bartek@aws: ~/news
$ whoami

Bartek Chojnacki

$ AWS Architect · DevOps · Cloud
Tuesday, August 25, 2026

Strands Agents Tools python_repl: Consent Bypass Vulnerability Patched

Amazon Strands Agents Tools versions before 0.8.5 contain CVE-2026-78379, a consent bypass flaw in the python_repl tool that lets attackers execute arbitrary Python code on your host by sneaking non_interactive_mode through the batch tool. The vulnerability bypasses the human approval gate that normally protects code execution. Action required: upgrade to version 0.8.5 or later immediately if you're running affected versions.

source: [aws/security-bulletin]

Amazon EC2 R8id Instances Expand to More Regions Worldwide

AWS just dropped EC2 R8id instances in seven new regions across Asia Pacific, Canada, and Europe, so you can now spin up serious memory-crunching workloads closer to home. These beasts pack 22.8TB of NVMe SSD storage and 43% better performance than R6id, plus you can now fine-tune network and EBS bandwidth allocation by 25% for smarter resource optimization.

source: [aws/whats-new]

AWS Expands EC2 C8id and M8id Instances to More Regions

Amazon EC2 C8id and M8id instances are now live in Sydney, Mumbai, and Canada Central, bringing serious compute power with up to 22.8 TB of local NVMe SSD storage. These beasts deliver 3x more vCPUs and memory than previous gen, plus 43% better compute performance—perfect for heavy lifting like video encoding, data analytics, and I/O-intensive workloads.

source: [aws/whats-new]

also that day:

Monday, August 24, 2026

Amazon SageMaker HyperPod Levels Up Ray Support with Built-In Observability and Resilient Training

Amazon SageMaker HyperPod now makes running Ray clusters way smoother with interactive development environments, automatic job recovery, and Grafana dashboards—no more kubectl wrestling matches. You can iterate on cluster-scale compute directly from JupyterLab or your local IDE, while HyperPod handles GPU faults and hung jobs automatically, plus accelerates Ray Serve inference with tiered KV caching.

source: [aws/whats-new]

also that day:

Friday, August 21, 2026

OpenSearch Dashboards XSS Vulnerability Requires Immediate Patching

OpenSearch Dashboards has a stored XSS flaw (CVE-2026-77811) in the dashboards-observability plugin that lets authenticated users inject malicious scripts. If you're running self-managed versions before 3.4 or 2.19.6, update immediately—AWS managed users are already patched. An attacker with write access can execute JavaScript in other users' browsers and hijack their API calls.

source: [aws/security-bulletin]

also that day: