EVA Tech BriefIT/DevOps

2026-07-20 - 7:30 PM PKT

Frontier LLMs

China's Kimi K3 and Qwen3.8 challenge frontier AI labs

Moonshot and Alibaba released large open-weight AI models that they say approach or beat top US systems in key coding and benchmark tasks. The shift matters for teams evaluating model cost, availability, and geopolitical risk, because Chinese labs are pushing strong open models while US leaders remain more closed.

GPUs and Silicon

Nvidia's Japan visit points to national AI infrastructure demand

Jensen Huang left Tokyo with deals spanning Japan's technology ecosystem. For GPU buyers, the signal is that national AI programs are competing directly with hyperscalers and labs for scarce accelerators, keeping supply allocation and deployment timelines strategic.

Cloud and Infra

Airbus move from AWS puts sovereign cloud back in focus

Airbus's move away from AWS for sensitive workloads puts sovereign cloud back on the procurement agenda. The broader risk for enterprise cloud teams is that compliance, data jurisdiction, and concentration risk can override pure platform convenience for critical systems.

Pakistan Tech

Security

Critical ServiceNow RCE is now exploited in attacks

Attackers are now exploiting CVE-2026-6875, a critical code execution flaw in the ServiceNow AI Platform. Teams running ServiceNow should verify patches and review logs for exploitation because the bug has already moved from disclosure to active attacks.

7-Zip XZ parsing flaw can run code during extraction

CVE-2026-14266 is a heap overflow in 7-Zip's XZ chunked-data handling that can execute code during extraction of a crafted archive. The fix is in 7-Zip 26.02, so endpoint images and admin tooling should be checked for older versions.

Dev Tools

Capital One open-sources AI-powered VulnHunter

Capital One released VulnHunter, an agentic security tool that analyzes code for exploitable flaws, maps attack paths, and proposes targeted remediations. It is another sign that AI-assisted code review is moving from demos into internal developer security workflows.

AI-assisted workflow finds a WordPress RCE cheaply

A researcher says a low-cost GPT-assisted workflow helped find a WordPress remote-code-execution bug that exploit brokers typically value highly. Even if the economics are anecdotal, it is a practical warning that AI-assisted vulnerability research can shrink discovery time for both defenders and attackers.