AWS Intelligence Digest

Machine-filtered, human-readable judgment for DevOps and Platform leaders.

--
Updates YTD
--
Avg/Month
--
This Week
Signal
Amazon Athena ๐Ÿ”ฅ REMEDIATE
Issues with Amazon Athena ODBC Driver

Update the Amazon Athena ODBC driver to version 2.1.0.0 to patch critical security vulnerabilities (CVE-2026-5485 through CVE-2026-35562) and ensure secure data access across your applications.

2026-06-05
Unknown ๐Ÿ”ฅ REMEDIATE
Overly Permissive Trust Policy in Harmonix on AWS EKS

Update the Harmonix on AWS deployment to version 0.4.2 or later to address the security vulnerability (CVE-2025-14503) and review IAM trust policies to restrict role assumption capabilities, particularly for the EKS environment provisioning role.

2026-06-05
Unknown ๐Ÿ”ฅ REMEDIATE
Issue with AWS Ops Wheel (CVE-2026-6911 and CVE-2026-6912

Update AWS Ops Wheel deployments to the latest version (PR #165) to address critical security vulnerabilities (CVE-2026-6911 and CVE-2026-6912) and restrict network access to API Gateway endpoints as a temporary workaround.

2026-06-05
Unknown ๐Ÿ”ฅ REMEDIATE
MariaDB Server Audit Plugin Comment Handling Bypass

Update Amazon Aurora MySQL, Amazon RDS for MySQL, and Amazon RDS for MariaDB to the specified versions to address the CVE-2026-3494 vulnerability and ensure proper logging of SQL statements.

2026-06-05
Unknown ๐Ÿ”ฅ REMEDIATE
Key Commitment Issues in S3 Encryption Clients

Update your S3 Encryption Client libraries to the latest versions to resolve key commitment issues and protect against potential security threats, ensuring compatibility with existing and new encrypted data.

2026-06-05
Unknown ๐Ÿ”ฅ REMEDIATE
IMDS impersonation

Update configurations for AWS CLI, SDK, and SSM Agent to follow AWS's guidelines, and monitor network traffic for unexpected IMDS endpoints to prevent impersonation issues.

2026-06-05
Unknown ๐Ÿ”ฅ REMEDIATE
Issues with AWS Research and Engineering Studio (RES)

Update AWS Research and Engineering Studio to version 2026.03 and apply patches to mitigate CVE-2026-5707, CVE-2026-5708, and CVE-2026-5709 vulnerabilities, ensuring secure session management and privilege controls.

2026-06-05
AWS CodeBuild ๐Ÿ”ฅ REMEDIATE
Unanchored ACCOUNT_ID webhook filters for CodeBuild

Update the regular expressions for AWS CodeBuild webhook filters in your repositories to ensure they are properly scoped and configured to allow-listed identities only, and consider implementing additional security measures such as credential rotations and pull request build policies to enhance CI/CD security.

2026-06-05
Unknown ๐Ÿ”ฅ REMEDIATE
Dirty Frag and other issues in Amazon Linux kernels

Update Amazon Linux kernels to the latest versions and apply the provided mitigations to disable affected modules and prevent unauthorized privilege escalation through the 'Dirty Frag' vulnerabilities.

2026-06-05
Amazon SageMaker ๐Ÿ”ฅ REMEDIATE
Security Findings in SageMaker Python SDK

Update the SageMaker Python SDK to versions v3.2.0 or v2.256.0 to patch the HMAC configuration issue and to versions v3.1.1 or v2.256.0 to address the insecure TLS configuration, ensuring secure and compliant machine learning model deployments.

2026-06-05
Unknown ๐Ÿ”ฅ REMEDIATE
CVE-2025-66478: RCE in React Server Components

Update React to versions 19.0.1, 19.1.2, and 19.2.1, and Next.js to the latest patched versions to address the RCE vulnerability, and consider deploying a custom AWS WAF rule for added protection.

2026-06-05
Unknown ๐Ÿ”ฅ REMEDIATE
[Redirected] Memory Dump Issue in AWS CodeBuild

Update your CodeBuild configurations to disable automatic builds from untrusted contributors and rotate any compromised credentials to prevent unauthorized code modifications.

2026-06-05
Unknown ๐Ÿ”ฅ REMEDIATE
CVE-2025-8904 - Issue with Amazon EMR Secret Agent component

Update Amazon EMR clusters to version 7.5 or higher to apply the security patch for CVE-2025-8904, which removes the vulnerable /tmp/ directory for storing Kerberos credentials, reducing the risk of privilege escalation.

2026-06-05
Unknown ๐Ÿ”ฅ REMEDIATE
CVE-2025-31133, CVE-2025-52565, CVE-2025-52881 - runc container issues

Update your container management systems to the latest versions of runc (version 1.3.2-2) to address the security vulnerabilities. For Amazon ECS, ensure you are using the latest AMIs or perform a 'yum update -security'. For EKS, update your nodes to the patched AMIs or delete existing Fargate pods to use the patched runtime.

2026-06-05
AWS Blog ๐Ÿ”ฅ REMEDIATE
Extending MCP support for Amazon Bedrock AgentCore Gateway

While deploying Model Context Protocol (MCP) servers in production, enterprises need fine-grained access control across servers, observability into which teams use which tools, security guarantees against data exfiltration, and centralized credential management, all at scale. Amazon Bedrock AgentCore Gateway sits between MCP servers and the clients that consume them, centralizing credential management, observability, and secure [โ€ฆ]

2026-06-01
Amazon ElastiCache ๐Ÿ” AUDIT
Announcing durability for Amazon ElastiCache for Valkey

Configure new ElastiCache clusters with durability options to ensure data resilience without compromising performance, utilizing synchronous writes for zero data loss scenarios and asynchronous writes for microsecond latency requirements.

2026-06-02
Unknown ๐Ÿ” AUDIT
AWS HealthOmics now supports Nextflow version 26.04

Update your AWS HealthOmics workflows to Nextflow v26.04 to benefit from the strict syntax parser, record types, workflow output summaries, and agent logging mode, which will reduce compute time and improve debugging efficiency.

2026-06-01
Unknown ๐Ÿ“‹ PLAN
AWS HealthOmics now supports Nextflow version pinning at run time

Configure the StartRun API to specify Nextflow engine versions (22.04, 23.10, 24.10, 25.10, 26.04) using the new engine-settings parameter, allowing for controlled environment testing and version management without modifying workflow source code.

2026-06-01
AWS Blog ๐Ÿ‘€ OBSERVE
Achieve least-privilege access for Amazon Route 53 Profiles

If you manage DNS across multiple AWS accounts with Amazon Route 53 Profiles, achieving least-privilege access for each team can be challenging. Without fine-grained permissions, one team might inadvertently modify another teamโ€™s resources leading to governance gaps, security risks, and slower adoption of centralized DNS management. The new fine-grained AWS Identity and Access Management (AWS [โ€ฆ]

2026-06-04
AWS Blog ๐Ÿ‘€ OBSERVE
Improve your application resilience with Amazon Cognito multi-Region replication

Amazon Cognito now offers multi-Region replication that automatically synchronizes user data, credentials, and pool configurations to a secondary AWS Region, enabling uninterrupted authentication during regional failovers without forced password resetsโ€”plus new support for customer managed KMS keys for encryption control.

2026-06-03
AWS Blog ๐Ÿ‘€ OBSERVE
Private connectivity patterns for Amazon Bedrock AgentCore Gateway Targets

Introduction Private connectivity from AgentCore Gateway to your targets reduces compliance scope and simplifies auditing making it a common requirement in regulated environments. Whether your targets run inside an Amazon Virtual Private Cloud (Amazon VPC), across AWS accounts, in other AWS Regions, on-premises, or in multicloud environments, you need connectivity patterns that keep traffic off the public [โ€ฆ]

2026-06-03
AWS Blog ๐Ÿ‘€ OBSERVE
AWS SDK for .NET V3 end-of-support announcement

Asโ€ฏpreviously announced, version 3 of the AWS SDK for .NETโ€ฏentered maintenance mode on March 1, 2026. In alignment with our SDKs and Tools Maintenance Policy,โ€ฏAWS SDK for .NET V3 has now reached end-of-support as of June 1, 2026.  Starting June 1, 2026, there are no plans for further updates or releases for V3, including security fixes. [โ€ฆ]

2026-06-01
AWS Blog ๐Ÿ‘€ OBSERVE
AWS Tools for PowerShell V4 end-of- support announcement

Asโ€ฏpreviously announced, version 4 of theโ€ฏAWS Tools for PowerShellโ€ฏentered maintenance mode on March 1, 2026. In accordance with ourโ€ฏSDKs and Tools Maintenance Policy,โ€ฏAWS Tools for PowerShell V4 has now reached end-of-support as of June 1, 2026.  Starting June 1, 2026, there are no plans for further updates or releases for V4, including security fixes. Previously published releases should continue [โ€ฆ]

2026-06-01

Weekly AWS Digest in Your Inbox

No spam, no headlines. Just a weekly summary of the 3โ€“7 AWS changes that matter for DevOps and Platform teams.