AWS Security Hub has released 36 new controls for its Foundational Security Best Practice standard (FSBP) to enhance your Cloud Security Posture Management (CSPM). These controls conduct fully-automatic checks against security best practices for AWS Auto Scaling, AWS CloudFormation, Amazon CloudFront, Amazon Elastic Compute Cloud (EC2), Amazon Elastic Container Registry (ECR), Amazon Elastic Container Service (ECS), Amazon Elastic File System (EFS), Amazon Elastic Kubernetes Service (EKS), Elastic Load Balancing (ELB), Amazon Kinesis, AWS Network Firewall, Amazon OpenSearch Service, Amazon Redshift, Amazon Simple Storage Service (S3), Amazon Simple Notification Service (SNS), and AWS WAF. If you have Security Hub set to automatically enable new controls and are already using AWS Foundational Security Best Practices, these controls are enabled for you by default. Security Hub now supports 223 security controls to automatically check your security posture in AWS.
Amazon SageMaker Feature Store now supports feature metadata and search
Amazon SageMaker Feature Store is a fully managed, purpose-built repository to store, update, search, and share machine learning (ML) features. The service provides feature management capabilities such as enabling easy feature reuse, low latency serving, time travel, and ensuring consistency between features used in training and inference workflows. A feature group is a logical grouping of ML features whose organization and structure is defined by a feature group schema. Until today, customers could add metadata tags only to feature groups which in turn enabled easy search and discovery of a feature group. To search for a specific feature however was more complicated. Customers needed to know which feature group the feature belongs and then scan for the relevant feature in the feature group, leading to additional overhead while searching for features..
AWS Identity and Access Management introduces IAM Roles Anywhere for workloads outside of AWS
AWS Identity and Access Management (IAM) now enables workloads that run outside of AWS to access AWS resources using IAM Roles Anywhere . IAM Roles Anywhere allows your workloads such as servers, containers, and applications to use X.509 digital certificates to obtain temporary AWS credentials and use the same IAM roles and policies that you have configured for your AWS workloads to access AWS resources.
AWS announces a streamlined deployment experience for .NET applications in .NET CLI and Visual Studio
We are happy to announce the general availability of the new streamlined deployment experience for .NET applications. With sensible defaults for all deployment settings, you can now get your .NET application up and running in just one click, or with a few easy steps – without needing deep expertise in AWS. You will receive recommendations on the optimal compute for your application, giving you more confidence in your initial deployments. You can find it in the AWS Toolkit for Visual Studio using the new “Publish to AWS” wizard. It is also available via the .NET CLI by installing AWS Deploy Tool for .NET .
Key capabilities:
- Compute recommendations – get the compute recommendations and learn which AWS compute is best suited for your application.
- Dockerfile generation – the Dockerfile will be auto-generated if required by your chosen AWS compute.
- Auto packaging and deployment – your application will be built and packaged as required by the chosen AWS compute. The tooling will provision the necessary infrastructure and deploy your application using AWS CDK.
- Repeatable and shareable deployments – you can generate well organized and documented AWS CDK deployment projects and start modifying them to fit your specific use-case. Then version control them and share with your team for repeatable deployments.
- CI/CD integration – turn off the interactive features and use different deployment settings to push the same application bundle to different environments.
- Help with learning AWS CDK for .NET! – gradually learn the underlying AWS tools that it is built on, such as the AWS CDK.
Amazon WorkMail now supports invoking Lambda to fetch availability (free/busy)
Amazon WorkMail now supports invoking AWS Lambda for user availability, through Custom Availability Provider Lambda (CAP Lambda). CAP Lambda are a new way for WorkMail to get availability information from external availability sources. A customer can use these CAP Lambda to give WorkMail access to availability information for users on other calendaring providers they own, even if their endpoints are private, or if they do not have an Exchange Web Services (EWS) endpoint.
AWS Snowcone SSD is now available in the AWS Europe (Paris) Region
The AWS Snowcone solid state drive (SSD) device is now available in the AWS Europe (Paris) Region, adding to our growing list of Regions already offering Snowcone SSD, including AWS US East (Ohio), US East (N. Virginia), US West (Oregon), US West (N. California) Asia Pacific (Singapore), Asia Pacific (Tokyo), Asia Pacific (Sydney), Europe (Frankfurt), Europe (Ireland), Europe (London), Asia Pacific (Mumbai), Canada (Central), and South America (São Paulo).
Amazon GuardDuty introduces new machine learning capabilities to more accurately detect potentially malicious access to data stored in S3 buckets
Amazon GuardDuty has incorporated new machine learning techniques that are highly effective at detecting anomalous access to data stored in Amazon Simple Storage Service (Amazon S3) buckets. This new capability continuously models S3 data plane API invocations (e.g. GET, PUT, and DELETE) within an account, incorporating probabilistic predictions to more accurately alert on highly suspicious user access to data stored in S3 buckets, such as requests coming from an unusual geo-location, or unusually high volumes of API calls consistent with attempts to exfiltrate data. The new machine learning approach can more accurately identify malicious activity associated with known attack tactics, including data discovery, tampering, and exfiltration. The new threat detections are available for all existing Amazon GuardDuty customers that have GuardDuty S3 Protection enabled, with no action required and at no additional costs. If you are not using GuardDuty yet, S3 protection will be on by default when you enable the service. If you are using GuardDuty, and are yet to enable S3 Protection, you can enable this capability organization-wide with one-click in the GuardDuty console or through the API.
FingerTip touchscreen controller
The FingerTip FTG2-SLP touchscreen controller from ST enables advanced features to support AMOLEDs. The device supports both synchronous and asynchronous display operations. This gives the OEMs the ability to maintain seamless user interactions as the refresh rate changes dynamically. The controller is also suitable for smartphones with flexible AMOLED displays that integrate the touch-sensitive panel directly …
The post FingerTip touchscreen controller appeared first on Electronics Weekly .
Virgin Orbit mission success cues up first UK launch
The success of a recent Virgin Orbit mission brings the first UK launch of satellites a step closer. On Saturday 2 July, Virgin Orbit successfully completed its fourth satellite delivery mission, which was a night launch from Mojave in California via Cosmic Girl, a modfied Boeing 747. It was seen as a preliminary stage before …
The post Virgin Orbit mission success cues up first UK launch appeared first on Electronics Weekly .
EW BrightSparks 2022 profile: Nishika Chettry
Now in its fifth year of awards, EW BrightSparks sees Electronics Weekly partner with RS Grass Roots to highlight the brightest and most talented young engineers in the UK today. Here, in our series on the latest EW BrightSparks of 2022, we highlight Nishika Chettry, an MEng Student at Aston University, who is also working as …
The post EW BrightSparks 2022 profile: Nishika Chettry appeared first on Electronics Weekly .