bartek@aws: ~/news
$ whoami

Bartek Chojnacki

$ AWS Architect · DevOps · Cloud
Friday, August 7, 2026

Amazon Cognito Joins Agent Toolkit for AWS – Your AI Can Now Handle Auth

Amazon Cognito is now available as a core skill in the Agent Toolkit for AWS, letting AI coding agents set up, configure, and troubleshoot authentication workflows automatically. This means faster implementation of secure sign-in flows for users, AI agents, and microservices—with best-practice patterns baked in, including OAuth 2.0, passkeys, and threat protection.

source: [aws/whats-new]

Amazon ECS Now Lets You Slice GPUs Into Smaller Pieces

Amazon ECS now supports fractional GPU scheduling on EC2 G6f instances, letting you run AI inference and graphics workloads on GPU partitions as small as one-eighth of an NVIDIA L4 GPU (3 GB memory) by setting GPU=0.125, 0.25, or 0.5 in your task definition. This capability is live across all AWS Regions where G6f instances are available, helping you cut infrastructure costs by right-sizing containers instead of provisioning full GPUs.

source: [aws/whats-new]

also that day:

Thursday, August 6, 2026

Amazon DocumentDB MCP Server: Authorization Bypass in Aggregation Pipeline

Amazon DocumentDB MCP Server versions below 1.0.12 have a nasty authorization flaw (CVE-2026-18954). Write-capable aggregation stages like $out and $merge can bypass read-only enforcement, letting authenticated clients sneak write operations past security controls. If you're running this open-source tool, upgrade immediately—this one requires your attention.

source: [aws/security-bulletin]

also that day:

Wednesday, August 5, 2026

AWS Transform MCP Server Path Traversal Vulnerability – Update Required

AWS Transform MCP Server versions 0.1.0 through 0.1.4 have a path traversal flaw (CVE-2026-18953) that lets attackers write files outside the intended directory via the savePath parameter, potentially enabling local code execution. If you're running this open-source MCP server locally, you need to upgrade to version 0.1.5 or later immediately. This is a context-dependent attack, but the risk is real for developers using AI assistants with AWS Transform integration.

source: [aws/security-bulletin]

DynamoDB Gets Real-Time Vector Search Powers

AWS just dropped general availability for vector search in Amazon DynamoDB, and it's a game-changer for AI workloads. You can now index and search billions or trillions of vectors with single-digit millisecond latency at 99%+ recall—no infrastructure headaches, just serverless magic. Store embeddings alongside your data, create vector indexes, and unlock semantic search for RAG, recommendations, and AI agent memory retrieval. Available globally on DynamoDB with your choice of embedding models, including Amazon Bedrock.

source: [aws/whats-new]

AWS Lambda Gets Serious Network Boost: Up to 3,000 Mbps Bandwidth

AWS Lambda just leveled up with scalable network bandwidth reaching 3,000 Mbps for functions packing 10 GB of memory—a massive jump from the old 625 Mbps cap. This means your data-hungry workloads outside a VPC can now transfer terabytes faster, cutting execution times and costs while keeping latency happy. The bandwidth scales automatically with your function's memory, and it's free everywhere AWS operates. Just request it through AWS Service Quotas and you're golden.

source: [aws/whats-new]

also that day: