We are pleased to announce automated sensitive data discovery , a new capability in Amazon Macie that provides continual, cost efficient, organization-wide visibility into where sensitive data resides across your Amazon Simple Storage Service (Amazon S3) estate. With this new capability, Macie automatically and intelligently samples and analyzes objects across your S3 buckets, inspecting them for sensitive data such as personally identifiable information (PII), financial data, and AWS credentials. Macie then builds and continuously maintains an interactive data map of where your sensitive data in S3 resides across all accounts and Regions where you’ve enabled Macie, and provides a sensitivity score for each bucket. Amazon Macie uses multiple automated techniques including resource clustering by attributes such as bucket name, file types, and prefixes to minimize the data scanning needed to uncover sensitive data in your S3 buckets. This helps you continuously identify and remediate data security risks without manual configuration and lowers the cost to monitor for and respond to data security risks.
AWS announces Amazon Verified Permissions (Preview)
Today, AWS is announcing the preview of Amazon Verified Permissions, a scalable, fine-grained permissions management and authorization service for custom applications. With Amazon Verified Permissions, application developers can let their end users manage permissions and share access to data. For example, application developers can use Amazon Verified Permissions to define and manage fine grained permissions to determine which Amazon Cognito users have access to which application resources.
AWS announces lower latencies for Amazon Elastic File System
Amazon Elastic File System (Amazon EFS) now delivers lower latencies enabling you to power an even broader set of applications with simple, scalable storage on AWS.
Announcing Amazon EC2 C7gn instances (Preview)
Starting today, the new Amazon Elastic Compute Cloud (Amazon EC2) C7gn instances, powered by the latest generation AWS Graviton processors, are available in preview. Featuring the new AWS Nitro Cards, Amazon EC2 C7gn instances deliver the highest network bandwidth, and the best packet-processing performance for Graviton-based Amazon EC2 instances. C7gn instances offer up to 200 Gbps network bandwidth and up to 50% higher packet-processing performance compared to previous generation C6gn instances. Amazon EC2 C7gn instances are built on the AWS Nitro System. The Nitro System is a collection of AWS designed hardware and software innovations that enables the delivery of efficient, flexible, and secure cloud services with isolated multi-tenancy, private networking, and fast local storage. Take advantage of the enhanced networking capabilities to scale performance and throughput while optimizing the cost of running network-intensive workloads. Workload examples include network virtual appliances, data analytics, and CPU based artificial intelligence and machine learning (AI/ML) inference.
Introducing Elastic Network Adapter (ENA) Express for Amazon EC2 instances
AWS announces the general availability of Elastic Network Adapter (ENA) Express for Amazon Elastic Compute Cloud (EC2) instances. All current generation EC2 instances use ENA, a purpose-built network interface, to deliver an enhanced networking experience. ENA Express is a new ENA feature that uses the AWS Scalable Reliable Datagram (SRD) protocol to improve network performance in two key ways: higher single flow bandwidth and lower tail latency for network traffic between EC2 instances.
Amazon FSx for NetApp ONTAP doubles the maximum throughput capacity and SSD IOPS per file system
Amazon FSx for NetApp ONTAP is doubling the maximum throughput capacity per file system from 2 GB/s to 4 GB/s and the maximum SSD IOPS from 80,000 to 160,000, enabling you to accelerate your performance-intensive workloads such as video rendering and database applications.
Announcing the general availability of AWS Local Zones in Buenos Aires, Copenhagen, Helsinki, and Muscat.
AWS Local Zones are now available in four new metro areas—Buenos Aires, Copenhagen, Helsinki, and Muscat. You can now use these Local Zones to deliver applications that require single-digit millisecond latency or local data processing.
AWS announces Amazon Inspector support for AWS Lambda functions
Amazon Inspector now supports AWS Lambda functions, adding continual, automated vulnerability assessments for Serverless compute workloads. With this expanded capability, Amazon Inspector now automatically discovers all eligible Lambda functions and identifies software vulnerabilities in application package dependencies used in the Lambda function code. All functions are initially assessed upon deployment to Lambda service and continually monitored and reassessed, informed by updates to the function and newly published vulnerabilities. When vulnerabilities are identified in the Lambda function or layer, actionable security findings are generated, aggregated in the Amazon Inspector console , and pushed to AWS Security Hub and Amazon EventBridge to automate workflows.
Announcing preview for Amazon Route 53 Application Recovery Controller zonal shift
Amazon Route 53 Application Recovery Controller now supports zonal shift to help you quickly recover from application failures in an AWS Availability Zone (AZ). Starting today, you can shift application traffic away from using an AZ with a single action for multi-AZ resources with support of Application Load Balancer and Network Load Balancer. This will help you quickly recover an unhealthy application in an AZ, and reduce the duration and severity of impact to the application due to events such as power outages and hardware or software failures.
Expanded API capabilities now generally available for Amazon QuickSight
Amazon QuickSight now offers expanded API capabilities, allowing programmatic access to the underlying structure of QuickSight dashboards and analyses with the AWS Software Development Kit. The new and expanded APIs let customers and developers treat QuickSight assets like software code and integrate with DevOps processes, such as code reviews, audits, and promotion across development and production environments.