Tools

AI-generated text

AWS embeds Continuum into OpenAI and Anthropic coding tools and expands Security Hub Extended with supply chain category

At Black Hat USA 2026, Amazon Web Services announced that its Continuum code‑vulnerability platform will integrate with Anthropic's Claude Code and OpenAI's Codex, and that Security Hub Extended adds a tenth category for supply chain security with partners Chainguard and Socket.

AWS embeds Continuum into OpenAI and Anthropic coding tools and expands Security Hub Extended with supply chain category

At Black Hat USA 2026, Amazon Web Services (AWS) announced that its Continuum code‑vulnerability platform will be integrated directly into Anthropic's Claude Code and OpenAI's Codex developer environments, while remaining available in AWS's own Kiro IDE. The integration places AWS security tooling at the point where developers write code, regardless of the AI model they use.

The announcement is part of AWS's effort to position itself as the default security control plane for enterprise software development in the AI era. AWS cited market context noting that the global cloud infrastructure market now exceeds $143 billion per quarter (Synergy Research Group).

Why the timing matters: Mythos and accelerating exploit timelines

The urgency behind these moves traces back in part to Anthropic's April preview of Claude Mythos. In pre‑release testing, Mythos demonstrated striking cybersecurity capabilities and identified thousands of previously unknown zero‑day vulnerabilities across major operating systems and browsers. More than 99% of those reported vulnerabilities remain unpatched by their maintainers.

Median time from vulnerability discovery to weaponized exploit has already collapsed: from 771 days in 2018 to under four hours by 2024, and projections cited in the industry suggest it could fall below one hour by the end of 2026.

How Continuum works

Chet Kapoor, AWS's vice president of search, security, and observability, says Continuum is designed to address the exponential growth in known vulnerabilities. Continuum operates as an “agent‑team loop architecture,” an orchestration layer that selects the most appropriate AI model for each task, connects to a customer's environment, and delivers validated secure code.

Continuum runs through four phases:

  • Discovery: multiple frontier AI models scan code and ingest an organization's existing vulnerability backlog.
  • Prioritization: findings are contextualized against the customer's actual environment and business risk to surface the most relevant issues.
  • Validation: reproducible exploits are constructed in an isolated sandbox to determine whether and how a vulnerability can be weaponized, including assessing blast radius; this applies to both first‑party and third‑party open source code.
  • Remediation: tested fixes—network or configuration changes, policy updates, or code patches—are proposed and can be applied with human approval at the desired autonomy level.

Kapoor notes that customers pay a single price for Continuum and AWS absorbs token costs for whichever frontier model performs best at each phase. The service is positioned as infrastructure orchestration rather than a wrapper around a single model.

Why OpenAI and Anthropic accepted a rival security layer

Strategically notable is that OpenAI and Anthropic agreed to allow Continuum to be embedded in their coding tools, even though all three companies compete in cloud AI services. Kapoor framed the relationship as partnership rather than pure competition, arguing that relying on a single model provider is insufficient because different models excel at different tasks.

AWS's contention is that the durable competitive asset is not the model engine but the harness—the orchestration layer that connects models to tools, guardrails, memory, and workflows.

Security Hub Extended adds supply chain category with Chainguard and Socket

Alongside Continuum news, AWS expanded Security Hub Extended, its curated single‑bill security marketplace launched in February, by adding a tenth category focused on supply chain protection. The two curated partners for this category are Chainguard and Socket.

Security Hub Extended now lists 23 curated partner solutions on a single AWS bill without mandatory long‑term commitments, covering areas such as endpoint, identity, email, network, data, browser, cloud, AI, security operations, and supply chain.

Michael Fuller, AWS's director of security services, said the addition was driven by customer demand as supply chain risks associated with open source have drawn growing attention over the past six to eight months.

Chainguard and Socket were chosen to be complementary: Chainguard provides hardened, secure‑by‑default container images and packages rebuilt from verified source code, while Socket performs behavioral monitoring of packages as they are pulled into developer environments, detecting threats like typosquatting, maintainer account takeover, and obfuscated malicious code. Together they address two distinct supply chain attack vectors—malicious packages that appear clean and legitimate packages compromised via maintainer account takeover.

Partner selection, build vs. buy, and pricing

Fuller explained that customers asked AWS not to present hundreds of options but to pick a small number of complementary providers per category—typically two—and to avoid head‑to‑head duplicates. In some categories AWS builds native tools (notably where it has structural advantage in understanding its own infrastructure), while in others it partners.

All Security Hub Extended offerings have public, pay‑as‑you‑go pricing, allowing customers to trial services without committing to multi‑year contracts.

Emerging threats: shadow agents and cost harvesting

AWS executives also highlighted two growing concerns for CISOs. The first is the rise of unregistered AI agents—so‑called “shadow agents”—which can evade registries and pose risks; discovery of such agents is difficult.

Fuller described new capabilities already added to Security Hub. A free AI inventory uses three data layers: AWS Config to identify AI‑related services (for example, SageMaker, Bedrock, Agent Core); Amazon Inspector to scan compute instances and containers for AI‑related software; and GuardDuty to compare DNS logs against known AI tools and agentic workloads.

GuardDuty now also monitors data‑plane events—prompts, prompt volume patterns, and inference cost analysis—to detect “cost harvesting,” where an attacker with compromised credentials tries to consume as much free AI inference as possible before detection, mirroring the crypto‑mining incidents that followed credential compromises in the past.

How the announcements fit together

AWS treats Continuum and Security Hub Extended as separate, standalone products, but they are complementary. Continuum focuses on code and third‑party dependencies; Security Hub Extended curates partner solutions for other areas, with the new supply chain category directly overlapping the same package attack surface that Continuum validates. One capability is developed in‑house, the other is partner‑curated, and they meet on the same risks.

Kapoor framed the market shift as one in which customers want opinionated guidance—not just a catalog—on how to secure systems in the AI era. Continuum represents AWS's most assertive recommendation in that regard.

Strategic stakes and market context

The announcements continue a rapid expansion of AWS security offerings in 2026: Security Hub was reconceptualized at re:Invent 2025, Security Hub Extended launched in February with 14 partners and expanded to 21 by May; it now lists 23 solutions across ten categories. Continuum launched at the New York Summit in June and broadened integrations at Black Hat in August.

AWS reported $42.2 billion in revenue in Q2 2026, with cloud sales growing 37% year over year. The company holds roughly 28% of the global cloud infrastructure market, ahead of Microsoft (20%) and Google (15%).

By making AWS the seller of record for 23 partner security solutions and embedding Continuum into the coding environments of OpenAI and Anthropic, AWS is building an orchestration layer that connects enterprises to multiple AI models, every open source package they consume, and the security vendors they deploy. In a fast‑moving frontier model landscape, AWS is betting the persistent layer of value will be the harness that ties models to customers' environments, policies, and risk tolerances.

Final note

Kapoor recalled a passenger's blunt assessment on a flight to Black Hat: "I don't feel safer now." His response, he said, was equally direct: "We're working on it." Whether that work materially increases enterprise safety or ultimately makes AWS indispensable to organizations may converge into the same commercial outcome.