AWS expanded Security Hub beyond its own cloud to add native visibility into Microsoft Azure, marking the service’s first direct monitoring of infrastructure outside AWS. The update lets Security Hub discover Azure virtual machines, container images, Function Apps, and identities, then evaluate them for misconfigurations, internet exposure, and vulnerable software. AWS said the Azure assessments align with the CIS Microsoft Azure Foundations Benchmark, giving organizations a standardized baseline for multicloud posture management.
AWS also introduced new AI-focused security capabilities, including GuardDuty AI Protection for Amazon Bedrock and SageMaker and AI-powered investigations in Security Hub. The AI protections are designed to detect threats such as anomalous model use, prompt injection attempts, and cost-harvesting abuse tied to stolen credentials, while the investigations feature uses up to 90 days of related activity to generate confidence-scored findings, MITRE ATT&CK mappings, and remediation guidance. AWS said the expansion is aimed at unifying security operations across multicloud environments while improving visibility into both cloud infrastructure and AI assets.

Map this exposure pattern across your cloud, code, and identities.
2 events from the most recent confirmed update back to the earliest known activity.
AWS announced a major Security Hub expansion that adds native monitoring for Microsoft Azure resources and introduces AI security features including GuardDuty AI Protection, AI-powered investigations, and an AI inventory. AWS said Security Hub can discover Azure assets and assess them against the CIS Azure Foundations Benchmark for issues such as misconfigurations, internet exposure, and vulnerable software.
AWS announced that Security Hub is expanding to unify security operations across multicloud environments. This marked the broader launch of multicloud capabilities later described as including Microsoft Azure support.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See where this exposure pattern shows up across your cloud, code, supply chain, and non-human identities.
4 references tracked. Mallory keeps watching after this page renders.
aws.amazon.com
Open sourcethenewstack.io
Open sourceaws.amazon.com
Open sourcecisecurity.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.