bartek@aws: ~/news
$ whoami

Bartek Chojnacki

$ AWS Architect · DevOps · Cloud
Monday, September 14, 2026

AWS Spreads Root User Sign-In Across Three Regions for Better Uptime

AWS now distributes root user sign-in traffic across US East (N. Virginia), US East (Ohio), and US West (Oregon), automatically routing your requests without any action needed on your end. This multi-region setup cuts dependency on a single region and keeps your account accessible even during regional hiccups—just remember to update your CloudTrail monitoring to track sign-ins across all three regions.

source: [aws/whats-new]

also that day:

Saturday, September 12, 2026

AWS Elemental MediaLive Drops Timecode Requirement for Frame-Perfect Sync

AWS Elemental MediaLive just rolled out Video Aligned Locking, letting you sync video pipelines without needing timecode from your source—a game-changer for digital streaming workflows. The feature uses visual signatures to nail frame-accurate input switching across standard and cross-region channels, supporting HLS, MediaPackage, CMAF Ingest, UDP, and SRT outputs.

source: [aws/whats-new]

Friday, September 11, 2026

Kiro IDE Vulnerability Lets Agents Leak Workspace Data

Kiro IDE versions below 0.8.135 have a security issue (CVE-2026-89332) where AI agents can modify workspace settings to exfiltrate sensitive data. A malicious repo could redirect the Powers registry URL to an external endpoint, sending your workspace info there—even before you approve the change. Update to version 0.8.135 or later immediately to stay safe.

source: [aws/security-bulletin]

AWS Advanced JDBC Wrapper XXE Vulnerability Requires Immediate Patching

AWS Advanced JDBC Wrapper versions 3.3.0–4.2.0 contain a critical XXE flaw in RemoteQueryCachePlugin that could leak database and IAM credentials. If you're using this library with shared caching enabled, update immediately—attackers with cache write access can inject malicious XML to exploit XML parsers. This one's serious: patch your Aurora, RDS MySQL, and RDS MariaDB connections ASAP.

source: [aws/security-bulletin]

also that day: