8/13/2026, 12:00:00 AM ~ 8/14/2026, 12:00:00 AM (UTC)
Recent Announcements
AWS Client VPN now supports CLI, administration controls, and faster connections
AWS Client VPN introduces a rebuilt AWS VPN Client v6.0.x which offers new features like command-line interface (CLI) support, enterprise administrative controls, and faster connection establishment time, making it easier you to automate VPN connectivity and centralize device management across your organization.\n The AWS VPN Client CLI provides full feature parity with the GUI. You can now script VPN connections into your automation workflows and infrastructure-as-code deployments. Previously, integrating VPN connectivity into automated environments required third-party tooling or manual intervention. This feature eliminates that by supporting background CLI operations. Previously, you had to distribute VPN profiles among all users in your organization, which could be managed by any user without permissions. Now, with administration controls on AWS client, you can centralize VPN policy enforcement by scoping profiles to specific users, manage global profiles available to all users on a device, and enforce approved VPN configurations across your organization. The client is rebuilt with OpenVPN3, delivering faster connection establishment across all supported operating systems. You can use both the GUI and CLI together as both run concurrently and VPN connections persist independently of either interface. The rebuilt client v6.0 onwards maintains full backward compatibility with existing AWS Client VPN endpoints, so no endpoint changes are required. The updated AWS VPN Client is available today for Windows (x64/ARM), macOS (x64/ARM), and Linux (x64). There are no additional charges beyond standard pricing of AWS Client VPN. Download the latest client version 6.0.x for macOS, Windows and Linux to start using it. To learn more about Client VPN, visit the AWS Client VPN product page or read the documentation.
Claude Opus 5 is now available in AWS GovCloud (US)
AWS GovCloud (US) now offers Claude Opus 5 — the most advanced Opus model yet, and compatible with zero data retention (ZDR) — bringing a step-change in coding, long-running agents, and complex professional work to teams building at the highest level. Claude Opus 5 is available via the bedrock-runtime endpoint in both AWS GovCloud (US) regions, and available via the bedrock-mantle endpoint in AWS GovCloud (US-West)\n Claude Opus 5 delivers advances in coding, understanding and navigating codebases like an experienced engineer and writing production-quality code while adapting its strategy as it works. It powers dependable agents that run for hours and even overnight, finding paths around obstacles, recovering from errors, and reaching their objectives. And it brings deeper reasoning to long documents and higher accuracy to complex analysis, with the largest gains on document-heavy enterprise work.
Amazon Bedrock offers Claude Opus 5 with zero data retention (ZDR) enabled by default, giving you Opus’ top-tier intelligence while meeting your data governance requirements. It keeps your data within AWS infrastructure with regional data residency and provides access through a unified service with AWS-managed features like Guardrails and Knowledge Bases. To learn more, see the Amazon Bedrock documentation and regional availability.
Amazon Quick Microsoft 365 extensions are now generally available
Today, Amazon Quick announces the general availability of Microsoft 365 extensions for Excel, PowerPoint, Word, and Outlook. These extensions enable Quick to perform tasks directly within users’ M365 environments, using AI to handle complex local tasks such as redlining documents, building financial models, creating presentation-ready decks, and managing Outlook inboxes.\n The Excel extension helps with complex spreadsheet analysis, creating pivot tables and charts, and importing and cleaning data. The PowerPoint extension helps you create and refine presentations from Quick data using organization-defined templates. The Word extension generates formatted documents with Word primitives, makes sweeping edits with track changes enabled, and participates as a reviewer in comments. The Outlook extension performs inbox and calendaring tasks such as prioritizing emails, organizing your inbox, scheduling meetings, and drafting replies using your Quick data and entire inbox context.
These extensions transform daily work across teams. Finance teams can build complex models by describing what they need. Sales teams can draft proposals that automatically pull from CRM data. Marketing teams can create branded presentations without manual formatting. Legal teams can streamline contract reviews. Operations teams can manage email workflows and schedule meetings intelligently, and IT teams can automate routine data analysis that previously required manual effort.
Amazon Quick Microsoft 365 extensions are available in US East (N. Virginia), US West (Oregon), Asia Pacific (Sydney), Europe (Ireland), Asia Pacific (Tokyo), and Europe (Frankfurt). To learn more, see Amazon Quick for Microsoft 365: Agentic AI where you work, and download extensions on the Quick download page.
Spot Placement Score now includes Local Zones
Today, AWS announces support for AWS Local Zones in Spot placement score, helping you identify locations where your Spot capacity request is most likely to succeed. Spot placement score evaluates your target capacity and compute requirements and returns scores for AWS Regions or Availability Zones.\n Previously, Spot placement scores excluded local zone capacity information when reporting zonal and regional scores. Now, you can optionally request local zones to be included in the zonal and regional score responses giving you a broader view of your Spot capacity options.
You can use Spot placement score through EC2 Spot Console, AWS CLI, or SDK. To learn more about Spot placement score see Spot placement score documentation.
Daybreak Red and Daybreak Blue from OpenAI are now available to eligible customers on Amazon Bedrock
Security teams can now access Daybreak Red and Daybreak Blue from OpenAI on Amazon Bedrock. Both are part of Daybreak, the cyber defense initiative from OpenAI that gives defenders governed access to frontier AI for cybersecurity work.\n Daybreak Blue is the starting point for most security teams across defensive workflows including vulnerability discovery, detection engineering, and incident response. Daybreak Red is designed for advanced, authorized tasks such as vulnerability research, exploit reproduction, and mitigation development. For these tasks, a lower refusal threshold matched by stronger identity verification, monitoring, and access controls improves the speed and depth of an investigation. Both models run on Bedrock’s next-generation inference engine with zero-operator access (ZOA) enforced at the chip. Your inference data is not used for model training, and neither model requires you to opt into sharing your data with OpenAI.
Daybreak Red: GPT-5.6 Cyber and Daybreak Blue: GPT-5.6 Sol are now available to eligible customers on Amazon Bedrock in the following AWS Region: US East (N. Virginia). Access to the models requires enrollment in Daybreak access from OpenAI. To enroll, contact OpenAI or reach out to your AWS account team for guidance on eligibility. Once approved, work with your account team to request access on AWS. To learn more, read the blog.
AWS Certificate Manager supports switching from e-mail to DNS validation
AWS Certificate Manager (ACM) now enables you to change the domain validation method on your existing ACM issued public TLS certificates from e-mail to DNS, without reissuing the certificate or changing its existing Amazon Resource Name (ARN). Due to the Certification Authority/Browser (CA/B) Forum’s mandated deprecation of email-based domain validation for publicly trusted certificates, effective March 15, 2028, ACM will phase out its support for email validation throughout 2027. ACM will no longer issue email-validated certificates starting March 31 2027, and stop renewing email-validated certificates on September 30 2027. More details on ACM’s deprecation of email validation can be found on the AWS Security Blog. By switching to DNS validation now, you can transition ahead of that deadline and enable fully automated renewals through DNS validated certificates.\n Your certificate ARN remains unchanged after switching from e-mail to DNS validation, so existing ARN references in your CI/CD pipelines, load balancer configurations, and other AWS service integrations continue to work without modification. To switch the validation method, use the ACM console or the UpdateCertificateOptions API. ACM provides a CNAME record for each domain in the certificate (the same mechanism used when provisioning new certificates with DNS validation) and you have up to 72 hours to add the records to your DNS configuration. You can monitor the validation status of each domain via the console or the ListCertificateDomainValidations API. We recommend DNS validation for new certificates, and HTTP validation for Amazon CloudFront distributions..
This feature is available in all AWS Regions where ACM certificates are available. To get started, refer to Migrating from email to DNS validation in the AWS Certificate Manager User Guide.
Amazon S3 adds additional policy details to access denied error messages
Amazon S3 now includes the specific AWS Identity and Access Management (IAM) and AWS Organizations policy Amazon Resource Name (ARN) in HTTP 403 Access Denied error messages for same-account and same-organization requests. This helps you quickly identify the exact policy responsible for a denied request and remediate the issue directly.\n Previously, S3 access denied error messages included the policy type and reason for denial, but when multiple policies of the same type existed, you still had to manually inspect each one to pinpoint the root cause. Now the error message includes the specific policy ARN for explicit deny cases, covering Service Control Policies (SCPs), Resource Control Policies (RCPs), identity-based policies, session policies, and permission boundaries.
This capability is available in all AWS Regions, including the AWS GovCloud (US) Regions and the AWS China Regions. To learn more about how to troubleshoot access denied errors in Amazon S3, visit the S3 User Guide and the IAM troubleshooting documentation.
AWS Blogs
AWS Japan Blog (Japanese)
- Genomic data storage and workflows enhanced by MGI, Sentieon, and AWS
- Benchmark the PacBio Whole-Genome Sequencing Variant Analysis Pipeline with the AWS HealthOmics Workflow
- Accelerating Life Sciences Research with Kiro: Integrated AI Interfaces to 100+ Open Source Databases
- [Event Report] Eight Joint AI-DLC Unicorn Gym for ISV SaaS Operators
- AWS Weekly Roundup: AWS Heroes Summit, Amazon Bedrock, Dogwood, Kiro Crew Web Search, etc. (2026/8/10)
- Oracle Exadata on Exascale can now be used with Oracle AI Database @AWS
AWS Japan Startup Blog (Japanese)
AWS Architecture Blog
- Track generative AI costs with Amazon Bedrock inference profiles
- Recovery strategies to meet data residency requirements
- Reducing Text2SQL latency with parameterized query templates
- Adobe Firefly: Simplified observability with Amazon Managed Prometheus
AWS Big Data Blog
AWS Compute Blog
AWS Contact Center
- Connect Flows Now Support Nested Modules and Cross-Flow Compatibility
- Amazon Connect Service Quota Monitor
Artificial Intelligence
- Monitor on-premises and multi-cloud AI agents with AgentCore Observability
- Automate legacy web applications with Amazon Bedrock AgentCore Browser Tool
- Accelerating M&A due diligence with Amazon Bedrock AgentCore
- Amazon Quick for Microsoft 365: Agentic AI where you work