AWS Releases
Amazon Web Services releases and Terraform AWS provider. New features, breaking changes, security advisories and deprecations - each summarised in plain English and updated continuously.
Tracking 678 AWS releases · Updated
- AWS What's New securityawsengineeraws-iam ·
IAM Policy Simulator integrated into IAM console with new features
AWS IAM Policy Simulator has been integrated into the IAM console, replacing the standalone tool and adding capabilities to test Service Control Policies (SCPs) and condition keys. The update allows for more flexible scenario modeling, including policy exclusion and detailed cross-account decision reporting. These enhancements aim to improve policy validation and automation for security and platform teams, and are available in all regions where the simulator is offered.
feature - AWS What's New securityawsengineerretail ·
AWS WAF adds pre-parse transformations and new text transformations
AWS WAF now supports pre-parse text transformations for query arguments and ten new text transformations, enhancing request normalization. These features help standardize how AWS WAF inspects requests, preventing evasion tactics like HTTP parameter pollution and parser differentials. The update is available in all AWS Regions and impacts engineers and architects responsible for web application security.
feature - AWS What's New securityawsengineeraws-iam ·
AWS IAM Identity Center adds multi-Region replication for its own directory
AWS IAM Identity Center now allows replication of its own identity directory to secondary regions, enhancing resilience and enabling geographically distributed application deployments. This feature, previously limited to external identity providers, extends to users managing their workforce directly within Identity Center. It is available in 17 commercial AWS Regions for organization instances, requiring a multi-Region KMS key.
feature - AWS What's New securityawsaws-iam ·
Amazon Neptune adds IAM tag-based access control for data plane operations
Amazon Neptune now supports tag-based access control (TBAC) for IAM, allowing control over data-plane operations using resource and principal tags. This enhances security for large-scale deployments by enabling dynamic, attribute-based access management, reducing the need to manage individual cluster ARNs in policies. The feature is available in all AWS Regions for Neptune engine version 1.2.0.0 or later with IAM authentication enabled.
feature - AWS What's New securityawshealthcarefinanceaws-lambda ·
AWS Lambda durable functions support customer-managed KMS encryption
AWS Lambda durable functions now supports encryption of execution data using customer-managed AWS KMS keys, offering enhanced control for regulated industries. This feature allows users in sectors like finance and healthcare to meet stricter data governance policies by managing their own encryption keys. It is available in all regions where Lambda durable functions are supported, with standard KMS charges applying.
feature - AWS What's New securityawsgasecurity-advisoryengineeraws-rds ·
Amazon RDS for SQL Server adds latest Microsoft CU and GDR updates
Amazon RDS for SQL Server now supports the latest Cumulative Updates (CU) and General Distribution Release (GDR) updates for SQL Server 2016, 2017, 2019, and 2022. These updates include security patches for vulnerabilities like CVE-2026-40370, improving instance security and stability. All Amazon RDS for SQL Server users are recommended to upgrade their instances to benefit from these fixes.
patch security - AWS What's New securityinfraawsengineeraws-iam ·
AWS CloudTrail enhances network activity event filtering by IAM identity
AWS CloudTrail now allows selective logging of network activity events for VPC endpoints based on the IAM user identity making the API call. This feature helps reduce logging costs and noise by filtering out routine traffic from trusted identities, enabling focus on critical security events like access denials. It is available in all regions supporting CloudTrail network activity events and can be configured via the console, CLI, and SDKs.
feature patch - AWS What's New securityawsengineer ·
CloudWatch Synthetics supports customer-managed KMS keys for encryption
Amazon CloudWatch Synthetics now allows using customer-managed AWS KMS keys for encrypting canary environment variables, providing greater control over sensitive data. This feature enhances security for regulated industries by enabling specific key management policies and auditability. It is available in all commercial AWS Regions, with options for per-region keys in multi-location canaries.
feature - AWS What's New securityawsengineerretailaws-s3aws-dynamodbaws-eksaws-ecsaws-iam ·
Amazon GameLift Streams adds IAM role credentials for secure resource access
Amazon GameLift Streams now supports assigning an IAM role to a stream session, allowing secure access to AWS resources like S3 and DynamoDB without embedding long-lived access keys. This feature simplifies security and operations by automatically providing short-lived, auto-refreshing AWS credentials, similar to mechanisms used by ECS task roles and EKS Pod Identity. It reduces security risks and operational challenges for game developers needing their streamed applications to interact with AWS services. IAM role support is available in all AWS Regions where GameLift Streams is offered.
feature - AWS What's New securityinfraaws ·
AWS Backup adds logically air-gapped vault support to 7 new regions
AWS Backup has expanded logically air-gapped vault support to seven new AWS Regions, offering immutable and isolated backup storage. This enhancement allows customers to store backups that are locked by default and encrypted, improving data resilience against ransomware and accidental deletion. The feature is now available to all users through the AWS Backup console, CLI, and SDKs, with detailed documentation available.
feature - AWS What's New securityawsengineer ·
Amazon Cognito adds support for importing users with password hashes
Amazon Cognito now allows importing users with pre-existing password hashes via CSV, eliminating the need for immediate password resets. This feature enables users to sign in with their existing credentials upon import, improving the user experience during migration. It supports common hashing algorithms like bcrypt, scrypt, Argon2id, and PBKDF2, and is available in all AWS Regions where Cognito is offered.
feature - AWS What's New securitycomplianceawsengineergovernmentaws-iam ·
AWS IAM Identity Center Achieves FedRAMP Class C Certification
AWS IAM Identity Center is now certified for FedRAMP Class C compliance in four US regions, enabling secure workforce access to government cloud services. This certification is crucial for U.S. government agencies and contractors needing to meet stringent security standards for cloud deployments. IAM Identity Center is the recommended service for managing this type of access.
announcement - AWS What's New aisecurityawsengineeraws-sagemakeraws-bedrock ·
Amazon GuardDuty adds AI Protection for AI workloads
Amazon GuardDuty now offers AI Protection, expanding threat detection to AI workloads like Amazon Bedrock and Amazon SageMaker. This new capability addresses the security gap for AI services by continuously monitoring for threats such as anomalous model invocations, cost harvesting, and prompt injection without requiring manual configuration. It analyzes CloudTrail events and integrates with Bedrock Guardrails, with findings flowing into Security Hub for a unified view and prioritized response. AI Protection is available with a 30-day free trial for existing GuardDuty customers.
feature - AWS What's New aisecurityawsengineeraws-ec2aws-sagemakeraws-bedrock ·
AWS Security Hub adds AI inventory for organization-wide asset visibility
AWS Security Hub now offers an AI inventory to provide central security teams with an organization-wide view of AI assets and their security posture. This feature addresses the growing challenge of visibility into rapidly deployed AI workloads across AWS environments. It automatically discovers and catalogs AI assets using various AWS services and includes security findings for prioritization, available at no additional cost.
feature - AWS News Blog blogsecurityawsengineer ·
AWS Security Agent Enhances DevSecOps with Threat Modeling and IDE Integrations
AWS Security Agent has introduced several new features, including threat modeling, expanded code review capabilities with pull request scanning and remediation, and new IDE integrations like Kiro power and a Claude Code plugin. These updates aim to proactively secure applications throughout the development lifecycle by identifying and mitigating risks earlier. The new features are available in AWS commercial regions and are geared towards engineers and architects involved in application security and development.
feature announcement - AWS What's New securitygovernanceawsengineer ·
AWS Organizations adds default security controls for new orgs
AWS Organizations now automatically applies security controls by default when creating new organizations via the console. This feature safeguards multi-account environments by preventing unintended member account departures, providing immediate protection from day one for CloudOps administrators and security teams. These lightweight controls help establish strong governance patterns for new or migrating enterprises, with the ability to modify or disable them at any time.
feature - AWS What's New aisecurityawsengineeraws-iam ·
AWS MCP Server adds OAuth support for AI agent connections
The AWS MCP Server now supports OAuth for direct AI agent connections, eliminating the need for extra authentication software and leveraging existing AWS identity and governance controls. This feature allows for both interactive and programmatic authorization, with administrators benefiting from enhanced IAM policy governance and new OAuth-specific controls. Developers can now integrate AI agents more seamlessly with the MCP Server.
feature - AWS What's New aisecurityawsengineerhealthcareaws-s3aws-ec2aws-lambdaaws-rdsaws-dynamodbaws-eksaws-ecsaws-kinesisaws-sagemakeraws-bedrockaws-redshiftaws-iamaws-sqsaws-sns ·
AWS Config adds 191 managed rules for AI and core services
AWS Config now includes 191 new managed rules covering services like Amazon Bedrock, SageMaker, ECS, EKS, RDS, Redshift, S3, and CloudTrail. This expansion enhances governance for AI workloads and cloud infrastructure by evaluating configurations for security, data protection, and operational best practices. These rules are available individually or as conformance packs in regions where the corresponding AWS services are supported.
feature - AWS What's New securityawsazureengineer ·
AWS Security Hub adds Network Scanning for public resource reachability
AWS Security Hub has introduced Network Scanning to detect resources, including VMs and load balancers, that are reachable from the public internet. This new capability actively probes resources to confirm actual reachability, unlike previous configuration-based checks. The feature generates findings for each reachable port and service, correlating them with existing data to assess broader risk across AWS and Azure environments.
feature - AWS What's New aisecurityawsaws-s3 ·
Amazon S3 Vectors expands to AWS GovCloud (US) Regions
Amazon S3 Vectors, a vector storage service for AI applications, is now available in AWS GovCloud (US-East) and AWS GovCloud (US-West). This expansion allows government agencies and their partners to leverage S3's elasticity and durability for AI workloads like RAG and semantic search. The service offers dedicated APIs for vector storage and querying without infrastructure provisioning.
feature announcement
About AWS release tracking on ReleaseBytes
AWS ships hundreds of service updates a month across EC2, Lambda, RDS, S3, EKS and the rest of the catalogue — far more than anyone can follow by reading the official What's New feed. ReleaseBytes ingests announcements from AWS's official release channels and the Terraform AWS provider changelog, summarises each one in plain English, and tags anything that is a breaking change, security advisory or deprecation so you can see at a glance whether it affects your workloads.
Frequently asked questions
How often are AWS release notes updated on ReleaseBytes? ›
Continuously. ReleaseBytes monitors the official AWS release channels around the clock and publishes a plain-English summary of each announcement shortly after it lands.
What kinds of AWS changes does ReleaseBytes track? ›
New features, enhancements, bug fixes, security advisories, breaking changes, deprecations and end-of-life announcements. Every item is tagged by type so you can filter to just the changes that need action.
How can I get alerts for new AWS releases? ›
Set up a free email or Slack alert filtered to AWS, subscribe to the weekly digest, or follow the RSS feed. Teams can also install the ReleaseBytes GitHub App or connect via MCP.
Where does the AWS release data come from? ›
From the official sources: Amazon Web Services releases and Terraform AWS provider. Every item links back to the original vendor announcement.