en.Wedoany.com Reported - Amazon Web Services (AWS) has launched a security service called "AWS Continuum," which automates the entire process from code vulnerability detection to verification, mitigation, and resolution.

AWS believes that traditional security operations can no longer cope with the rapidly changing threat landscape. The new generation of cybersecurity AI models can automatically discover vulnerabilities and infer complex attack paths, leading to a rapid increase in the backlog of vulnerabilities that enterprises need to manage. The service is being launched in a limited preview. Its core lies in not relying on a specific AI model but using the most suitable leading model based on the task, automatically handling the entire lifecycle from discovering code vulnerabilities to taking action.
The service process of AWS Continuum is divided into three phases. In the vulnerability discovery and prioritization phase, it comprehensively analyzes existing vulnerability backlogs and its own scan results, evaluates attack paths, and prioritizes based on actual deployment status, external exposure, and business impact. In the verification phase, the service confirms whether there are false positives and generates reproducible attack examples in a sandbox environment, enabling security leaders to make evidence-based judgments about the likelihood of actual exploitation. In the mitigation and resolution phase, after analyzing the existing defense system, the service proposes response plans such as network configuration changes, policy modifications, and code patches; patch suggestions are automatically verified by the same system that detected the vulnerability, while also providing the scope of impact and rollback paths.
AWS stated that Continuum not only analyzes structured data but also unstructured data such as documents, communications, and business priorities. Therefore, it can perform security judgments that reflect the organization's actual operating environment and business context, rather than uniform rule-based detection. The original AWS security agent penetration testing and code scanning features have been integrated into "Continuum Penetration Testing" and "Continuum Code Scanning," respectively. The "Continuum Threat Modeling" feature, which automatically generates threat models based on design documents and source code, has also been released as a preview.
AWS plans to first apply this service to the security of its own developed code and third-party code, and gradually expand it to overall security in the future. Initially, it will operate in a learning mode with manual review. Once trust is established, it will support automatically executing solutions based on user-defined risk levels.
This article is compiled by Wedoany. All AI citations must indicate the source as "Wedoany". If there is any infringement or other issues, please notify us promptly, and we will modify or delete it accordingly. Email: news@wedoany.com









