惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

M
MIT News - Artificial intelligence
罗磊的独立博客
Hugging Face - Blog
Hugging Face - Blog
Apple Machine Learning Research
Apple Machine Learning Research
Last Week in AI
Last Week in AI
S
SegmentFault 最新的问题
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
美团技术团队
人人都是产品经理
人人都是产品经理
WordPress大学
WordPress大学
The Cloudflare Blog
IT之家
IT之家
雷峰网
雷峰网
小众软件
小众软件
博客园 - 叶小钗
博客园 - 聂微东
爱范儿
爱范儿
博客园 - 司徒正美
博客园 - 三生石上(FineUI控件)
V
Visual Studio Blog
博客园 - 【当耐特】
V
V2EX
博客园_首页
T
Tailwind CSS Blog

Recent Announcements

Amazon EC2 X8i instances are now available in Europe (Paris) Amazon CloudWatch pipelines now supports drop and conditional processing AWS Deadline Cloud supports monitor creation in multiple regions Amazon CloudWatch pipelines introduces new compliance and governance capabilities Second-generation Amazon FSx for NetApp ONTAP is now available in four additional AWS commercial and AWS GovCloud (US) Regions AWS Billing and Cost Management Dashboards Now Supports Scheduled Email Delivery AWS RTB Fabric supports health checks for real-time bidding workloads AWS Backup extends Amazon FSx support to 5 additional AWS Regions and expands cross-Region and cross-account copy to 14 AWS Regions Amazon RDS now supports the latest CU and GDR updates for Microsoft SQL Server Amazon Timestream for InfluxDB Now Supports Customer-Defined Maintenance Windows Amazon Bedrock now supports cost allocation by IAM user and role Amazon OpenSearch Service supports Managed Prometheus and agent tracing Amazon S3 Lifecycle pauses actions on objects that are unable to replicate Amazon RDS Blue/Green Deployments now supports Amazon RDS Proxy AWS Marketplace announces the Discovery API for programmatic access to catalog data AWS Agent Registry for centralized agent discovery and governance is now available in Preview Amazon OpenSearch Serverless now supports Zstandard (zstd) codec for index compression AWS Private CA now supports customer managed permissions for cross-account sharing Amazon EC2 Capacity Manager now supports tag-based dimensions Amazon Route 53 Resolver endpoints now support DNS delegation for private hosted zones in AWS GovCloud (US) Regions SageMaker HyperPod now supports gang scheduling for distributed training workloads Amazon IVS 实时直播功能现已支持冗余摄取 Amazon EKS 托管节点组现在支持 EC2 Auto Scaling 暖池 Amazon Bedrock AgentCore 浏览器新增操作系统级交互功能 Amazon WorkSpaces Advisor now available for AI-powered troubleshooting Amazon OpenSearch Service now supports Graviton4 based i8ge instances Oracle Database@AWS is now available in twelve AWS Regions AWS Lambda expands response streaming support to all commercial AWS Regions AWS Cost Explorer launches Natural Language Query capabilities powered by Amazon Q Amazon Lightsail 现已在亚太地区(马来西亚)区域推出
AWS Security Hub 现可识别因未使用访问权限导致的身份风险
Amazon Web Services · 2026-05-21 · via Recent Announcements

发布于: 2026年5月20日

今天,AWS Security Hub 将身份风险纳入其统一控制台,中央安全团队已在该控制台中管理威胁、泄露和态势调查发现。Security Hub 现在可以检测 AWS 组织中未使用的 IAM 权限、角色和凭证,帮助中央安全团队大规模识别并降低身份风险。到目前为止,管理数百个账户的身份风险需要在多款工具间反复切换,无法通过统一的视图将未使用的权限与实际资源泄露情况关联起来。Security Hub 现在可以在统一控制台中展示这些身份风险以及威胁、泄露和态势调查发现,助力团队根据实际组织风险确定补救措施的优先顺序。

在您为组织启用 Security Hub 后,系统会自动在每个成员账户中创建一个服务关联的 IAM 访问权限分析器,无需额外进行其他配置。Security Hub 会根据 90 天的实际访问活动评估 IAM 主体,检测未使用的访问权限,并将身份调查发现与泄露上下文关联起来,使团队能够专注于处理极紧要的风险。Security Hub 还会根据实际使用模式,按需生成推荐的最低权限策略,帮助团队优化 IAM 权限并减小攻击面。这些功能为 Security Hub 向更广泛的云基础设施权限管理迈进奠定了坚实的基础,并依托一致的工作流程、自动化规则及下游集成来实现。 它们已包含在 Security Hub Essentials 中,无需额外付费。

要了解更多信息,请参阅 AWS Security Hub 用户指南中的“了解 Security Hub 中的未使用访问权限调查发现”和 AWS Security Hub 产品页面。如需了解已推出 Security Hub 的完整 AWS 区域列表,请参阅 AWS 区域服务列表