Automated Daily Intelligence · Est. 2026

TIDOX.HUB
EPISODE 134 · 2026.08.03

Intelligence Brief

Alibaba announced Qwen3.8-Max's full weights will , Sonatype found ~27.8% of one leading LLM's package, zhaoxuya520/reverse-skill, yesterday's viral GitHu

27B

also going open

INTELLIGENCE BRIEF
August 3, 2026
DAILY EDITION
2026-08-03INTELLIGENCE BRIEF
0:00 / 5:49
Daily intelligence brief · Two-voice podcast with visuals
· RSS · Get daily email (coming soon)

Today's Insights

Alibaba announced Qwen3.8-Max's full weights will ship open next week -- the first time a Max-tier (flagship) Qwen model has been open-sourced -- alongside a new Qwen3.8-27B also going open-weight. Independent tracking of Alibaba's own figures puts the model at 2.4T total / 95B active parameters, with a DeepSWE score rising from Qwen3.7's 21.6 to 56.6 (vs. DeepSeek V4 Flash's 54.4, Kimi K3's 69, GLM-5.2's 44) -- Alibaba's own benchmark table and license terms remain unpublished.

local-model-inferencqwenopen-weight Hacker News / MarkTechPost

Sonatype found ~27.8% of one leading LLM's package-dependency recommendations were hallucinated (nonexistent packages), and 43% of those hallucinated names reappeared on every one of ten identical re-runs -- meaning attackers can identify and pre-register the highest-probability hallucinations with near-certainty. Real 'slopsquatting' incidents already exploit this, including a still-live malicious npm package with ~233 weekly downloads despite being registry-flagged.

supply-chain-attacksai-dev-toolssecurity Cloud Security Alliance / Socket.dev

India's mobile app market posted a record $345M in Q2 2026 consumer spending (+35% YoY, per Sensor Tower via TechCrunch) -- ChatGPT and Claude together take ~83% of India's AI-app revenue, non-gaming categories now make up 68% of India's H1 2026 app revenue (up from 58% three years ago), and Google One was the quarter's single highest-grossing app. Same-day, this pipeline's own (Portugal-localized) Play Store scrape shows ChatGPT jumping to #2, its highest recorded position, up from an 08-01 low of #30.

play-store-trust-bifindie-monetizationindia TechCrunch / Sensor Tower

A ProPublica investigation reveals Microsoft has used Anthropic's own Mythos vulnerability-hunting model (via 'Project Glasswing') to find hundreds of critical/important bugs across SharePoint, Microsoft 365, Teams, and Copilot -- 90 critical + 141 important bugs in SharePoint alone in April -- and had patched over 600 by July 14 ('the bug apocalypse has fully descended upon us,' per one Microsoft engineer). This lands four days after Microsoft CEO Satya Nadella pitched Microsoft's homegrown MAI models as an independent alternative to Anthropic and OpenAI.

verification-stackfrontier-tripolar-prmicrosoft ProPublica

Trending Repos