AWS WAF Fraud Control announces Account Creation Fraud Prevention, a managed protection for AWS WAF that is designed to prevent creation of fake or fraudulent accounts. Fraudsters use fake accounts to initiate activities, such as abusing promotional and sign-up bonuses, impersonating legitimate users, and carrying out phishing attacks. These activities can lead to several direct or indirect costs such as damaged customer relationships, reputational loss, and exposure to financial fraud. Account Creation Fraud Prevention protects your account sign-up or registration pages by allowing you to continuously monitor requests for anomalous digital activity and automatically block suspicious requests based on request identifiers and behavioral analysis.
Amazon CodeGuru Security is now available in preview
Today, AWS announces the preview release of Amazon CodeGuru Security, a static application security testing (SAST) tool that uses Machine Learning to help you identify code vulnerabilities and provide guidance you can use as part of remediation. CodeGuru Security also provides in-context code patches for certain classes of vulnerabilities, helping you reduce the effort required to fix code vulnerabilities.
Amazon GuardDuty enhances console experience with findings summary view
Today, AWS announces a new summary page in the Amazon GuardDuty console to help you more quickly identify and take action on the highest-priority findings across your AWS environment. The summary page presents trends of findings over time, a breakdown of findings by severity and finding type, and top finding volume resources such as Amazon Elastic Compute Cloud (Amazon EC2) instances, Amazon Simple Storage Service (Amazon S3) buckets, Amazon Relational Database Service (Amazon RDS) databases, AWS Lambda functions, or Amazon Elastic Kubernetes Service (Amazon EKS) clusters. If you are operating in a multi-account environment, the new summary page consolidates findings from across the organization, and helps you to more quickly identify top-impacted accounts.
Announcing third-party risk assessments and CSV exports in AWS Audit Manager
Today, AWS Audit Manager announces expanded support for third-party risk assessments with the launch of two new features: a third-party questionnaire and the ability to export evidence as a comma-separated values (CSV) file. Customers can already share custom frameworks with vendors on AWS, so that vendors can create assessments on these frameworks and automatically collect evidence from their environments. Together, these features make it easier for enterprises to customize their third-party vendor risk assessments on AWS.
Amazon Personalize now supports VPC endpoints
Amazon Personalize now supports Amazon Virtual Private Cloud (VPC) endpoints, allowing Amazon Personalize to communicate with your resources on your VPC without going through the open internet. Amazon VPC is a service that you use to launch AWS resources in a private virtual network that you define and manage. To connect your VPC to Amazon Personalize, you define a VPC endpoint for Amazon Personalize. An endpoint is an elastic network interface with a private IP address that serves as an entry point for traffic destined to a supported AWS service. The endpoint provides reliable, scalable connectivity to Amazon Personalize, and doesn’t require an internet gateway or VPN connection. For more information, see What is Amazon VPC in the Amazon VPC User Guide.
Amazon Rekognition improves face search accuracy with user vectors
Today, AWS launched a new capability that significantly improves face search accuracy by leveraging multiple face images of a user. Currently, Amazon Rekognition allows customers to search users represented by individual face vectors. Face vectors are mathematical representations of faces from images. Now, customers can create user vectors, which aggregate multiple face vectors of the same user. User vectors offer higher face search accuracy with more robust depictions, as they contain varying degrees of lighting, sharpness, pose, appearance, etc.
EMR on EKS now supports container log rotation for Apache Spark
We’re excited to announce the ability to control container log rotation when running Apache Spark jobs in EMR on EKS. Amazon EMR on EKS enables customers to run open-source big data frameworks such as Apache Spark on Amazon EKS. Customers can now enable container log rotation to avoid excessive log files impacting pod execution.
AWS IAM Identity Center now supports automated user provisioning from Google Workspace
Customers can now connect their Google Workspace to AWS IAM Identity Center (successor to AWS Single Sign-On) once and manage access to AWS accounts and applications centrally, in IAM Identity Center. This integration enables end users to sign in using their Google Workspace identity to access all their assigned AWS accounts and applications. The integration helps administrators simplify AWS access management across multiple accounts while maintaining familiar Google Workspace experiences for end users as they sign in. IAM Identity Center and Google Workspace use Google auto-provisioning to securely provision users into IAM Identity Center, saving administrative time.
Amazon Connect now publishes new contact lifecycle events for callbacks
Amazon Connect now provides new contact lifecycle events for callbacks, including when a callback was queued, answered, or disconnected. Contact events can be used to create analytics dashboards to monitor and track contact activity, integrate into workforce management (WFM) solutions to better understand contact center performance, or take follow up actions such as updating your customer databases with a record of the callback attempt. Amazon Connect contact events are published in near real-time via Amazon EventBridge, and can be set up in a couple of clicks by going to the Amazon EventBridge AWS console and creating a new rule.
ECR basic scanning now uses version 3 of the Common Vulnerability Scoring System (CVSS) framework
Starting today, Amazon Elastic Container Registry (ECR) basic scanning feature will use Common Vulnerability Scoring System (CVSS) version 3 information when determining the severity for new Common Vulnerabilities and Exposures (CVEs). This enables customers to get the most recent severity information for vulnerabilities in their ECR container images. We use CVSS information to determine the severity of a vulnerability when the upstream distribution source does not have this information.