Skip to content
NINTECH

the nintech journal

Insights

Field notes from building AI systems, securing them, and running the infrastructure underneath — plus the advisories, releases, and industry news worth your attention. Written by the engineers who do the work, not a content team.

news & advisories

Industry7 July 2026UK launches Cyber Resilience Pledge as Bill reaches the LordsSeventy founding signatories including M&S, Nationwide and Vodafone signed a new voluntary cyber pledge at Downing Street, while the Cyber Security and Resilience Bill — which brings MSPs into regulation — heads to its Lords second reading.Release watch6 July 2026OpenAI previews GPT-5.6 as the mid-2026 model wave landsOpenAI's three-tier GPT-5.6 family (Sol, Terra, Luna) entered limited preview on 26 June, with Anthropic shipping Claude Sonnet 5 and Google's Gemini 3.5 Pro slipping to July.Advisory1 July 2026SharePoint RCE CVE-2026-45659 joins CISA's exploited listA deserialisation flaw in on-premises SharePoint, patched out-of-band in late May, is now confirmed under active exploitation — with attacks linked to the Warlock ransomware operator Storm-2603.Advisory30 June 2026CitrixBleed returns: NetScaler flaw exploited within 24 hoursCitrix has patched six NetScaler ADC/Gateway vulnerabilities including CVE-2026-8451, a pre-authentication memory disclosure bug in SAML parsing that honeypots caught being exploited within a day of disclosure.Industry29 June 2026EU defers AI Act high-risk duties to December 2027The Council gave final approval to the AI Act simplification omnibus on 29 June, pushing Annex III high-risk obligations back sixteen months — but chatbot transparency duties still bite on 2 August 2026.Release watch18 June 2026Node.js ships fixes for twelve CVEs across 22, 24 and 26 linesThe Node.js project released v22.23.0, v24.17.0 and v26.3.1 to fix twelve vulnerabilities, including two high-severity flaws — one enabling a TLS wildcard authentication bypass.

field notes

Zero Trust, in practice: beyond the buzzwordCyber Security

Cyber Security · 6 July 2026 · 8 min read

Zero Trust, in practice: beyond the buzzword

The perimeter is dead, but most architectures haven't noticed. What Zero Trust actually means in practice — identity over network location, mTLS and microsegmentation — and how to roll it out without buying a box.

Read the article →
Getting quantum-ready: a practical migration to post-quantum cryptoCyber Security

Cyber Security · 8 min read

Getting quantum-ready: a practical migration to post-quantum crypto

Harvest-now-decrypt-later has already started the clock. Crypto-agility over any single algorithm, hybrid ML-KEM key exchange, and finding the cryptography you can't see.

4 July 2026
Evaluating LLMs before they reach productionAI & LLMs

AI & LLMs · 5 min read

Evaluating LLMs before they reach production

Demos lie. A practical method for building eval sets from real tickets, gating model changes in CI, and knowing when to fine-tune.

2 July 2026
An enterprise AI adoption playbook that survives contact with realityEnterprise

Enterprise · 8 min read

An enterprise AI adoption playbook that survives contact with reality

Enterprise AI fails when it starts with a model, not a number. The data gate, evaluation before rollout, trust as an operational property, and killing the zombies.

30 June 2026
Kubernetes without the bill shock: cost and reliability togetherCloud & Infra

Cloud & Infra · 8 min read

Kubernetes without the bill shock: cost and reliability together

Most Kubernetes bills are high because every default over-asks. Right-sizing from real usage, autoscaling that survives spot, per-team cost visibility — and whether you need Kubernetes at all.

27 June 2026
The case for ticket-based managed hostingCloud & Infra

Cloud & Infra · 4 min read

The case for ticket-based managed hosting

Autoprovisioning optimizes for the provider. Why putting an engineer between you and the infrastructure produces better outcomes.

24 June 2026
Securing the software supply chain: SBOMs, provenance, and signingCyber Security

Cyber Security · 8 min read

Securing the software supply chain: SBOMs, provenance, and signing

Your dependencies are the attack surface now. SBOMs you can query at 2am, SLSA provenance and signing, and what SolarWinds and the xz backdoor actually teach.

20 June 2026
SLOs over dashboards: observability that drives decisionsDevOps

DevOps · 7 min read

SLOs over dashboards: observability that drives decisions

Dashboards show everything and decide nothing. SLIs tied to user experience, error budgets as a shared language, and alerting on symptoms not causes.

17 June 2026
RAG systems that survive contact with real dataAI & LLMs

AI & LLMs · 6 min read

RAG systems that survive contact with real data

Retrieval quality beats model size. Chunking as a product decision, citations as a guardrail, and the one metric that matters.

12 June 2026
Blockchain beyond the hype: where distributed ledgers actually pay offBlockchain

Blockchain · 8 min read

Blockchain beyond the hype: where distributed ledgers actually pay off

A decade of pilots died quietly for a reason. The honest three-part test for when a distributed ledger earns its cost — and why the answer is usually Postgres.

9 June 2026
Smart-contract security: auditing what money runs onBlockchain

Blockchain · 8 min read

Smart-contract security: auditing what money runs on

Immutable, transparent, adversarial, and directly monetised — a threat model almost nothing else shares. Reentrancy, oracle manipulation, upgradeability trade-offs, and why passing tests proves almost nothing.

5 June 2026
Platform engineering: paving the road for your teamsEnterprise

Enterprise · 8 min read

Platform engineering: paving the road for your teams

Golden paths, not golden cages. Why cognitive load is the real budget, treating the platform as a product with users — and when you shouldn't build one at all.

2 June 2026
Insights — Nintech