NB590: Blue Origin Wins NASA Bid for Mars Telecoms; Fortinet Offers High School Hackers Curriculum
The Fat Pipe - All Packet Pushers Pods
September 8, 2026
Take a Network Break! We begin with follow-up on the Cisco/Teleport deal and Chinese models on US public clouds.
Speakers Daniel Mudge, Johna Johnson
TopicsTechnology
Daniel Mudge (0:00)
Take a network break, I'm too, Conner Murray.
Johna Johnson (0:02)
I'm Johna Johnson, and it is time to smell the fresh scent of autumn, grab a toasty virtual donut, and speed walk through the week's tech news. We've got a couple of follow-ups from listeners named John. I approve.
Announcements from VMware, Tailscale, AWS, HPE, and Kato Networks, and NASA is planning its link to Mars. There's a cybersecurity high school curriculum from Fortinet, quarterly earnings from Broadcom and HPE, and more. But first, a quick thank you to our sponsor, Itential.
SPEAKER_3 (0:31)
Sponsor Itential's Flow AI delivers agentic operations for infrastructure, meaning easily build AI agents that actually work the way engineers need them to, governed, terministic, and built for production. Add intelligent automations to your network operations without the usual AI chaos. Find out more at itential.com/flowai.
That is itential.com/flowai.
Daniel Mudge (0:57)
Yeah. Thanks, Itential, for being a sponsor. We did get a couple of follow-up from listeners, both named John. Just so you know, John is not a requirement to offer us follow-up. It's just how it worked out this time.
First, John Howard contacted me on the Packet Pushers Community Slack. Last week, John and we talked about Cisco partnering with Teleport to offer cryptographically derived infrastructure identities. He wrote, Teleport is primarily offering SSH certs as a service, as backing for the just-in-time cred concept. Basically, you don't need to provision a specific user on a device, you provision a certificate authority. So long as the user has a cert signed by that authority, the device trusts the user is legit. Where Teleport adds value in the server landscape is that you have their agent run on the server and it does extra fancy auth and maybe tunneling, session recording and so on. He says, in networking, it's easy to do the SSH cert bits, but maybe Cisco is going to make Teleport integrate with IOSX slash whatever so you can replace the somewhat crappy TechAx Plus, which he says is fully and arguably proper. So thanks, John. I appreciate that feedback and context. If you're interested in our Packet Pushers community Slack, you can join for free packetpushers.net/community.
Second follow-up also from a John, separate John. This one comes in regard to the story we did about Chinese AI model maker Moonshot wanting to enter into revenue sharing with the big three US Cloud providers. John, I think you and I were both curious about whether the Chinese models would actually be allowed to be hosted by US Cloud providers.
Johna Johnson (2:19)
Yeah.
Daniel Mudge (2:20)
We did not look that up. John did. He says they're already there.
Johna Johnson (2:24)
I'm going to guess that he probably works at one of the big three and was like, what are these lunatics saying?
Daniel Mudge (2:31)
Yeah. Azure already has models from Moonshot, DeepSeq, and Alibaba, AWS, and Google Cloud offer models from DeepSeq and perhaps others. So much appreciated, John, and I feel a bit red in the face for not having just looked it up myself.
Johna Johnson (2:44)
Likewise, likewise. But thankfully, he does conclude with, love you guys, thank you for the great shows and the great community. So we appreciate the thanks even though we got that one wrong, and thank you, John, for writing in. Again, as Drew says, you don't have to be named John to write in.
Daniel Mudge (2:58)
Right. He also notes, he wants, I guess he's trying out a new tagline for us, too many virtual donuts would never be enough.
I like it. I like it.
Johna Johnson (3:08)
That's true.
Daniel Mudge (3:08)
Yeah. All right. Take us to the red alerts, John.
Johna Johnson (3:11)
Okay. So 2,252 CVEs were created in the week ending September 3rd.
6,298 were updated. And by the way, if you think these numbers are going up week by week, you are correct.
Daniel Mudge (3:25)
If you have detected a trend.
Johna Johnson (3:27)
Yes. And they are actually going up exponentially for real. I graphed it earlier this summer. It's going to be very, very interesting. This is one of the known and anticipated corollaries of Mythos and its ilk coming out.
Anyway, of the new ones, 334 critical with CVSS of 9 or higher, with 20 getting 10 out of 10 This week, we are awarding the red alert to embrace the vulnerabilities in HPE's Aruba Networking Fabric Composer, both getting 10 out of 10 CVE 202676657 describes an API-based authentication bypass allowing an unauthenticated remote attacker to gain administrative control of the host. 202676658 describes vulnerability in the SSH daemon that likewise allows an unauthenticated remote attacker to take over the host. Both affect Fabric Composer through version 7.3.3. Workaround, Motherhood and Apple Pie only expose the CLI API and web interfaces on a dedicated layer 2 segment or VLAN, protect them with firewall policies and track and log user activities and resource use. The Fix, oh wait, what a surprise, upgrade to 7.3.4 or 7.4.0 or above. A note, we're only detailing these two CVEs, but there are 50 more for the same products week this week. But they're all scoring less than 10, all fixed by updating the software. HPE also released a patch for CVE 202673-749, a cluster of vulnerabilities in the Aruba Network Operating System, which was scoring in at a mere 9.8. Seems like HPE is announcing the results of its fire hardening over the summer.
21 more minutes of transcript below
Thousands of transcripts fetched by people building searchable podcast archives
Fetch the whole transcript
The demo key returns a sample episode in full, no card needed:
curl -H "x-api-key: pt_demo" \
https://spoken.md/transcripts/1000651996090Markdown with the speakers named, for your notes, your knowledge base, or anything that makes HTTP calls.
From $0.10 per transcript. No subscription. Credits never expire. Prices exclude VAT, added at checkout for EU customers. Not what you expected? Email us within 14 days with 20 or fewer credits used and we refund the pack in full.
Using your own key:
curl -H "x-api-key: YOUR_KEY" \
https://spoken.md/transcripts/1000788513712