News Aug 4, 2026 ๐Ÿ‘ 15

IT News Roundup: Alibaba Qwen3.8-Max, N-able Critical Vulnerability, and Amgen Patient Data Breach - August 4, 2026

This week in IT news: Alibaba unveils its largest AI model yet, a critical N-able N-central authentication bypass reaches managed endpoints, Amgen discloses a major patient data breach via third-party cloud, open-source vulnerabilities double year-over-year, cloud infrastructure spending hits an eight-year high, and SentinelOne debuts autonomous AI response at Black Hat 2026.

The past few days have seen significant developments across AI, cybersecurity, and cloud infrastructure. Alibaba has released its most ambitious AI model to date, while the security landscape faces renewed pressure from critical RMM vulnerabilities, a major healthcare data breach, and a report showing open-source vulnerabilities have doubled. Meanwhile, cloud infrastructure spending continues its AI-driven surge.

Alibaba Unveils Qwen3.8-Max, Its Largest AI Model Yet

Alibaba Group has released Qwen3.8-Max, described as the company's biggest AI model to date. The model, which boasts 2.4 trillion parameters, claims performance on par with Anthropic's PBC on key benchmarks and has already taken the top spot on the BenchLM leaderboard with a score of 78.2.

The release represents a significant escalation in China's AI push, directly challenging US-based leaders like OpenAI and Anthropic. Alibaba said the model is scheduled for general availability next week. Industry analysts note that Qwen3.8-Max edges out rival Moonshot AI's Kimi K3 on several important benchmarks, intensifying competition in the Chinese AI market.

Source: Bloomberg, Fortune

Critical N-able N-central Authentication Bypass Reaches Managed Endpoints

N-able has confirmed that attackers are actively exploiting a critical authentication bypass vulnerability (CVE-2026-18577) in its N-central remote monitoring and management platform. The flaw allows attackers to gain remote administrative access to N-central servers and subsequently reach the customer endpoints managed through those servers.

Complicating matters, N-able's initial fix for a related issue (CVE-2026-18556) proved incomplete, enabling the secondary vulnerability. The company released build 2026.3.1.7 on August 2 as the first fully patched version. All supported versions through 2026.3.1 โ€” both cloud-hosted and on-premises deployments โ€” are affected.

Security researchers at Huntress and others have already observed exploitation in the wild, with attackers using compromised N-central instances to pivot into managed customer environments. IT professionals running N-central are urged to upgrade immediately.

Source: The Hacker News, Huntress

Amgen Discloses Major Data Breach Exposing Patient Health Information

Biopharmaceutical giant Amgen has confirmed a material cybersecurity incident in which attackers infiltrated cloud storage systems operated by third-party service providers. The breach, detected in July, resulted in the theft of proprietary corporate data and files containing patients' protected health information (PHI).

The company disclosed the incident on July 31 via an SEC Form 8-K filing, classifying it as a material breach. Amgen stated that there has been no disruption to manufacturing, financial reporting, product availability, or its ability to supply medicines. The full scope of the data compromised and the identity of the threat actors remain unclear.

This breach adds to a growing pattern of attacks targeting healthcare and life sciences organizations through their cloud supply chain. Check Point's latest threat intelligence report highlighted Amgen among several major incidents in its August 2026 briefing.

Source: BioTech Reality, Mercury News

Open-Source Vulnerabilities Double Year-over-Year, Black Duck Report Finds

Black Duck's 2026 Open Source Security Risk Analysis (OSSRA) report reveals that the mean number of vulnerabilities per codebase has more than doubled, climbing from 280 to 581 in a single year. The report found that 87% of codebases are now at risk, with 65% having been hit by attacks.

The surge is largely attributed to the explosive growth in AI-driven development tools, which have accelerated code production but also introduced more third-party dependencies into software supply chains. The report warns that organizations relying on single-source vulnerability intelligence are falling behind, recommending multi-source monitoring and exploit-aware prioritization.

Christopher Robinson, CTO of the Open Source Security Foundation, issued a stark warning earlier this year that a major AI-driven cyberattack on open-source infrastructure is imminent โ€” a concern now reflected in the data.

Source: Black Duck, Help Net Security

Cloud Infrastructure Spending Hits Eight-Year High Amid AI Boom

Cloud infrastructure spending reached an eight-year high in the second quarter of 2026, according to Synergy Research Group. The surge is driven almost entirely by AI-related investments, with the largest tech companies collectively planning over $650 billion in AI infrastructure capital expenditures for the year.

AWS maintains its lead at 30% of global cloud infrastructure spend, followed by Microsoft Azure at 25% and Google Cloud at 13%. Together the three hyperscalers control 68% of total enterprise cloud spending. Microsoft executives noted the company is well-positioned with its current data center investments as cloud revenue continues to accelerate.

The spending boom has also prompted innovation beyond the hyperscalers, with AI-focused infrastructure providers like CoreWeave and Flexential gaining traction, and the race to build data centers โ€” including experimental orbital facilities โ€” intensifying globally.

Source: IT Pro, Tech Insider

SentinelOne Debuts Autonomous AI Response Platform at Black Hat 2026

At Black Hat USA 2026, SentinelOne unveiled an update to its Singularity Platform featuring "Purple AI" โ€” a governed, closed-loop autonomous response system. The technology allows an AI agent to investigate security alerts, reach verdicts, and execute containment actions within boundaries set by security teams, with every action fully traceable and reversible.

The platform is expected to reach general availability later this quarter. The announcement reflects a broader industry shift toward AI-assisted security operations, where autonomous systems handle initial triage and response while human analysts focus on complex incidents. Similar autonomous response capabilities have been announced by several other vendors this year, signaling a maturing category.

Source: SecurityWeek


โ† Back to Blog