NB591: Altera Adds PQC to FPGAs; Europe Spend Billions to Boost Satellite Broadband
The Fat Pipe - All Packet Pushers Pods
September 14, 2026
Take a Network Break! Ivanti takes center stage with a red alert on four critical CVEs in its Neuron platform, and MikroTik also gets a mention for an actively exploited flaw in its OS.
Speakers Drew Connery-Murray, Jonna Johnson, Scott Robon
TopicsTechnology
Drew Connery-Murray (0:00)
Take a network break, I'm Drew Connery-Murray.
Jonna Johnson (0:02)
I'm Jonna Johnson.
Scott Robon (0:03)
I'm Scott Robon.
Jonna Johnson (0:05)
Pick a pick of pickled pumpkins, and join us as we zip through this week's news items. We've got news from Amazon, AT&T, Arista, Altera, and even some companies that don't begin with the letter A, like BackBox, Cisco, and Inflection. Plus, we've got a metric ton of space networking news.
Drew Connery-Murray (0:21)
John, I think that is the most alliterative intro we've ever had, so congratulations, you get the crown.
Jonna Johnson (0:26)
Do I get a pickled pick of pumpkins?
Drew Connery-Murray (0:28)
If you want pickled pumpkins, I guess, I don't know, but yes, you are welcome to them.
We don't have any ad spots today, so I'm just going to take the opportunity to remind you there's much more that you can hear from Packet Pushers besides Network Break, including Heavy Strategy with John and Johnson and John Burke, Total Network Operations with Scott Raban. I also co-host Packet Protector with me and Jennifer Jabush and Heavy Networking with Ethan Banks. You can also subscribe to our free weekly newsletter, Human Infrastructure, where each week, Ethan Banks and I scour the internet for technical blogs, career resources, interesting product announcements, a global listing of live events, and some dad joke tier memes. You can subscribe for it at packetpushers.net/newsletters. We do not share or sell your contact info ever, and the only email you get from us is the one you signed up for. All right, Johnna, let's dive into the red alert.
Jonna Johnson (1:12)
Okay. Well, today's red alert is about hypervigilance needed for Ivanti's hyper automation. But first, some background. There were 3,907 new CVEs published in the week ending September 10th. 7,608 were updated. Of the new ones, 376 were critical, with a CVSS of 9 or higher. 19 got a full 10 out of 10 This is really sounding like great inflation at the Olympics.
The red alert this week goes to Ivanti for a clutch of four CVEs for its hyper automation platform, Neurons, below version 2026.2. So anything below that version, 2 All four scored 9.9.
CVE 2026.12645 through 647 concern missing authorization vulnerabilities. CVE 2026.1265 is a deserialization of untrusted data vulnerability, and that rounds out the set. All four allow remote authenticated users to execute arbitrary code on the server. For those running the product themselves, there's a patch available to download if you're using the Cloud Service, and the patches were already applied back on August 9th. Just a reminder, folks, not only should you be applying the patches in a timely fashion, but you really should be implementing Zero Trust as an approach overall, and focus a lot of attention on robust management of permissions and identities as the critical support to Zero Trust. The problem with hyper automation services is that they expect to be able to send commands to a bunch of other systems, and getting to compromise one is really awesome for the bad guys. So tightly controlling what systems can reach the server is really important, and also controlling what accounts have access to it, and removing access privileges when they're not needed, even if in normal course of events, they may be needed again.
Remove the privileges unless they're actively needed, remove the accounts when they're no longer needed.
Scott Robon (3:08)
I can't emphasize enough how much Zero Trust as an assumption is absolutely necessary. The network perimeter isn't disappearing, it's gone, right? Think about the whole, remember the industry for mobile device management? Where is that today? It's gone because we've given up, right? And networking is more important and more built into everything we do. So Zero Trust, operational principle, don't forget it.
Yeah.
Drew Connery-Murray (3:36)
And I'll note in our most recent human infrastructure newsletter, the Cloud Security Alliance just released a blueprint or a framework around implementing Zero Trust, and I believe it's fairly vendor neutral. It's more about principles and practices than it is about products, which I think is the way to go. So check that out if you can. And there's also tons of other resources on Zero Trust, but yeah, definitely something to think about.
I've got a runner up for our Red Alert. It's some serious vulnerabilities in the MikroTik router platform, and there are exploits in the wild. I know from the Packet Pushers community slack that MikroTik is popular both for people using it at home and in their businesses. So just wanted to flag this especially for our audience. Maybe links in the show and also where you can just go do your own Google searches and find out what you need to know.
28 more minutes of transcript below
Thousands of transcripts fetched by people building searchable podcast archives
Fetch the whole transcript
The demo key returns a sample episode in full, no card needed:
curl -H "x-api-key: pt_demo" \
https://spoken.md/transcripts/1000651996090Markdown with the speakers named, for your notes, your knowledge base, or anything that makes HTTP calls.
From $0.10 per transcript. No subscription. Credits never expire. Prices exclude VAT, added at checkout for EU customers. Not what you expected? Email us within 14 days with 20 or fewer credits used and we refund the pack in full.
Using your own key:
curl -H "x-api-key: YOUR_KEY" \
https://spoken.md/transcripts/1000789579079