Skip to main content

July 2026

Blog posts from July 2026.

Cloud MigrationJuly 31, 20269 min read

CloudFormation-to-Pulumi Migration Starts With Inventory, Not a Rewrite

Pulumi’s Discovered Stacks feature reinforces a lesson many engineering teams learn the hard way: infrastructure modernization depends on knowing what exists before rewriting how it is managed. For teams moving from CloudFormation to Pulumi, the migration path should begin with discovery, ownership mapping, drift analysis, and incremental stack design.

Luke Geaves
AI & ModelsJuly 31, 20268 min read

GPT-Realtime signals OpenAI’s push toward always-on multilingual voice agents

OpenAI’s GPT-Realtime, referenced this week as the model behind avatarin’s 24/7 multilingual retail agent, points to a faster, more natural class of speech-to-speech AI systems. While OpenAI has not disclosed full pricing or context specifications, the model is notable for its focus on real-time conversational audio, multilingual support, and customer-facing voice-agent use cases.

Vibgrate
DevOpsJuly 30, 20269 min read

AWS Lambda Self-Managed Code Storage Changes Serverless Maintenance Economics, Not Deployment Discipline

AWS Lambda can now reference deployment packages from self-managed storage, lifting the account-level code storage quota that often constrained large serverless estates. But the per-function package size limit still applies, which means teams still need disciplined packaging, artifact management, rollback planning, and pipeline controls.

Luke Geaves
AI & ModelsJuly 29, 20267 min read

Qwen3.7 Flash Targets Faster Reasoning for Long-Document and Coding Workloads

Alibaba’s Qwen3.7 Flash arrived on OpenRouter this week as a hosted, low-latency Qwen variant aimed at long-context analysis, general assistant use, reasoning, and code generation. Its most important pitch is not just scale, but the combination of fast interaction with very large text inputs — useful for teams that need practical throughput without giving up long-context capability.

Vibgrate
SecurityJuly 28, 20268 min read

TeamCity RCE Risk Makes CI/CD Modernization a Security Priority

A critical TeamCity On-Premises authentication bypass shows why CI/CD servers must be treated as production-critical systems, not back-office tooling. Beyond emergency patching, engineering leaders should use incidents like this to modernize build infrastructure, reduce secret exposure, segment runners, and shrink the blast radius of compromised delivery systems.

Peter Chapman
AI & ModelsJuly 27, 20269 min read

Claude Opus 5 Arrives With a Production-First Push Into Advanced Reasoning Agents

Anthropic’s Claude Opus 5 and Claude Opus 5 Fast headline this week’s model releases, bringing a new top-tier hosted Claude family aimed at complex reasoning, agentic workflows, and production inference. The notable story is not just scale, but Anthropic’s positioning of Opus 5 as a model for long-running, tool-using systems where reliability, latency, and deployment fit matter as much as raw intelligence.

Vibgrate
SecurityJuly 23, 202611 min read

AI-Era Security Debt: Persistent Agents, Fake AI Tools, and Malware That Ranks Victims

Recent security reports show how attackers are adapting to AI adoption: recruiting AI agents as persistent insiders, disguising malware as AI tooling, and using AI-branded workflows to prioritize victims. Engineering leaders should treat agents, endpoints, approved tools, and audit trails as part of one modern software supply chain threat model.

Luke Geaves
Page 1 of 4