Automate certificates with ACME support in AWS Certificate Manager

TutoSartup excerpt from this article:
Customers that are using third-party certificate authorities (CAs) can point their existing ACME-compatible clients at ACM instead of their current CA, with minimal reconfiguration... This launch brings the ACM automation model to that same infrastructure, using the standard ACME protocol with AWS managed certificate endpoints... How it works The feature introduces a new centrally provisio...

Route Amazon Bedrock Guardrails interventions to Amazon Security Lake

TutoSartup excerpt from this article:
It transforms matching events into OCSF-compliant Detection Finding records (class_uid 2004) and delivers them to Security Lake as Parquet files... Guardrail interventions are detection events: the guardrail detected and blocked prohibited content, so OCSF class 2004 (Detection Finding) under the Findings category is the appropriate classification... The Lambda function transforms each interven...

Securing AI agents with temporal policies in Amazon Bedrock AgentCore

TutoSartup excerpt from this article:
Before AI agents, it was generally sufficient for access controls to treat each action as an independent event... AI agents behave in fundamentally different ways than traditional applications... That flexibility, combined with increasingly intelligent models, makes agents equal measures capable and challenging to control... The question then becomes, how do you enforce authorization rules that ac...

Configure rate limits for AI traffic on AgentCore gateway

TutoSartup excerpt from this article:
Today, we are announcing support for rate limiting on AgentCore gateway, giving you fine-grained control over how much traffic individual users can consume through your gateway... Rate limiting in AgentCore gateway gives you per-user control over how users consume your tools, inference models, and agents... Centralized rate limiting for AI traffic with AgentCore gateway AgentCore gateway provi...

Control agent behaviors and cost beyond a single action: new capabilities in Amazon Bedrock AgentCore

TutoSartup excerpt from this article:
According to McKinsey, roughly 80% of organizations have already encountered risky behavior from AI agents... As a result, security and risk concerns are the leading barrier to scaling agentic AI (McKinsey’s State of AI Trust in 2026, and Trust in the age of AI agents 2026)... That makes trust the pacing factor for agent innovation and adoption... We believe that investment in trust and securi...

Caching KMS data keys in multi-thread environments: Per-tenant encryption for event-driven systems at scale

TutoSartup excerpt from this article:
By rethinking how they cache encryption keys, they reduced their AWS Key Management Service (AWS KMS) costs by 77% while maintaining strict security guarantees and per-tenant encryption isolation... In this post, we explore the cache stampede problem that emerges when envelope encryption meets high-concurrency, multi-tenant architectures... The cache stampede problem Envelope encryption r...

Trump’s Calls to Warsh Add Political Crosscurrent to Fed’s Path

TutoSartup excerpt from this article:
The Federal Reserve is steering through a thicket of macro crosscurrents, and the challenge is sharpening amid a new report that President Trump has been calling Chair Kevin Warsh since he took the helm at the central bank in May...The Wall Street Journal reports that President Trump has “repeatedly” called Fed Chair Kevin Warsh—discussing AI and Iran, but avoiding interest rates... Th...