Post

Infosec Reading List - April 2026

On a monthly basis I will publish my reading recommendations which mainly focus on Information Security (InfoSec) and Outdoor Sports. All InfoSec Reading Lists can be found here. Text in italic represent quotes from the original article.

InfoSec

  • Another BRICKSTORM: Stealthy Backdoor Enabling Espionage into Tech and Legal Sectors - [link]
  • A serious conversation about Mythos - [link]
  • Reverse engineering Apple’s silent security fixes - [link]
  • How Amazon uses agentic AI for vulnerability detection at global scale - At AWS, we built RuleForge, an agentic-AI system that generates detection rules directly from examples of vulnerability-exploiting code, achieving a 336% productivity advantage over manual rule creation while maintaining the precision required for production security systems and enhanced customer security. - [link]
  • Best mini PC for local LLMs in 2026 (Strix Halo era) - [link]
  • Most Companies Aren’t Anywhere Near Ready for AI - The number one question you should be asking as a company is not what AI can do for you, but whether or not your company is in the state where AI can help at all. And if not, then you need to get into that state as quickly as possible. - [link]
  • Cyber Brief 26-05 - April 2026 - [link]
  • When paradigms are shifting: InfoSec in the age of AI - The paradox is this: we’re being asked to certify compliance for systems whose behavior we cannot fully predict. We’re expected to assure our stakeholders (colleagues, management, customers, suppliers, regulators, the general public) that our AI-integrated processes are secure, controlled, and governed. But the very nature of these systems resists the kind of deterministic assurance that traditional compliance demands. - a lot of great food for thought in this article - [link]
This post is licensed under CC BY 4.0 by the author.