10/1/2026, 12:00:00 AM ~ 10/2/2026, 12:00:00 AM (UTC)

Recent Announcements

AWS Well-Architected Agent is now available in preview

AWS announces the preview of AWS Well-Architected Agent, a AI-powered service that is the next-gen evolution of AWS Trusted Advisor and the AWS Well-Architected Tool. The agent analyzes and optimizes AWS infrastructure across cost, security, performance, and reliability, delivering contextualized recommendations prioritized by business goals. It automatically correlates key metrics and application topology against Well-Architected best practices and analyzes Terraform, CDK templates and CloudFormation templates to deliver automation-ready fixes where applicable.\nWith AWS Well-Architected Agent, teams can define their business goals and get prioritized recommendations prioritized by impact and effort at the resource, application, and architecture levels. For example, a team prioritizing reliability can receive recommendations to add multi-AZ failover to a critical database, complete with an SSM runbook that automates the configuration change and a cross-pillar analysis showing how this change affects cost and performance before you commit. Where applicable, recommendations are delivered with SSM runbooks, prescriptive CLI scripts, and guided console walkthroughs so teams can move quickly. The agent can also conduct automated reviews of your IaC templates that include Terraform, CloudFormation, or CDK templates, identifying gaps, and returning the IaC code changes needed to align with Well-Architected best practices. Access to the AWS Well-Architected Agent and its recommendations is available in US East (N. Virginia), US East (Ohio), and US West (Oregon). You can onboard workloads from any AWS commercial Region. AWS Well-Architected Agent is delivered by AWS Support and available to AWS customers with an AWS Support plan. Learn more about AWS Well-Architected Agent in the User Guide. Get started here.

Amazon DynamoDB introduces filtered export to Amazon S3

Amazon DynamoDB export to Amazon S3 allows you to export your table data for analytics, data sharing, and other offline uses, as either a full export or an incremental export over a time window. Filtered export enables you to specify exactly which items and attributes to export, producing a dataset that contains only the data relevant to your use case.\nWith filtered export, you use a key condition expression on a key attribute and a filter expression on any attribute to select which items to export, and a projection expression to choose which attributes to include. The export then returns only the items and attributes you want. You can use that subset of data to perform granular data recovery, move a slice of data between accounts, or run analytics while meeting your compliance rules. Filtered export works with both full exports and incremental exports. Filtered export is available in all AWS Regions, except the AWS GovCloud (US) Regions. To get started, see the following resources: DynamoDB data export to Amazon S3 in the DynamoDB developer guide Filtering a table export in the DynamoDB developer guide Introducing filtered export from Amazon DynamoDB to Amazon S3 blog post

Amazon DynamoDB Accelerator (DAX) is now available in additional Regions

Today, AWS announces the availability of Amazon DynamoDB Accelerator (DAX) in 17 additional AWS Regions: Asia Pacific (Hong Kong), Asia Pacific (Hyderabad), Asia Pacific (Jakarta), Asia Pacific (Malaysia), Asia Pacific (Melbourne), Asia Pacific (New Zealand), Asia Pacific (Osaka), Asia Pacific (Seoul), Asia Pacific (Taipei), Asia Pacific (Thailand), Canada West (Calgary), Europe (Milan), Europe (Zurich), Israel (Tel Aviv), Mexico (Central), AWS GovCloud (US-East), and AWS GovCloud (US-West). DAX is a fully managed, highly available, in-memory cache for Amazon DynamoDB that delivers up to 10 times performance improvement—from single-digit milliseconds to microseconds—even at millions of requests per second. This expansion brings DAX to more geographies, helping customers accelerate read-heavy DynamoDB workloads without managing their own cache infrastructure.\nWith DAX, you can accelerate read-intensive and bursty workloads such as real-time bidding, gaming leaderboards, and retail product catalogs, while offloading read traffic from your DynamoDB tables. DAX is API-compatible with DynamoDB, so you can add microsecond-latency caching to your applications with minimal code changes. Customers in these Regions can now meet local data residency and low-latency requirements while benefiting from DAX’s fully managed operations, including automated patching, failover, and scaling. To see the full list of Regions where DAX is available, see the following resources: AWS Capabilities by Region.

Amazon GuardDuty now supports centralized management using AWS Organizations declarative policies

Amazon GuardDuty now supports AWS Organizations declarative policies, enabling you to centrally enable GuardDuty threat detection across every account and Region in your AWS organization. Using an organization policy, you can now apply a centrally managed GuardDuty enablement configuration. The configuration applies to existing accounts and is automatically maintained as new accounts join your organization.\nEnabling GuardDuty across all relevant accounts and Regions helps ensure comprehensive threat detection coverage. Previously, keeping enablement aligned across a large multi-account, multi-Region environment meant configuring GuardDuty’s enablement settings separately in each Region, which could drift over time. Now you can define a central GuardDuty policy from your delegated administrator account that sets an enablement baseline across your organization (at the organization root, OUs, or individual accounts). The policy supports a default configuration that applies in every Region where GuardDuty is available, as well as per-Region overrides for Regions that require different enablement. Enablement set by a policy cannot be overridden via the GuardDuty console or API. GuardDuty declarative policy support is available in all AWS commercial Regions and the AWS GovCloud (US) Regions. To get started, make sure the delegated administrator has permission to manage GuardDuty policies. Then, sign in to the GuardDuty console and choose Organization policies, or create a policy programmatically using AWS Organizations APIs. To learn more, see Managing accounts using organization policies in the Amazon GuardDuty User Guide and Amazon GuardDuty policies in the AWS Organizations User Guide.

Amazon Corretto 8 September 2026 Patch Updates

On September 30, 2026, Amazon announced a patch update for the following Amazon Corretto Long-Term Support (LTS) version of OpenJDK: Corretto 8u504 is now available for download. Amazon Corretto is a no-cost, multi-platform, production-ready distribution of OpenJDK. This patch includes the tzdata 2026d updates.\nVisit Corretto home page to download Corretto 27, Corretto 25, Corretto 21, Corretto 17, Corretto 11, or Corretto 8. You can also get the updates on your Linux system by configuring a Corretto Apt, Yum, or Apk repo. Feedback is welcomed!

Amazon S3 Object Lock variable retention with event holds is now available in AWS GovCloud (US) Regions

Amazon S3 Object Lock support for variable retention with event holds is now available in AWS GovCloud (US-East) and AWS GovCloud (US-West).\nAmazon S3 Object Lock variable retention allows you to apply write-once-read-many (WORM) protection to objects whose required retention period starts with a future event, such as a contract closing or an audit completing. You place an event hold with a retention duration on an object and S3 protects the object while the hold is in place. When you release the hold, S3 retains the object for the duration you specified. Unlike legal holds, which end protection immediately upon removal, event holds provide WORM compliance for the required retention period after the triggering event, so you can meet event-based retention requirements without retaining data longer than your policy requires.

AWS Storage Blog post, the S3 Object Lock overview page, and the S3 documentation. This capability has been assessed by Cohasset Associates for use in environments subject to SEC Rule 17a-4(f), FINRA Rule 4511, and CFTC Regulation 1.31.

AWS Glue Data Catalog now supports table optimization, statistics, and crawlers for Apache Iceberg V3

AWS Glue Data Catalog now supports table optimization, statistics, and crawlers for Apache Iceberg Version 3 (V3) tables. With these new capabilities, you can automatically maintain V3 tables, optimize them for query performance, and discover them in Amazon S3.\nWith table optimization, you can compact V3 tables using binpack, sort, or z-order strategies to improve query performance, and remove expired snapshots and orphan files to reduce storage costs. These optimizations support V3 data types, including variant, geospatial, and nanosecond-precision timestamps. You can also generate number of distinct values (NDV) statistics for V3 tables, which analytics engines use to plan queries efficiently. In addition, you can use Glue crawlers to discover V3 tables stored in Amazon S3 and register them in Glue Data Catalog, making them available to query with any V3-compatible engines. These capabilities are available for Iceberg V3 tables in all AWS Regions where Glue Data Catalog table optimization, statistics, and crawlers are available. To learn more, see Glue Optimization, Glue Statistics, and Glue crawlers in the Glue Developer Guide.

Serverless Storage on Amazon EMR Serverless now supports terabyte-scale shuffle

Amazon EMR Serverless now offers enhanced serverless storage capabilities with support for up to 1TB shuffle operations, raising the previous 200 GB per-job limit. Amazon EMR Serverless makes it simple for data engineers and data scientists to run open-source big data analytics frameworks without configuring, managing, and scaling clusters or servers. This enhancement enables enterprise customers to run production-scale Apache Spark workloads that require processing large volumes of shuffle data during complex operations such as joins, aggregations, and sorting.\nEnterprise data teams can now confidently migrate production workloads that routinely process terabyte-scale datasets without worrying about storage constraints. This enhancement is particularly valuable for workloads involving large table joins across multi-terabyte datasets, and complex aggregations on high-cardinality data that require extensive data shuffling. The addition of spill support ensures that jobs can seamlessly handle memory-intensive operations by offloading data to disk when necessary, improving job reliability and success rates for demanding analytical workloads. This feature is available with Amazon emr-7.14, emr-spark-8.1 and later, in 18 AWS Regions where Amazon EMR Serverless is available. See the Amazon EMR documentation for the full list of supported Regions and their applicable limits. To learn more about Amazon EMR Serverless and get started with terabyte-scale shuffle support, visit the Amazon EMR Serverless page.

Announcing DNS analytics and insights for Route 53 Global Resolver and DNS Firewall

Route 53 Global Resolver and DNS Firewall now provide DNS analytics and insights through native Amazon CloudWatch integration. These new capabilities enable network administrators and security teams to gain full observability into DNS query patterns, monitor DNS Firewall rule effectiveness, detect anomalous activity, and optimize DNS infrastructure performance. DNS analytics and insights is available in all AWS Regions where Amazon CloudWatch, Route 53 Global Resolver, and DNS Firewall are available.\nWith CloudWatch Metrics and Contributor Insights, customers can search and analyze DNS query logs, create metric filters for specific patterns such as blocked queries and DNS response codes, and set automated alarms. A new Analytics tab in both the Global Resolver and DNS Firewall consoles provides streamlined access to all analytics in one place. For example, customers can create a metric filter for blocked DNS queries by VPC and set an alarm to trigger when more than 10 queries are blocked within an hour, enabling rapid response to potential security threats. Standard Amazon CloudWatch pricing applies to the metrics that customers opt in to. To learn more, visit the Route 53 documentation.

Improve your secrets security posture with actionable recommendations in the AWS Secrets Manager console

​​​AWS Secrets Manager now integrates with the AWS Recommended Actions framework to surface contextual, actionable suggestions for your secrets directly in the Secrets Manager console. ​​\n​​With this launch, you can view tailored recommendations alongside your secrets to improve your security posture and follow best practices without leaving the console. For example, you can identify secrets that need rotation configured, use a customer managed key instead of default service-provided key for encryption, and act on secrets configuration improvements, all from a single view.​ ​​This feature is available in all AWS Regions in the AWS partition where AWS Secrets Manager is offered, at no additional cost. To get started, visit the AWS Secrets Manager console.​

AWS IAM Identity Center extends multi-Region support to more AWS Regions

IAM Identity Center helps you connect your workforce identities to AWS once and streamline access management to AWS accounts and applications. You can now replicate IAM Identity Center to opt-in AWS Regions, and between Regions within the AWS GovCloud (US) and AWS China Regions. Previously, multi-Region support was available in the enabled-by-default commercial AWS Regions. This helps you improve the resilience of user access to AWS accounts and deploy AWS applications in the AWS Regions that best align with your business needs.\nWhen you enable multi-Region support, IAM Identity Center automatically replicates your identities, entitlements, and other information from the primary Region to additional Regions. If IAM Identity Center is affected by a disruption in the primary Region, users continue to have access to their AWS accounts using already provisioned entitlements in the additional Regions. AWS application administrators can use the standard application deployment workflow to deploy their application in an additional Region while you continue to administer IAM Identity Center in the primary Region. Multi-Region support is available for organization instances that use an external identity provider or the IAM Identity Center directory as the identity source, and requires a multi-Region customer managed KMS key (CMK). When you create a new instance, you can enable multi-Region support with a single click, which also creates the CMK. For existing instances, create a multi-Region CMK in AWS KMS, then configure it in IAM Identity Center. Standard AWS KMS charges apply for storing and using CMKs. IAM Identity Center is provided at no additional cost.

AWS Capabilities by Region. To learn more about multi-Region support, see Using IAM Identity Center across multiple AWS Regions. To find out which AWS applications support deployment in additional Regions, visit AWS applications that you can use with IAM Identity Center.

Amazon S3 Tables now support up to 100 table buckets per AWS Region in an AWS account

Amazon S3 Tables now support up to 100 table buckets per AWS Region in an AWS account, increased from 10. This allows you to create up to 1 million tables per AWS Region in an AWS account. With a higher table bucket allowance, you can create a separate table bucket for each dataset, workload, or team, and apply table bucket-level settings such as encryption, access policies, and replication to each. The higher quota applies by default to all accounts at no additional cost.\nS3 Tables deliver the first cloud object store with built-in Apache Iceberg support, and the easiest way to store tabular data at scale. S3 Tables perform continual table maintenance to automatically optimize query efficiency and storage cost over time, even as your data lake scales and evolves. The higher default quota is available in all AWS Regions where S3 Tables are available. If you need a quota beyond the default, you can request an increase through AWS Support. To learn more, visit the S3 Tables overview page, user guide, and quotas documentation.

AWS Blogs

AWS Japan Blog (Japanese)

AWS News Blog

AWS Architecture Blog

AWS Cloud Operations Blog

AWS Big Data Blog

AWS Contact Center

Containers

AWS Database Blog

AWS DevOps & Developer Productivity Blog

Artificial Intelligence

Open Source Project

AWS CLI