9/18/2026, 12:00:00 AM ~ 9/21/2026, 12:00:00 AM (UTC)
Recent Announcements
AWS Continuum now supports credential testing and accessible domain suggestions
AWS Continuum for penetration testing is a frontier agent that proactively secures applications throughout the development lifecycle by offering on-demand, customized penetration testing with real exploitability testing. Developers and security teams can now test login credentials and receive suggested domains before a penetration test runs. This makes it easier to configure an accurate network scope from the start, reducing misconfiguration and wasted test cycles.\n Previously, identifying all the URLs your application reaches required manual effort, and authentication failures were only discovered after a full test cycle completed, costing time and resources. With this launch, when you add login credentials during test configuration, AWS Continuum authenticates into your application exactly as a real user would, capturing every accessible domain reached during login and surfacing them as in-scope URL suggestions. You can review accessible domains, validate credentials, and confirm the agent covers the right endpoints, all before the real test begins. Accessible domains are returned regardless of whether the credential test succeeds, fails, or times out. You can learn more about this feature in our updated documentaiton.
This capability is available in all regions where AWS Continuum for penetration testing is available and is detailed on the AWS Continuum product page.
Amazon ECS Express Mode now supports AWS Graviton (ARM64) workloads
Amazon Elastic Container Service Express Mode now supports specifying ARM64 as the CPU architecture for your service, making it easy to deploy ARM-based container images on AWS Graviton-powered compute and benefit from up to 40% better price-performance compared to x86-based instances.\n Amazon ECS Express Mode makes it easy to rapidly launch containerized applications, including web applications and APIs, by orchestrating and managing the cloud architecture for your application. You provide your container image, and ECS Express Mode handles the rest, configuring networking, load balancing, auto scaling, and deployments, and providing your application with an auto-generated URL. With ARM64 architecture support, you can choose the compute architecture that fits your workload, whether you’re optimizing for cost with Graviton, matching your existing fleet, or deploying images built natively for ARM.
You can configure the CPU architecture for new and existing Amazon ECS Express Mode services using the AWS Management Console, AWS CLI, AWS SDKs, and infrastructure as code (IaC) tools. This capability is available in all AWS commercial Regions and AWS GovCloud (US) Regions. To learn more, see the ECS Express Mode documentation.
AWS Resilience Hub adds three new capabilities
The next generation of AWS Resilience Hub is a central location in the AWS that helps platform engineering and site reliability teams assess and strengthen the resilience of their workloads running on AWS. It provides automated dependency discovery, generative AI-powered failure mode analysis, modular resilience policies, resilience testing, and organization-wide resilience posture reporting. Today, AWS Resilience Hub adds three new capabilities: EKS labels support for service input sources, dependency insights, and resilience policy sharing through AWS Organizations.\n EKS labels support for service input sources. Resilience Hub now supports EKS labels within a namespace as a service input source, allowing customers to use their existing Kubernetes labeling conventions to scope exactly which resources Resilience Hub discovers and uses during failure mode analysis. This ensures assessments stay aligned with how teams organize their EKS workloads.
Dependency insights. Customers who enable dependency discovery can now generate dependency insights, a new generative AI-powered capability that analyzes discovered application dependencies and highlights meaningful patterns. Dependency insights surfaces new dependencies, identifies cross-Region dependencies, and flags unusual usage patterns. This helps teams accelerate dependency analysis and identify potential new risks.
Resilience policy sharing through AWS Organizations. Resilience Hub now supports sharing resilience policies through AWS Organizations, enabling central teams to build and manage policies that can be applied across multiple accounts. This provides organization-wide observability into which services are using each policy, making it easier to monitor adoption and ensure consistent resilience posture across the organization.
To get started, visit the AWS console. To learn more, see the product page or visit the documentation.
AWS RTB Fabric now supports configurable Availability Zone affinity
AWS RTB Fabric now supports configurable Availability Zone (AZ) affinity for responder gateways. With this capability, you can configure how your partners connect to your responder gateway: either in their own Availability Zone or to any Availability Zone that the gateway spans. This launch helps advertising technology (AdTech) companies use their infrastructure more efficiently—with no extra charges on RTB Fabric.\n Demand-side platforms (DSPs) and supply-side platforms (SSPs) run their bidding systems across multiple Availability Zones. Previously, AWS RTB Fabric sent each request to available gateway capacity in the requester’s own Availability Zone (AZ), so capacity in other AZs could go unused. Now you can set a client routing policy to control this: prefer the requester’s own AZ to avoid added latency of crossing a boundary, or use every AZ that the responder gateway spans to give each requester access to more gateway capacity. Configurable Availability Zone affinity is available in all AWS Regions where AWS RTB Fabric is available. See the AWS RTB Fabric User Guide for fleet requirements before enabling.
AWS RTB Fabric helps you connect with your AdTech partners such as Amazon Ads, GumGum, Kargo, MobileFuse, Sovrn, TripleLift, Viant, Yieldmo, and more in three steps while delivering single-digit millisecond latency through a private, high-performance network environment. RTB Fabric reduces standard cloud networking costs by up to 80% and does not require upfront commitments. AWS RTB Fabric is generally available in the following AWS Regions: US East (N. Virginia), US West (Oregon), Asia Pacific (Singapore), Asia Pacific (Tokyo), Europe (Frankfurt), and Europe (Ireland). See the AWS RTB Fabric Product Page to learn more.
Kimi K3 by Moonshot AI is now generally available on Amazon Bedrock
Amazon Bedrock continues to expand its open weight model portfolio with the same security and governance that customers rely on. Today, Kimi K3 from Moonshot AI is generally available on Amazon Bedrock, giving you a powerful new option for coding and knowledge work.\n According to Moonshot AI, Kimi K3 is its most capable model and the first open model to reach 2.8 trillion parameters. It combines native vision capabilities with a 1-million-token context window, making it well suited to long-running coding sessions across large repositories, multi-document analysis including scanned pages and screenshots, and extended agent workflows. Moonshot AI reports an approximate 2.5x improvement in scaling efficiency over Kimi K2. On Amazon Bedrock, Kimi K3 runs within the same security boundary as proprietary models, and the same controls for access, encryption, and auditing across your model portfolio. Kimi K3 is the first open weight model on Amazon Bedrock to support explicit prompt caching, helping reduce latency and input costs when reusing context across model calls.
Kimi K3 is available in all AWS Regions where Amazon Bedrock is available through cross-Region inferencing. To get started, visit the Amazon Bedrock Console. To learn more, see the Amazon Bedrock documentation and read the launch blog post.
Amazon SNS now supports message payloads up to 1 MiB
Amazon Simple Notification Service (Amazon SNS) now supports message payloads up to 1 MiB, a 4x increase from the previous 256 KiB limit, so you can publish larger messages to your SNS topics.\n Amazon SNS is a fully managed pub/sub messaging service that enables you to decouple and scale microservices, distributed systems, and serverless applications. As workloads such as application integration, IoT, and generative AI increasingly exchange larger volumes of data in a single message, the previous 256 KiB limit required customers to offload or split payloads before publishing.
With this launch, you can publish message payloads up to 1 MiB by setting the new MaximumMessageSize topic attribute on both SNS Standard and SNS FIFO topics. Topics with MaximumMessageSize set above 256 KiB support Amazon SQS, Amazon Data Firehose, and AWS Lambda subscriptions, with up to 100 total subscriptions per topic.
Amazon SNS 1 MiB support is available today in all AWS Regions where Amazon SNS is available. To learn more about sending large payloads with Amazon SNS, see the Amazon SNS Developer Guide.
The new AgentCore Runtime is now available in Amazon Bedrock AgentCore
Today, AWS announces the availability of the next generation of AgentCore Runtime, the serverless microVM compute within Amazon Bedrock AgentCore. The new Runtime delivers elastic memory management that reclaims unused memory throughout the session so you pay for actual usage rather than the peak, and consistent cold start times regardless of container image size or concurrency. You get the serverless model you already rely on: no pre-provisioning, scale to zero, hardware-enforced session isolation, and pay only for what you use - now with lower costs and faster starts.\n With the new Runtime, each session starts with a small, efficient memory profile. Additional memory is allocated on demand as the workload needs it, and memory that is no longer actively used is reclaimed rather than held until the session ends. For cold starts, the new Runtime prepares the agent environment once and snapshots it. Every new instance restores from that snapshot instead of repeating the full startup sequence, keeping start times consistent regardless of image size. In testing, the new Runtime delivered a P75 cold start of 1.9 to 2.0 seconds for container images from 200 MB to 2 GB, compared to 5.4–30 seconds with V1.
The new AgentCore Runtime is available in the following regions: us-east-1, us-east-2, us-west-2, eu-west-1, and ap-northeast-1. To get started, set platformVersion to V2 when creating or updating a runtime.
To learn more, visit the AgentCore Runtime documentation or the AWS News Blog. For pricing details, visit AgentCore pricing.
AWS PrivateLink announces Tunnel Endpoints to access network segments
AWS PrivateLink customers can now use VPC endpoint to privately and securely access network segments in another VPC/account. They can use a ‘tunnel’ endpoint, a new type of VPC endpoint, to tunnel into the network segment and access resources located within it.\n AWS PrivateLink is a highly available and scalable technology that enables private access across VPC and account boundaries to load balanced services, appliances, and resources such as databases and domains. Prior to this launch, customers who wanted to share their resources with another party such as an external vendor had to do it one at a time by creating a Resource Configuration for every resource. Now, customers can create a Resource Configuration to represent a CIDR range in their network, and share it with a vendor via AWS Resource Access Manager (RAM). The vendor can then create a tunnel endpoint and use GENEVE encapsulation to tunnel through it into the customer’s VPC to access resources located in CIDR range specified by the customer. There is an hourly charge for the tunnel endpoint and a per-GB charge for data processed through it. Please refer to the pricing page for AWS PrivateLink. The capability is available in the following AWS Regions: US East (N. Virginia), US East (Ohio), US West (N. California), US West (Oregon), Africa (Cape Town), Asia Pacific (Hong Kong), Asia Pacific (Hyderabad), Asia Pacific (Jakarta), Asia Pacific (Malaysia), Asia Pacific (Melbourne), Asia Pacific (Mumbai), Asia Pacific (Osaka), Asia Pacific (Seoul), Asia Pacific (Singapore), Asia Pacific (Sydney), Asia Pacific (Tokyo), Canada (Central), Canada West (Calgary), Europe (Frankfurt), Europe (Ireland), Europe (London), Europe (Milan), Europe (Paris), Europe (Spain), Europe (Stockholm), Europe (Zurich), Mexico (Central), South America (São Paulo).
To learn more about this capability and get started, please refer to the AWS PrivateLink documentation.
AWS Blogs
AWS Japan Blog (Japanese)
- Convert an RDS for SQL Server instance from License Included to Bring Your Own Media (BYOM)
- Achieve license mobility with Bring Your Own Media with fully managed Amazon RDS for SQL Server
- Integrating SAP Commerce Cloud with SAP Cloud ERP Private on AWS — a practical and proven approach
- Automate ERP exception handling with AWS agent-type standard operating procedures (SOPs)
- [Contribution] Lester Co., Ltd. builds an information platform connecting customer issues and group resolution capabilities with Amazon Bedrock
- AI-DLC implementation at NTT DOCOMO Mobile Innovation Tech Department (Part 2): Experimental results and findings of parallel development by 2 teams
- AI-DLC implementation at NTT DOCOMO Mobile Innovation Tech Department (Part 1): Application to ML development in the physical AI field
AWS Architecture Blog
- ReadyOn’s Four Walls of tenant isolation on Amazon EKS
- How CSIRO built scalable, cost-optimized genomic variant querying on AWS
AWS Cloud Financial Management
- How To Scale Cost Optimization Across 1,000s of Accounts with a FinOps EBA
- Implementing Proportional Reserved Instance and Savings Plans Chargeback with AWS Billing Conductor
AWS Compute Blog
Artificial Intelligence
- Amazon SageMaker Inference: 2026 year-to-date launches in review
- Introducing Kimi K3 on Amazon Bedrock
- Migrating multi-model AI agents to Amazon Bedrock AgentCore runtime
- The new AgentCore runtime: Elastic, optimized, and consistently fast starts
- Deploy Hugging Face models on Amazon SageMaker AI with coding agents
- Introducing Amazon SageMaker HyperPod Inference Gateway