aws AWS Security Blog ·

AWS Security's August 2026 Digest Highlights New Features and Compliance Updates

blogsecurityawsdeprecationengineer
feature announcement deprecation

AWS Security's August 2026 digest recaps the latest security features, compliance updates, and hands-on resources. It highlights advancements in identity and access management, data protection, and AI security, impacting engineers and architects. Key updates include self-service rate limits for Amazon Cognito, ACME protocol support in AWS Certificate Manager, and extended Guardrails for Amazon Bedrock.

  • →Amazon Cognito adds self-service authentication rate limit management
  • →Extend data perimeter to Console with Private Access for isolated VPCs
  • →Automate public certificates with ACME protocol support in AWS Certificate Manager
  • →AWS Certificate Manager to discontinue email-validated public certificates
  • →Extend Amazon Bedrock Guardrails to cover tool interactions
Deprecations (1) ›
  • AWS Certificate Manager to discontinue email-validated public certificates

    ACM will stop supporting email-validated public certificates by September 30, 2027, to align with CA/B Forum standards. Users should migrate to DNS validation methods.

Features (5) ›
  • Amazon Cognito adds self-service authentication rate limit management

    Amazon Cognito now offers provisioned limits, allowing on-demand authentication rate limit adjustments in minutes. This replaces a previous support ticket process that took 10–14 days.

  • Extend data perimeter to Console with Private Access for isolated VPCs

    AWS Management Console Private Access now supports VPCs without internet connectivity. All console traffic, including authentication and service API calls, can be routed through AWS PrivateLink endpoints.

  • Automate public certificates with ACME protocol support in AWS Certificate Manager

    AWS Certificate Manager now supports the ACME protocol, enabling automation of public certificate issuance and renewal. This allows use of standard clients like Certbot and cert-manager with enterprise controls.

  • Extend Amazon Bedrock Guardrails to cover tool interactions

    Amazon Bedrock Guardrails can now extend beyond the model boundary to include tool calls, external data, and MCP server interactions. This is achieved using three validation checkpoints with Strands Agents SDK lifecycle hooks.

  • AWS Security Hub Extended adds supply chain security category

    AWS Security Hub Extended now includes supply chain security, featuring curated partners like Chainguard and Socket. This helps verify open source dependencies and block malicious packages.

Read the original announcement →

https://aws.amazon.com/blogs/security/icymi-august-2026-aws-security/

Related releases