CLOUDSTACKER LAB

Cloud & DevOps Radar

Important cloud, infrastructure, DevOps, container and security updates — collected from trusted technical sources.

Automatically refreshed from RSS feeds
AWS What’s New

AWS Health introduces the version catalog for software lifecycle management

Today, AWS Health introduces the version catalog which provides a centralized source of lifecycle information for software versions across AWS services. The version catalog helps customers move from reactive to proactive management of version upgrades and end-of-support risk. It is available in the AWS Health Dashboard, and customers on Business Support Plus, Enterprise Support, or Unified Operations can use the AWS Health API to integrate lifecycle data into their operational workflows. Customers running applications on AWS need to stay current with software versions to maintain a strong security and operational posture. AWS Health already …

2 days ago
Why it mattersWorth checking promptly because it may affect security, exposure, compatibility, or production operations.

Read original

SECURITY★★★★★

Amazon EVS now in scope for FedRAMP Class C

The Amazon Elastic VMware Service (EVS) service is now in scope for FedRAMP Class C (formerly Moderate baseline) in all United States Regions. The Federal Risk and Authorization Management Program (FedRAMP) is a US government-wide program that delivers a standard approach to the security assessment, authorization, and continuous monitoring for cloud products and services. Amazon EVS lets you run the latest VMware Cloud Foundation (VCF) software directly within your Amazon Virtual Private Cloud (VPC) on EC2 bare-metal instances. You can set up a complete VCF environment in just a few hours, enabling rapid workload migration to AWS to help you…

AWS What’s New · 21 Sep 2026Read →
SECURITY★★★★★

AWS Continuum now supports credential testing and accessible domain suggestions

AWS Continuum for penetration testing is a frontier agent that proactively secures applications throughout the development lifecycle by offering on-demand, customized penetration testing with real exploitability testing. Developers and security teams can now test login credentials and receive suggested domains before a penetration test runs. This makes it easier to configure an accurate network scope from the start, reducing misconfiguration and wasted test cycles. Previously, identifying all the URLs your application reaches required manual effort, and authentication failures were only discovered after a full test cycle completed, costing t…

AWS What’s New · 18 Sep 2026Read →
SECURITY★★★★★

Kimi K3 by Moonshot AI is now generally available on Amazon Bedrock

Amazon Bedrock continues to expand its open weight model portfolio with the same security and governance that customers rely on. Today, Kimi K3 from Moonshot AI is generally available on Amazon Bedrock, giving you a powerful new option for coding and knowledge work. According to Moonshot AI, Kimi K3 is its most capable model and the first open model to reach 2.8 trillion parameters. It combines native vision capabilities with a 1-million-token context window, making it well suited to long-running coding sessions across large repositories, multi-document analysis including scanned pages and screenshots, and extended agent workflows. Moonshot …

AWS What’s New · 18 Sep 2026Read →
SECURITY★★★★★

Kubernetes v1.37: Hardening Container Storage with Bind Mount Options and EmptyDir Permissions

Kubernetes v1.37 brings important storage security features: emptyDir permission modes and bind mount options. They help application programmers and security professionals implement rigorous security policies, for example, prohibiting deletion of files across containers or execution of arbitrary binaries from writable volumes, directly in Kubernetes without any complicated circumvention. Linux storage and permission fundamentalsBefore diving into the new Kubernetes features, let us briefly review the low-level Linux security mechanisms that make them possible. Bind mount flagsWhen Linux mounts or remounts a directory, Virtual File System (VF…

Kubernetes Blog · 16 Sep 2026Read →
SECURITY★★★★★

AWS STS simplifies session token size limits and adds session token size monitoring

AWS Security Token Service (STS) now enforces a single 4,096-byte size limit on session tokens. Previously, STS enforced separate limits on session token size and passed-in parameters (i.e., inline policies, managed policies, and session tags). STS has removed that separation, providing more flexibility for larger combinations of session policies and session tags. Additionally, STS now returns response elements indicating session token size and percentage utilization relative to the token size limit. STS logs these values in AWS CloudTrail and publishes corresponding metrics in Amazon CloudWatch. A new optional API parameter also lets you ge…

AWS What’s New · 15 Sep 2026Read →
SECURITY★★★★★

Analyze your CloudTrail events using natural language in Amazon Q Console

AWS CloudTrail, a service that records API activity across your AWS account for security auditing, compliance, and operational troubleshooting, now integrates with Amazon Q Console to help you investigate your AWS account activity using natural language. You can ask Amazon Q Console questions about your CloudTrail configuration, query your logged events for security investigations, and troubleshoot operational issues without writing queries or manually parsing log files. With this integration, you can ask Amazon Q Console to check whether your CloudTrail trails are properly configured, identify gaps in your logging coverage, and confirm whic…

AWS What’s New · 15 Sep 2026Read →
SECURITY★★★★★

OpenAI GPT-6 Astra is now generally available on Amazon Bedrock

Today, AWS announces the general availability of GPT-6 Astra from OpenAI on Amazon Bedrock. The latest and most capable model from OpenAI to date, GPT-6 Astra brings deeper reasoning and judgment, professional-quality writing and design, and advanced computer and browser use to demanding business workflows. It supports a context window of up to 1 million input tokens and can produce output aligned with organizational voice, templates, and standards. The Amazon Bedrock inference engine delivers the performance, security, and scale required for production workloads. You can call GPT-6 Astra directly through supported Amazon Bedrock APIs or con…

AWS What’s New · 08 Sep 2026Read →
SECURITY★★★★★

Amazon RDS for MariaDB now supports community MariaDB minor versions 10.6.28, 10.11.19, 11.4.13, 11.8.9, and 12.3.3

Starting today, Amazon Relational Database Service (Amazon RDS) for MariaDB now supports MariaDB minor versions 10.6.28, 10.11.19, 11.4.13, 11.8.9, and 12.3.3, the latest minors released by community MariaDB. In addition to operational improvements, these minor versions introduce support for post-quantum TLS (PQ-TLS) key exchange, providing you with post-quantum cryptography options for encrypting your data in-transit. We recommend upgrading to the newer minor versions to accept fixes for Common Vulnerabilities and Exposures (CVEs) in prior versions of MariaDB and to benefit from bug fixes, performance improvements, and new functionality add…

AWS What’s New · 08 Sep 2026Read →
SECURITY★★★★★

Amazon EMR extends support at no additional cost for customers migrating off older releases

Amazon EMR now gives you more time, at no additional cost, to migrate off older releases before they reach end of support. If you are actively migrating, your workloads on eligible releases keep receiving support while you move to a current release, with no opt-in and at no charge. To give you more time to plan and migrate, Amazon EMR provides critical security fixes for releases 5.36 and 6.6 through 6.15 on a best-effort basis through June 30, 2027, and extended Standard Support for 7.0 through 7.10 releases through August 31, 2027. To receive an extension, contact AWS Support with your migration plan and any help you need with the upgrade.…

AWS What’s New · 08 Sep 2026Read →
SECURITY★★★★★

AWS announces Nx Plugin for AWS for scaffolding full-stack applications

Version 1.0 of the Nx Plugin for AWS, an open source toolkit for scaffolding full-stack applications on AWS, is now available. AI assistants can stand up an application on AWS in minutes, but rarely get security, observability, and type-safety right in one pass. The plugin extends Nx, an open source, language-agnostic build system for monorepos, with generators that each build one part of an application on request, alongside the infrastructure to run it. Generators cover AI agents and Model Context Protocol servers on Amazon Bedrock AgentCore, plus APIs, websites, and databases, built on proven open source frameworks in TypeScript and Python…

AWS What’s New · 08 Sep 2026Read →
SECURITY★★★★★

Amazon RDS now supports the latest CU and GDR updates for Microsoft SQL Server

Amazon Relational Database Service (Amazon RDS) for SQL Server now supports the latest Cumulative Updates (CU) and General Distribution Release (GDR) updates for Microsoft SQL Server. This release includes support for Microsoft SQL Server 2016 SP3+GDR KB5102340 (RDS version 13.00.6500.1.v1), SQL Server 2017 CU31+GDR KB5102337 (RDS version 14.00.3540.1.v1), SQL Server 2019 CU32+GDR KB5102335 (RDS version 15.09.4480.2.v1), SQL Server 2022 CU26 KB5093420 (RDS version 16.00.4265.3.v1) and SQL Server 2025 CU7 KB5096981 (RDS version 17.00.4065.4.v1). The GDR updates address vulnerabilities described in CVE-2026-47295, CVE-2026-47296, CVE-2026-5411…

AWS What’s New · 08 Sep 2026Read →
SECURITY★★★★★

Amazon Aurora MySQL 8.4.8 (compatible with MySQL 8.4.8) is now generally available

Starting today, Amazon Aurora MySQL-Compatible Edition 8.4 will support MySQL 8.4.8. In addition to several security enhancements and bug fixes, Aurora MySQL 8.4.8 includes several improvements, such as support for post-quantum TLS (PQ-TLS) key exchange, transaction timeout, multi-source replication, and delayed replication. PQ-TLS provides you with post-quantum cryptography options for encrypting your data in-transit. Transaction timeout helps prevent performance issues caused by long-running transactions blocking innoDB purge. Multi-source replication allows consolidation of data from multiple sources into a single replica to enable critic…

AWS What’s New · 03 Sep 2026Read →