AWS Releases
Amazon Web Services releases and Terraform AWS provider. New features, breaking changes, security advisories and deprecations - each summarised in plain English and updated continuously.
Tracking 678 AWS releases · Updated
- AWS What's New securityawsazureengineer ·
AWS Security Hub integrates with Azure for cross-cloud security management
AWS Security Hub now monitors Microsoft Azure resources, unifying security posture management, risk analytics, and vulnerability assessment across both clouds. This addresses the challenge of managing separate security tools for multi-cloud environments, offering a single pane of glass for detection and response. The integration automatically discovers Azure resources, evaluates them against security standards, and presents findings in a unified view, with a 30-day free trial available. It is available in most AWS Regions and can be integrated independently with AWS Security Hub's CSPM and Amazon Inspector.
feature announcement - AWS What's New securitygovernanceawsengineer ·
AWS VPC Encryption Controls support declarative policies
AWS has introduced declarative policies for VPC Encryption Controls, allowing users to centrally define and enforce encryption in transit across all VPCs in their environment. This simplifies management for security teams by enabling a single policy for all existing and future VPCs, providing central visibility and aiding compliance with standards like HIPAA and PCI. This feature is available in all regions supporting VPC Encryption Controls at no additional charge for AWS Organizations users.
feature - AWS What's New securityawsengineeraws-iam ·
AWS Security Hub adds impact analysis for exposure findings
AWS Security Hub now includes impact analysis for exposure findings, enabling security teams to understand the potential reach of an exploited vulnerability. This feature maps downstream resources and identifies privilege escalation paths using effective IAM permissions. The analysis is integrated into severity scoring and displayed in a new potential attack path graph and Impact Assessment tab, prioritizing exposures with greater downstream risk.
feature - AWS What's New securityawssnowflakeengineer ·
AWS Secrets Manager adds managed external secrets for Paddle and GitLab
AWS Secrets Manager now supports managed external secrets for Paddle API Keys and GitLab Access Tokens, enabling automatic rotation of third-party credentials directly within Secrets Manager. This enhancement simplifies credential management and enhances security by allowing seamless key rotation for supported services. These new integrations join existing ones, offering centralized management for a growing list of third-party software vended secrets across all supported AWS Regions.
feature - AWS What's New securityawsengineer ·
AWS Certificate Manager supports ACME for public certificates
AWS Certificate Manager (ACM) now offers a managed ACME server endpoint for provisioning public TLS certificates with a 45-day validity. This feature automates certificate issuance and renewal using standard ACMEv2 clients, addressing the increasing difficulty of manual certificate management due to shorter mandated lifetimes. It allows PKI administrators to enforce governance and delegate certificate requests, with all activity logged in ACM and CloudTrail.
feature - AWS What's New securityawsgaengineer ·
Amazon Connect adds rule-based redaction for agent screen recordings
Amazon Connect now supports rule-based redaction for agent screen recordings, allowing customers to protect sensitive information by specifying applications or URLs to be redacted. This feature enhances compliance and privacy by automatically obscuring identified content in post-contact recordings. It is available in all AWS Regions where Connect is offered and supports Windows operating systems.
feature - AWS What's New securityawspreviewengineeraws-ec2 ·
EC2 Dedicated Hosts Add AMD SEV-SNP Support
Amazon EC2 now supports AMD SEV-SNP on Dedicated Hosts, allowing confidential computing workloads on dedicated physical servers. This provides confidential computing benefits alongside Dedicated Host features like placement control and host affinity. The feature is available in all AWS commercial regions with AMD instances.
feature - AWS What's New securityawsengineeraws-iam ·
AWS Artifact Assurance Assistant aids compliance inquiries
AWS Artifact now includes Assurance Assistant, an AI-powered tool that provides citation-backed answers to security and compliance questions about AWS services. This feature accelerates vendor assessments for risk managers, compliance officers, and auditors by grounding responses in verified AWS documentation. It offers single-question and bulk processing modes and is available at no additional charge in all commercial AWS Regions.
feature announcement - AWS What's New securityawsgaarchitectaws-ec2aws-eksaws-ecsaws-sns ·
Amazon GuardDuty adds sensitive file modification threat detections
Amazon GuardDuty Runtime Monitoring now detects when sensitive files are modified on EC2, EKS, and ECS workloads. These new threat detections, including Persistence:Runtime/SensitiveFileModified, help identify post-compromise attacker activities like persistence and privilege escalation. Designed for security teams and architects, this feature monitors specific file operations to catch obfuscated techniques and reduces false positives with correlation-based analysis. The detections are available to all customers with Runtime Monitoring enabled, with a 30-day free trial for new users.
feature - AWS What's New securityawspreviewengineer ·
AWS Security Agent expands to new regions with threat modeling and code review
AWS Security Agent, now part of AWS Continuum, is now available in three new AWS regions: Asia Pacific (Mumbai), Asia Pacific (Singapore), and South America (São Paulo). This expansion offers customers enhanced security capabilities, including preview features for STRIDE-based threat modeling and full-repo/PR-level code reviews across popular platforms. On-demand penetration testing and simulated validation (US East only) are also available, aiming to scale security expertise alongside development velocity.
feature announcement - AWS What's New securitygovernancecomplianceawsgovernment ·
Amazon Managed Service for Prometheus Gains FedRAMP High, DoD IL-4/5 Authorization in AWS GovCloud
Amazon Managed Service for Prometheus has achieved FedRAMP High and DoD CC SRG IL-4/5 authorization in AWS GovCloud (US) Regions. This allows federal and public sector organizations to confidently monitor sensitive workloads, meeting stringent security and compliance standards. The service is a managed, Prometheus-compatible monitoring solution designed for scalable ingestion and storage of operational metrics.
announcement - AWS What's New securityinfraawsengineer ·
Amazon GameLift Servers Adds DDoS Protection SDKs for C# and Unity
Amazon GameLift Servers now provides client SDKs for C# and Unity to protect multiplayer games against DDoS attacks. This feature integrates a relay network and token-based authentication to secure game sessions. It offers proactive UDP traffic protection with minimal latency, available at no extra cost to existing customers. The SDKs complement existing C++ and Unreal Engine support, enhancing developer flexibility.
feature - AWS What's New securityawsengineeraws-rdsaws-iam ·
Amazon RDS improves IAM database authentication with connection rate scaling
Amazon RDS now dynamically scales IAM database authentication connection rates based on instance resources. This enhancement is crucial for enterprise workloads needing to support high-volume connection patterns with IAM authentication. The scaling capability is available across all AWS Regions for supported RDS and Aurora engines. Reusing IAM principals or authentication tokens is recommended for optimal performance.
feature - AWS What's New aisecurityawsengineeraws-sagemakeraws-bedrock ·
AWS Security Hub CSPM adds AI Security Best Practices standard
AWS Security Hub CSPM has launched a new AI Security Best Practices standard, featuring 31 automated controls to assess AI resource security. This standard helps continuously evaluate Amazon Bedrock and SageMaker workloads against security best practices, detecting misconfigurations without manual effort. It covers critical domains like network isolation and encryption, with controls spanning various AI infrastructure components and is available in all Security Hub CSPM regions.
feature - AWS What's New securityawsengineeraws-iam ·
AWS IAM Identity Center allows programmatic account access for customer apps
AWS IAM Identity Center now enables customer-managed applications to programmatically access AWS accounts on behalf of users, discovering accounts and roles, and retrieving temporary credentials. This integration, by configuring an external IdP as a trusted token issuer, eliminates redundant sign-ins for users accessing AWS resources. The feature is available for organization instances and requires explicit enablement by administrators in all commercial and specialized AWS Regions.
feature - AWS What's New aisecurityawsengineeraws-bedrock ·
AWS WAF protects Amazon Bedrock AgentCore Gateway
AWS WAF now offers protection for Amazon Bedrock AgentCore Gateway, shielding agentic AI applications from common web exploits and abuse as they move to production. This feature allows security and platform teams to enforce consistent, customizable web protections like IP-based access controls and rate-based rules at the Gateway layer. A single configuration applied at the Gateway protects all downstream agents and integrations, and is available in all regions where both services are offered.
feature announcement - AWS What's New securityawssecurity-advisoryengineeraws-rds ·
Amazon RDS Custom for SQL Server adds latest CU/GDR updates
Amazon RDS Custom for SQL Server now supports the latest Cumulative Updates and General Distribution Releases, including versions for SQL Server 2019 and 2022. This enhancement allows users to easily apply critical security patches and performance improvements to their database instances. The updates are available for all RDS Custom for SQL Server users and can be applied via the AWS Management Console, SDK, or CLI.
patch security - AWS What's New securityawsengineergovernment ·
AWS Network Firewall adds VisionHeight managed threat intelligence rules
AWS Network Firewall now supports two new managed rule groups from VisionHeight via AWS Marketplace: Zero-Day Threat Protection and Noisy Scanners and Tor Protection. These additions leverage proprietary threat intelligence to proactively block emerging threats and reduce log noise, benefiting security teams and potentially lowering SIEM costs. The rules are available now, with daily refresh cycles for threat intelligence.
feature - AWS What's New aisecurityawsgovernment ·
Kiro Achieves FedRAMP High and DoD IL-4/5 Authorization on AWS GovCloud
Kiro, an agentic AI development platform, has achieved FedRAMP High and Department of Defense (DoD) Cloud Computing Security Requirements Guide (CC SRG) Impact Level (IL) 4 and 5 authorization in AWS GovCloud (US) Regions. This allows federal agencies and public sector organizations to use Kiro for sensitive workloads with confidence in its security and compliance. Kiro aids in building applications by converting prompts into specs, code, and documentation, and integrates with enterprise resources via the Model Context Protocol (MCP).
announcement - AWS What's New securityawssecurity-advisoryengineeraws-rds ·
Amazon RDS for SQL Server adds support for latest Microsoft GDR updates
Amazon RDS for SQL Server now supports the latest General Distribution Release (GDR) updates for multiple SQL Server versions, including specific patch identifiers. These GDR updates address critical vulnerabilities like CVE-2026-32167 and CVE-2026-32176, enhancing security for SQL Server instances. Users running SQL Server 2016 through 2022 on RDS are recommended to upgrade their instances to benefit from these security fixes, which can be performed via the RDS Management Console, AWS SDK, or CLI.
security patch
About AWS release tracking on ReleaseBytes
AWS ships hundreds of service updates a month across EC2, Lambda, RDS, S3, EKS and the rest of the catalogue — far more than anyone can follow by reading the official What's New feed. ReleaseBytes ingests announcements from AWS's official release channels and the Terraform AWS provider changelog, summarises each one in plain English, and tags anything that is a breaking change, security advisory or deprecation so you can see at a glance whether it affects your workloads.
Frequently asked questions
How often are AWS release notes updated on ReleaseBytes? ›
Continuously. ReleaseBytes monitors the official AWS release channels around the clock and publishes a plain-English summary of each announcement shortly after it lands.
What kinds of AWS changes does ReleaseBytes track? ›
New features, enhancements, bug fixes, security advisories, breaking changes, deprecations and end-of-life announcements. Every item is tagged by type so you can filter to just the changes that need action.
How can I get alerts for new AWS releases? ›
Set up a free email or Slack alert filtered to AWS, subscribe to the weekly digest, or follow the RSS feed. Teams can also install the ReleaseBytes GitHub App or connect via MCP.
Where does the AWS release data come from? ›
From the official sources: Amazon Web Services releases and Terraform AWS provider. Every item links back to the original vendor announcement.