OFICIAL AWS What's New

AWS Security Hub MCP App brings exposure findings into your AI-assisted workflow (Preview)

What happened
Based on AWS What's New · Jul 27, 2026

AWS launched a preview of the AWS Security Hub MCP App, a local MCP server integrating Security Hub exposure findings into AI workflows like Claude Desktop to streamline security investigations.

Key points
·
AWS announces the preview of the AWS Security Hub MCP App, a local Model Context Protocol (MCP) server that adds your Security Hub exposure findings directly into Claude Desktop.
·
This capability can help accelerates your security investigations by reducing context switching and manual triage, letting you explore and act on your exposures without leaving your AI-assisted workflow.
·
Each tool call returns both a text summary for your AI agent to reason overover and an interactive visualization for you to verify in the same conversation.
·
The MCP server runs locally on your machine using your existing AWS credentials, and every tool is read-only,-- no changes are made to your environment.

The AWS Security Hub MCP App is a new local Model Context Protocol server that connects Security Hub exposure findings directly to AI-assisted tools such as Claude Desktop. This integration allows security teams to investigate exposures without switching contexts or manually triaging data, reducing the time spent gathering and correlating information. The app is designed to operate within existing AI workflows, enabling natural language queries to retrieve and analyze security posture details efficiently. All interactions are performed locally using established AWS credentials, ensuring no changes are made to the environment.

Users can now view top exposure findings, explore attack paths and network paths associated with specific findings, and examine correlated findings and affected resource configurations. The app also provides remediation recommendations tailored to the identified exposures. Each tool call generates both a text summary for AI reasoning and an interactive visualization for manual verification within the same conversation. This dual output supports both automated analysis and human oversight during investigations.

The Security Hub MCP App operates as a read-only tool, meaning it does not modify any resources or configurations in the AWS environment. It relies on the user’s existing AWS credentials and permissions, maintaining security best practices by limiting actions to data retrieval and analysis. The app is available at no additional cost to existing Security Hub customers, making it accessible without additional licensing fees.

The feature is currently available in preview across all AWS commercial Regions that support Security Hub. Organizations interested in testing the integration can refer to the AWS Security Hub User Guide and the AWS Security Hub product page for detailed instructions. For a complete list of supported Regions, users should consult the AWS Regional Services List. The preview period allows AWS to gather feedback before a potential general release.

Original source → Deals on Clipraptor.com →