#AwsSecurityHub
50 AWS Security Hub Interview questions and answers:

https://tapurl.to/awssecurityhub
September 27, 2026 at 1:31 PM
🆕 AWS Security Hub AI Inventory now supports Azure self-hosted AI assets, broadening multi-cloud security discovery. Free with Security Hub Essentials, it maps AI to infrastructure and correlates findings. Available in all commercial AWS regions.

#AWS #AwsSecurityHub #Aiml
AWS Security Hub AI Inventory adds Azure self-hosted instance support
AWS Security Hub AI Inventory now supports discovering and cataloging AI assets running on self-hosted instances in Microsoft Azure. This expansion extends Security Hub's existing self-hosted discovery capabilities beyond AWS, enabling central security teams to gain a continuously updated, organization-wide view of AI assets and their security posture across multi-cloud environments. Security Hub leverages the software bill of materials (SBOM) analysis from Amazon Inspector, which has been enhanced to identify inference endpoints, models, and AI agents installed on Azure virtual machines, including frameworks such as Ollama, vLLM, Hugging Face TGI, and others. Each discovered AI asset is mapped to its underlying infrastructure and correlated with security findings, enabling teams to filter, group, and query their AI inventory across both AWS and Azure environments. This capability is included with Security Hub Essentials at no additional cost. It is available in all AWS commercial Regions where Security Hub is offered. To learn more, see the AWS Security Hub User Guide and the AWS Security Hub product page.
aws.amazon.com
September 22, 2026 at 8:10 PM
AWS Security Hub AI Inventory adds Azure self-hosted instance support

AWS Security Hub AI Inventory now supports discovering and cataloging AI assets running on self-hosted instances in Microsoft Azure. This expansion extends Security Hub's existing self-hosted discov...

#AWS #AwsSecurityHub #Aiml
AWS Security Hub AI Inventory adds Azure self-hosted instance support
AWS Security Hub AI Inventory now supports discovering and cataloging AI assets running on self-hosted instances in Microsoft Azure. This expansion extends Security Hub's existing self-hosted discovery capabilities beyond AWS, enabling central security teams to gain a continuously updated, organization-wide view of AI assets and their security posture across multi-cloud environments. Security Hub leverages the software bill of materials (SBOM) analysis from Amazon Inspector, which has been enhanced to identify inference endpoints, models, and AI agents installed on Azure virtual machines, including frameworks such as Ollama, vLLM, Hugging Face TGI, and others. Each discovered AI asset is mapped to its underlying infrastructure and correlated with security findings, enabling teams to filter, group, and query their AI inventory across both AWS and Azure environments. This capability is included with Security Hub Essentials at no additional cost. It is available in all AWS commercial Regions where Security Hub is offered. To learn more, see the https://docs.aws.amazon.com/securityhub/latest/userguide/securityhub-v2-ai-inventory.html and the https://aws.amazon.com/security-hub/.
aws.amazon.com
September 22, 2026 at 8:05 PM
AWS Security Hub CSPM now supports CIS AWS Foundations Benchmark v5.0

https://aws.amazon.com/security-hub/cspm/features/) now supports the Center for Internet Security (CIS) AWS Foundations Benchmark v5.0. This industry-standard benchmark provides security ...

#AWS #AwsGovcloudUs #AwsSecurityHub
AWS Security Hub CSPM now supports CIS AWS Foundations Benchmark v5.0
https://aws.amazon.com/security-hub/cspm/features/) now supports the Center for Internet Security (CIS) AWS Foundations Benchmark v5.0. This industry-standard benchmark provides security configuration best practices for AWS with clear implementation and assessment procedures. The new standard includes 40 controls that perform automated checks against AWS resources to evaluate compliance with the latest version 5.0 requirements. The standard is now available in all AWS Regions where Security Hub CSPM is currently available, including the AWS GovCloud (US) and the China Regions. To quickly enable the standard across your AWS environment, we recommend that you use Security Hub CSPM central configuration. With this approach, you can enable the standard in all or only some of your organization's accounts and across all AWS Regions that are linked to Security Hub CSPM with a single action. To learn more, seehttps://docs.aws.amazon.com/securityhub/latest/userguide/cis-aws-foundations-benchmark.html in the AWS Security Hub CSPM User Guide. To receive notifications about new Security Hub CSPM features and controls, subscribe to the https://docs.aws.amazon.com/securityhub/latest/userguide/securityhub-announcements.html. You can also try https://aws.amazon.com/security-hub/pricing/ with the AWS Free Tier offering.
aws.amazon.com
October 16, 2025 at 9:05 PM
🆕 AWS Security Hub MCP App preview integrates exposure findings into your AI-assisted workflow for easier investigation. Free, it provides local, read-only access to security posture, findings, and remediation, reducing manual triage. Available in all commercial regions suppo…

#AWS #AwsSecurityHub
AWS Security Hub MCP App brings exposure findings into your AI-assisted workflow (Preview)
AWS announces the preview of the AWS Security Hub MCP App, a local Model Context Protocol (MCP) server that brings your Security Hub exposure findings directly into Claude Desktop.  This capability can help accelerates your security investigations by reducing context switching and manual triage, letting you explore and act on your exposures without leaving your AI-assisted workflow. With the Security Hub MCP App, you can investigate your security posture in natural language: view your top exposure findings, drill into a finding’s attack path and expanded network path, examine correlated findings and affected resource configurations, and get remediation recommendations. Each tool call returns both a text summary for your AI agent to reason overover and an interactive visualization for you to verify in the same conversation. The MCP server runs locally on your machine using your existing AWS credentials, and every tool is read-only,-- no changes are made to your environment. The Security Hub MCP App is available at no additional cost to Security Hub customers. This feature is available in preview in all AWS commercial Regions that support Security Hub. To learn more, see the AWS Security Hub User Guide and the AWS Security Hub product page. For the full list of Regions, see the AWS Regional Services List.
aws.amazon.com
July 27, 2026 at 8:10 PM
🆕 AWS announces AWS Security Incident Response for general availability

#AWS #AmazonGuardduty #AwsSecurityHub #AwsOrganizations
AWS announces AWS Security Incident Response for general availability
Today, AWS announces the general availability of AWS Security Incident Response, a new service that helps you prepare for, respond to, and recover from security events. This service offers automated monitoring and investigation of security findings to free up your resources from routine tasks, communication and collaboration features to streamline response coordination, and direct 24/7 access to the AWS Customer Incident Response Team (CIRT). Security Incident Response integrates with existing detection services, such as Amazon GuardDuty, and third-party tools through AWS Security Hub to rapidly review security alerts, escalate high-priority findings, and, with your permission, implement containment actions. It reduces the number of alerts your team needs to analyze, saving time and allowing your security personnel to focus on strategic initiatives. The service centralizes all incident-related communications, documentation, and actions, making coordinated incident response across internal and external stakeholders possible and reducing the time to coordinate from hours to minutes. You can preconfigure incident response team members, set up automatic notifications, manage case permissions, and use communication tools like video conferencing and in-console messaging during security events. By accessing the service through a single, centralized dashboard in the AWS Management Console, you can monitor active cases, review resolved security incident cases, and track key metrics, such as the number of triaged events and mean time to resolution, in real time. If you require specialized expertise, you can connect 24/7 to the AWS CIRT in only one step. For more information about AWS Regions where Security Incident Response is available, refer to the following service documentation. To get started, visit the Security Incident Response console, and explore the overview page to learn more. For configuration details, refer to the Security Incident Response User Guide.
aws.amazon.com
December 2, 2024 at 4:54 AM
🆕 AWS Security Hub CSPM now supports CIS AWS Foundations Benchmark v5.0, adding 40 automated compliance checks. Available globally, it can be centrally configured for quick deployment across accounts. Details in the user guide.

#AWS #AwsGovcloudUs #AwsSecurityHub
AWS Security Hub CSPM now supports CIS AWS Foundations Benchmark v5.0
AWS Security Hub Cloud Security Posture Management (CSPM) now supports the Center for Internet Security (CIS) AWS Foundations Benchmark v5.0. This industry-standard benchmark provides security configuration best practices for AWS with clear implementation and assessment procedures. The new standard includes 40 controls that perform automated checks against AWS resources to evaluate compliance with the latest version 5.0 requirements. The standard is now available in all AWS Regions where Security Hub CSPM is currently available, including the AWS GovCloud (US) and the China Regions. To quickly enable the standard across your AWS environment, we recommend that you use Security Hub CSPM central configuration. With this approach, you can enable the standard in all or only some of your organization's accounts and across all AWS Regions that are linked to Security Hub CSPM with a single action. To learn more, see CIS v5.0 in the AWS Security Hub CSPM User Guide. To receive notifications about new Security Hub CSPM features and controls, subscribe to the Security Hub CSPM SNS topic. You can also try Security Hub at no cost for 30 days with the AWS Free Tier offering.
aws.amazon.com
October 16, 2025 at 8:40 PM
🆕 AWS Security Hub now detects unused IAM permissions and roles, integrating identity risks into its unified console for central security teams to manage threats and exposures, reducing attack surface with least-privilege policy recommendations at no extra cost.

#AWS #AwsSecurityHub
AWS Security Hub now uncovers identity risks from unused access
Today, AWS Security Hub brings identity risk into the same unified console where central security teams already manage threats, exposures, and posture findings. Security Hub now detects unused IAM permissions, roles, and credentials across your AWS organization, helping central security teams identify and reduce identity risk at scale. Until now, managing identity risk across hundreds of accounts required toggling between multiple tools, with no unified view connecting unused permissions to actual resource exposure. Security Hub now surfaces these identity risks alongside threats, exposures, and posture findings in a unified console, enabling teams to prioritize remediation based on actual organizational risk. When you enable Security Hub for your organization, a service-linked IAM Access Analyzer is automatically created in each member account with no additional configuration required. Security Hub evaluates IAM principals against 90 days of actual access activity, detects unused access, and correlates identity findings with exposure context so teams can focus on the risks that matter most. Security Hub also provides on-demand generation of recommended least-privilege policies based on actual usage patterns, helping teams refine IAM permissions and reduce their attack surface. These capabilities represent a foundational step toward broader cloud infrastructure entitlement management in Security Hub, delivered with consistent workflows, automation rules, and downstream integrations. These capabilities are included with Security Hub Essentials at no additional cost. To learn more, see Understanding unused access findings in Security Hub in the AWS Security Hub User Guide and the AWS Security Hub product page. For the full list of AWS Regions where Security Hub is available, see the AWS Regional Services List.
aws.amazon.com
May 20, 2026 at 10:09 PM
AWS Security Hub now uncovers identity risks from unused access

Today, AWS Security Hub brings identity risk into the same unified console where central security teams already manage threats, exposures, and posture findings. Security Hub now detects unused IAM permissions, ...

#AWS #AwsSecurityHub
AWS Security Hub now uncovers identity risks from unused access
Today, AWS Security Hub brings identity risk into the same unified console where central security teams already manage threats, exposures, and posture findings. Security Hub now detects unused IAM permissions, roles, and credentials across your AWS organization, helping central security teams identify and reduce identity risk at scale. Until now, managing identity risk across hundreds of accounts required toggling between multiple tools, with no unified view connecting unused permissions to actual resource exposure. Security Hub now surfaces these identity risks alongside threats, exposures, and posture findings in a unified console, enabling teams to prioritize remediation based on actual organizational risk. When you enable Security Hub for your organization, a service-linked IAM Access Analyzer is automatically created in each member account with no additional configuration required. Security Hub evaluates IAM principals against 90 days of actual access activity, detects unused access, and correlates identity findings with exposure context so teams can focus on the risks that matter most. Security Hub also provides on-demand generation of recommended least-privilege policies based on actual usage patterns, helping teams refine IAM permissions and reduce their attack surface. These capabilities represent a foundational step toward broader cloud infrastructure entitlement management in Security Hub, delivered with consistent workflows, automation rules, and downstream integrations. These capabilities are included with Security Hub Essentials at no additional cost. To learn more, see Understanding unused access findings in Security Hub in the https://docs.aws.amazon.com/securityhub/latest/userguide/what-is-securityhub-v2.htmland the https://aws.amazon.com/security-hub/. For the full list of AWS Regions where Security Hub is available, see the https://aws.amazon.com/about-aws/global-infrastructure/regional-product-services/.
aws.amazon.com
May 20, 2026 at 10:05 PM
AWS Security Hub Extended adds supply chain security as its 10th category

The AWS Security Hub Extended plan now includes Supply Chain Security as its 10th security category, with Chainguard and Socket as the curated partners. As developers adopt open-source libraries at sc...

#AWS #AwsSecurityHub
AWS Security Hub Extended adds supply chain security as its 10th category
The AWS Security Hub Extended plan now includes Supply Chain Security as its 10th security category, with Chainguard and Socket as the curated partners. As developers adopt open-source libraries at scale, security teams need confidence that the packages entering their environments are trustworthy and free from malicious code. With this addition, you can detect and block malicious dependencies before they are built into your applications, with the same streamlined activation and pay-as-you-go pricing as every other Extended category. This brings the Extended plan to 23 curated partner solutions. All solutions are on a single AWS bill and no required long-term commitments. Security Hub Extended is a plan within AWS Security Hub that helps simplify how you procure, deploy, and integrate a full-stack enterprise security solution across endpoint, identity, email, network, data, browser, cloud, AI, security operations, and supply chain. Security findings from all participating solutions are emitted in the Open Cybersecurity Schema Framework (OCSF) and automatically aggregated in AWS Security Hub. With the Extended plan, you can combine AWS and curated partner solutions to quickly identify and respond to risks that span boundaries. We will continue to expand the Extended plan based on customer feedback. The two new curated partner solutions are available today in all AWS commercial Regions where Security Hub is available. For a list of supported Regions, see the/about-aws/global-infrastructure/regional-product-services/?p=ngi&loc=4&refid=d8ec3b19-0f37-4f8c-8c12-189f913e205c For more information about pricing, visit the/security-hub/pricing/. To get started, visit the https://console.aws.amazon.com/securityhub/v2/home or /security-hub/
aws.amazon.com
August 4, 2026 at 8:05 PM
🆕 AWS Control Tower adds 176 new Security Hub controls for better security, cost, and governance. Enable them via the Control Catalog. For more, check the AWS Control Tower User Guide.

#AWS #AwsSecurityHub #AwsGovcloudUs #AwsControlTower
Announcing 176 new AWS Security Hub controls in AWS Control Tower
Today, AWS announces that AWS Control Tower supports an additional 176 Security Hub controls in Control Catalog for use cases such as security, cost, durability, and operations. With this launch, you can now search, discover, enable and manage these additional controls directly from AWS Control Tower and govern more use cases for your multi-account environment. To get started, in AWS Control Tower go to the Control Catalog and search for controls with the Control owner filter set to AWS Security Hub , you will then see all the AWS Security Hub controls present in the Catalog. If you find controls that are relevant for you, you can then directly enable them from the AWS Control Tower console. You can also use ListControls, GetControl and EnableControl APIs. You can search the new AWS Config rules in all AWS Regions where AWS Control Tower is available, including AWS GovCloud (US). When you want to deploy a rule, reference the list of supported regions for that rule to see where it can be enabled. To learn more, visit the AWS Control Tower User Guide.
aws.amazon.com
December 18, 2025 at 11:41 PM
Announcing 176 new AWS Security Hub controls in AWS Control Tower

Today, AWS announces that AWS Control Tower supports an additional 176 Security Hub controls in Control Catalog for use cases such as security, cost, durability, and operati...

#AWS #AwsSecurityHub #AwsGovcloudUs #AwsControlTower
Announcing 176 new AWS Security Hub controls in AWS Control Tower
Today, AWS announces that AWS Control Tower supports an additional 176 Security Hub controls in Control Catalog for use cases such as security, cost, durability, and operations. With this launch, you can now search, discover, enable and manage these additional controls directly from AWS Control Tower and govern more use cases for your multi-account environment. To get started, in AWS Control Tower go to the Control Catalog and search for controls with the Control owner filter set to AWS Security Hub , you will then see all the AWS Security Hub controls present in the Catalog. If you find controls that are relevant for you, you can then directly enable them from the AWS Control Tower console. You can also use ListControls, GetControl and EnableControl APIs. You can search the new AWS Config rules in all https://aws.amazon.com/about-aws/global-infrastructure/regional-product-services/ where AWS Control Tower is available, including AWS GovCloud (US). When you want to deploy a rule, reference the list of supported regions for that rule to see where it can be enabled. To learn more, visit the https://docs.aws.amazon.com/controltower/latest/controlreference/config-controls.html.
aws.amazon.com
December 19, 2025 at 12:05 AM
🆕 AWS Security Hub provides an AI inventory for organization-wide visibility of AI assets, automatically discovering and cataloging workloads, mapping to security findings, and prioritizing remediation based on threat levels and risk. Available at no extra cost.

#AWS #AwsSecurityHub
AWS Security Hub now provides AI inventory for organization-wide visibility of AI assets
Today, AWS announces that AWS Security Hub now provides an AI inventory, giving central security teams a continuously updated, organization-wide view of AI assets and their security posture. As organizations rapidly deploy AI agents, models, and pipelines, security teams may lack visibility into what AI assets exist across their organization. Without centralized visibility connecting AI assets to active threats and misconfigurations, organizations cannot secure what they don't know exists. Security Hub AI inventory automatically discovers and catalogs AI workloads across your AWS environment through three discovery methods. For managed AI services, Security Hub inventories AWS Config resources from Amazon Bedrock, Bedrock AgentCore and Amazon SageMaker, with no additional configuration. For self-hosted AI workloads, Security Hub leverages the software bill of materials (SBOM) analysis from Amazon Inspector, which has been enhanced to identify inference endpoints, models and AI agents installed on Amazon EC2 instances and Amazon ECR container images, including frameworks such as Ollama, vLLM, Hugging Face TGI, and others. Security Hub also leverages Amazon GuardDuty DNS telemetry to discover external AI API endpoints (such as calls to third-party model providers) being accessed from your EC2 instances, revealing third-party AI dependencies that may not have been previously identified.  Each discovered AI asset is mapped to its underlying infrastructure and correlated with security findings from across the AWS security stack, including threat findings from Amazon GuardDuty. Teams can filter, group, and query their AI inventory by account, resource type, discovery method, and specific model identity, enabling them to prioritize remediation based on which AI workloads are actively under threat and carry the highest organizational risk. AI Inventory is included with Security Hub Essentials at no additional cost and requires no new enablement. It is available in all AWS commercial Regions where Security Hub is offered. To learn more, see the AWS Security Hub User Guide and the AWS Security Hub product page.
aws.amazon.com
July 14, 2026 at 7:10 PM
Introducing AWS Security Hub for risk prioritization and response at scale (Preview)

AWS announces an enhanced AWS Security Hub to prioritize your critical security issues and help respond at scale to reduce security risks, improve your team’s productivity, and protect ...

#AWS #AwsSecurityHub
Introducing AWS Security Hub for risk prioritization and response at scale (Preview)
AWS announces an enhanced AWS Security Hub to prioritize your critical security issues and help respond at scale to reduce security risks, improve your team’s productivity, and protect your cloud environment. It detects critical issues by correlating and enriching security signals, for example, from threat detection and vulnerability management. This enables you to quickly surface and prioritize active risks in your cloud environment. The unified solution provides more comprehensive visibility into your security posture while reducing the complexity of manually piecing together information from multiple security tools. Security Hub transforms correlated security signals into actionable insights through intuitive visualizations and contextual analytics, helping you identify critical patterns and trends and centralize security operations in your environment. For example, it detects and correlates scenarios where publicly exposed resources with highly exploitable vulnerabilities have access to storage with sensitive data. These insights provide enhanced risk context so you can make more informed decisions and take immediate action on security issues. Enhanced capabilities include exposure findings, security-focused asset inventory, attack path visualization, and automated response workflows with ticketing system integration. This centralized management enables streamlined remediation at scale while helping you minimize potential operational disruptions.  For more information about AWS Regions where Security Hub is available, see the https://aws.amazon.com/about-aws/global-infrastructure/regional-product-services/?p=ngi&loc=4. You can enable Security Hub for individual accounts or across your entire AWS Organization with centralized deployment and management. The service integrates with existing AWS security capabilities including Amazon GuardDuty, Amazon Inspector, AWS Security Hub CSPM, and Amazon Macie, providing more comprehensive security posture without additional operational overhead.   To learn more about the enhanced Security Hub and join the Preview, visit the https://console.aws.amazon.com/securityhub/v2/home or the AWS Security Hub https://aws.amazon.com/security-hub/. 
aws.amazon.com
June 17, 2025 at 5:05 PM
AWS Security Hub now provides AI inventory for organization-wide visibility of AI assets

Today, AWS announces that AWS Security Hub now provides an AI inventory, giving central security teams a continuously updated, organization-wide view of AI assets and their security pos...

#AWS #AwsSecurityHub
AWS Security Hub now provides AI inventory for organization-wide visibility of AI assets
Today, AWS announces that AWS Security Hub now provides an AI inventory, giving central security teams a continuously updated, organization-wide view of AI assets and their security posture. As organizations rapidly deploy AI agents, models, and pipelines, security teams may lack visibility into what AI assets exist across their organization. Without centralized visibility connecting AI assets to active threats and misconfigurations, organizations cannot secure what they don't know exists. Security Hub AI inventory automatically discovers and catalogs AI workloads across your AWS environment through three discovery methods. For managed AI services, Security Hub inventories AWS Config resources from Amazon Bedrock, Bedrock AgentCore and Amazon SageMaker, with no additional configuration. For self-hosted AI workloads, Security Hub leverages the software bill of materials (SBOM) analysis from Amazon Inspector, which has been enhanced to identify inference endpoints, models and AI agents installed on Amazon EC2 instances and Amazon ECR container images, including frameworks such as Ollama, vLLM, Hugging Face TGI, and others. Security Hub also leverages Amazon GuardDuty DNS telemetry to discover external AI API endpoints (such as calls to third-party model providers) being accessed from your EC2 instances, revealing third-party AI dependencies that may not have been previously identified.  Each discovered AI asset is mapped to its underlying infrastructure and correlated with security findings from across the AWS security stack, including threat findings from Amazon GuardDuty. Teams can filter, group, and query their AI inventory by account, resource type, discovery method, and specific model identity, enabling them to prioritize remediation based on which AI workloads are actively under threat and carry the highest organizational risk. AI Inventory is included with Security Hub Essentials at no additional cost and requires no new enablement. It is available in all AWS commercial Regions where Security Hub is offered. To learn more, see the https://docs.aws.amazon.com/securityhub/latest/userguide/what-is-securityhub-v2.html and the https://aws.amazon.com/security-hub/.
aws.amazon.com
July 14, 2026 at 7:05 PM
🆕 AWS Security Hub now includes Supply Chain Security, adding Chainguard and Socket to detect and block malicious dependencies in open-source libraries, integrating with enterprise security solutions on a single bill with pay-as-you-go pricing.

#AWS #AwsSecurityHub
AWS Security Hub Extended adds supply chain security as its 10th category
The AWS Security Hub Extended plan now includes Supply Chain Security as its 10th security category, with Chainguard and Socket as the curated partners. As developers adopt open-source libraries at scale, security teams need confidence that the packages entering their environments are trustworthy and free from malicious code. With this addition, you can detect and block malicious dependencies before they are built into your applications, with the same streamlined activation and pay-as-you-go pricing as every other Extended category. This brings the Extended plan to 23 curated partner solutions. All solutions are on a single AWS bill and no required long-term commitments. Security Hub Extended is a plan within AWS Security Hub that helps simplify how you procure, deploy, and integrate a full-stack enterprise security solution across endpoint, identity, email, network, data, browser, cloud, AI, security operations, and supply chain. Security findings from all participating solutions are emitted in the Open Cybersecurity Schema Framework (OCSF) and automatically aggregated in AWS Security Hub. With the Extended plan, you can combine AWS and curated partner solutions to quickly identify and respond to risks that span boundaries. We will continue to expand the Extended plan based on customer feedback. The two new curated partner solutions are available today in all AWS commercial Regions where Security Hub is available. For a list of supported Regions, see the AWS Region table. For more information about pricing, visit the AWS Security Hub pricing page. To get started, visit the AWS Security Hub console or product page.
aws.amazon.com
August 4, 2026 at 8:10 PM
AWS Security Hub MCP App brings exposure findings into your AI-assisted workflow (Preview)

AWS announces the preview of the AWS Security Hub MCP App, a local Model Context Protocol (MCP) server that brings your Security Hub exposure findings directly into Claude Desktop.  T...

#AWS #AwsSecurityHub
AWS Security Hub MCP App brings exposure findings into your AI-assisted workflow (Preview)
AWS announces the preview of the AWS Security Hub MCP App, a local Model Context Protocol (MCP) server that brings your Security Hub exposure findings directly into Claude Desktop.  This capability can help accelerates your security investigations by reducing context switching and manual triage, letting you explore and act on your exposures without leaving your AI-assisted workflow. With the Security Hub MCP App, you can investigate your security posture in natural language: view your top exposure findings, drill into a finding’s attack path and expanded network path, examine correlated findings and affected resource configurations, and get remediation recommendations. Each tool call returns both a text summary for your AI agent to reason overover and an interactive visualization for you to verify in the same conversation. The MCP server runs locally on your machine using your existing AWS credentials, and every tool is read-only,-- no changes are made to your environment. The Security Hub MCP App is available at no additional cost to Security Hub customers. This feature is available in preview in all AWS commercial Regions that support Security Hub. To learn more, see the https://docs.aws.amazon.com/securityhub/latest/userguide/securityhub-v2-mcp-app.html and the https://aws.amazon.com/security-hub/. For the full list of Regions, see the https://aws.amazon.com/about-aws/global-infrastructure/regional-product-services/.
aws.amazon.com
July 27, 2026 at 8:05 PM
🆕 AWS Security Hub now offers Network Scanning to detect publicly reachable resources, confirming actual reachability from the internet and identifying exposed ports and services, enhancing security by complementing existing network reachability findings.

#AWS #AwsSecurityHub
AWS Security Hub now offers Network Scanning to identify publicly reachable resources
Today, AWS Security Hub introduces Network Scanning, a capability that identifies resources in your environment that are reachable from the public internet.  Network Scanning probes your resources from the internet to detect actual reachability, not just what could be reachable based on security group rules and route tables. It discovers public IP addresses, virtual machines, and load balancers across your AWS and Azure environments, identifies reachable ports, and determines what services are running behind them. This complements Security Hub’s existing network reachability findings, which identify configurations that could make a resource reachable from the internet.  Network Scanning confirms actual reachability from the internet. Each reachable port generates a Security Hub finding with evidence of the port and service discovered. Security Hub Exposures then automatically correlates these findings with other findings and resource configurations to determine broader risk.
aws.amazon.com
July 8, 2026 at 9:10 PM
AWS Security Hub now offers Network Scanning to identify publicly reachable resources

Today, AWS Security Hub introduces Network Scanning, a capability that identifies resources in your environment that are reachable from the public internet.  Network Scanning probes your r...

#AWS #AwsSecurityHub
AWS Security Hub now offers Network Scanning to identify publicly reachable resources
Today, AWS Security Hub introduces Network Scanning, a capability that identifies resources in your environment that are reachable from the public internet.  Network Scanning probes your resources from the internet to detect actual reachability, not just what could be reachable based on security group rules and route tables. It discovers public IP addresses, virtual machines, and load balancers across your AWS and Azure environments, identifies reachable ports, and determines what services are running behind them. This complements Security Hub’s existing network reachability findings, which identify configurations that could make a resource reachable from the internet.  Network Scanning confirms actual reachability from the internet. Each reachable port generates a Security Hub finding with evidence of the port and service discovered. Security Hub Exposures then automatically correlates these findings with other findings and resource configurations to determine broader risk.
aws.amazon.com
July 8, 2026 at 9:05 PM
🆕 AWS Security Hub now monitors Microsoft Azure, offering unified security management across clouds. It finds Azure misconfigurations and provides a single console for risk detection and response, simplifying security operations. Free trial available.

#AWS #AwsSecurityHub #AmazonInspector
AWS Security Hub extends unified security management to Microsoft Azure
Today, AWS announces that AWS Security Hub now monitors Microsoft Azure resources, extending risk analytics, cloud security posture management, vulnerability management, and security response management across both clouds. Many AWS customers running workloads in AWS and Azure have had to operate separate security tools for each environment, making it difficult to prioritize risks holistically or respond consistently. Security Hub now provides a single, unified experience to detect and respond to risks across your AWS and Azure environments. Security Hub automatically discovers Azure resources, including Azure Virtual Machines (VMs), Azure Container Registry (ACR) container images, Azure Function Apps, and Azure identities, and evaluates them for misconfigurations, internet exposure, and software vulnerabilities. You receive posture checks against security standards including the CIS Benchmarks™ for Microsoft Azure Foundations, unified resource inventory, risk and exposure analysis, and automated response through existing EventBridge integrations. AWS and Azure findings appear in the same prioritized view with the same finding formats and automation workflows, so security teams can operate from one console rather than switching between tools. Security Hub includes an independent 30-day free trial to monitor Azure resources that begins once you create your integration with Microsoft Azure. After the trial, you pay the same price for monitoring Azure resources and equivalent AWS resources. You can create an integration to Azure from all AWS Regions where Security Hub is available except Middle East (UAE), Middle East (Bahrain), Asia Pacific (Taipei), and Asia Pacific (New Zealand). You can also create integrations to Microsoft Azure for AWS Security Hub CSPM for posture management checks and Amazon Inspector for vulnerability management independently from AWS Security Hub. To learn more, see AWS Security Hub Pricing and AWS Security Hub documentation.
aws.amazon.com
July 7, 2026 at 11:10 PM
AWS Security Hub extends unified security management to Microsoft Azure

Today, AWS announces that AWS Security Hub now monitors Microsoft Azure resources, extending risk analytics, cloud security posture management, vulnerability management, and security re...

#AWS #AmazonInspector #AwsSecurityHub
AWS Security Hub extends unified security management to Microsoft Azure
Today, AWS announces that AWS Security Hub now monitors Microsoft Azure resources, extending risk analytics, cloud security posture management, vulnerability management, and security response management across both clouds. Many AWS customers running workloads in AWS and Azure have had to operate separate security tools for each environment, making it difficult to prioritize risks holistically or respond consistently. Security Hub now provides a single, unified experience to detect and respond to risks across your AWS and Azure environments. Security Hub automatically discovers Azure resources, including Azure Virtual Machines (VMs), Azure Container Registry (ACR) container images, Azure Function Apps, and Azure identities, and evaluates them for misconfigurations, internet exposure, and software vulnerabilities. You receive posture checks against security standards including the CIS Benchmarks™ for Microsoft Azure Foundations, unified resource inventory, risk and exposure analysis, and automated response through existing EventBridge integrations. AWS and Azure findings appear in the same prioritized view with the same finding formats and automation workflows, so security teams can operate from one console rather than switching between tools. Security Hub includes an independent 30-day free trial to monitor Azure resources that begins once you create your integration with Microsoft Azure. After the trial, you pay the same price for monitoring Azure resources and equivalent AWS resources. You can create an integration to Azure from all AWS Regions where Security Hub is available except Middle East (UAE), Middle East (Bahrain), Asia Pacific (Taipei), and Asia Pacific (New Zealand). You can also create integrations to Microsoft Azure for AWS Security Hub CSPM for posture management checks and Amazon Inspector for vulnerability management independently from AWS Security Hub. To learn more, see https://aws.amazon.com/security-hub/pricing/ and https://docs.aws.amazon.com/securityhub/latest/userguide/what-is-securityhub-v2.html.
aws.amazon.com
July 7, 2026 at 10:05 PM
🆕 AWS Security Hub now provides impact analysis for exposure findings, helping teams grasp attacker reach by mapping vulnerable downstream resources, showing attack paths, and adjusting severity scores based on impact scope. For more, see the AWS Security Hub User Guide.

#AWS #AwsSecurityHub
AWS Security Hub adds impact analysis for exposure findings
Today, AWS Security Hub adds impact analysis to exposure findings, helping security teams understand the full scope of what an attacker could reach if an exposure is exploited. Impact analysis extends exposure findings by mapping the downstream resources that could be compromised beyond the initially exposed resource, giving teams deeper visibility into organizational risk. Security Hub analyzes the effective permissions of IAM principals associated with exposed resources to identify privilege escalation paths to other resources in your account. The resulting scope of impact is displayed in the potential attack path graph, and a new Impact Assessment tab shows the prioritized chains of resources an attacker could traverse along with the specific permissions at each step. Security Hub factors the scope of impact into its severity scoring for exposure findings, and adjusts existing exposures as their scope of impact is identified or changes, so that exposures with greater downstream reach are prioritized appropriately. To learn more, see Understanding exposure findings in the AWS Security Hub User Guide and the AWS Security Hub product page. For the full list of AWS Regions where Security Hub is available, see the AWS Regional Services List.
aws.amazon.com
July 7, 2026 at 4:10 PM