News Aug 6, 2026 👁 12

IT News Roundup: Cloud Spending Peaks, Open Source Vulnerabilities Double, and RMM Campaigns Surge - August 6, 2026

Cloud infrastructure spending hits an eight-year high driven by AI investment, open source vulnerabilities double to 581 per codebase, and threat actors intensify RMM deployment campaigns targeting businesses worldwide.

The technology landscape continues to shift at breakneck pace. Cloud infrastructure spending has surged to levels not seen in eight years, fueled almost entirely by the AI arms race among hyperscalers. Meanwhile, the open source security situation is deteriorating, with vulnerabilities doubling year over year as AI-generated code floods repositories. On the threat side, attackers are increasingly deploying remote monitoring tools through sophisticated social engineering, while tens of thousands of server management interfaces remain dangerously misconfigured.

Cloud Infrastructure Spending Reaches Eight-Year High

Cloud infrastructure spending climbed to its highest level in eight years during the second quarter of 2026, according to data from Synergy Research Group. The surge is being driven almost entirely by artificial intelligence investment, with hyperscale cloud providers expanding data center capacity at unprecedented rates to support AI workloads.

The trend underscores how AI has become the dominant force shaping cloud infrastructure decisions. Organizations that were previously cautious about cloud migration are now accelerating adoption to access AI capabilities, while cloud providers are investing heavily in specialized hardware including GPUs and custom AI accelerators. For homelab enthusiasts and IT professionals, this means the gap between consumer and enterprise-grade AI infrastructure continues to widen, making local AI experimentation increasingly challenging without significant hardware investment.

Source: IT Pro

Big Tech Plans Combined $650 Billion in AI Infrastructure Spending

Amazon, Alphabet, Microsoft, and Meta are collectively planning over $650 billion in capital expenditures for AI infrastructure in 2026, according to industry analysis. This represents an extraordinary concentration of investment in data centers, AI chips, and the power infrastructure needed to support them.

The spending is reshaping not just the technology sector but the broader economy. Deals between tech giants and nuclear energy providers are accelerating as traditional power sources prove insufficient for the electricity demands of large-scale AI training and inference. The market impact extends to semiconductor manufacturers like Nvidia, memory chip producers, and the entire supply chain supporting AI hardware. IT professionals should note that this level of investment could lead to both innovation and potential consolidation as smaller players struggle to compete.

Source: Tech Insider

Open Source Vulnerabilities Double to 581 Per Codebase

Black Duck's 2026 Open Source Security Risk Analysis (OSSRA) report reveals that the average number of vulnerabilities per codebase has doubled to 581 compared to the previous year. The report found that 87% of codebases are at risk, with 65% having been hit by attacks. The increase is largely attributed to the explosion of AI-generated code entering open source repositories.

The findings paint a concerning picture of the open source ecosystem. AI coding assistants are generating vast amounts of code that often contains security flaws, and these components are being incorporated into projects faster than they can be properly reviewed. The report emphasizes that multi-source vulnerability intelligence and continuous monitoring are becoming essential rather than optional. Organizations relying on open source components need to invest in automated dependency scanning and vulnerability management programs.

Source: Black Duck

Microsoft Launches New AI Advisory Company for Enterprise Customers

Microsoft announced the creation of a new company designed to help enterprise customers select and implement AI technologies that deliver measurable returns on investment. The venture addresses a growing pain point for organizations navigating the complex AI landscape — knowing which tools and platforms are right for their specific business needs.

This move positions Microsoft to capture additional revenue from the AI consulting and implementation market, which is expected to grow significantly as more organizations move beyond experimentation to production AI deployments. For IT professionals, the announcement signals that AI strategy and governance are becoming formalized disciplines within enterprise IT, with dedicated roles and processes emerging around AI adoption decisions.

Source: Reuters

Google Cloud Next 2026: "Gentic" AI and Massive Token Processing

At Google Cloud Next 2026, Google highlighted that nearly 75% of its cloud customers are now using AI products, with 330 customers processing over a trillion tokens each in the past 12 months. Google also showcased its "gentic" technology, described as revolutionizing how organizations work with AI systems.

The scale of token processing among Google Cloud's largest customers illustrates how AI workloads have become mainstream rather than experimental. The trillion-token milestone for hundreds of customers indicates that AI is no longer a proof-of-concept exercise but a core operational workload. Google's emphasis on gentic technology suggests a shift toward more autonomous, agent-driven AI systems that can handle complex workflows with minimal human intervention.

Source: Google Cloud Blog

Sophisticated Campaign Deploys RMM Tools via Social Engineering

Cybersecurity researchers have disclosed details of an active, multi-wave attack campaign that uses social engineering lures themed around Adobe and Zoom software updates, business document reviews, and system maintenance utilities to stealthily deploy Remote Monitoring and Management (RMM) programs including ConnectWise ScreenConnect.

RMM tools are designed for legitimate IT support and remote administration, but when deployed by attackers, they provide persistent access to victim networks. The use of familiar software update themes makes these lures particularly convincing. Organizations should ensure that RMM software is properly inventoried, that endpoint detection solutions can identify unauthorized RMM installations, and that employees are trained to verify software update prompts through official channels.

Source: The Hacker News

Over 24,000 Server Management Interfaces Expose Authentication Hashes

Security researchers have identified more than 24,000 internet-accessible server management interfaces that disclose authentication hashes before users even log in. This misconfiguration effectively hands attackers credential material without requiring any exploitation beyond finding the exposed interface.

Server management interfaces including IPMI, iDRAC, and similar out-of-band management systems are critical infrastructure components that are often overlooked during security hardening. Best practices include placing these interfaces behind firewalls with strict access controls, using strong authentication, and ensuring that management traffic is encrypted. System administrators should audit their infrastructure for exposed management endpoints and implement network segmentation to isolate management interfaces from public-facing networks.

Source: SecurityWeek


← Back to Blog