This week in IT — August 9, 2026

Published 2026-08-08 · updated 2026-08-09

In short

  • Anthropic launched Claude Opus 5 at the same price as last year's model, but with a claimed jump in coding and agentic performance — the AI price-versus-capability trade just got better.
  • CompTIA is building SecOT+, its first certification for securing the industrial systems behind factories, power grids and pipelines.
  • CompTIA's own labor-market research shows US tech employment growing again in 2026, after shrinking in 2025.
  • N-able shipped a second emergency patch for N-central after attackers found a way around the first one. If you or your MSP runs it on-premises, this is this week's one must-do.

Claude Opus 5 halves the price of Anthropic's best model

What happened. Anthropic released Claude Opus 5 on July 24. It's priced at $5 per million input tokens and $25 per million output tokens — the same as the older Opus 4.8, but Anthropic says it beats that model on coding benchmarks and is now the default model on Claude Max. A separate flagship, Fable 5, costs twice as much.

Why it matters to you. For years, "the good model" and "the cheap model" were different products. That gap is closing. If you're a sysadmin scripting against an API, or a career changer using Claude to learn, the model doing the heavy lifting is no longer the expensive option — it's the default one.

What to do. If you tried an AI coding assistant six months ago and found it too shallow or too pricey for real use, it's worth another look now. Nothing to buy or configure — Opus 5 is already live wherever you use Claude.

Anthropic: Claude Opus 5

CompTIA is building a certification for the systems that run factories and power grids

What happened. CompTIA confirmed SecOT+ (exam code SOT-001), its first certification dedicated to operational technology security — the industrial control systems behind manufacturing lines, utilities and critical infrastructure. It's aimed at experienced professionals, with recommended prerequisites of three-plus years in OT environments and two-plus years doing OT cybersecurity work. It launches in December 2026.

Why it matters to you. This isn't a beginner cert, and CompTIA isn't pretending otherwise. But it's a signal: OT security is becoming its own recognized specialty, distinct from regular IT security, with pay and demand to match. If you're already in networking or security and bored of the same three vendors' badges, this is a lane worth watching.

What to do. Nothing to book yet — it's four months out. If OT interests you, spend those months on the fundamentals: CompTIA's own Security+ plus some hands-on time with SCADA or ICS concepts will make SecOT+ far more approachable when it opens.

CompTIA: SecOT+ Certification

Tech hiring is growing again, not shrinking

What happened. CompTIA's State of the Tech Workforce 2026 report projects net US tech employment will grow 1.9% this year — about 185,499 new jobs — after a 0.3% dip in 2025. Cybersecurity analyst and engineer roles are forecast to grow 346% faster than the national average job growth rate over the next decade, and software roles 188% faster. Texas, California and Florida lead in projected new positions, and CompTIA counts all 50 states as net gainers.

Why it matters to you. The framing you'll see elsewhere this year is "AI is coming for tech jobs." CompTIA's own numbers, drawn from the same labor data everyone else uses, tell a less dramatic story: the field is expanding, and security specifically is expanding faster than IT as a whole. That's the sector this site is built around.

What to do. If you're weighing where to specialize, security keeps showing up at the top of every growth list this year — this report included.

CompTIA: State of the Tech Workforce 2026

An N-central authentication bypass let attackers take over MSP dashboards

What happened. N-able's N-central — a remote monitoring and management (RMM) platform MSPs use to manage client machines — had an authentication bypass flaw, CVE-2026-18577, actively exploited to gain admin access on unpatched, self-hosted servers. It turned out to be an incomplete fix for an earlier bug, CVE-2026-18556. N-able's own writeup says attackers used the "Take Control" feature to reach managed endpoints and set up Cloudflare tunnels for persistence. CISA added both CVEs to its Known Exploited Vulnerabilities catalog this week, with a federal patch deadline of August 7.

Why it matters to you. N-central sits on top of every endpoint an MSP manages. A compromised RMM console isn't one breach — it's a key to every client behind it. If you support clients through N-central, this is squarely your problem this week, not a headline to skim past.

What to do. Hosted N-central customers were patched automatically. Self-hosted instances need a manual upgrade to build 2026.3.1.10 — N-able says to do this immediately, not on your next maintenance window.

N-able: N-central Security Update, August 6, 2026

Try this: check your N-central server for this week's compromise indicators

If you run N-central on-premises, don't stop at patching. N-able published concrete indicators of compromise from the incident: unexpected svchost.exe files sitting in user Documents folders, and a service or scheduled task masquerading as "Cloudflared" that you didn't install. Fifteen minutes checking both is cheap insurance against a bypass that was already being used to reach client machines before the patch shipped.

N-able status: N-central 2026.3 Hotfix 1

Worth a click

  • Apache Tomcat clustering bug also under active exploitation (CVE-2026-34486) — bypasses the encryption protecting inter-node cluster traffic. Fixed in 9.0.117, 10.1.54 and 11.0.21. Tomcat 9 security page
  • A Langflow RCE let attackers chain two API endpoints into full remote code execution on unpatched AI-workflow servers (CVE-2026-9198). IBM recommends upgrading to 1.10.2 or later. CISA advisory
  • CompTIA's SecAI+ (CY0-001), its first cert on securing and governing AI systems, has been live since February — worth a look if SecOT+'s December timeline feels too far off. CompTIA: SecAI+

Sources: every link above was checked on August 9, 2026.

Rate this post
…
Was this helpful?
Comments (—)
0/2000