惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

WordPress大学
WordPress大学
博客园 - 司徒正美
宝玉的分享
宝玉的分享
阮一峰的网络日志
阮一峰的网络日志
The Cloudflare Blog
月光博客
月光博客
博客园 - 【当耐特】
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
博客园 - 三生石上(FineUI控件)
博客园 - 聂微东
小众软件
小众软件
Hugging Face - Blog
Hugging Face - Blog
酷 壳 – CoolShell
酷 壳 – CoolShell
Apple Machine Learning Research
Apple Machine Learning Research
V
V2EX
Jina AI
Jina AI
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
罗磊的独立博客
雷峰网
雷峰网
博客园 - 叶小钗
量子位
IT之家
IT之家

Recent Announcements

Amazon EC2 X8i instances are now available in Europe (Paris) Amazon CloudWatch pipelines now supports drop and conditional processing AWS Deadline Cloud supports monitor creation in multiple regions Amazon CloudWatch pipelines introduces new compliance and governance capabilities Second-generation Amazon FSx for NetApp ONTAP is now available in four additional AWS commercial and AWS GovCloud (US) Regions AWS Billing and Cost Management Dashboards Now Supports Scheduled Email Delivery AWS RTB Fabric supports health checks for real-time bidding workloads AWS Backup extends Amazon FSx support to 5 additional AWS Regions and expands cross-Region and cross-account copy to 14 AWS Regions Amazon RDS now supports the latest CU and GDR updates for Microsoft SQL Server Amazon Timestream for InfluxDB Now Supports Customer-Defined Maintenance Windows Amazon Bedrock now supports cost allocation by IAM user and role Amazon OpenSearch Service supports Managed Prometheus and agent tracing Amazon S3 Lifecycle pauses actions on objects that are unable to replicate Amazon RDS Blue/Green Deployments now supports Amazon RDS Proxy AWS Marketplace announces the Discovery API for programmatic access to catalog data AWS Agent Registry for centralized agent discovery and governance is now available in Preview Amazon OpenSearch Serverless now supports Zstandard (zstd) codec for index compression AWS Private CA now supports customer managed permissions for cross-account sharing Amazon EC2 Capacity Manager now supports tag-based dimensions Amazon Route 53 Resolver endpoints now support DNS delegation for private hosted zones in AWS GovCloud (US) Regions SageMaker HyperPod now supports gang scheduling for distributed training workloads Amazon IVS 实时直播功能现已支持冗余摄取 Amazon EKS 托管节点组现在支持 EC2 Auto Scaling 暖池 Amazon Bedrock AgentCore 浏览器新增操作系统级交互功能 Amazon WorkSpaces Advisor now available for AI-powered troubleshooting Amazon OpenSearch Service now supports Graviton4 based i8ge instances Oracle Database@AWS is now available in twelve AWS Regions AWS Lambda expands response streaming support to all commercial AWS Regions AWS Cost Explorer launches Natural Language Query capabilities powered by Amazon Q Amazon Lightsail 现已在亚太地区(马来西亚)区域推出
AWS Security Hub 现可识别因未使用访问权限导致的身份风险
Amazon Web Services · 2026-05-21 · via Recent Announcements

发布于: 2026年5月20日

今天,AWS Security Hub 将身份风险纳入其统一控制台,中央安全团队已在该控制台中管理威胁、泄露和态势调查发现。Security Hub 现在可以检测 AWS 组织中未使用的 IAM 权限、角色和凭证,帮助中央安全团队大规模识别并降低身份风险。到目前为止,管理数百个账户的身份风险需要在多款工具间反复切换,无法通过统一的视图将未使用的权限与实际资源泄露情况关联起来。Security Hub 现在可以在统一控制台中展示这些身份风险以及威胁、泄露和态势调查发现,助力团队根据实际组织风险确定补救措施的优先顺序。

在您为组织启用 Security Hub 后,系统会自动在每个成员账户中创建一个服务关联的 IAM 访问权限分析器,无需额外进行其他配置。Security Hub 会根据 90 天的实际访问活动评估 IAM 主体,检测未使用的访问权限,并将身份调查发现与泄露上下文关联起来,使团队能够专注于处理极紧要的风险。Security Hub 还会根据实际使用模式,按需生成推荐的最低权限策略,帮助团队优化 IAM 权限并减小攻击面。这些功能为 Security Hub 向更广泛的云基础设施权限管理迈进奠定了坚实的基础,并依托一致的工作流程、自动化规则及下游集成来实现。 它们已包含在 Security Hub Essentials 中,无需额外付费。

要了解更多信息,请参阅 AWS Security Hub 用户指南中的“了解 Security Hub 中的未使用访问权限调查发现”和 AWS Security Hub 产品页面。如需了解已推出 Security Hub 的完整 AWS 区域列表,请参阅 AWS 区域服务列表