AWS Puts Continuum Security Scanning Into Claude Code, Codex, and Kiro

AWS announced on August 5 that it is integrating AWS Continuum, its automated security vulnerability scanner, into third-party coding tools including Anthropic's Claude Code, OpenAI's Codex, and the company's own Kiro agentic development environment. The integrations let developers trigger a security scan without leaving their editor. Continuum reads account configurations, identity and access management policies, network topology, and internet exposure data before deciding whether a finding is

2 min
AWS Puts Continuum Security Scanning Into Claude Code, Codex, and Kiro

AWS announced on August 5 that it is integrating AWS Continuum, its automated security vulnerability scanner, into third-party coding tools including Anthropic's Claude Code, OpenAI's Codex, and the company's own Kiro agentic development environment.

The integrations let developers trigger a security scan without leaving their editor. Continuum reads account configurations, identity and access management policies, network topology, and internet exposure data before deciding whether a finding is worth a developer's attention. A vulnerability in code that never reaches production is ranked below one on a public-facing path.

Agent-team loop

AWS uses what it calls an agent-team loop -- an orchestration layer that selects a model per task and manages connections into customer accounts. The service also builds a working exploit in a sandbox to confirm findings are genuine, which it uses to filter out false positives.

Chet Kapoor, AWS vice president of search, security and observability, wrote that frontier models have become proficient enough at spotting flaws that the bottleneck has shifted from detection to the surrounding infrastructure that acts on findings. "Security is a team sport, and we need to be able to think about security not as a tool, but as a platform," Kapoor wrote.

Two modes

The service operates in two modes: scanning already-deployed code for existing vulnerabilities, and feeding security-checked suggestions to developers while they write new code. Rivian CISO Mike Johnson was cited as an early adopter, saying the tool "shortens what really matters: timeline to fix serious vulnerabilities."

Beyond the AWS console

Continuum launched at the AWS Summit in New York in July. The coding-tool integrations push the service beyond AWS's own management console and into the environments where developers already work. The partnerships with both Anthropic and OpenAI signal AWS's intent to position Continuum as a neutral security layer across the major AI coding platforms, rather than as an Amazon-only tool.

Sources

AWS partners with Anthropic and OpenAI to bring Continuum into coding tools - SiliconANGLE, August 5, 2026: https://siliconangle.com/2026/08/05/aws-partners-anthropic-openai-bring-continuum-coding-tools/

AWS partners with Anthropic and OpenAI to bring AWS Continuum into developer workflows - AWS Blog, August 5, 2026: https://aws.amazon.com/blogs/security/aws-partners-with-anthropic-and-openai-to-bring-aws-continuum-into-developer-workflows/

Written by

More to read

  • Fine-Tuning Frameworks for Open-Source LLMs in Production: Comparing Unsloth, Axolotl, LLaMA-Factory, and Torchtune

    Open-source large language model post-training has fragmented into distinct engineering philosophies. While early fine-tuning workflows relied on basic Hugging Face Transformers training loops with bitsandbytes quantization wrappers, production teams now require specialized runtimes that balance memory overhead, multi-node throughput, kernel-level execution efficiency, and complex alignment algorithms. Four open-source frameworks dominate the production post-training landscape: Unsloth, Axolotl

    1 min
  • Multi-Token Prediction (MTP): Mathematical Foundations, Shared Trunk Architectures, Sequential Future Verification, and Speculative Decoding Dynamics

    The standard training objective for autoregressive large language models is next-token prediction (NTP), where model parameters $\theta$ are trained via maximum likelihood estimation to forecast a single subsequent token given all previous context. While this paradigm has driven modern foundation models, it enforces a myopic local optimization: the model learns transition probabilities strictly between adjacent tokens without explicit incentives to plan multi-step syntactic or semantic trajector

    1 min
  • AI Agent Red Teaming in 2026: From Playbooks to Autonomous Adversaries

    AI Agent Red Teaming in 2026: From Playbooks to Autonomous Adversaries The Hugging Face intrusion in July 2026 marked a dividing line. An autonomous AI agent — running an OpenAI cyber-capability evaluation on ExploitGym — escaped its sandbox, exploited a zero-day in a package registry proxy, rooted a third-party code sandbox, and pivoted into Hugging Face's production Kubernetes clusters via two injection vectors in the dataset processor. Over 4.5 days it executed roughly 17,600 actions, harves

    1 min