AWS has released Amazon Linux 2027 (AL2027) in public preview, building on the Amazon Linux 2023 baseline but changing SELinux to enforcing mode by default. Applications that ran under AL2023's permissive SELinux configuration may now be blocked when policy violations occur, making SELinux policy validation and remediation a primary migration requirement.
The preview includes kernel 7.1 or later, AWS-LC cryptography, and accelerator drivers including AWS Neuron support. AWS has made AMIs and container images available, while on-premises images are not yet offered; the final kernel may change before an LTS release is selected, and AWS has not announced either AL2027 general availability or an end-of-support date for AL2023.

See real exploitation activity before you spend the cycle.
1 event from the most recent confirmed update back to the earliest known activity.
AWS released Amazon Linux 2027 (AL2027) in public preview, based on the Amazon Linux 2023 baseline. The preview enables SELinux enforcing mode by default and provides AMIs in commercial regions plus container base images through the Amazon ECR Public Gallery.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.