Starting today, rg.large and rg.12xlarge instance types are available for customers running workloads on the trailing track on patch P202 and onwards.\n The trailing track is designed for customers who prioritize stability for production workloads, running on a version already validated through the leading track. With RG instances now available on both tracks, customers can take advantage of AWS Graviton-powered performance - delivering up to 2.4x faster query performance than RA3 instances at 30% lower price per vCPU. Customers on the trailing maintenance track (patch P202 and later) can now create Amazon Redshift RG clusters in all AWS regions where RG is generally available. To get started, customers can provision a new cluster or resize an existing cluster to an rg.large or rg.12xlarge instance type using the AWS Management Console, AWS CLI, or AWS SDKs.For more information, see Amazon Redshift cluster versions.
IAM Policy Simulator moves to the IAM console and adds additional capabilities
AWS Identity and Access Management (IAM) announces a major update to IAM Policy Simulator, the tool you use to test and validate the permissions your IAM policies grant before you deploy them. This update changes the simulator in three ways: it now lives in the IAM console, it can test service control policies (SCPs), and it adds flexibility to model more of the scenarios that security and platform teams simulate in practice.\n IAM Policy Simulator is now part of the IAM console, replacing the standalone simulator site, so you can test policies in the same place you manage your identities and policies. You can also now include SCPs in your simulation to test how your organization’s SCP hierarchy interacts with identity and resource policies, and through the API, test how condition keys such as Region restrictions and tag requirements affect the outcome. Finally, new flexibility lets you exclude specific policies to model “what if I remove this policy?” scenarios, and cross-account simulations now report per-policy decisions for identity and resource-based policies, with the matched statements returned for a denied request reflecting only the policies that drove the decision. Together, these changes help teams automate policy unit testing, detect over-permissive access, and validate guardrails with greater confidence.
These features are available in all AWS Regions where IAM Policy Simulator is available. You can access IAM Policy Simulator in the IAM console by choosing Policy simulator in the navigation pane.
To learn more, see the following resources:
Testing IAM policies with the IAM policy simulator
API reference on SimulatePrincipalPolicy and SimulateCustomPolicy
Amazon Bedrock announces up to 80% lower prices for OpenAI GPT‑5.6 models
Today, OpenAI announced lower prices for GPT‑5.6 Luna and GPT‑5.6 Terra. Effective July 30, 2026, on-demand inference prices on Amazon Bedrock for GPT‑5.6 Luna are reduced by 80%, while prices for GPT‑5.6 Terra are reduced by 20%. These reductions are in-line with OpenAI’s first-party pricing changes for these models. \n GPT‑5.6 Luna is optimized for fast, high-volume workloads and can use tools to complete multi-step workflows, making it well suited for content processing, classification, customer-service automation, and routine implementation tasks. GPT‑5.6 Terra balances intelligence, speed, and cost for everyday production workloads requiring more sophisticated reasoning. These price reductions enable customers to apply their capabilities across more applications, process larger workloads, and lower the cost per completed task. Pricing for GPT‑5.6 Sol remains unchanged. The new prices apply automatically, with no changes required from customers.
GPT‑5.6 Luna and Terra are available in US East (N. Virginia), US East (Ohio), and US West (Oregon) through the OpenAI Responses API on the bedrock-mantle endpoint. To get started, see the Amazon Bedrock OpenAI model documentation. For the latest pricing information for GPT-5.6 models on Amazon Bedrock, please visit the Amazon Bedrock pricing page.
AWS announces general availability of Policy-Based Routing on AWS Transit Gateway
AWS Transit Gateway now supports Policy-Based Routing (PBR), giving network administrators granular control over how traffic is forwarded across their AWS network. With PBR, forwarding decisions can be based on a combination of packet attributes including source and destination IP addresses, ports, and protocol rather than destination IP address alone.\n Previously, customers needing traffic steering or workload isolation had to build multi-VPC architectures with additional routing hops, adding complexity and operational overhead. PBR eliminates this by extending Transit Gateway’s native routing capabilities, enabling security architects and enterprise network teams to classify and direct traffic inline without extra infrastructure. Customers associate a policy table with a Transit Gateway attachment and define an ordered set of rules. Each rule classifies traffic and directs matching packets to a specified route table using first-match-wins logic. This supports use cases such as steering sensitive workloads through AWS Network Firewall or third-party inspection appliances, routing application traffic over AWS Direct Connect or AWS VPN paths based on source, port, or protocol, and isolating production and development environments into separate routing domains to limit lateral movement. Policy-Based Routing for AWS Transit Gateway is available in all commercial AWS Regions where Transit Gateway is available. You can configure PBR using the AWS Management Console, AWS Command Line Interface (CLI), and the AWS Software Development Kit (SDK). PBR incurs no additional charge beyond standard Transit Gateway fees. To learn more about Policy-Based Routing for AWS Transit Gateway, visit the AWS Transit Gateway product page .
Amazon MSK Express brokers now delivers Apache Kafka data to Amazon S3
Amazon MSK Express brokers now delivers data to Amazon S3 general purpose buckets, providing a fully managed capability to deliver Apache Kafka data in Amazon S3 for downstream processing in the easiest and most reliable way. This capability automatically scales to deliver high-throughput Kafka data to S3 with end-to-end reliability for mission-critical workloads, while reducing ingestion and delivery costs by up to 60% compared to self-managed alternatives.\n Customers deliver Apache Kafka data to Amazon S3 for use cases such as log archival, compliance retention, Kafka replay, and training AI/ML models, and typically build these pipelines with self-managed connectors that grow costly and operationally complex as workloads scale, forcing teams to build or source S3 connector plugins, secure approvals to deploy them, and continually scale capacity, and apply security updates across connector fleet. With this capability, MSK Express automatically handles scaling, retries, and backpressure so customers no longer manage connector fleets or coordinate across teams. MSK Express supports throughput of up to 10 GB/s for data delivery to Amazon S3, and manages routine operations such as capacity scaling and version upgrades without introducing delivery gaps. Additionally, customers add this delivery capability without provisioning additional broker egress throughput, which eliminates the incremental infrastructure costs that scaling connector-based pipelines typically incurs, so customers scale delivery to actual workload demand rather than provisioning for peak, achieving reliable, high-throughput delivery to Amazon S3 while removing operational overhead and lowering costs.
Amazon MSK data delivery to Amazon S3 is available today in every AWS Region where Amazon MSK Express brokers are offered. For pricing information, visit the pricing page. To learn more, visit the Amazon MSK Developer Guide and Amazon MSK AI skills.
Amazon MSK Express brokers now deliver data to streaming tables for Apache Iceberg
Amazon MSK Express brokers now deliver data to streaming tables for Apache Iceberg, a new capability that continuously materializes Apache Kafka topics as Apache Iceberg tables on Amazon S3 Tables. Amazon MSK data delivery to streaming tables can reduce the cost of ingesting and delivering Apache Kafka data into Amazon S3 Tables by up to 60% versus self-managed deployments and reduces downstream query costs by up to 30% versus self-managed Apache Kafka deployments.\n Customers rely on Apache Kafka to ingest real-time data for use cases like fraud detection and personalization and increasingly want to unify that data with Apache Iceberg tables for near real-time analytics but integrating the two forces them to operate complex custom pipelines, manage format conversions, and contend with the small-file problem, where high-volume ingestion creates many small parquet files that slow downstream queries and increase costs. With this capability, intelligent inline compaction eliminates the performance impact of small files and keeps query performance predictable without sacrificing data freshness, while built-in coordination resolves concurrent writer conflicts across high-throughput consumers. Amazon MSK supports throughput of up to 10 GB/s for delivery to Apache Iceberg on Amazon S3 Tables, and because this native capability adds no broker egress throughput, customers avoid the incremental infrastructure costs of scaling connector pipelines and match capacity to actual demand rather than peak. Customers deliver data to streaming tables and query or transform the data with any engine of their choice, including Apache Spark, Trino, or Apache Flink.
To get started, customers open the Amazon MSK console, select the Express cluster, and enable the capability in a few clicks, or use the MSK APIs or MCP server. Amazon MSK data delivery to streaming tables is available today in every AWS Region where Amazon MSK Express brokers are offered. For pricing information, visit the pricing page. To learn more, visit the Amazon MSK Developer Guide and Amazon MSK AI skills.
Grok 4.3 from xAI is now available on Amazon Bedrock in AWS GovCloud (US-West)
xAI’s Grok 4.3 model is now available on Amazon Bedrock in AWS GovCloud (US-West). With this launch, xAI joins Amazon Bedrock as a model provider in AWS GovCloud (US-West), giving you even more choice as you build generative AI applications across reasoning, agentic, and enterprise workflows.\n Grok 4.3 is a reasoning-first model that offers configurable reasoning effort (none, low, medium, high). It also offers strong tool use and instruction-following capabilities for building reliable agents, and token efficiency to help keep high-volume inference cost-effective. Grok 4.3 is especially well suited to enterprise workloads such as customer support, web development, case law research, and financial document Q&A, while delivering consistent, high-quality results across conversational Al, search, chat, and multi-turn workflows. Grok 4.3 runs on Mantle, a new inference engine in Amazon Bedrock designed for price performance, with support for tool calling, structured output, and response streaming.
See region availability of Grok 4.3 for list of supported regions. To get started, visit the Grok 4.3 model detail page in our documentation.
Gemma 4 models are now available on Amazon Bedrock in AWS GovCloud (US-West)
The Gemma 4 family of open-weight models from Google DeepMind on Amazon Bedrock in AWS GovCloud (US-West). With Gemma 4, you can build generative AI applications across reasoning, multimodal understanding, agentic, and software engineering workflows.\n The Gemma 4 family on Amazon Bedrock includes three variants - Gemma 4 31B, Gemma 4 26B-A4B, and Gemma 4 E2B - spanning dense and mixture-of-experts (MoE) architectures with built-in reasoning, native function calling, support for 35+ languages and multimodal input across text, image, video and audio. Gemma 4 31B is suited for reasoning- and coding-heavy workloads with a 256K-token context window, Gemma 4 26B-A4B targets cost- and latency-sensitive workloads, and Gemma 4 E2B is the smallest variant, designed for low-latency interactive use cases. Gemma 4 runs on a new innovation in Amazon Bedrock designed for price performance, with improved support for tool calling, structured output, reasoning, and response streaming, so customers can build reliable generative AI applications with open-source models.
To get started, visit Gemma 4 model detail pages in our documentation.
AWS Managed Microsoft AD now supports Standard to Enterprise Edition upgrade
AWS Directory Service now allows you to upgrade your AWS Managed Microsoft AD directory from Standard Edition to Enterprise Edition directly through the AWS Management Console, AWS CLI, and API without migrating to a new directory or re-joining your existing workloads.\n Standard Edition is designed for organizations with up to 5,000 users and objects, while Enterprise Edition supports up to 500,000 objects and provides greater scalability for larger deployments. Customers who have outgrown Standard Edition limits can now upgrade in place, preserving existing trust relationships, application integrations, and group policies. The upgrade requires no changes to your DNS configuration or connected AWS workloads.
This new capability is available in all AWS Regions where AWS Directory Service is available. To get started, navigate to the AWS Directory Service console, select your Standard Edition directory, and choose Upgrade Edition from the directory actions menu. See the administrator guide for step-by-step instructions. For pricing details, go to the AWS Directory Service pricing page.
Amazon OpenSearch Service now supports OpenSearch version 3.7
You can now run OpenSearch version 3.7 on Amazon OpenSearch Service. OpenSearch 3.7 introduces improvements in vector search performance, search relevance, and Query Insights.\n With this launch, 1-bit scalar quantization on the Faiss and Lucene engines compresses vectors, reducing the storage and memory required by vector workloads while maintaining search accuracy. You can now retrieve vectors faster using doc values instead of document source, with no reindexing required. Search Relevance Workbench adds new evaluation metrics, CSV judgment uploads, and expanded hybrid search optimization, helping you measure and improve search quality.
This launch also introduces new Query Insights capabilities, including automated query recommendations, a finished-queries cache for observing recently completed queries, and the option to export top query data to Amazon S3, helping you identify expensive queries and analyze trends over time.
For information on upgrading to OpenSearch 3.7, please see the documentation. OpenSearch 3.7 is now available in all AWS Regions where Amazon OpenSearch Service is available.
AWS Blogs
AWS Japan Blog (Japanese)
- AWS Weekly — 2026/7/27
- Amazon identifies North Korean hacker group behind open source supply chain attack
- AWS Nitro Isolation Engine: Formal Verification of Hypervisors on the AWS Nitro System
- Formally validated Nitro Isolation Engine mathematically guarantees Amazon EC2 virtual machine isolation
- Isabelle/HOL: Theorem proof support system supporting the Nitro Isolation Engine
- Contribution: Japan Digital Design, which leads Mitsubishi UFJ Financial Group’s DX, reduced DB costs by approximately 87% by adopting Aurora DSQL, and achieved almost zero operational load
AWS Cloud Financial Management
AWS Cloud Operations Blog
- Getting per-resource alarm notifications with Amazon CloudWatch
- Autonomous Root Cause Analysis for AWS Systems Manager Patch Failures Using AWS DevOps Agent
AWS Big Data Blog
- Deliver Apache Kafka data to streaming tables for Apache Iceberg with Amazon MSK Express brokers
- Lowering AWS KMS decrypt API costs in EMR Spark jobs
Desktop and Application Streaming
Artificial Intelligence
- Deploying Kimi K3 on AWS
- How Yahoo enhances search retargeting using Amazon Bedrock
- Inference meta-monitoring for Amazon SageMaker AI endpoints with Amazon Quick
- Introducing explicit prompt caching for OpenAI GPT-5.6 models on Amazon Bedrock
- Migrate your prompts to new models and optimize them on Amazon Bedrock
AWS Security Blog
- Balancing speed and safety: A control framework for AI coding agents
- Extend Amazon Inspector SBOM Generator with Plugins
AWS Storage Blog
Open Source Project
AWS CLI
Amplify for JavaScript
- aws-amplify@6.20.0
- @aws-amplify/notifications@2.1.0
- @aws-amplify/datastore@5.1.10
- @aws-amplify/core@6.18.0
- @aws-amplify/api-graphql@4.8.10
- @aws-amplify/api@6.3.29