What happened
AWS Compute Optimizer extended its idle-resource detection to six additional service types: DynamoDB provisioned tables, ElastiCache for Redis and Valkey, MemoryDB, DocumentDB in both provisioned and serverless modes, WorkSpaces, and SageMaker endpoints. The feature analyzes utilization patterns and flags resources that are running but generating little to no meaningful workload, surfacing them as candidates for rightsizing or termination. Separately, Cloudflare introduced a direct integration between its Cloudforce One threat-intelligence platform and the Web Application Firewall, exposing new cf.intel fields that security teams can reference inside custom WAF rules. The result is that blocking decisions can now be tied to specific tracked threat actors or targeted industry profiles rather than relying solely on generic traffic signatures.
Why it matters for your business
On the cost side, idle compute and data-service resources are among the largest sources of unplanned AWS spend, and the expansion to databases, caches, and managed endpoints means finance and engineering teams now have a single tool covering a much broader slice of the bill. Organizations running SageMaker inference endpoints or DocumentDB clusters that outlived their original projects are especially likely to find quick wins. On the security side, the Cloudflare update closes the gap between knowing about a threat and acting on it — intelligence that previously required a separate analyst workflow to operationalize can now trigger automatic blocks at the network edge in real time. The practical takeaway: teams should audit Compute Optimizer recommendations this quarter and evaluate whether WAF ruleset templates based on cf.intel fields fit their threat model.
What to watch next
AWS has been steadily broadening Compute Optimizer's scope, and further expansion to additional managed services such as OpenSearch or RDS read replicas would be a logical next step. On the Cloudflare side, watch for richer cf.intel field categories as Cloudforce One's threat-actor tracking matures — finer-grained industry or campaign tagging could make automated WAF policy far more precise. Both announcements reflect a broader industry shift toward embedding cost governance and security enforcement closer to the infrastructure layer rather than treating them as separate operational concerns.
