Industry Watch

What I'm reading.

A curated feed of recent publications from sources I trust on infrastructure, cybersecurity, AI, and the practice of IT leadership. Auto-refreshed every 6 hours.

Last refresh: 2026-07-27 02:42 UTC · 40 articles shown · 15 sources

All Categories

Latest — Mixed Feed

Newest first, across all tracked sources.

Malvertising Sends Malware in Pieces, Then Makes the Browser Build the Executable

The Hacker News Jul 25, 2026

A malvertising operation dubbed SourTrade is making victims' browsers build the final Windows executable themselves, using a legitimate Bun runtime as its base instead of serving one complete malicious file from a fixed URL. Confiant, which detailed the campaign on July 23, 2026, said it has oper...

Fastjson 1.x RCE Vulnerability Targeted in Attacks With No Patched Available

The Hacker News Jul 25, 2026

Security firms ThreatBook and Imperva say attackers are targeting a critical flaw in Fastjson, Alibaba's JSON library for Java. In affected Spring Boot applications, a malicious JSON request can execute code without authentication, with the privileges of the Java process. Tracked as CVE-2026-1672...

Researcher Publishes GitLab RCE PoC Letting Authenticated Users Run Commands as Git

The Hacker News Jul 25, 2026

Security researchers at depthfirst published working exploit code on July 24 for a GitLab flaw that GitLab patched six weeks earlier, on June 10. It runs commands as git on any self-managed 18.11.3 server that has not taken the update. Any authenticated user who can push to a project can run it. ...

OpenAI confirms ChatGPT is down worldwide

BleepingComputer Jul 25, 2026

ChatGPT, the famous artificial intelligence chatbot that allows users to converse with various personalities and topics, has connectivity issues worldwide. [...]

BlueNoroff Zoom Phishing Kit Profiles Crypto Wallets Before Malware Delivery

The Hacker News Jul 24, 2026

The North Korean threat actors behind the ClickFix-style campaigns that employ typosquatted Zoom and Microsoft Teams domains have been found to operate an active phishing kit to impersonate the videoconferencing platforms in social engineering campaigns designed to deliver malware. "BlueNoroff ha...

Slopsquatting, Phantom Domains, and HalluSquatting Are the Same AI Attack

BleepingComputer Jul 24, 2026

Slopsquatting, phantom squatting, and HalluSquatting all exploit the same late-binding attack pattern, where AI coding agents trust hallucinated package, repo, or domain names. ActiveState explains how pre-fetch verification and governed dependency management can help stop these attacks before ma...

ChatGPT AgentForger Flaw Could Deploy Rogue Workspace Agents via a Phishing Link

The Hacker News Jul 24, 2026

Cybersecurity researchers have disclosed a critical vulnerability in OpenAI's ChatGPT Workspace Agents that could have allowed a single phishing link to stealthily build, authorize, and deploy an autonomous artificial intelligence (AI) agent inside a victim's organization. The vulnerability has b...

Bing Images Flaws Let Crafted SVGs Run Commands as SYSTEM on Microsoft's Servers

The Hacker News Jul 24, 2026

A crafted SVG submitted to Bing's image search ran commands as NT AUTHORITY\SYSTEM on Microsoft's production image-processing workers, and as root on the Linux machines in the same fleet. XBOW's testing got the same result on workers across different hosts and network ranges, so the problem sat i...

Seeing AI Agents Is Not Enough. Security Teams Must Enforce What They Can Do

The Hacker News Jul 24, 2026

AI agent security is moving through a familiar maturity curve: adoption, then visibility, and finally, control. But what we've collectively discovered is that enforcing least privilege for AI agents is harder than we ever imagined. This is why there are so many approaches, from prompt filtering t...

Why AI Needs a “Genie Coefficient”

Schneier on Security Jul 24, 2026

This essay was written with Barath Raghavan, and originally appeared in IEEE Spectrum. Major benchmarks measure what AI can do. None measure whether it does what you mean: the distance between what you ask an AI to do and the unspoken assumptions about how you want the AI to do it. We propose a n...

Golden Chickens Resurfaces With Four New Malware Families and Modular Implants

The Hacker News Jul 24, 2026

The threat actors behind the Golden Chickens malware-as-a-service (MaaS) ecosystem have resurfaced with four new malware families, indicating that the operators are showing no signs of stopping despite extensive public disclosures into their inner workings. The malware families in question are: T...

Article: The Self-Building Agent: A LangChain4j Experiment

InfoQ - Architecture Jul 24, 2026

The article discusses an experiment where a code assistant had to design an agentic system using LangChain4j documentation. The assistant created a coding framework capable of writing, testing, and debugging code autonomously. Results showed that two architectural patterns—supervisor and workflow...

NodeBB Patches Eight AI-Found Flaws Exposing Admin Access and Private Chats

The Hacker News Jul 24, 2026

Eight security flaws in NodeBB went public on Wednesday, along with the code to exploit them. Aikido Security rates all eight as high severity and says its AI pentest agents found them in a six-hour review of the forum software's source code. Every version before 4.14.0 is affected. NodeBB has fi...

Kimi K3 Agents Found Redis Zero-Days and Built RCE Exploit, Researchers Say

The Hacker News Jul 24, 2026

Redis shipped seven security releases on July 23 after researchers published authenticated RCE PoCs for stock Redis 6.2.22, 7.4.9, 8.6.4, and 8.8.0. All four chains require RESTORE. The Streams chains also need EVAL and XGROUP; the 8.8.0 chain needs EVAL and the bundled RedisBloom module. Redis s...

Fake Notepad++ Plugin Delivers MATCHBOIL.V2 in UAC-0099 Attacks

The Hacker News Jul 24, 2026

The Computer Emergency Response Team of Ukraine (CERT-UA) has warned of a new campaign that involves the use of a malicious program that's dressed up as a Notepad++ plugin to compromise Windows systems. The activity has been attributed by the agency to a threat cluster it tracks as UAC-0099, a Ru...

New Dolphin X malware uses AI to rank high-value targets

BleepingComputer Jul 23, 2026

A new Dolphin X remote access trojan claims to use an AI-powered profiling feature to score and rank infected users, helping cybercriminals identify which victims should be targeted first. [...]

Russian Espionage Group Exploited Zimbra Zero-Day to Steal Mail and 2FA Codes

The Hacker News Jul 23, 2026

A Russian state-supported espionage group spent months reading Western mailboxes through a then-unknown flaw in Zimbra's webmail client. The payload goes after the last 90 days of email, the organization's entire email directory, the password saved in the browser and the codes kept for two-factor...

Claude Cowork Flaw Could Let AI Agent Escape Its VM and Access Mac Files

The Hacker News Jul 23, 2026

Cybersecurity researchers have uncovered a sandbox escape vulnerability in Anthropic's Claude Cowork that makes it possible to break out of the confines of a Linux virtual machine (VM) within which the agent runs to read or write files anywhere on the Mac. Accomplish AI, which shared details of t...

Chaos Ransomware Uses msaRAT to Route C2 Traffic Through Headless Chrome and Edge

The Hacker News Jul 23, 2026

The Chaos ransomware group ran its command-and-control through the victim's own browser. Cisco Talos on Thursday detailed msaRAT, the Rust implant behind it, found on a compromised Windows machine ahead of the encryptor. The implant never opens an outbound connection of its own. Its process talks...

How AI helps scientists design the next generation of medicines

MIT Tech Review AI Jul 23, 2026

Designing and developing a new medicine is an expensive, failure-prone scientific challenge. A new drug can take many years to develop, at the cost of a significant investment. And even then, most possible candidates never reach the patient. For biologic medicines, therapies made from engineered ...

End-to-End Encryption and “Going Dark”

Schneier on Security Jul 23, 2026

New paper: “Encryption and Globalization 15 Years Later: End-to-End Encryption and the Third Round of the ‘Going Dark’ Debate“: Abstract: This Article updates and expands on 2012 research on encryption and globalization, analyzing what the authors call “Round 3” of the Going Dark Debate: the curr...

Security

Security — Recent

Malvertising Sends Malware in Pieces, Then Makes the Browser Build the Executable

The Hacker News Jul 25, 2026

A malvertising operation dubbed SourTrade is making victims' browsers build the final Windows executable themselves, using a legitimate Bun runtime as its base instead of serving one complete malicious file from a fixed URL. Confiant, which detailed the campaign on July 23, 2026, said it has oper...

Fastjson 1.x RCE Vulnerability Targeted in Attacks With No Patched Available

The Hacker News Jul 25, 2026

Security firms ThreatBook and Imperva say attackers are targeting a critical flaw in Fastjson, Alibaba's JSON library for Java. In affected Spring Boot applications, a malicious JSON request can execute code without authentication, with the privileges of the Java process. Tracked as CVE-2026-1672...

Researcher Publishes GitLab RCE PoC Letting Authenticated Users Run Commands as Git

The Hacker News Jul 25, 2026

Security researchers at depthfirst published working exploit code on July 24 for a GitLab flaw that GitLab patched six weeks earlier, on June 10. It runs commands as git on any self-managed 18.11.3 server that has not taken the update. Any authenticated user who can push to a project can run it. ...

Infrastructure

Infrastructure — Recent

Building a serverless AI assistant at Pelago: concept to care in two weeks

AWS Architecture Jul 22, 2026

Healthcare organizations face a critical scaling challenge – how to maintain deeply personalized patient interactions as member bases grow, without overwhelming care teams or compromising quality. At Pelago, a digital health company specializing in substance use disorder support, the engineering ...

Building multi-Region resiliency for AWS CloudFormation custom resource deployment

AWS Architecture Jul 22, 2026

AWS CloudFormation is the foundational tool of infrastructure-as-code for thousands of organizations running workloads on AWS. But as teams push the boundaries of what CloudFormation can do natively, custom resources have emerged as a powerful extension mechanism that unlocks a broad range of pos...

Automate custom PII detection at scale with Amazon Macie and Step Functions

AWS Architecture Jul 22, 2026

Organizations in regulated industries like financial services, insurance, healthcare, and government ingest large volumes of data containing personally identifiable information (PII). Your applications, claims processing systems, partner data feeds, and internal workflows produce files that may i...

Eclipse Dataspace Components on AWS: Cost optimization strategies

AWS Architecture Jul 17, 2026

When you deploy Eclipse Dataspace Components (EDC) connectors on AWS, one of the first challenges you face is predicting and controlling the cost of the required infrastructure. Without clear benchmarks, it is difficult to make informed decisions about workload sizing, environment configuration, ...

Eclipse Dataspace Components on AWS: Architecture patterns in production

AWS Architecture Jul 17, 2026

Running Eclipse Dataspace Components (EDC) connectors in production on AWS requires deliberate architecture decisions around isolation, managed services, and security layering. In Part 1 of this series, we covered the fundamentals of data space architectures and EDC per the International Data Spa...

Eclipse Dataspace Components on AWS: Data sharing fundamentals

AWS Architecture Jul 17, 2026

This three-part blog series guides you through implementing Eclipse Dataspace Components (EDC) on AWS, from foundational concept to production deployment. Part 1 establishes the theoretical foundation with IDSA standards, the Dataspace Protocol (DSP), and core EDC architecture. Part 2 provides pr...

Prioritize your AWS Health alerts using AWS User Notifications

AWS Architecture Jul 16, 2026

If you run critical workloads on AWS, such as a contact center on Amazon Connect Customer, database workloads on Amazon Relational Database Service (Amazon RDS), or hybrid connectivity through AWS Direct Connect, service health events demand your attention. But not all events are equal. An operat...

AI

AI — Recent

How AI helps scientists design the next generation of medicines

MIT Tech Review AI Jul 23, 2026

Designing and developing a new medicine is an expensive, failure-prone scientific challenge. A new drug can take many years to develop, at the cost of a significant investment. And even then, most possible candidates never reach the patient. For biologic medicines, therapies made from engineered ...

Launching Health in ChatGPT

OpenAI Blog Jul 23, 2026

Health in ChatGPT now lets eligible U.S. users securely connect medical records and Apple Health to get more personalized insights and better understand their health.

3 Google updates from Galaxy Unpacked 2026

Google AI Blog Jul 22, 2026

Gentle Monster glasses, Warby Parker glasses, a prompt asking for the history behind a pictured building, and a prompt asking to book a table at a pictured restaurant

Advancing the next era of national science

OpenAI Blog Jul 22, 2026

OpenAI outlines its commitment to advancing American science working with the U.S. Department of Energy and national labs to use frontier AI to accelerate discovery.

Introducing OpenAI Presence

OpenAI Blog Jul 22, 2026

Introducing OpenAI Presence, a proven enterprise AI agent platform that helps organizations deploy trusted voice and chat agents for customer and internal workflows.

Practice

Practice — Recent

Article: The Self-Building Agent: A LangChain4j Experiment

InfoQ - Architecture Jul 24, 2026

The article discusses an experiment where a code assistant had to design an agentic system using LangChain4j documentation. The assistant created a coding framework capable of writing, testing, and debugging code autonomously. Results showed that two architectural patterns—supervisor and workflow...

Industry

Industry — Recent

Transparency

Sources I Track

These are the feeds I personally read. If you have a recommendation for another trusted source, let me know.

📡

AWS Architecture

Infrastructure

Visit Source →

📡

Microsoft Tech Community

Infrastructure

Visit Source →

📡

Google Cloud Blog

Infrastructure

Visit Source →

📡

CISA Advisories

Security

Visit Source →

📡

Krebs on Security

Security

Visit Source →

📡

The Hacker News

Security

Visit Source →

📡

BleepingComputer

Security

Visit Source →

📡

Schneier on Security

Security

Visit Source →

📡

Google AI Blog

AI

Visit Source →

📡

OpenAI Blog

AI

Visit Source →

📡

MIT Tech Review AI

AI

Visit Source →

📡

InfoQ - Architecture

Practice

Visit Source →

📡

MIT Sloan Management

Practice

Visit Source →

📡

Ars Technica - IT

Industry

Visit Source →

📡

Gartner Blog Network

Industry

Visit Source →