Industry Watch

What I'm reading.

A curated feed of recent publications from sources I trust on infrastructure, cybersecurity, AI, and the practice of IT leadership. Auto-refreshed every 6 hours.

Last refresh: 2026-09-10 03:05 UTC · 40 articles shown · 15 sources

All Categories

Latest — Mixed Feed

Newest first, across all tracked sources.

Testing application resilience with Amazon SQS and AWS Fault Injection Service

AWS Architecture Sep 09, 2026

Learn how to use AWS Fault Injection Service and AWS Systems Manager Automation to run progressive chaos experiments against Amazon SQS queues. Validate that your retry logic, circuit breakers, and dead-letter queues actually work under failure before a real outage hits production.

Validating multi-Region DR for Terraform Enterprise with AWS FIS

AWS Architecture Sep 09, 2026

Learn how AWS, HashiCorp, and Athenahealth designed and chaos-tested a multi-Region disaster recovery strategy for Terraform Enterprise on AWS. This post walks through three-phase AWS Fault Injection Service experiments across Amazon EC2, Aurora, and Amazon S3, the 12-14 minute recovery times ach...

Skullcandy Dime 3 earbuds expose users to Bluetooth hijacking

BleepingComputer Sep 09, 2026

The Carnegie Mellon University CERT Coordination Center (CERT/CC) is warning that Skullcandy Dime 3 wireless earbuds accept Bluetooth pairing requests from nearby unpaired devices without requiring user interaction. [...]

U.S. Disrupts Xinbi Guarantee Scam Marketplace, Freezes $52.8 Million in Crypto

The Hacker News Sep 09, 2026

The U.S. Department of Justice (DoJ) on Wednesday announced coordinated actions aimed at an illicit online marketplace called Xinbi Guarantee that offered scam services, including seizing Telegram channels used to run the service, confiscating two cryptocurrency wallets, and deploying the Scam Ce...

Four Spy Groups Used the Same Chrome and Windows Exploit Kit Within a Week

The Hacker News Sep 09, 2026

Multiple espionage-motivated threat activity clusters have been found deploying a previously undocumented exploit kit called BlueMoon that chains together multiple vulnerabilities in Microsoft Windows and Google Chrome. The first in-the-wild use of BlueMoon has been attributed to the China-aligne...

Driver’s License Data for Sale

Schneier on Security Sep 09, 2026

A database of 153 million drivers licenses is for sale on the dark web. Brian Krebs has more detail.

Get ready for the game with new football features in Search

Google AI Blog Sep 09, 2026

An illustrated graphic set against a vibrant green background featuring American football elements, including a gold trophy, a blue helmet, a silver whistle, a football, a mini scoreboard, and play diagrams, with the icon for AI Mode in Google Search in t

Infostealer Logs Expose Replayable AI Tokens That Can Bypass MFA

The Hacker News Sep 09, 2026

Cybercriminals are hijacking artificial intelligence (AI) user accounts via information stealer logs to create "stolen keys" that grant illicit access to tools from model providers like Google, Anthropic, and others.  Information stealers like Lumma Stealer or Vidar are equipped to harvest a wide...

MFA's Weakest Link: Account Recovery Is the New Attack Path

BleepingComputer Sep 09, 2026

MFA makes account takeover harder, but attackers are increasingly targeting the recovery processes used to reset passwords and authentication methods. Specops explains why stronger identity verification at the service desk is critical to preventing social engineering attacks from turning account ...

The AI policy window is open. We need to act.

OpenAI Blog Sep 09, 2026

Chris Lehane argues that stronger AI capabilities require stronger safety evidence, shared standards, and durable policy action while the policy window remains open.

Webinar: Learn How to Answer “Are We Exposed?” Faster After a New CVE

The Hacker News Sep 09, 2026

A major vulnerability is disclosed. The alert lands immediately. Then comes the harder question: Are we actually exposed? For many security teams, answering that means jumping between vulnerability scanners, endpoint tools, cloud inventories, SBOMs, repositories, and application data to build eno...

DeepSeek Harness Flaw Let AI Agents Disable Their Own File Sandbox Without Approval

The Hacker News Sep 09, 2026

A flaw in DeepSeek Harness, DeepSeek's open-source tool for running AI coding agents on a developer's machine, let a sandboxed agent turn off its own sandbox with a single command. The tool runs an agent's commands inside an operating-system sandbox, so that an agent working on untrusted files ca...

Claude Fable Solves a Historical Cipher

Schneier on Security Sep 09, 2026

Claude Fable 5.1 solved a 370-year-old cipher in forty-four minutes. This tracks with what I wrote about AIs doing mathematics: It’s good at things that involve lots of searching and testing.

U.S. Agencies Accuse China AI Firms of Distilling Claude, GPT, Gemini, and Grok

The Hacker News Sep 09, 2026

U.S. cybersecurity and intelligence agencies have accused China-based artificial intelligence (AI) companies of conducting "systematic extraction" of proprietary functionalities and capabilities of American frontier models through distillation attacks. The activity has been described as occurring...

Chrome V8 Zero-Day Exploited in the Wild Enables Code Execution Inside Sandbox

The Hacker News Sep 09, 2026

Google on Thursday released updates to patch 230 security vulnerabilities, including one that has come under active exploitation in the wild. The medium-severity vulnerability, assigned the CVE identifier CVE-2026-87491 (CVSS score: N/A), has been described as an out-of-bounds bug in V8, Chrome's...

New cPanel Flaw Lets a Hosting Account With Mail Privileges Run Code as Root

The Hacker News Sep 09, 2026

cPanel has patched a flaw that it says lets a single hosting account take control of an entire server. An authenticated account holder with mail-related privileges can create files of their choosing on the server through EmailTrack and, from there, run code as the root user. cPanel published the ...

F5 BIG-IP APM Malware Injects a PHP Web Shell Into Memory, Evading Disk Scans

The Hacker News Sep 09, 2026

Malware linked to break-ins at F5 BIG-IP Access Policy Manager appliances hides a PHP web shell in memory instead of in a file on disk, Sophos said in an analysis published on September 7. When Apache loads any of the three appliances' own PHP scripts, the malware adds the web shell to the copy h...

SAP Patches CVSS 10.0 Kernel Flaw Enabling Unauthenticated Remote Code Execution

The Hacker News Sep 09, 2026

SAP has released security updates to address multiple vulnerabilities, including a maximum-severity flaw in SAP Extended Passport (EPP) Processing that could have a severe impact on the confidentiality, integrity, and availability of the application The vulnerability, tracked as CVE-2026-44756 (C...

Microsoft Patches Record 974 Flaws, Including Two Exploited Windows Zero-Days

The Hacker News Sep 09, 2026

Microsoft on Tuesday broke Patch Tuesday records by addressing an earth-shattering 974 vulnerabilities spanning its software portfolio, including two flaws that it said have been actively exploited in the wild. These include 723 flaws in Windows, 111 in Office and Office 2016, 62 in SQL, and 22 i...

N-able N-central Pre-Auth RCE Flaw Exploited in the Wild

The Hacker News Sep 09, 2026

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday added a maximum-severity security flaw impacting N-able N-central to its Known Exploited Vulnerabilities (KEV) catalog, requiring Federal Civilian Executive Branch (FCEB) agencies to apply the fixes by September 11, 2026....

What OpenAI’s latest controversy tells us about the future of math

MIT Tech Review AI Sep 09, 2026

OpenAI’s latest mathematical milestone has quickly become mired in controversy. Today, the company announced that its agents have solved one of the Millennium Prize Problems, some of the most important open problems in mathematics. Under normal circumstances, that solution would be a huge feather...

Microsoft Plugs Nearly 1,000 Security Holes

Krebs on Security Sep 08, 2026

Microsoft Corp. today issued updates to plug at least 974 security holes in its Windows operating systems and other software, by far its biggest single patch batch ever. Microsoft says artificial intelligence is helping to speed the discovery of vulnerabilities, but security experts warn that man...

The EU CRA's Real Question: What Shipped, and When Did You Know?

BleepingComputer Sep 08, 2026

The EU Cyber Resilience Act's vulnerability reporting requirements take effect September 11, giving software vendors as little as 24 hours to report actively exploited flaws. ActiveState explains why knowing exactly what shipped and when vulnerabilities were discovered will be critical to meeting...

Security

Security — Recent

Skullcandy Dime 3 earbuds expose users to Bluetooth hijacking

BleepingComputer Sep 09, 2026

The Carnegie Mellon University CERT Coordination Center (CERT/CC) is warning that Skullcandy Dime 3 wireless earbuds accept Bluetooth pairing requests from nearby unpaired devices without requiring user interaction. [...]

U.S. Disrupts Xinbi Guarantee Scam Marketplace, Freezes $52.8 Million in Crypto

The Hacker News Sep 09, 2026

The U.S. Department of Justice (DoJ) on Wednesday announced coordinated actions aimed at an illicit online marketplace called Xinbi Guarantee that offered scam services, including seizing Telegram channels used to run the service, confiscating two cryptocurrency wallets, and deploying the Scam Ce...

Four Spy Groups Used the Same Chrome and Windows Exploit Kit Within a Week

The Hacker News Sep 09, 2026

Multiple espionage-motivated threat activity clusters have been found deploying a previously undocumented exploit kit called BlueMoon that chains together multiple vulnerabilities in Microsoft Windows and Google Chrome. The first in-the-wild use of BlueMoon has been attributed to the China-aligne...

Driver’s License Data for Sale

Schneier on Security Sep 09, 2026

A database of 153 million drivers licenses is for sale on the dark web. Brian Krebs has more detail.

Infrastructure

Infrastructure — Recent

Testing application resilience with Amazon SQS and AWS Fault Injection Service

AWS Architecture Sep 09, 2026

Learn how to use AWS Fault Injection Service and AWS Systems Manager Automation to run progressive chaos experiments against Amazon SQS queues. Validate that your retry logic, circuit breakers, and dead-letter queues actually work under failure before a real outage hits production.

Validating multi-Region DR for Terraform Enterprise with AWS FIS

AWS Architecture Sep 09, 2026

Learn how AWS, HashiCorp, and Athenahealth designed and chaos-tested a multi-Region disaster recovery strategy for Terraform Enterprise on AWS. This post walks through three-phase AWS Fault Injection Service experiments across Amazon EC2, Aurora, and Amazon S3, the 12-14 minute recovery times ach...

MCP went stateless: Is your AWS MCP server deployment well-architected?

AWS Architecture Sep 01, 2026

On July 28, 2026, MCP made its protocol core stateless, removing the initialize handshake and session header. This post maps the MCP 2026-07-28 specification to the AWS Well-Architected Agentic AI Lens, pillar by pillar, and shows why the stateless design lets you delete the sticky sessions and s...

Closing the AI agent trust gap with graduated autonomy

AWS Architecture Aug 26, 2026

Most teams give AI agents either full access or read-only, leaving value unused or risk unmanaged. This post describes graduated autonomy, an architectural pattern in which agents earn expanded permissions through sustained reliability and lose them when performance degrades, built on Amazon Bedr...

Build a unified AI agent architecture with DynamoDB and Bedrock

AWS Architecture Aug 21, 2026

With native vector search in Amazon DynamoDB, you can store vector embeddings alongside your operational data in a single table. This post shows how to build a unified AI agent architecture where an Amazon Bedrock agent uses one DynamoDB table for both structured lookups and semantic search, with...

AI

AI — Recent

Get ready for the game with new football features in Search

Google AI Blog Sep 09, 2026

An illustrated graphic set against a vibrant green background featuring American football elements, including a gold trophy, a blue helmet, a silver whistle, a football, a mini scoreboard, and play diagrams, with the icon for AI Mode in Google Search in t

The AI policy window is open. We need to act.

OpenAI Blog Sep 09, 2026

Chris Lehane argues that stronger AI capabilities require stronger safety evidence, shared standards, and durable policy action while the policy window remains open.

What OpenAI’s latest controversy tells us about the future of math

MIT Tech Review AI Sep 09, 2026

OpenAI’s latest mathematical milestone has quickly become mired in controversy. Today, the company announced that its agents have solved one of the Millennium Prize Problems, some of the most important open problems in mathematics. Under normal circumstances, that solution would be a huge feather...

The Work Now Within Reach

OpenAI Blog Sep 08, 2026

Explore how more capable, affordable AI can expand the work people and businesses can accomplish—and make growth more economical.

Practice

Practice — Recent

Article: Eliminating Long-Lived Credentials in GCP with Workload Identity Federation

InfoQ - Architecture Aug 31, 2026

Long-lived GCP service account keys are secrets that must be managed forever, are hard to rotate, and are easy to leak. Scaling Workload Identity Federation to 120+ production projects shows why it changes how machine identity is approached entirely: keys are secrets to manage, federated identiti...

Industry

Industry — Recent

Transparency

Sources I Track

These are the feeds I personally read. If you have a recommendation for another trusted source, let me know.

📡

AWS Architecture

Infrastructure

Visit Source →

📡

Microsoft Tech Community

Infrastructure

Visit Source →

📡

Google Cloud Blog

Infrastructure

Visit Source →

📡

CISA Advisories

Security

Visit Source →

📡

Krebs on Security

Security

Visit Source →

📡

The Hacker News

Security

Visit Source →

📡

BleepingComputer

Security

Visit Source →

📡

Schneier on Security

Security

Visit Source →

📡

Google AI Blog

AI

Visit Source →

📡

OpenAI Blog

AI

Visit Source →

📡

MIT Tech Review AI

AI

Visit Source →

📡

InfoQ - Architecture

Practice

Visit Source →

📡

MIT Sloan Management

Practice

Visit Source →

📡

Ars Technica - IT

Industry

Visit Source →

📡

Gartner Blog Network

Industry

Visit Source →