Quick Facts
- AWS Security Hub now natively discovers and monitors Microsoft Azure resources, including virtual machines, containers, and user identities.
- Amazon GuardDuty AI Protection is generally available, detecting cost harvesting attacks, prompt injection attempts, and unusual model usage on Amazon Bedrock and SageMaker.
- A new AI inventory feature gives security teams an organization-wide view of AI assets at no additional cost under the Security Hub Essentials plan.
Amazon Web Services has expanded Security Hub into a multicloud security control plane, adding native Microsoft Azure monitoring, AI workload threat detection, and automated investigation tools. The announcements, made July 14, mark one of the most significant expansions of the platform since AWS unified GuardDuty and Inspector under Security Hub at re:Invent 2025.
The Azure integration is now generally available. Security Hub can discover and monitor Azure virtual machines, containers, function applications, and user identities. The service checks those assets against the CIS Azure Foundations Benchmark, scanning for misconfigurations, software vulnerabilities, and internet exposure.
Azure findings appear in the same format as AWS findings, using the same automation and response workflows. AWS said this allows security teams to work from a single view of risk rather than reconciling alerts across separate systems. AWS said support for additional cloud platforms will follow.
AI Workload Protection Goes GA
Amazon GuardDuty AI Protection is now generally available to all GuardDuty customers, with a 30-day free trial. The service provides threat detection for Amazon Bedrock and Amazon SageMaker by analyzing CloudTrail management and data events from AWS AI services.
GuardDuty AI Protection targets three specific threat types: unusual model invocation patterns, cost harvesting attacks where threat actors force AI resources to consume excessive GPU time and tokens, and prompt injection attempts detected through integration with Amazon Bedrock Guardrails.
A separate capability, GuardDuty AI-Powered Investigations, is available in preview across 10 AWS regions. It automatically analyzes findings and account activity from the past 90 days, using knowledge graphs and threat intelligence to assess whether alerts represent real threats or benign activity. AWS said the tool completes in minutes what previously took hours of manual review.
AI Asset Inventory Added at No Extra Cost
Security Hub now includes an AI inventory that continuously tracks AI assets across an organization. The inventory covers Amazon Bedrock, Amazon SageMaker, and AgentCore resources through AWS Config. It also identifies self-hosted models running on Amazon EC2, Amazon ECS, and Amazon EKS, including the external model endpoints those workloads access.
The inventory maps AI assets to their underlying compute, networking, IAM roles, and data stores. It then correlates those assets with active GuardDuty alerts. The feature is included in the Security Hub Essentials plan at no additional charge.
Network Scanning and Impact Analysis Round Out the Updates
Two additional capabilities launched earlier in July. Network Scanning, released July 8, probes resources from the public internet to determine actual reachability rather than inferring exposure from security group rules. It identifies reachable ports and services across both AWS and Azure environments.
Impact Analysis, released July 6, maps downstream resources that could be compromised if an exposed asset is exploited. It analyzes IAM permissions associated with exposed resources to identify privilege escalation paths. Results appear in a potential attack path graph and a new Impact Assessment tab.
Partner Ecosystem Grows to 21 Vendors
Security Hub Extended now includes 21 curated partner solutions across nine categories, including endpoint, identity, email, network, data, browser, cloud, AI, and security operations. Partners include CrowdStrike, SentinelOne, Splunk, Okta, Proofpoint, Zscaler, SailPoint, and Varonis, among others.
All partner findings conform to the Open Cybersecurity Schema Framework and aggregate automatically inside Security Hub. AWS acts as the seller of record, offering pay-as-you-go pricing, a single bill, and no long-term commitments. AWS Enterprise Support customers receive unified Level 1 support across the partner integrations.
Read more: AWS turns Security Hub into an AI and multicloud security control plane
This article was written by an AI agent. Spotted an error? Send a correction and we will fix it.
