· artificial intelligence · 4 min read

AI and cloud briefing: a 2,500-company supply chain breach, Alibaba's Qwen3.8-Max, and Azure's $100bn year

A compromised build pipeline in the widely used LiteLLM project exposed more than 434,000 CI/CD pipelines across 2,500+ companies. Alibaba launches Qwen3.8-Max, a 2.4-trillion-parameter open-weight model aimed at Anthropic and OpenAI. And Microsoft's Azure cloud business crosses $100 billion in annual revenue for the first time.

A compromised build pipeline in the widely used LiteLLM project exposed more than 434,000 CI/CD pipelines across 2,500+ companies. Alibaba launches Qwen3.8-Max, a 2.4-trillion-parameter open-weight model aimed at Anthropic and OpenAI. And Microsoft's Azure cloud business crosses $100 billion in annual revenue for the first time.

Here is our latest round-up of what’s changing in AI and cloud for UK businesses, with links to the original sources so you can read further.

Lead story: supply chain breach exposes 2,500+ companies through LiteLLM

Security researchers at CloudSEK have uncovered what they describe as the largest AI supply chain breach found so far in 2026. A threat actor group compromised two versions of the popular LiteLLM PyPI package back in March 2026, using a weakness in the Trivy security scanner inside LiteLLM’s own build pipeline. The tampered packages stayed live for around 20 days before being caught. The exposure map now includes more than 2,500 companies and roughly 434,000 CI/CD pipelines worldwide, with high-confidence matches including Nvidia, AWS, Cisco, Salesforce, Siemens and X Corp. The FBI issued a flash advisory in July 2026 warning that credentials stolen during the exposure window could still be reused in future attacks. Full detail is available from CloudSEK and CXtoday.

A compromised LiteLLM build pipeline exposed more than 2,500 companies and 434,000 CI/CD pipelines in the largest AI supply chain breach found so far in 2026

Why this matters: this breach ran quietly for weeks inside a build tool many teams trust by default, which is exactly how supply chain attacks do the most damage. If your business uses LiteLLM, or any AI tooling with dependencies pulled from public package registries, it’s worth checking with your development team whether you were exposed, and rotating any credentials that may have been touched during that window.

AI: Alibaba launches Qwen3.8-Max, its largest model yet

Alibaba has unveiled Qwen3.8-Max, its most capable AI model to date. It’s a 2.4-trillion-parameter mixture-of-experts model that activates only around 95 billion parameters per query, keeping running costs down while supporting a context window of up to 1 million tokens. The model is multimodal, handling text and images natively, and is available now through Alibaba Cloud’s Model Studio, with open model weights due for release shortly after, the first time Alibaba has open-sourced a model at this scale. Alibaba’s own benchmarks show Qwen3.8-Max performing close to leading Western models on coding and general agent tasks. Coverage is available from Alibaba Group and Computerworld.

Alibaba launches Qwen3.8-Max, a 2.4-trillion-parameter open-weight model with a 1 million token context window

Why this matters: an open-weight model at this scale, competitive with the leading closed models, gives businesses another option beyond the usual providers, particularly useful where cost control or running models on your own infrastructure matters. Worth watching once the open weights are released and independent benchmarks confirm the claims.

Cloud: Microsoft’s Azure business tops $100 billion in annual revenue

Microsoft’s fiscal Q4 2026 results, reported on 29 July, show Azure and other cloud services revenue crossed $100 billion for the full fiscal year for the first time, up 41% year on year. Growth actually accelerated through the year, with the most recent quarter alone up 43%, faster than the 40% growth reported the quarter before. Microsoft’s wider cloud business reached $59.3 billion in quarterly revenue, up 27%. Full detail is available from CNBC and Yahoo Finance.

Microsoft's Azure cloud business crosses $100 billion in annual revenue for the first time, with growth accelerating to 43% in the latest quarter

Why this matters: this scale of growth is being driven largely by AI workloads, and it points to continued heavy investment, and continued competition on price and capacity, among the major cloud providers. For UK businesses running workloads on Azure, AWS or Google Cloud, that ongoing competition is generally good news for pricing and available capacity, though it’s also a reminder to keep reviewing your cloud contracts and usage rather than assuming last year’s deal is still the best one.

The takeaway

This week’s stories sit at three different points of the same picture: a serious reminder that AI tooling supply chains need the same scrutiny as any other software dependency, a fast-moving frontier of open-weight models giving businesses more choice, and continued heavy investment from the cloud providers that host most of this activity. If your business runs AI tooling in its development pipeline, that’s the one to act on first: check your exposure to the LiteLLM breach and rotate credentials if needed. If you’d like help reviewing your AI tooling supply chain or your cloud contracts, get in touch.


AI Agent based research and content, AI can do mistake, please help us to improve.

Back to Blog