AWS、競合のAIコードツールにセキュリティ機能を統合
本文の状態
日本語全文を表示中
詳細モードで約22分の本文を読めます。
同じ出来事の情報源
この情報源を基点に整理
VentureBeat AI
AWS は Black Hat USA 2026 で、競合他社の Claude Code や Codex へ自社のセキュリティ基盤 Continuum を統合し、AI エージェントによる自律的な脆弱性対策を推進すると発表した。
Continue in AI NEW LAB
このニュースを、実務の判断につなげる
AI NEW LABで、試したことや先に確認したい条件を共有できます。まずはログインなしで読めます。
AI NEW LABで論点を見るAI深層分析を開く2026年8月11日 06:06
AI深層分析
キーポイント
競合 IDE へのセキュリティ統合
AWS は Anthropic の Claude Code と OpenAI の Codex に自社の Continuum プラットフォームを直接統合し、開発者がどの AI モデルを使用してもセキュリティ層を制御する方針を示した。
サプライチェーン保護の強化
AWS Security Hub Extended にサプライチェーン保護に特化した 10 番目のカテゴリを追加し、Chainguard や Socket を新たなパートナーとして迎え入れた。
脆弱性バックログの深刻化
Anthropic の Claude Mythos Preview が数千件の未発見ゼロデイ脆弱性を特定したことで、脆弱性の発見から悪用までの時間が 1 時間未満に短縮される可能性が示唆された。
自律型セキュリティへの転換
AWS は人間の監視中心のテロメトリから、エージェントによる文脈理解と自動実行を特徴とする「機械速度での自律的セキュリティ」へとビジョンをシフトさせた。
4段階のアーキテクチャと検証プロセス
発見、優先順位付け、検証、修正の4フェーズで構成され、サンドボックス環境で脆弱性の実際の影響範囲を再現して確認する。
重要な引用
CISOs have had code vulnerabilities for a while, and then Mythos came along, and it just made it a lot worse
They already had a backlog. Now the backlog is 5x more, and that causes a problem.
autonomous security at machine speed
"You go from 100 to 2,000, and now you're like, whoa, I didn't even know which 100 to focus on."
編集コメントを表示
編集コメント
競合の IDE に自社のセキュリティ機能を直接統合する戦略は、AWS が「モデルを支配する」のではなく「セキュリティ層を支配する」ことで市場を再定義しようとする大胆な試みである。Claude Mythos のような高能力 AI モデルが脆弱性を発見・悪用する速度が加速している現状を背景に、開発プロセスの根本的な見直しが迫られている。
Source Article
元記事を日本語で読む
本文に関係しない購読案内、埋め込み通知、サイト内プロモーションは除いています。
Amazon Web Services は、競合他社が構築したコーディング環境に、AI を活用したセキュリティインフラを直接組み込む動きを進めています。これは、モデルそのものを支配するよりも、セキュリティ層を制御することが重要だと判断した大胆な賭けです。
AWS は今月開催された Black Hat USA 2026 で、コードの脆弱性対策プラットフォーム「Continuum」が、Anthropic の Claude Code や OpenAI の Codex、そして AWS 自社の Kiro IDE と直接統合されることを発表しました。この動きにより、開発者がどの AI モデルを利用しているかに関わらず、コード作成の現場に AWS のセキュリティツールを埋め込むことになります。
同時に、AWS は今年 2 月に立ち上げた単一請求書で管理できるセキュリティマーケットプレイス「Security Hub Extended」を拡張し、サプライチェーン保護に特化した第 10 のカテゴリを追加しました。これには Chainguard と Socket がパートナーとして参加しています。
これらの発表は、AI エラにおけるエンタープライズソフトウェア開発のデフォルトとなるセキュリティ制御プレーンとしての AWS の地位確立に向けた、これまでで最も包括的な試みです。この役割は、Synergy Research Group によると世界規模のクラウドインフラ市場が四半期あたり 1430 億ドルを超えたことで、極めて大きな商業的意義を帯びています。
なぜ最先端 AI モデルが脆弱性の蓄積問題を深刻な火災へと変えたのか
今年初に企業のセキュリティ環境を根本から変えた一つの転換点が、今回の二つの発表の背景にある緊迫感を生んでいます。Anthropic が 4 月に発表した「Claude Mythos Preview」は汎用 AI モデルですが、テスト段階で既存のどのシステムも及ばないほど驚異的なサイバーセキュリティ能力を発揮することが判明しました。
リリース前の評価では、Mythos は主要なオペレーティングシステムや Web ブラウザ全体にわたって数千もの未発見のゼロデイ脆弱性を特定しました。これらの脆弱性の 99% 以上は現在もパッチが適用されておらず、脆弱性が発見されてから実際に悪用されるまでの期間(2018 年には 771 日でしたが 2024 年には 4 時間未満に短縮されています)は、2026 年末にはさらに 1 時間未満になると予測されています。
AWS の検索・セキュリティ・観測担当バイスプレジデントである Chet Kapoor 氏は、VentureBeat との独占インタビューでこの課題を厳しい言葉で語りました。「CISO(最高情報セキュリティ責任者)たちは以前からコード上の脆弱性に悩まされていましたが、Mythos が現れたことで事態はさらに悪化しました。すでに処理しきれない backlog(後回し案件)を抱えていたのに、それが 5 倍に膨れ上がり、大きな問題を引き起こしているのです」と Kapoor 氏は述べています。
この問題、すなわち既知の脆弱性の指数関数的な増加が、どの組織も追いつき修正する能力を上回ってしまうという課題こそが、Continuum が解決するために設計されたものです。カプール氏は AWS のより広範なセキュリティビジョンについて、「人間のためのテレメトリ、ストレージ、クエリ、ダッシュボード」から「エージェントによるテレメトリ、文脈、推論、そしてアクション」へとシフトするものだと説明しました。このビジョンを要約したのが、Black Hat 会議で AWS が繰り返し使用したフレーズ、「機械の速度での自律型セキュリティ」です。
コードの欠陥を自動的に発見し修正するための Continuum の 4 つのフェーズシステム
Continuum は、AWS が「エージェントチームループアーキテクチャ」と呼ぶ仕組みとして機能します。これは高度なオーケストレーションハーンであり、各タスクに最適な AI モデルを選択し、顧客環境に接続して検証済みの安全なコードを配信します。その内部では、4 つの明確なフェーズが実行されます。
カプール氏はこれを VentureBeat 向けに解説しました。「発見(Discovery)」フェーズでは複数の最先端 AI モデルを使用してコードをスキャンし、顧客が抱える既存の脆弱性バックログを取り込みます。「優先順位付け(Prioritization)」は、カプール氏によれば「我々の最大の価値提供の一つ」であり、各発見事項を顧客の実際の環境とビジネスリスクという文脈で位置づけます。カプール氏はこう述べています。「100 件から 2,000 件に増えると、『どれに注目すべきかさえわからない』となるでしょう。」
検証フェーズでは、再現可能な攻撃シナリオを隔離されたサンドボックス内で構築し、脆弱性が実際に悪用可能かどうかを確認します。カプール氏は「実行した際にどう振る舞うか」を問うと説明しました。「サンドボックスを作成してその挙動を検証し、被害が及ぶ範囲(ブラスト・レイディアス)を把握できるのです」と続けます。
この検証フェーズでは、顧客自身が記述したファーストパーティコードと、依存するサードパーティのオープンソースコードの両方を対象とします。最後に、リメディー(対策)フェーズでは、ネットワーク設定の変更やポリシー調整、あるいはコードパッチといった修正策を提示します。これらはすべて、システムが同じサンドボックス内で事前にテスト済みのものです。最終的な決定権は常に人間にあり、組織が許容できる自律性のレベルに応じて、各段階での結果承認を行います。
ビジネスモデルも同様に計算され尽くしています。顧客は AWS に対して Continuum の利用料として単一の価格を支払うだけでよく、スキャンの各フェーズで最も性能を発揮する最先端モデルの使用に伴うトークンコストはすべて AWS が負担します。「顧客が購入するのは『Continuum』そのものです」とカプール氏は VentureBeat に語りました。「どのモデルを何に使うかについては私たちが最適化します。正直なところ、GPT Cyber はある分野で優れていますが、Mythos も別の分野では優れた性能を発揮するからです」
AWS が競合他社のセキュリティレイヤーに対して OpenAI と Anthropic のコーディングツール開放をどのように実現したか
今回の発表において最も戦略的に注目すべき点は、OpenAI Codex と Anthropic Claude Code への統合だ。AWS はクラウド AI サービスの分野で両社と直接競合している。Amazon は Anthropic に巨額の投資を行っており、OpenAI も同様のエンタープライズ向け AI ワークロードを巡って自社のインフラを拡大させている。それにもかかわらず、両社は Continuum をそれぞれの開発環境に組み込むことに合意した。
VentureBeat が Kapoor 氏に対し、競合関係の構図について直接質問した際、彼はその前提自体を否定した。「誰が競争相手なのか?」と Kapoor は問い返す。「私は Anthropic や OpenAI をパートナーとして捉え続けています。あなたの質問に含まれる『競争相手』という言葉の意味が理解できません」と述べた。さらに「彼らは私たちのパートナーです。私たちは彼らのモデルを利用し、その環境に接続しています。だからこそ、これらをつなぐために一緒に取り組んだのです」と付け加えた。
Kapoor 氏は、単一のモデルプロバイダーとの連携だけでは不十分だと主張した。「1 つの企業とだけ対応するだけでは十分ではないと思います。時間とともに各社は互いに先を越していくでしょう」と語った。AWS はトークンコストを引き受け、顧客に対して請求書を1枚にまとめることで、Continuum を「モデルのラッパー」ではなく「インフラストラクチャ」として位置づけている。エンジンそのものではなく、それを支えるハッチ(基盤)こそが、持続的な競争優位性の源泉となるのだ。
カプール氏はパートナーシップ発表のブログ記事でこう記しています。「AI ハーネスとは、モデルを囲むオーケストレーション層であり、ツール、ガードレール、メモリ、ワークフローと接続して成果を実現するものです。モデルはエンジンだと考えればよく、ハーネスはその周囲にあるすべての要素です。高性能な車を作るには、この両方が必要なのです。」
AWS のパートナーも同様の論理を支持しています。「企業が直面する最大の課題は、どのモデルを選ぶかではありません。本番環境でそのモデルが何を成し遂げるかを信頼できるかどうかです」と、CRN が報じたコメントの中で、AWS プレミアパートナーである Caylent の CEO、ヴァル・ヘンダーソン氏は述べています。
オープンソース脅威の激化に伴い、AWS はキュレーション済みマーケットプレイスにサプライチェーンセキュリティを追加しました。
Black Hat での AWS の発表のもう一つの柱は、Security Hub Extended を第10のカテゴリとしてサプライチェーンセキュリティへ拡張したことです。これには Chainguard と Socket がキュレーションパートナーとして参加しています。Extended プランでは、現在23のキュレーション済みパートナーソリューションが利用可能で、すべてを単一の AWS 請求書で管理できます。長期契約の必要はなく、エンドポイント、ID、メール、ネットワーク、データ、ブラウザ、クラウド、AI、セキュリティ運用に加え、今回新たにサプライチェーンもカバー対象となっています。
AWSのセキュリティサービス担当ディレクター、マイケル・フルラー氏はVentureBeatに対し、今回の統合は顧客からの要請が唯一の動機だったと明かしました。
「ここ6〜8カ月の間、オープンソースを基盤とする企業がほとんどであるという事実もあり、サプライチェーン分野での動きが大きく注目されています」とフルラー氏。その上で、「顧客からすぐに『Security Hub Extended』への関心が高まっているとの声が寄せられました。主要プレイヤーが揃ったサプライチェーンセキュリティのカテゴリが必要だ、これは私たちにとってホットなトピックだと。そう要望されたのです」。
選ばれた2社のパートナーは、重複を避け補完し合う役割を担うよう選定されました。Chainguardは、検証済みのソースコードから再構築したパッケージや、デフォルトで堅牢化されたコンテナイメージの提供に注力しています。一方、Socketは開発環境に取り込まれるパッケージの振る舞いを監視し、タイポスクワッティング(ドメイン名の類似を利用した攻撃)、メaintainerアカウント乗っ取り、悪意のあるコードの隠蔽といった脅威を検知します。
「この3者で力を合わせれば、AWSが統合を推進し、Chainguardが堅牢化されたクリーンなイメージとパッケージを提供し、Socketがその上に行動分析を重ねることで、顧客には包括的なサプライチェーンセキュリティの提供が可能になります」とフルラー氏は語りました。
この補完的なアプローチは、2 つの異なる攻撃ベクトルに対応しています。1 つ目は、既知の脆弱性を持たない悪意あるパッケージを公開する攻撃です。これに対して Chainguard のクリーンビルド方式が防御します。2 つ目は、正当なメンテナのアカウントを乗っ取り、信頼されるパッケージに汚染された更新をプッシュする攻撃です。Socket の行動検知がこのタイプを検出します。Fuller 氏は、AI コーディング時代において両方のベクトルが増幅されていると指摘しています。その理由は、AI エージェントも人間開発者と同じサプライチェーンリスクに直面しているからです。「エージェントは『探しているのはよく知られたパッケージだ』という情報に騙され、悪意ある隠蔽が施されたものをダウンロードしてしまう可能性があります」。
なぜ AWS はセキュリティ市場を構築するのではなく、各カテゴリで 2 つのパートナーを選んだのか
Security Hub Extended の背後にあるパートナー選定戦略には、AWS Marketplace と明確に異なる哲学が込められています。同マーケットプレイスにはすでに数万件のセキュリティ製品が掲載されています。
Fuller 氏は VentureBeat に対し、顧客は明確な原則を提示したと語りました。「1 つ目は、数百もの選択肢を提供しないでほしいということです。私たちは既に AWS Marketplace を持っています」と Fuller 氏。「2 つ目は、最適なバランスの取れた選択肢を提供してほしいというものです。顧客たちは『各カテゴリで 2 つ選んでほしい』と言っていました。そしてその 2 つは、互いに直接競合するものであってほしくないのです。1 つはよく知られており確立されたプレイヤーを選び、もう 1 つは異なるアプローチを取るプレイヤーを選ぶようにしてください」
フルラー氏は、セキュリティ運用のカテゴリをテンプレートとして挙げました。「Splunk はセキュリティ運用における確立されたリーダーであり、その地位に異論の余地はありません。一方、Seven AI は全く異なるアプローチを採用しており、両者は多くの点で補完関係にあります。」
自社開発とパートナーシップのどちらを選ぶかという判断も、同様のロジックに基づいています。エンドポイント検知・対応(EDR)については、AWS に構造的な優位性がないため、独占的にパートナー企業に委ねています。一方、クラウドセキュリティにおいては、自社のインフラを深く理解しているため、ネイティブツールの自社開発を選択しますが、顧客に第二の選択肢を提供するために Upwind とも提携しています。
「結局のところ、私たちが目指しているのは、AWS 上で顧客が可能な限り安全に運用できる環境を整えることです。セキュリティ事業そのものを拡大することが主目的ではありません」とフルラー氏は語りました。「だからこそ、自社で開発を進めつつ、同時にパートナー企業にも参画を呼びかけるという、両方の道を選ぶことが容易になるのです。」
価格モデルもこのアクセシビリティを強化しています。フルラー氏によると、顧客は従来の長期契約に加え、従量課金型のオプションを求めていました。「Security Hub の拡張版(Extended offerings)には、AWS 内の自社製品と同様に、一般公開された従量課金プランが用意されています。これにより、顧客は従来の販売サイクルを経ずに、実際にサービスを試し、利用を開始し、必要に応じてスケールアップすることが可能になります。」
シャドウエージェントや AI を活用したコストの搾取は、クラウドセキュリティ脅威の新たな最前線として浮上しています
両社の経営陣は、CISO(最高情報セキュリティ責任者)の間で関心が高まっている新たなセキュリティ課題——業界が「シャドウエージェント」と呼ぶようになっている、登録されていないAIエージェントの蔓延と、それによって可能になる新しい攻撃パターン——について言及しました。
カプール氏はベンチャービートに対し、シャドウエージェントは実際に深刻かつ増大する問題だと指摘しましたが、その上でこの問題をコンティニュアムの発表とは区別して説明することに注意を払いました。「Vertex や Agent Core といった登録ディレクトリに登録されているエージェントは数多く存在しますが、登録されていないエージェントも多数あります。これこそがシャドウエージェントと呼ばれる所以であり、実際に害を及ぼす可能性があります」とカプール氏は語りました。「シャドウエージェントを発見するのは容易ではありません。業界全体で対策が進められています。」
フルーラー氏は、AWS がすでに導入している具体的な対策についてより詳細な情報を提供しました。Security Hub には現在、無料の AI インベントリ機能が追加されており、3 つのデータレイヤーを活用しています。まず AWS Config が組織全体の SageMaker、Bedrock、Agent Core といった AI 関連サービスを特定します。次に Amazon Inspector が計算インスタンスやコンテナをスキャンし、AI 関連ソフトウェアを検出します。さらに GuardDuty は DNS のリクエストとレスポンスログを照合し、既知の AI ツールやエージェントワークロードとの不一致を検知します。
インベントリの取得に加え、フルーラー氏は GuardDuty がデータプレーンのイベントも監視していることを明らかにしました。これにはプロンプト内容、プロンプト量のパターン、推論コストの分析などが含まれ、AWS が「コストハーベスト」と呼ぶ不正なコスト搾取を検出する目的で活用されています。
この攻撃は、クラウド認証情報が侵害された後に一般的になった仮想通貨マイニングと似ています。攻撃者は AWS アカウントへのアクセス権を奪い、検知されるまでに可能な限り多くの無料 AI 推論リソースを使い果たそうとします。
「私たちはこれを『コストの収穫』と呼んでいます」とファラー氏は語りました。「攻撃者はインスタンスを起動し、発見されるまでできるだけ多くの無料推論を利用しようと試みます」。ファラー氏によると、これは仮想通貨マイニングで起きたことと同じことが AI の分野でも起きているというものであり、GuardDuty が認証情報の侵害や不正なコンピューティング使用を検知する仕組みは、この新たな脅威に対してもそのまま適用されます。
AWS のエンタープライズセキュリティ戦略において、Continuum と Security Hub Extended はどのように連携するのか
両方の発表が同じ週に行われましたが、AWS はこれらを支える製品を別々のものとして扱っています。カプール氏は VentureBeat に対し、Continuum を Security Hub Extended とは区別される独自のスタンドアロン製品であると説明しました。AWS は、この 2 つ製品の長期的なロードマップについては議論しない方針です。
設計の方向性は明確です。Continuum は、企業が自前で書くコードと、継承したオープンソースに対応します。一方、Security Hub Extended はそれ以外の領域をカバーし、その新カテゴリこそが両者の重なり合う部分です。Continuum の検証フェーズでは、サードパーティ製依存関係だけでなく顧客自身のコードも対象となります。Chainguard と Socket は、別の角度から同じパッケージの強化と監視を行います。一つは自社開発機能、もう一つはパートナーからの選定機能ですが、両者は同じ攻撃面において合流します。
両者の前提となるのは共通しています。つまり、企業は単なるカタログを求めているのではなく、推奨事項を望んでいるのです。
「AI 時代におけるセキュリティ対策について、顧客は明確な指針を求めています」と Kapoor は VentureBeat に語りました。「Security Hub Extended の目的はまさにそれです。自社の見解を提示することでした」。彼はさらに、「自社製品かパートナー製かを問わず、顧客には選択肢を提供し続ける」と付け加えました。
この指針は推奨事項であり、例外措置も用意されていますが、厳選されたマーケットプレイスと自社エージェントプラットフォームを結ぶ共通の軸となっています。これにより、両者の境界線は、個別の発表が示唆する以上に流動的なものになっています。Security Hub はすでに 1 年前には存在しなかった機能を吸収しており、フルラー氏が説明した無料の AI インベントリ機能やコスト関連の検知機能がその例です。コンソールこそが、AWS が企業に対して自社の考え方を提示する場であり、Continuum は同社がこれまでに出してきた中で最も明確な意見表明と言えます。
この指針に対する対象者も変化していますとカプール氏は語りました。Mythos によってセキュリティは CISO の責任領域から、CEO や取締役会レベルの最重要課題へと昇格したのです。「現在、取締役会は企業のセキュリティ状況について頻繁に更新を求めています。なぜなら、それはもはやビジネス上の脅威であり、リスクだからです」。
AWS のセキュリティへの野心は、オーケストレーション層の支配権を握るという計算された賭けを反映しています。
この 2 つの発表は、2026 年を通じて AWS が爆発的なペースで構築してきたより広範な戦略的流れの一部です。同社は re:Invent 2025 で Security Hub を再設計し、GuardDuty、Inspector、CSPM、Access Analyzer を単一のコンソールに統合しました。2 月には「Security Hub Extended」を 14 の厳選されたパートナーソリューションと共に発表。5 月にはカテゴリ数を 9 から 10 に拡大し、ソリューション数は 21 に増えました。現在では、10 カテゴリで 23 のソリューションが利用可能です。Continuum は 6 月のニューヨーク・サミットで登場し、8 月の Black Hat では OpenAI と Anthropic との連携が追加されました。
AWS は 2026 年第 2 四半期に 422 億ドルの売上を記録し、クラウド部門の販売は前年同期比で 37% 拡大しました。同社はグローバルなクラウドインフラ市場において 28% のシェアを握り、Microsoft(20%)や Google(15%)をリードしています。
フルーラー氏は VentureBeat に対し、「AWS は世界中のあらゆる地域と業界、そして民間・政府部門問わず、数万もの顧客が 1 つ以上のセキュリティサービスを利用している」と語りました。この「Extended」プランは、既存の顧客基盤をパートナー製のセキュリティソリューションの利用者へと転換させることを目指しており、これにより顧客とのエンゲージメントを深め、競合他社が AWS をデフォルトプラットフォームから追い落とすことを困難にする狙いがあります。
AWS は 23 のパートナー製セキュリティソリューションの販売元となり、さらに OpenAI や Anthropic のコーディング環境に「Continuum」を組み込むことで、単なる製品ラインを超えたものを構築しようとしています。これは、企業が利用するあらゆる AI モデルや、取り込むオープンソースパッケージ、展開するセキュリティベンダーをつなぐ接着剤のような役割を果たすものです。最先端モデルの進化があまりにも速く、今日の最強のスキャナーですら明日には必須条件に過ぎなくなる世界において、残存し続けるのはモデルそのものではなく、モデルを顧客の環境やポリシー、リスク許容度へと結びつけるハッチ(harness)なのです。
ブラックハットへの飛行機の中で偶然の会話を行ったカプール氏は、なぜこれらが重要なのかを最もシンプルに説明しました。隣に座っていた元CISOで現在はCTOを務める人物が、現在の状況を率直に評価しました。「今も安全になったと感じていません」と。
ベンチャービートに対して語ったカプール氏の返答もまた、同様に率直でした。「取り組んでいます」。
この取り組みが世界を本当に安全にするのか、それともその目標に向かうあらゆる組織にとってAWSを不可欠なものにするのか。いずれにせよ、最終的には同じ結果につながるのかもしれません。
原文を表示
Amazon Web Services is threading its AI-powered security infrastructure directly into the coding environments built by two of its fiercest rivals — and in doing so, it is making a bold bet that controlling the security layer matters more than controlling the model.
AWS announced at Black Hat USA 2026 this month that its Continuum platform for code vulnerabilities will integrate directly into Anthropic's Claude Code and OpenAI's Codex, alongside AWS's own Kiro IDE.
The move embeds AWS security tooling at the point where developers write code, regardless of which AI model they use to do it. Simultaneously, AWS expanded Security Hub Extended — its curated, single-bill security marketplace launched in February — with a 10th security category focused on supply chain protection, bringing in Chainguard and Socket as partners.
Together, the announcements are AWS's most sweeping attempt yet to position itself as the default security control plane for enterprise software development in the AI era — a role that carries enormous commercial implications as the global cloud infrastructure market surpasses $143 billion per quarter, according to Synergy Research Group.
Why frontier AI models turned the vulnerability backlog into a five-alarm fire
The urgency behind both launches traces back to a single inflection point that reshaped enterprise security earlier this year. Claude Mythos Preview, announced by Anthropic in April, is a general-purpose AI model that during testing revealed striking cybersecurity capabilities far exceeding any prior system.
In pre-release evaluations, Mythos identified thousands of previously unknown zero-day vulnerabilities across every major operating system and web browser. More than 99% of those vulnerabilities remain unpatched by their maintainers, and the median time from vulnerability discovery to weaponized exploit — already collapsed from 771 days in 2018 to under four hours by 2024 — is projected to reach under one hour by the end of 2026.
Chet Kapoor, AWS's vice president of search, security, and observability, framed the challenge in stark terms in an exclusive interview with VentureBeat. "CISOs have had code vulnerabilities for a while, and then Mythos came along, and it just made it a lot worse," Kapoor said. "They already had a backlog. Now the backlog is 5x more, and that causes a problem."
That problem — the exponential growth in known vulnerabilities outpacing any organization's ability to triage and fix them — is precisely what Continuum is designed to address. Kapoor described AWS's broader security vision as a shift from "telemetry, storage, query, dashboards for humans to telemetry, context, reasoning, and actions by agents." The shorthand for that vision is a phrase AWS repeated throughout Black Hat: autonomous security at machine speed.
Inside Continuum's four-phase system for finding and fixing code flaws automatically
Continuum operates as what AWS calls an “agent-team loop architecture” — a sophisticated orchestration harness that selects the right AI model for each task, connects to a customer's environment, and delivers validated secure code. Under the hood, it runs through four distinct phases.
Kapoor broke them down for VentureBeat. Discovery uses multiple frontier AI models to scan code and ingest a customer's existing vulnerability backlog. Prioritization — which Kapoor called "one of our biggest value adds" — contextualizes each finding against a customer's actual environment and business risk. "You go from 100 to 2,000, and now you're like, whoa, I didn't even know which 100 to focus on," he said.
Validation then builds reproducible exploits in an isolated sandbox to confirm whether a vulnerability is genuinely exploitable. "Once I do them, how will it behave?" Kapoor explained. "You create a sandbox to go off and make that happen. So you can figure out what the blast radius is." The validation phase covers both first-party code that customers wrote themselves and third-party open source code they depend on. Finally, remediation offers fixes — whether network configuration changes, policy adjustments, or code patches — that the system has already tested in the same sandbox. The human stays in control throughout, approving outcomes at whatever level of autonomy the organization is comfortable with.
The commercial model is equally deliberate. Customers pay AWS a single price for Continuum. AWS absorbs the underlying token costs for whichever frontier model performs best at each phase of the scan. "The customer purchases Continuum, period," Kapoor told VentureBeat. "We optimize on which model to use for what because, quite frankly, GPT Cyber is good at some things, Mythos is good at some things."
How AWS convinced OpenAI and Anthropic to open their coding tools to a rival's security layer
The most strategically striking element of the announcement is the integration with OpenAI Codex and Anthropic Claude Code. AWS competes directly with both companies across cloud AI services. Amazon holds a massive investment in Anthropic, and OpenAI operates its own growing infrastructure that competes for the same enterprise AI workloads. Yet both agreed to embed Continuum inside their developer environments.
When VentureBeat asked Kapoor directly about the competitive dynamics, he pushed back on the framing entirely. "Who is the competitor?" Kapoor said. "I can keep thinking about Anthropic and OpenAI to be partners. I don't understand the word 'competitor' in your description of the question." He added: "They're partners with us. We use their models. We plug into their environments. Which is why we actually brought them together to do this."
Kapoor argued that working with a single model provider would be insufficient. "I don't think it's good enough to just do it with one company," he said. "Everybody is going to leapfrog each other over a period of time." By absorbing token costs and presenting a single bill to the customer, AWS positions Continuum as infrastructure — not a model wrapper. The harness, not the engine, becomes the durable competitive asset.
As Kapoor wrote in his blog post announcing the partnership: "An AI harness is the orchestration layer that wraps around a model to connect it to tools, guardrails, memory, and workflows, so it delivers outcomes. Think of the model as the engine and the harness as everything around it. You need both to have a high-performance car."
AWS partners echoed the logic. "Model choice was never the hard part for enterprises. Trust in what the model does in production is," said Val Henderson, CEO of AWS Premier Partner Caylent, in comments reported by CRN.
AWS adds supply chain security to its curated marketplace as open source threats intensify
The second prong of AWS's Black Hat announcements extends Security Hub Extended into supply chain security as its 10th category, with Chainguard and Socket as curated partners. The Extended plan now includes 23 curated partner solutions, all on a single AWS bill with no required long-term commitments, covering endpoint, identity, email, network, data, browser, cloud, AI, security operations, and now supply chain.
Michael Fuller, AWS's director of security services, told VentureBeat that the addition was driven entirely by customer demand. "Over the last six to eight months, it's gotten quite a bit of news around what's happening in the supply chain space, with the fact that everybody builds on open source," Fuller said. "Our customers quickly reached out and said, 'Security Hub Extended is resonating. We would love to see a supply chain security category with some key players there because it's a hot topic for us.'"
The two partners were chosen to be complementary rather than duplicative. Chainguard focuses on providing hardened, secure-by-default container images and packages rebuilt from verified source code. Socket performs behavioral monitoring of packages as they are pulled into a developer's environment, detecting threats like typosquatting, maintainer account takeover, and obfuscated malicious code. "Together, between the three of us — us with consolidating that, ChainGuard providing really good hardened and cleaned images and packages, and then Socket providing a behavioral analysis over the top — gives customers a really good holistic supply chain security offering," Fuller said.
The complementary approach addresses two distinct attack vectors. An attacker can publish a malicious package that contains no known vulnerabilities — Chainguard's clean-build approach defends against that. Separately, an attacker can compromise a legitimate maintainer's account and push a tainted update to a trusted package — Socket's behavioral detection catches that. Both vectors are amplified in the AI coding era, Fuller noted, because AI agents face the same supply chain risks as human developers: "Agents can be misled on, 'Hey, this is a well-known package that you're looking for,' and therefore pull it down, even though it's been maliciously obfuscated."
Why AWS chose two partners per category instead of building a security marketplace
The partner selection strategy behind Security Hub Extended reveals a deliberate philosophy that distinguishes it from the AWS Marketplace, which already hosts tens of thousands of security offerings.
Fuller told VentureBeat that customers articulated clear principles for what they wanted. "One was don't give me hundreds of offerings. We already have the AWS Marketplace," he said. "Two was give me a sweet spot. Our customers were saying, give me two in each category, and when you look at those two, don't give me head-to-head competitors. Give me one that I may know well, that is an established player, and give me one that's taking a different approach."
Fuller pointed to the security operations category as the template. "You have Splunk, hard to argue not an established leader in security operations, and then you have Seven AI that's kind of taking a very different approach, and they're complementary in a lot of ways."
The decision to build internally versus partner follows a similar logic. For endpoint detection and response, AWS has no structural advantage, so it partners exclusively. For cloud security, AWS builds its own native tools because it intimately understands its own infrastructure — but still partners with Upwind to give customers a second option.
"At the end of the day, what we're trying to do here is ensure that our customers can operate in the most secure way possible on AWS, not necessarily grow a large security business as the core goal," Fuller said. "That's why it's very easy for us to decide to do both building ourselves, but also then inviting partners to participate."
The pricing model reinforces this accessibility. Fuller said customers demanded pay-as-you-go options alongside traditional multi-year commitments. "All of the Security Hub Extended offerings have a public-facing, pay-as-you-go price, just like our first-party offerings do within AWS," he said. "So that gives customers the option to go kick the tires, get going, even scale up and use the services without going through a traditional sales cycle."
Shadow agents and AI cost harvesting emerge as the next frontier of cloud security threats
Both AWS executives addressed an emerging security concern gaining traction among CISOs: the proliferation of unregistered AI agents — what the industry has begun calling "shadow agents" — and the novel attack patterns they enable.
Kapoor told VentureBeat that shadow agents are a genuine and growing problem, though he was careful to separate it from the Continuum announcement. "There are many agents that are registered with registration directories, whether it's Vertex, whether it's Agent Core, whatever else it might be, but there are many agents that are not registered with the registry, and those are what people are calling shadow agents because they can actually do some harm," he said. "Discovering shadow agents is not easy. The industry is working on it."
Fuller provided more granular detail on what AWS has already deployed. Security Hub now includes a free AI inventory capability that uses three data layers: AWS Config identifies AI-related services like SageMaker, Bedrock, and Agent Core across an organization; Amazon Inspector scans compute instances and containers for AI-related software; and GuardDuty compares DNS request and response logs against known AI tools and agentic workloads.
Beyond inventory, Fuller revealed that GuardDuty now monitors data plane events — including prompts, prompt volume patterns, and inference cost analysis — to detect what AWS calls "cost harvesting."
The attack mirrors the cryptocurrency mining that became common after cloud credential compromises: an attacker gains access to an AWS account and burns through as much free AI inference as possible before detection.
"We're seeing what we're calling cost harvesting," Fuller said. "They'll spin up, basically try to get as much free inference as they can until that's discovered." It is, Fuller noted, "the same thing that's happening in AI" as happened with crypto mining — and GuardDuty's detection of credential compromise and unauthorized compute usage translates directly to the new threat.
How Continuum and Security Hub Extended fit together in AWS's enterprise security strategy
Although both announcements landed the same week, AWS is treating the products behind them as separate. Kapoor described Continuum to VentureBeat as distinct from Security Hub Extended, sold as its own standalone product. AWS declined to discuss its longer-term roadmap for the two.
The design logic points in one direction. Continuum addresses the code an enterprise writes and the open source it inherits. Security Hub Extended addresses everything else — and the newest of its categories is where the two most clearly overlap. Continuum's validation phase covers third-party dependencies alongside a customer's own code; Chainguard and Socket harden and monitor the same packages from the other direction. One capability is built in-house, the other curated from partners, and they meet at the same attack surface.
Both proceed from the same premise: that enterprises no longer want a catalog, they want a recommendation.
"Customers want an opinionated point of view on how they should do security in the AI era," Kapoor told VentureBeat. "That's what Security Hub Extended was about — actually going off and giving them our opinion." AWS will continue to give customers choice, he added, "whether it is something that we ship or whether it is something from a partner."
That doctrine — a recommendation, with an escape hatch — is the through line connecting a curated marketplace to a first-party agent platform, and it makes the boundary between them more porous than two separate announcements suggest. Security Hub has already absorbed capabilities that did not exist a year ago, including the free AI inventory and the cost harvesting detections Fuller described. The console is where AWS delivers its opinion to the enterprise. Continuum is the sharpest opinion it has shipped.
The audience for that opinion has changed as well, Kapoor said. Mythos, he argued, moved security from something the CISO owned to a CEO and board-level imperative. "Boards are now asking for updates on what's going on with security in the enterprise because it's a business threat now, it's a business risk."
AWS's security ambitions reflect a calculated bet on owning the orchestration layer
The twin launches fit within a broader strategic arc AWS has been building throughout 2026 at a breakneck pace. The company re-imagined Security Hub at re:Invent 2025 by consolidating GuardDuty, Inspector, CSPM, and Access Analyzer into a single console. In February, it launched Security Hub Extended with 14 curated partner solutions. By May, that number grew to 21 across nine categories. Now it stands at 23 across 10. Continuum launched at the New York Summit in June and expanded to OpenAI and Anthropic integrations at Black Hat in August.
AWS generated $42.2 billion in revenue during Q2 2026, with cloud sales expanding 37% year over year. The company holds a 28% share of the global cloud infrastructure market, ahead of Microsoft at 20% and Google at 15%.
Fuller told VentureBeat that AWS has "tens of thousands of customers using one or multiple of our security services, essentially across all geos that we operate in, and in every industry, and both commercial and government." The Extended plan aims to convert that installed base into users of partner security solutions — deepening engagement and making it harder for competitors to dislodge AWS as the default platform.
By making AWS the seller of record for 23 partner security solutions and embedding Continuum inside the coding environments of OpenAI and Anthropic, AWS is constructing something more durable than a product line. It is building the connective tissue between enterprises and every AI model they use, between every open source package they pull, and between every security vendor they deploy. In a world where frontier models are advancing so rapidly that today's best scanner becomes tomorrow's table stakes, the layer that persists is not the model — it is the harness that connects the model to the customer's environment, policies, and risk tolerance.
Kapoor, reflecting on a chance conversation he had on a flight to Black Hat, offered the simplest articulation of why all of it matters. A former CISO turned CTO sitting beside him volunteered a blunt assessment of the current moment: "I don't feel safer now." Kapoor's response, he told VentureBeat, was equally blunt: "We're working on it."
Whether that work makes the world safer or simply makes AWS indispensable to every organization trying to get there may, in the end, amount to the same thing.
関連記事
News to Guide
ニュースの次に確認する
発表内容を、現在の料金や仕様と照らし合わせられる関連ガイドです。
今日のまとめ
AIデイリーブリーフで今日の重要ニュースをまとめ読み