<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>Amazon-Bedrock on ZX Cloud Security</title><link>https://zxcloudsecurity.co.uk/tags/amazon-bedrock/</link><description>Recent content in Amazon-Bedrock on ZX Cloud Security</description><generator>Hugo</generator><language>en-GB</language><lastBuildDate>Wed, 03 Jun 2026 20:00:00 +0000</lastBuildDate><atom:link href="https://zxcloudsecurity.co.uk/tags/amazon-bedrock/index.xml" rel="self" type="application/rss+xml"/><item><title>AWS Step Functions Adds AI Agent Steps via AgentCore</title><link>https://zxcloudsecurity.co.uk/posts/aws-step-functions-agentcore-agentic-reasoning-integration/</link><pubDate>Wed, 03 Jun 2026 20:00:00 +0000</pubDate><guid>https://zxcloudsecurity.co.uk/posts/aws-step-functions-agentcore-agentic-reasoning-integration/</guid><description>AWS Step Functions integrates with Amazon Bedrock AgentCore to embed AI reasoning steps in workflows. Key security considerations for architects.</description><content:encoded><![CDATA[<p>🟢 <strong>Low</strong>  |  <strong>Source:</strong> <a href="https://aws.amazon.com/about-aws/whats-new/2026/06/aws-step-functions-agentcore/">AWS What&rsquo;s New</a></p>
<hr>
<p>AWS Step Functions now integrates with Amazon Bedrock AgentCore (currently in preview) to allow AI agent reasoning steps — such as document classification and data extraction — to be embedded directly into automated workflows. This enables multiple agents to run in parallel or sequence within a single workflow, with human approval gates and full audit trails via CloudWatch. For security teams, this introduces AI-driven decision-making into business-critical automation pipelines, expanding the attack surface and governance considerations.</p>
<blockquote>
<p><strong>Architect&rsquo;s Take:</strong> Review IAM permissions granted to Step Functions execution roles that invoke AgentCore harnesses, ensuring least-privilege access and that per-invocation model/prompt overrides cannot be manipulated by untrusted inputs. Establish logging and alerting on CloudWatch agent turn details from day one, and apply human approval steps before any agent action with write or destructive permissions.</p>
</blockquote>
<p><strong>Original advisory:</strong> <a href="https://aws.amazon.com/about-aws/whats-new/2026/06/aws-step-functions-agentcore/">AWS Step Functions adds AgentCore-powered agentic reasoning step</a></p>
]]></content:encoded></item><item><title>OpenAI GPT-5.4 on AWS Bedrock GovCloud (US-West)</title><link>https://zxcloudsecurity.co.uk/posts/openai-gpt-5-4-amazon-bedrock-aws-govcloud-us-west/</link><pubDate>Wed, 03 Jun 2026 19:58:00 +0000</pubDate><guid>https://zxcloudsecurity.co.uk/posts/openai-gpt-5-4-amazon-bedrock-aws-govcloud-us-west/</guid><description>OpenAI GPT-5.4 is now available on Amazon Bedrock in AWS GovCloud (US-West), offering isolated inference for government and regulated-industry workloads.</description><content:encoded><![CDATA[<p>🟢 <strong>Low</strong>  |  <strong>Source:</strong> <a href="https://aws.amazon.com/about-aws/whats-new/2026/06/GPT54-available-in-aws-govcloud-us-west/">AWS What&rsquo;s New</a></p>
<hr>
<p>OpenAI&rsquo;s GPT-5.4 model is now generally available on Amazon Bedrock within AWS GovCloud (US-West), extending access to government and regulated-industry customers. The deployment leverages Bedrock&rsquo;s isolated inference infrastructure, ensuring prompts and responses remain within the customer&rsquo;s AWS environment and are not used for model training. This expands the options available for sensitive workloads requiring complex reasoning and document analysis under strict compliance controls.</p>
<blockquote>
<p><strong>Architect&rsquo;s Take:</strong> Evaluate data residency and access control policies before enabling GPT-5.4 for sensitive workloads — confirm that Bedrock resource policies, VPC endpoints, and CloudTrail logging are configured to meet your organisation&rsquo;s compliance requirements, particularly if handling OFFICIAL-SENSITIVE or equivalent data in GovCloud.</p>
</blockquote>
<p><strong>Original advisory:</strong> <a href="https://aws.amazon.com/about-aws/whats-new/2026/06/GPT54-available-in-aws-govcloud-us-west/">OpenAI GPT-5.4 generally available on Amazon Bedrock in AWS GovCloud (US-West)</a></p>
]]></content:encoded></item><item><title>AWS Config Adds 9 New Resource Types for Bedrock &amp; SageMaker</title><link>https://zxcloudsecurity.co.uk/posts/aws-config-new-resource-types-bedrock-sagemaker/</link><pubDate>Wed, 03 Jun 2026 15:00:00 +0000</pubDate><guid>https://zxcloudsecurity.co.uk/posts/aws-config-new-resource-types-bedrock-sagemaker/</guid><description>AWS Config now supports 9 new resource types across Bedrock and SageMaker, improving compliance visibility for AI/ML workloads in your AWS environment.</description><content:encoded><![CDATA[<p>🟢 <strong>Low</strong>  |  <strong>Source:</strong> <a href="https://aws.amazon.com/about-aws/whats-new/2026/05/aws-config-new-resource-types">AWS What&rsquo;s New</a></p>
<hr>
<p>AWS Config has added support for nine new resource types spanning Amazon Bedrock, Bedrock AgentCore, and SageMaker. This means organisations can now track, audit, and enforce compliance rules against these resources automatically if they have enabled recording for all resource types. The expansion is particularly relevant as AI/ML workloads become a growing part of enterprise cloud environments.</p>
<blockquote>
<p><strong>Architect&rsquo;s Take:</strong> Review your AWS Config recording settings to confirm these new resource types are being captured, and consider authoring or adapting Config rules to enforce security baselines — such as network isolation, encryption, and access controls — for the newly supported Bedrock and SageMaker resources before they proliferate across your environment.</p>
</blockquote>
<p><strong>Original advisory:</strong> <a href="https://aws.amazon.com/about-aws/whats-new/2026/05/aws-config-new-resource-types">AWS Config now supports 9 new resource types</a></p>
]]></content:encoded></item><item><title>AWS SageMaker Studio Auto-IAM Policy: Security Review</title><link>https://zxcloudsecurity.co.uk/posts/aws-sagemaker-studio-auto-iam-policy-model-customization/</link><pubDate>Tue, 02 Jun 2026 16:23:00 +0000</pubDate><guid>https://zxcloudsecurity.co.uk/posts/aws-sagemaker-studio-auto-iam-policy-model-customization/</guid><description>SageMaker Studio now auto-attaches an IAM policy for model customisation. Security architects should audit this managed policy against least-privilege prin</description><content:encoded><![CDATA[<p>🟢 <strong>Low</strong>  |  <strong>Source:</strong> <a href="https://aws.amazon.com/about-aws/whats-new/2026/01/quick-setup-model-customization-sagemaker-studio/">AWS What&rsquo;s New</a></p>
<hr>
<p>Amazon SageMaker Studio&rsquo;s quick setup time has been reduced from over two minutes to under twenty seconds. New Studio environments now automatically receive a managed IAM policy granting serverless model customisation permissions, including fine-tuning, evaluation, and deployment to SageMaker or Bedrock endpoints. This reduces friction for ML practitioners but introduces pre-configured IAM permissions that security teams should review.</p>
<blockquote>
<p><strong>Architect&rsquo;s Take:</strong> Review the scope of the automatically attached AmazonSageMakerModelCustomizationCoreAccess managed policy against your least-privilege baselines — auto-provisioned IAM policies with deployment permissions to Bedrock and SageMaker endpoints may exceed what individual users or teams require. Consider whether your landing zone or Service Control Policies should restrict or audit automatic policy attachment in SageMaker Studio environments.</p>
</blockquote>
<p><strong>Original advisory:</strong> <a href="https://aws.amazon.com/about-aws/whats-new/2026/01/quick-setup-model-customization-sagemaker-studio/">Amazon SageMaker Studio now sets up in seconds with model customization ready from the start</a></p>
]]></content:encoded></item><item><title>Secure Multi-Tenant AI Agents on AWS Bedrock AgentCore</title><link>https://zxcloudsecurity.co.uk/posts/aws-bedrock-agentcore-multi-tenant-ai-resource-based-policies/</link><pubDate>Tue, 02 Jun 2026 16:00:11 +0000</pubDate><guid>https://zxcloudsecurity.co.uk/posts/aws-bedrock-agentcore-multi-tenant-ai-resource-based-policies/</guid><description>Learn how AWS Bedrock AgentCore resource-based policies enforce tenant isolation, cross-account access controls, and VPC-only traffic for SaaS AI workloads</description><content:encoded><![CDATA[<p>🟡 <strong>Medium</strong>  |  <strong>Source:</strong> <a href="https://aws.amazon.com/blogs/security/secure-multi-tenant-ai-agents-with-amazon-bedrock-agentcore-resource-based-policies/">AWS Security Blog</a></p>
<hr>
<p>AWS has published guidance on securing multi-tenant AI agent deployments using Amazon Bedrock AgentCore resource-based policies. SaaS providers can use these controls to isolate tenants, enforce VPC-only traffic for regulated workloads, and manage cross-account access — all from a shared infrastructure. This matters because poorly isolated multi-tenant AI systems can expose one customer&rsquo;s data or capabilities to another.</p>
<blockquote>
<p><strong>Architect&rsquo;s Take:</strong> If you are building or reviewing a multi-tenant SaaS platform on Bedrock AgentCore, implement resource-based policies now to enforce tenant isolation boundaries — pay particular attention to cross-account trust conditions and VPC endpoint restrictions to meet regulatory obligations such as UK GDPR and financial sector requirements.</p>
</blockquote>
<p><strong>Original advisory:</strong> <a href="https://aws.amazon.com/blogs/security/secure-multi-tenant-ai-agents-with-amazon-bedrock-agentcore-resource-based-policies/">Secure multi-tenant AI agents with Amazon Bedrock AgentCore resource-based policies</a></p>
]]></content:encoded></item></channel></rss>