AWS Weekly Roundup: AWS re:Inforce 2025, AWS WAF, AWS Control Tower, and more (June 16, 2025)

Today marks the start of AWS re:Inforce 2025, where security professionals are gathering for three days of technical learning sessions, workshops, and demonstrations. This security-focused conference brings together AWS security specialists who build and maintain the services that organizations rely on for their cloud security needs.

AWS Chief Information Security Officer (CISO) Amy Herzog will deliver the conference keynote along with guest speakers who will share new security capabilities and implementation insights. The event offers multiple learning paths with sessions designed for various technical roles and expertise levels. Many of my colleagues from across AWS are leading hands-on workshops, demonstrating new security features, and facilitating community discussions. For those unable to join us in Philadelphia, the keynote and innovation talks will be viewable by livestream during the event, and available to watch on demand after the event. Look out for the key announcements and technical insights from the conference in upcoming posts!

Let’s look at last week’s new announcements.

Last week’s launches
Here are the launches that got my attention.

Extend Amazon Q Developer IDE plugins with MCP toolsAmazon Q Developer now supports Model Context Protocol (MCP) in its integrated development environment (IDE) plugins, helping developers integrate external tools for enhanced contextual development workflows. You can now augment the built-in tools with any MCP server that supports the stdio transport layer. These servers can be managed within the Amazon Q Developer user interface. This makes it easy to add, remove, and modify tool permissions. The integration enables more customized responses by orchestrating tasks across both native and MCP server-based tools. MCP support is available in Visual Studio Code and JetBrains IDE plugins, as well as in the Amazon Q Developer command line interface (CLI), with detailed documentation and implementation guides available in the Amazon Q Developer documentation.

AWS WAF now supports automatic application layer DDoS protection – AWS has enhanced its application layer (L7) distributed denial of service (DDoS) protection capabilities with faster automatic detection and mitigation that responds to events within seconds. This AWS Managed Rules group automatically detects and mitigates DDoS attacks of any duration to keep applications running on Amazon CloudFront, Application Load Balancer, and other AWS WAF supported services available to users. The system establishes a baseline within minutes of activation using machine learning (ML) models to detect traffic anomalies, then automatically applies rules to address suspicious requests. Configuration options help you customize responses such as presenting challenges or blocking requests. The feature is available to all AWS WAF and AWS Shield Advanced subscribers in all supported AWS Regions, except Asia Pacific (Thailand), Mexico (Central), and China (Beijing and Ningxia). To learn more about AWS WAF application layer (L7) DDoS protection, visit the AWS WAF documentation or the AWS WAF console.

AWS Control Tower now supports service-linked AWS Config managed AWS Config rulesAWS Control Tower now deploys service-linked AWS Config rules directly in managed accounts, replacing the previous CloudFormation StackSets deployment method. This change improves deployment speed when enabling service-linked AWS Config rules across multiple AWS Control Tower managed accounts and Regions. These service-linked rules are managed entirely by AWS services and can’t be edited or deleted by users. This helps maintain consistency and prevent configuration drift. AWS Control Tower Config rules detect resource noncompliance within accounts and provide alerts through the dashboard. You can deploy these controls using the AWS Control Tower console or AWS Control Tower control APIs.

Powertools for AWS Lambda introduces Bedrock Agents Function utility – The new Amazon Bedrock Agents Function utility in Powertools for AWS Lambda simplifies building serverless applications integrated with Amazon Bedrock Agents. This utility helps developers create AWS Lambda functions that respond to Amazon Bedrock Agents action requests with built-in parameter injection and response formatting, eliminating boilerplate code. The utility seamlessly integrates with other Powertools features like Logger and Metrics, making it easier to build production-ready AI applications. This integration improves the developer experience when building agent-based solutions that use AWS Lambda functions to process actions requested by Amazon Bedrock Agents. The utility is available in Python, TypeScript, and .NET versions of Powertools.

Announcing open sourcing pgactive: active-active replication extension for PostgreSQL – Pgactive is a PostgreSQL extension that enables asynchronous active-active replication for streaming data between database instances, and AWS has made it open source. This extension provides additional resiliency and flexibility for moving data between instances, including writers located in different Regions. It helps maintain availability during operations like switching write traffic. Building on PostgreSQL’s logical replication features, pgactive adds capabilities that simplify managing active-active replication scenarios. The open source approach encourages collaboration on developing PostgreSQL’s active-active capabilities while offering features that streamline using PostgreSQL in multi-active instance environments. For more information and implementation guidance, visit the GitHub repository.

For a full list of AWS announcements, be sure to keep an eye on the What’s New at AWS page.

We launched existing services and instance types in additional Regions:

Other AWS events
Check your calendar and sign up for upcoming AWS events.

AWS GenAI Lofts are collaborative spaces and immersive experiences that showcase AWS expertise in cloud computing and AI. They provide startups and developers with hands-on access to AI products and services, exclusive sessions with industry leaders, and valuable networking opportunities with investors and peers. Find a GenAI Loft location near you and don’t forget to register.

AWS Summits are free online and in-person events that bring the cloud computing community together to connect, collaborate, and learn about AWS. Register in your nearest city: Milano (June 18), Shanghai (June 19 – 20), Mumbai (June 19) and Japan (June 25 – 26).

Browse all upcoming AWS led in-person and virtual events here.

That’s all for this week. Check back next Monday for another Weekly Roundup!

— Esra

This post is part of our Weekly Roundup series. Check back each week for a quick roundup of interesting news and announcements from AWS!

from AWS News Blog https://ift.tt/w9fFSzt
via IFTTT

Over 80,000 Microsoft Entra ID Accounts Targeted Using Open-Source TeamFiltration Tool

Cybersecurity researchers have uncovered a new account takeover (ATO) campaign that leverages an open-source penetration testing framework called TeamFiltration to breach Microsoft Entra ID (formerly Azure Active Directory) user accounts.
The activity, codenamed UNK_SneakyStrike by Proofpoint, has affected over 80,000 targeted user accounts across hundreds of organizations’ cloud tenants since a

from The Hacker News https://ift.tt/A2Qa7zI
via IFTTT

Digital rights groups sound alarm on Stop CSAM Act 

Digital rights groups are urging Senate leaders not to move forward with a bill that would impose new regulations on companies around child sexual abuse material, arguing that the legislation could be a privacy nightmare for Americans.

In a letter addressed to Senate Judiciary Committee leaders Sens. Chuck Grassley, R-Iowa, and Dick Durbin, D-Ill., the groups – which include the American Civil Liberties Union, Freedom of the Press Foundation, Defending Rights and Dissent and RootsAction – say the STOP CSAM Act, reintroduced in May, “walks back a number of important privacy protections that had been included in a previous version of the bill.”

“The current bill creates enormous incentives for platforms to stop offering encrypted services that are critical for enabling all of us to have private conversations and securely store files from our most personal moments, like photos from a child’s birthday,” the letter reads.. “While all of our groups want to stop the harmful transmission of child sexual abuse material (CSAM), its transmission is already illegal, and these modifications to the bill do nothing more than undermine privacy and security.”

The Stop CSAM Act would impose new requirements on companies to prevent the hosting and distribution of child sexual abuse material on their platforms.

It expands companies’ legal obligations by requiring them to report instances of such material on their sites to the National Center for Missing and Exploited Children.  It also introduces stricter privacy protections for children who testify in court. Additionally, and would require businesses with more than 1 million unique monthly visitors or users or $50 million in annual revenue to submit annual reports to the Federal Trade Commission and Department of Justice.

It would also seek to alter immunity under Section 230 of the Communications Decency Act for “interactive computer services,” allowing victims to file civil lawsuits against companies that fail to remove CSAM content from their platforms in a timely fashion.

The bill includes language specifying that “any person who is a victim of the intentional, knowing, or reckless hosting or storing of child pornography or making child pornography available to any person by a provider of an interactive computer service, and who suffers personal injury as a result of such hosting, storing, or making available, regardless of when the injury occurred, may bring a civil action.”

Digital rights groups say that the new version of the legislation includes “recklessness” as a legal standard for liability and by applying it to any “interactive computer service,” the legislation would capture virtually all applications that rely on end-to-end encryption.

That in turn could open up providers of these services to civil lawsuits for hosting material that they can’t view without breaking the encryption of their users.

“[The bill] goes much further than current law and threatens to punish any service that works to keep its users secure, including those that do their best to eliminate and report CSAM,” wrote India McKinney of the Electronic Frontier Foundation. “The bill applies to ‘interactive computer services,’ which broadly includes private messaging and email apps, social media platforms, cloud storage providers, and many other internet intermediaries and online service providers.”

It’s not clear whether the groups’ warnings on data privacy will have much influence in this Congress. Politically, forcing private companies do more to counter child sexual abuse material on their platforms and websites has been broadly popular with the public, and online child safety is a top issue for congressional Republicans, who control both houses of Congress. Grassley is not known as a strong advocate of unrestricted encryption. He previously led a bipartisan congressional effort in 2018 to develop legislation that would would have compelled companies to grant law enforcement access to encrypted communications in investigations.

Another bill introduced this Congress, the Take It Down Act, carried similar take down requirements for companies around AI-generated nonconsensual deepfake pornography. Though many of the same groups loudly opposed the measure on similar privacy grounds, it ultimately passed 402-2 in the House and unanimously in the Senate before being swiftly signed into law by President Donald Trump.

The letter to Grassley and Durbin emphasizes that private communications – underpinned by strong digital encryption – are critical to healthy, functioning democratic societies and have many benefits to marginalized or targeted populations.

“That is why encrypted services are popular amongst journalists who use encrypted messages to contact their sources, protesters seeking to organize to raise their voices against unjust government action, doctors who use it to speak with patients, domestic violence victims who rely on completely private communications to escape dangerous situations at home, and businesses discussing finances with clients,” the letter reads. “But there would also be severe consequences for groups that are being targeted by governments domestically and globally.”

The post Digital rights groups sound alarm on Stop CSAM Act  appeared first on CyberScoop.

from CyberScoop https://ift.tt/HvAfyWV
via IFTTT

How Amazon Web Services uses AI to be a security ‘force multiplier’

When Amazon Web Services deploys thousands of new digital sensors around the globe, it often runs into a ruthless truth of the internet: Within minutes, the sensors are poked, prodded, and attacked. However, using large language models, the company is turning those immediate attacks into actionable security intelligence for its vast array of cloud-centered services.  

According to Stephen Schmidt, the company’s chief security officer, examples like this demonstrate how AI enables capabilities that weren’t possible with earlier tools. During remarks at the AWS Summit on Tuesday, Schmidt highlighted this example to illustrate how AI is fundamentally transforming AWS’s approach to security — especially in areas like application security reviews and incident response.

“What we can do with AI is allow engineers to ask questions about what’s going on with that data much more easily than they could otherwise, and they can say things like ‘Find me all of the examples of situations where someone tried to break into this particular version of this particular database, and came from IP addresses that are associated with the VPNs that are normally used by this particular threat actor,” he told CyberScoop. “You can’t do that otherwise, and the tooling allows them to really dig into things much more deeply.”

The technology allows for more consistent and efficient security assessments, especially for junior engineers who may lack extensive experience.

By training large language models on previous security reviews, organizations can effectively transfer knowledge from senior security professionals to newer team members. This approach raises the overall security standard by embedding institutional expertise directly into AI-powered review processes.

“A junior engineer may not have all the knowledge, the background, the experience of the more senior engineers,” he said. “By training our large language models internally on the prior security reviews, it allows us to apply the knowledge and learning that our more senior staff have embodied in the documents that we all own, trained on, to our more junior staff. So it really raises the bar on the absolute level of security.” 

The cybersecurity industry faces persistent personnel shortages, a problem AI can help mitigate. Schmidt noted that AI tools can handle significant “heavy lifting” previously performed manually, allowing security staff to focus on more complex tasks.

Critically, Schmidt highlighted the non-deterministic nature of AI systems, meaning identical queries can produce different responses. He pointed to this as a reason why humans still need to be involved in making decisions based on the model’s output.

“We look at it this way, if you’re just asking a question and getting an answer, that’s one set of scrutiny that you have to give a system,” he said. “But if you’re going to take an action to block something, to prevent something from occurring, you’ve got to be really sure it’s correct. So there has to be that skilled person at the end of the AI-use process, saying, ‘Yes, this is the right thing to do at this point in time with this context.’”

That need for a human in the process is why Schmidt believes that AI will not supplant entry- or junior-level positions, even if the technology continues to improve. He said conversations around AI replacing junior engineers are rooted in “FUD,” and he expects the models to raise the skill level faster than ever before. 

“I don’t think it’s going to happen,” he said of AI replacing human-led security work. “The thing about security that’s both great and difficult is you’re never done, and it’s never perfect. So we always have the ability to raise the bar across things, and by using tooling that allows us to get those junior engineers up to speed more quickly and to learn more about why senior engineers make decisions. It means we’ve got this middle ground of staff who are really good, much more quickly than we would otherwise.”

The post How Amazon Web Services uses AI to be a security ‘force multiplier’ appeared first on CyberScoop.

from CyberScoop https://ift.tt/CKWwrI4
via IFTTT

Adobe Releases Patch Fixing 254 Vulnerabilities, Closing High-Severity Security Gaps

Adobe on Tuesday pushed security updates to address a total of 254 security flaws impacting its software products, a majority of which affect Experience Manager (AEM).
Of the 254 flaws, 225 reside in AEM, impacting AEM Cloud Service (CS) as well as all versions prior to and including 6.5.22. The issues have been resolved in AEM Cloud Service Release 2025.5 and version 6.5.23.
“Successful

from The Hacker News https://ift.tt/9Mx1qIO
via IFTTT

Researchers Uncover 20+ Configuration Risks, Including Five CVEs, in Salesforce Industry Cloud

Cybersecurity researchers have uncovered over 20 configuration-related risks affecting Salesforce Industry Cloud (aka Salesforce Industries), exposing sensitive data to unauthorized internal and external parties.
The weaknesses affect various components like FlexCards, Data Mappers, Integration Procedures (IProcs), Data Packs, OmniOut, and OmniScript Saved Sessions.
“Low-code platforms such as

from The Hacker News https://ift.tt/kr8VQeb
via IFTTT