bartek@aws: ~/news
$ whoami

Bartek Chojnacki

$ AWS Architect · DevOps · Cloud
Tuesday, September 1, 2026

Amazon SageMaker Python SDK: Critical HMAC Key Exposure Vulnerability

Amazon SageMaker Python SDK has a serious security flaw where HMAC signing keys are stored in cleartext in pipeline definitions. Attackers with account access can extract these keys via DescribePipeline API and execute arbitrary code in other users' pipelines. Update immediately: SDK v3 to v3.11.0+ or v2 to v2.256.0+. Action required for all users running affected versions.

source: [aws/security-bulletin]

Claude Fable 5.1 Lands on AWS with Serious Reasoning Chops

Anthropic's Claude Fable 5.1 is now generally available on AWS through Amazon Bedrock and Claude Platform, bringing frontier-level AI to your coding, research, and enterprise workflows. This beast handles multi-hour sessions across entire codebases, admits when it's stuck instead of faking success, and won't ghost you with confident wrong answers—plus Enterprise Frontier Safeguards let you keep your data in your own cloud.

source: [aws/whats-new]

Amazon Quick Now Lets You Build Apps Without Code

Amazon Quick is now generally available, letting you create custom business applications just by describing what you need in plain English—no coding required. The tool connects to your existing systems like Salesforce, Jira, and Microsoft 365, building live apps with real-time data that you can share instantly across your organization.

source: [aws/whats-new]

also that day:

Monday, August 31, 2026

OpenSearch SQL Plugin: Critical Deserialization Flaw Lets Attackers Execute Code

OpenSearch SQL Plugin has a nasty vulnerability (CVE-2026-83497) that lets authenticated users with basic read permissions run arbitrary code via a crafted cursor parameter. If you're running v2.8–v3.6 (self-managed) or v2.9–v3.5 (AWS managed), you need to patch immediately. Update to v3.7, v2.19.6, or apply the AWS service software update to stay safe.

source: [aws/security-bulletin]

Redshift Gets IAM Identity Center Auth with Private Network Routing

Amazon Redshift now lets you authenticate using AWS IAM Identity Center while keeping all traffic inside your VPC through enhanced VPC routing—perfect if your compliance rules demand zero public internet exposure. This works for both provisioned clusters and serverless workgroups across all AWS Regions, and even supports multi-Region Identity Center setups.

source: [aws/whats-new]

also that day:

Saturday, August 29, 2026

Kinesis Data Streams Gets Serverless Iceberg Delivery—No Pipeline Coding Required

Amazon Kinesis Data Streams now streams data directly to Apache Iceberg tables on S3 Tables without you building custom pipelines, cutting delivery costs by up to 50% and query costs by 30%. The fully serverless streaming tables handle scaling, compaction, and reliability automatically across all AWS regions, including GovCloud and China.

source: [aws/whats-new]

AWS Graviton4-Powered EC2 C8gn Instances Land in Paris

Amazon EC2 C8gn instances, featuring the new Graviton4 processors, are now live in the Paris region alongside 20+ other global locations. These beasts deliver 30% better performance than their Graviton3 predecessors, pack up to 600 Gbps network bandwidth, and support instance sizes up to 48xlarge—perfect for crushing network-intensive workloads like AI/ML inference and data analytics without breaking the bank.

source: [aws/whats-new]