AWS Security shares July 2026 recap of new capabilities and guidance
This post summarizes AWS Security updates from July 2026, covering new capabilities and guidance across AI security, data protection, and infrastructure. Key announcements include the Amazon GuardDuty investigation agent in public preview, AWS Security Hub's new multicloud support for Azure, and enhancements to AWS WAF Bot Control. These updates aim to bolster security posture, streamline operations, and help organizations meet evolving compliance and threat detection requirements.
- →Infrastructure Security and DDoS Protection Enhancements
- →New Threat Detection and Multicloud Security Hub Capabilities
- →July Security Bulletins
- →AI Security Best Practices and Guidance
- →Data Protection and Key Management Guidance
Security (1) ›
- July Security Bulletins
AWS published 21 security bulletins in July 2026, addressing vulnerabilities across open-source SDKs, MCP servers, and developer tools. Key issues included credential disclosure, SSRF, and command/code injection affecting various services and SDKs, including HealthLake, HealthOmics, and API MCP servers.
Features (2) ›
- Infrastructure Security and DDoS Protection Enhancements
AWS Network Firewall now supports container attribute-based rules for Amazon EKS and ECS workloads using native attributes. AWS WAF Bot Control introduces Web Bot Authentication to cryptographically verify legitimate AI agent traffic. AWS Shield Advanced is also adopting the AWS WAF Anti-DDoS managed rule group for application-layer DDoS protection, with a phased migration planned.
- New Threat Detection and Multicloud Security Hub Capabilities
Amazon GuardDuty introduces a new investigation agent (public preview) for on-demand AI-powered threat assessment with structured risk analysis. Amazon Inspector SBOM Generator now supports custom Lua plugins for extending package ecosystem inventory. AWS Security Hub adds monitoring for Microsoft Azure resources and GuardDuty AI Protection for Amazon Bedrock and Amazon SageMaker AI workloads.
Notes (2) ›
- AI Security Best Practices and Guidance
This section highlights blog posts detailing how to enforce least-privilege authorization in multi-agent AI chains with Cedar, implement zero data retention on Amazon Bedrock using service control policies, and mitigate system prompt leakage in generative AI applications. It also provides a control framework for securing AI coding agents.
- Data Protection and Key Management Guidance
Guidance includes configuring the AWS Workload Credentials Provider for cross-account secret retrieval, a strategic playbook for CISOs on post-quantum cryptography migration, and advice on choosing between AWS KMS and AWS CloudHSM. It also details implementing dependency cooldowns for npm and pip packages in Amazon Linux to enhance supply chain security.
https://aws.amazon.com/blogs/security/icymi-july-2026-aws-security/
Related releases
- Amazon Connect Customer Adds Points-Based Scoring for Agent Evaluations AWS What's New ·
- HashiCorp Terraform AWS Provider v6.62.0 Adds New Resources and Enhancements Terraform AWS Provider Releases ·
- MSK Replicator now supports OAuth 2.0 for migrating Kafka clusters AWS Big Data Blog ·
- Amazon MSK Now Supports In-Place ZooKeeper-to-KRaft Cluster Upgrades AWS Big Data Blog ·
- AWS CLI integrates Agent Toolkit for AWS to enhance AI coding agents AWS Developer Tools Blog ·
- Detecting Multi-Stage Attacks on AWS: A Guide to Cross-Service Signal Correlation AWS Security Blog ·