AWS Releases

Amazon Web Services releases and Terraform AWS provider. New features, breaking changes, security advisories and deprecations - each summarised in plain English and updated continuously.

Tracking 680 AWS releases · Updated

  • AWS What's New securityawsengineeraws-iam ·

    AWS Backup adds OTP verification for multi-party approval

    AWS Backup now requires one-time password (OTP) verification for multi-party approval actions on logically air-gapped vaults. This enhances security by ensuring only verified approvers authorize protected vault operations. The feature is automatically applied to all existing and new approval sessions for air-gapped vaults at no extra cost and requires no setup.

    feature security
  • AWS What's New securitygovernanceawsengineeraws-s3 ·

    GuardDuty Malware Protection adds S3 continuous backup scanning

    Amazon GuardDuty Malware Protection now supports S3 continuous backups, enabling malware scanning for recovery points. This feature allows users to identify clean points in time, verify recovery safety, and initiate restores with greater confidence. Support is available in all regions where GuardDuty Malware Protection is offered, accessible via the AWS Backup console, API, or CLI.

    feature
  • AWS What's New securityawsengineer ·

    AWS Security Agent generates scripts to verify pentest findings

    AWS Security Agent can now automatically generate scripts to reproduce penetration test findings. This feature allows security teams to independently validate discovered vulnerabilities, reducing manual effort and accelerating remediation. The scripts include setup instructions and are available in all supported AWS Regions.

    feature
  • AWS What's New securityawssnowflakeengineer ·

    AWS Secrets Manager supports Datadog keys and Snowflake PATs

    AWS Secrets Manager now supports managed external secrets for Datadog keys and Snowflake Programmatic Access Tokens (PATs). This feature automates the rotation of third-party credentials, reducing manual effort and potential security risks for engineers managing secrets across different services. These new integrations are available in all supported AWS Regions where managed external secrets are offered.

    feature
  • AWS What's New securityawssecurity-advisoryengineeraws-rds ·

    Amazon RDS Custom for SQL Server adds latest GDR updates

    Amazon RDS Custom for SQL Server now supports recent General Distribution Release (GDR) updates for Microsoft SQL Server, including critical security patches. This enhancement is available for SQL Server 2019 and 2022 instances, offering improved security and stability. Users can apply these updates via the AWS Management Console, SDK, or CLI.

    patch security
  • AWS What's New securityawsgaengineer ·

    Amazon QuickSight now supports customer-managed keys

    Amazon QuickSight now allows customers to encrypt data using their own AWS Key Management Service (KMS) customer-managed keys (CMK). This feature enhances security and compliance for organizations by providing greater control over encryption and auditability via CloudTrail. It is now generally available in all AWS Regions where QuickSight is offered, requiring CMKs to be created in the same account and region, and supporting only symmetric KMS keys.

    feature
  • AWS What's New securityawsengineeraws-iam ·

    AWS Security Hub detects unused IAM permissions

    AWS Security Hub now identifies unused IAM permissions, roles, and credentials across your organization, centralizing identity risk management within the existing console. This feature helps security teams reduce identity risk at scale by correlating unused permissions with actual resource exposure. It is automatically enabled via a service-linked IAM Access Analyzer in each member account and included with Security Hub Essentials at no additional cost.

    feature
  • AWS What's New securityawsgaarchitect ·

    AWS Security Hub Extended adds 21 partner solutions in 9 categories

    AWS Security Hub Extended now offers 21 curated partner solutions across nine security categories, including new additions for endpoint, identity, and data security. This expansion provides customers greater flexibility in selecting solutions tailored to their enterprise needs, with unified billing and support benefits. The new solutions are available today in all commercial AWS Regions, enabling better risk identification and response across security domains.

    feature announcement
  • AWS What's New securityinfraawsgaengineeraws-ec2aws-lambda ·

    Amazon Inspector now available in AWS Asia Pacific (Taipei) Region

    AWS announces the expansion of its automated vulnerability management service, Amazon Inspector, to the Asia Pacific (Taipei) Region. This move extends security coverage to customers in this new region, enabling continuous vulnerability assessments and automated scanning of EC2 instances, container images, and Lambda functions. New users are eligible for a 15-day free trial to evaluate the service's capabilities and associated costs.

    announcement feature
  • AWS What's New securityinfraawsengineeraws-iam ·

    AWS Secrets Manager Agent adds pre-fetching and IAM role assumption

    The AWS Secrets Manager Agent now supports pre-fetching secrets at startup and assuming IAM roles for retrieval. These features reduce application latency, optimize costs by using the BatchGetSecretValue API, and enhance security through role-based cross-account access. The updates are available in all AWS Regions where Secrets Manager is offered and benefit developers managing secrets in multi-account architectures.

    feature

About AWS release tracking on ReleaseBytes

AWS ships hundreds of service updates a month across EC2, Lambda, RDS, S3, EKS and the rest of the catalogue — far more than anyone can follow by reading the official What's New feed. ReleaseBytes ingests announcements from AWS's official release channels and the Terraform AWS provider changelog, summarises each one in plain English, and tags anything that is a breaking change, security advisory or deprecation so you can see at a glance whether it affects your workloads.

Frequently asked questions

How often are AWS release notes updated on ReleaseBytes?

Continuously. ReleaseBytes monitors the official AWS release channels around the clock and publishes a plain-English summary of each announcement shortly after it lands.

What kinds of AWS changes does ReleaseBytes track?

New features, enhancements, bug fixes, security advisories, breaking changes, deprecations and end-of-life announcements. Every item is tagged by type so you can filter to just the changes that need action.

How can I get alerts for new AWS releases?

Set up a free email or Slack alert filtered to AWS, subscribe to the weekly digest, or follow the RSS feed. Teams can also install the ReleaseBytes GitHub App or connect via MCP.

Where does the AWS release data come from?

From the official sources: Amazon Web Services releases and Terraform AWS provider. Every item links back to the original vendor announcement.