AWS will now watch Microsoft’s cloud for you
The New Stack Frederic Lardinois
AWS's Security Hub can now scan Microsoft Azure resources too, not just its own cloud. It's AWS's first native step outside its own walls — and Google Cloud support is still a question mark.
Based on reporting by The New Stack, Frederic Lardinois — read the original for the full story.
Summary, retelling and take written by AI under human oversight; images are AI-generated illustrations. How we work · Report an error
AWS spent Tuesday proving it's serious about a promise it made back in March, ahead of RSA: Security Hub, its security operations tool, now natively watches Azure resources alongside AWS ones. That's a first for the service, and it's not a small tweak. Security Hub can find a customer's Azure virtual machines, container images, serverless Function Apps, and identities on its own, then run them against the CIS Azure Foundations Benchmark to catch misconfigurations, exposed endpoints, and outdated software. Those findings land in the same ranked queue as AWS findings and can trigger whatever automation a team already built. Pricing mirrors the AWS equivalent, with no extra platform fee, plus a 30-day free trial to test it out.
The launch actually bundles four things, and three of them are live now. Beyond Azure monitoring, there's GuardDuty AI Protection, aimed squarely at Bedrock and SageMaker workloads, watching for anomalous model calls, prompt injection attempts caught through Bedrock Guardrails, and what AWS calls cost harvesting — attackers using stolen credentials to quietly run up someone else's inference bill. Michael Fuller, AWS's director of security services, says he's heard this story before: a security team that only found a compromised account after finance noticed the invoice.
The fourth piece, GuardDuty AI-powered investigations, is still in preview across 10 AWS regions. It takes a first automated pass at GuardDuty findings, separating real threats from noise, and hands back a disposition with a confidence score, a MITRE ATT&CK classification, and remediation suggestions pulled from 90 days of activity. AWS says that turns hours of triage into minutes. Rounding things out is a free AI inventory tool bundled into Security Hub's Essentials plan, which catalogs everything from managed services like Bedrock, SageMaker, and AgentCore to self-hosted models on EC2, ECS, or EKS, and even outside model APIs that internal systems call — all linked back to the infrastructure underneath and any related GuardDuty alerts.
None of this happens in a vacuum. Microsoft's Defender for Cloud has covered AWS since late 2021 and Google Cloud since early 2022, so AWS is late to cross-cloud monitoring, not first. And the timing is a little pointed: Google closed its $32 billion Wiz acquisition in March, a day after AWS pre-announced this very expansion, and Wiz already covers all three major clouds. AWS's AI security tools land in a crowded space too, with Wiz, Palo Alto Networks, and CrowdStrike already selling similar protections.
For now, Security Hub's multicloud reach stops at Azure, and AWS hasn't said a word about whether Google Cloud is next. The whole bet rests on customers wanting one console and one bill to follow their workloads wherever they land. Whether "multicloud" stays a euphemism for "Azure, for now" is the thing to watch.
My take — AI-written commentary, not fact-checked reporting
Calling this a multicloud move while it only covers Azure feels like AWS testing the water with one toe. The real tell will be whether Google Cloud support ever shows up, given that AWS just watched a rival close a $32 billion acquisition that already does all three clouds without blinking. Bundling AI threat detection into the same launch is smart timing, since prompt injection and runaway inference bills are the kind of thing that actually scares finance teams into caring about security. But "one console, one bill" only works if AWS is willing to compete honestly on a rival's turf, not just dip a toe in it.“}}
Read more about this at: The New Stack