aws AWS Security Blog ·

AWS Security shares July 2026 recap of new capabilities and guidance

blogsecurityawssecurity-advisoryarchitect
announcement feature security

This post summarizes AWS Security updates from July 2026, covering new capabilities and guidance across AI security, data protection, and infrastructure. Key announcements include the Amazon GuardDuty investigation agent in public preview, AWS Security Hub's new multicloud support for Azure, and enhancements to AWS WAF Bot Control. These updates aim to bolster security posture, streamline operations, and help organizations meet evolving compliance and threat detection requirements.

  • Infrastructure Security and DDoS Protection Enhancements
  • New Threat Detection and Multicloud Security Hub Capabilities
  • July Security Bulletins
  • AI Security Best Practices and Guidance
  • Data Protection and Key Management Guidance
Security (1)
  • July Security Bulletins

    AWS published 21 security bulletins in July 2026, addressing vulnerabilities across open-source SDKs, MCP servers, and developer tools. Key issues included credential disclosure, SSRF, and command/code injection affecting various services and SDKs, including HealthLake, HealthOmics, and API MCP servers.

Features (2)
  • Infrastructure Security and DDoS Protection Enhancements

    AWS Network Firewall now supports container attribute-based rules for Amazon EKS and ECS workloads using native attributes. AWS WAF Bot Control introduces Web Bot Authentication to cryptographically verify legitimate AI agent traffic. AWS Shield Advanced is also adopting the AWS WAF Anti-DDoS managed rule group for application-layer DDoS protection, with a phased migration planned.

  • New Threat Detection and Multicloud Security Hub Capabilities

    Amazon GuardDuty introduces a new investigation agent (public preview) for on-demand AI-powered threat assessment with structured risk analysis. Amazon Inspector SBOM Generator now supports custom Lua plugins for extending package ecosystem inventory. AWS Security Hub adds monitoring for Microsoft Azure resources and GuardDuty AI Protection for Amazon Bedrock and Amazon SageMaker AI workloads.

Notes (2)
  • AI Security Best Practices and Guidance

    This section highlights blog posts detailing how to enforce least-privilege authorization in multi-agent AI chains with Cedar, implement zero data retention on Amazon Bedrock using service control policies, and mitigate system prompt leakage in generative AI applications. It also provides a control framework for securing AI coding agents.

  • Data Protection and Key Management Guidance

    Guidance includes configuring the AWS Workload Credentials Provider for cross-account secret retrieval, a strategic playbook for CISOs on post-quantum cryptography migration, and advice on choosing between AWS KMS and AWS CloudHSM. It also details implementing dependency cooldowns for npm and pip packages in Amazon Linux to enhance supply chain security.

Read the original announcement →

https://aws.amazon.com/blogs/security/icymi-july-2026-aws-security/

Related releases