Amazon iconAmazonSep 23, 2026 ~6 min source read

ICYMI: August 2026 @AWS Security — Monthly digest of new features, guidance, and hands-on content

August’s AWS Security monthly digest collects 20 blog posts across seven categories. This brief summarizes the most actionable launches and guidance for identity, data protection, AI agent security, threat detection, governance, and networking.

ICYMI: August 2026 @AWS Security

Share this story

Send the public story page.

Useful takeaways from this story.

Identity updates led August with five posts that include self-service rate limits for Amazon Cognito, a redesigned AWS sign-in experience, and console Private Access for VPCs without internet connectivity.

AI security guidance focuses on agent integrations: custom authentication for AgentCore Gateway, propagating user authorization context through Bedrock AgentCore, and extending Bedrock Guardrails to tool interactions.

# What this digest covers

AWS Security published 20 posts in August 2026 across seven categories. The month concentrated on identity and access (five posts), data protection (four posts), and AI security (four posts), plus additional material on threat detection, governance, and networking. The posts include new features, migration timelines, implementation patterns, and hands-on examples.

# Identity and access highlights

  • AWS Managed Microsoft AD: A retrospective notes 10 years of the managed AD offering and mentions Standard, Enterprise, and Hybrid editions, multi-Region replication, and integrations with 20+ AWS services.
  • Sign-in experience: AWS is rolling out a redesigned sign-in page with a unified email entry point, social identity provider options, and an updated session selection flow for managing multiple active sessions.
  • Access feature now supports VPCs without internet connectivity by routing console traffic (authentication, static assets, service API calls) through PrivateLink endpoints.
  • IAM Identity Center governance: A post shows how to deploy event-driven discovery and reporting for IAM Identity Center applications and assignments, enabling near real-time governance checks and naming convention validation.

# Data protection and certificates

  • KMS data key caching: Authors present approaches for multi-tenant envelope encryption at scale, including a hierarchical keyring pattern and a Caffeine-based cache approach to reduce KMS calls and cost while avoiding cache-stampede issues.
  • AWS Certificate Manager (ACM): ACME protocol support is now available to automate public certificate issuance and renewal with standard clients (Certbot, cert-manager) and enterprise controls for domain scoping and visibility.
  • S3 over-permissioned buckets: Guidance shows how to detect and remediate over-permissioned S3 buckets across multi-account environments using Lambda, AWS Config, and Security Hub, with automation for continuous monitoring.
  • ACM email validation deprecation: AWS will discontinue email-validated public certificates on September 30, 2027. The post outlines the timeline and migration advice to DNS validation.

# AI security and agent integrations

  • AgentCore Gateway: A request Lambda interceptor pattern shows how to integrate legacy authentication (for example Basic Auth) with AgentCore Gateway while keeping credentials in Secrets Manager instead of agent code.
  • Propagating authorization: Guidance explains how to pass user identity through Amazon Bedrock AgentCore to downstream services (DynamoDB, knowledge bases, Salesforce) so agents enforce least-privilege without embedding authorization logic.
  • Guardrails to manage tool interactions within agent workflows.

# Quick operational takeaways

  • If you use Cognito and previously relied on support tickets for rate limits, you can now scale limits yourself in minutes.
  • Migrate ACM email-validated certificates to DNS validation well before Sept 30, 2027 to avoid service disruption.
  • For multi-tenant systems using envelope encryption, consider the hierarchical keyring or caching patterns to cut KMS costs while preventing cache stampedes.

# Where to look next

Read the individual posts linked in the August digest for code samples, deployment patterns, and step-by-step migration guidance on the items summarized above.

More context around this story.

ICYMI: What landed for AI builders in August 2026
Amazon iconAmazonSep 9, 2026

ICYMI: What landed for AI builders in August 2026

A recap of August 2026 launches for AI builders across Amazon Bedrock, Amazon Bedrock AgentCore, and Strands: million-token context for OpenAI models, cross-Region inference, agents that run for up to 14 days on dedicated compute, expanded AWS GovCloud availability, and Strands Robots for physical deployment.

Loading more related stories...

Keep reading in the app

Open the app view to save this story, compare related coverage, and continue from the same source.

Open in app