NB592: AWS Recommends UAE Migration; FCC Wants More Spectrum for Satellite Broadband
The Fat Pipe - All Packet Pushers Pods
September 21, 2026
Take a Network Break! We start with listener follow-up on Arista’s vulnerability reporting, and Cisco ISE takes center stage for our Red Alert.
Speakers Drew Connery-Murray, Jonah Johnson, Daniel Caruso, Jamil Boukir
TopicsTechnology
Drew Connery-Murray (0:00)
Take a network break, I'm Drew Connery-Murray.
Jonah Johnson (0:02)
I'm Jonah Johnson. Grab a fresh baked tasty snack as we crunch through this week's news items. We've got some great listener follow up on Arista, another slew of CVEs from Cisco, something called ephemeral networking from startup EVA Networks, some sobering data center news from AWS, cognitive operations from Nokia, high altitude pseudo satellites from the UK government, more AI models behaving badly. What a surprise, a quantum competition from the US government and more.
SPEAKER_3 (0:30)
Sponsor Itential's Flow AI delivers agentic operations for infrastructure, meaning easily build AI agents that actually work the way engineers need them to, governed, terministic and built for production. Add intelligent automations to your network operations without the usual AI chaos. Find out more at itential.com/flowai.
That is itential.com/flowai.
Drew Connery-Murray (0:56)
And thanks to Itential for being a sponsor. And by the way, stick around. After the news, we have a sponsored TechBytes podcast with Firezone. They offer a secure remote access solution built on WireGuard. And instead of just hearing from Firezone, they've brought a customer from a construction firm. This customer was looking for a VPN option to help them protect the company's remote desktop infrastructure. So we'll talk about what they were looking for, why they chose Firezone, what day-to-day operations are like, and more. And we'll also hear from Firezone founder Jamil Boukir. So stick around for that after the news.
Johnna, before we get to the red alert, I have one follow-up. Last week, you and I were talking about Arista releasing dozens of CVEs in a mass disclosure. And I noted that the sort of public non-customer view that they had on their web page was just like a dump of disclosures, a lot of scrolling, a lot of clicking to figure out what ones might be relevant. And I assumed this isn't just how Arista does it, they must have a better system. And several listeners responded to say, yes, if you are a Cloud Vision customer, there's a compliance portal that has IDs and tracks vulnerabilities and advisories. One listener shared a link to an Arista post that describes the compliance dashboard for bugs and CVEs, so we'll link it to the show notes. Another listener wrote in to say, quote, Cloud Vision adds details to each advisory or vulnerability specific to which of your managed devices are impacted or exposed, and which EOS version of the vulnerability is fixed if there is a fix available. So just generally, thanks to everybody for reaching out for telling us. We love that our audience has these insights that they can share.
And if you ever have anything you want to tell us, packupusher.net/fu, the FU for follow up, and we do take every interaction seriously.
Jonah Johnson (2:31)
And kudos to Arista for having a very solid platform to the point where customers are writing in to say, no, it's actually good.
Drew Connery-Murray (2:38)
Yeah, exactly.
Jonah Johnson (2:40)
Good job, Arista. All right. Jumping into red alerts, another good job Cisco has had a very productive week. There were 5,044 new CVEs created in the week ending September 17th and 7,190 updated. We are yet again giving the red alert to Cisco for even more fruit from its quote, ongoing commitment to proactive security and product quality and quote, multiple CVEs applying to Cisco Identity Services Engine, that's Cisco ICE, and ICE Passive Identity Connector, ICE PIC.
2026.2013 covers a cluster of vulnerabilities related to improper neutralization of special elements that can result in command injection. CVE 2026.20192 covers vulnerabilities due to improper access controls, one of which is being actively exploited, both of them are rated 10 out of 10 Oh, and we also have CVE 2026.76423 at all, covering issues with ICE and ICE PIC APIs, also at 10
Drew Connery-Murray (3:38)
Don't forget the APIs.
Jonah Johnson (3:39)
Right. No workarounds, just patches. Since these are problems with identity services, please fix them right away if you haven't already, since identity is the core of zero trust. And oh, by the way, there's a whole ton of CVEs that didn't get to 10 but are super serious nonetheless. You can see links in the show notes. It's nice to see that everybody spent the summer following Project Glasswing and hammering the living daylights out of their infrastructure.
One would wish that they had done so before, but better late than never, right?
Drew Connery-Murray (4:11)
I guess that is kind of funny, like write your essay on what you did this summer. Well, I found a lot of bugs is what I did this summer. And now you have a lot of bugs. Oh boy. Yeah, you're right though, better late than never and links in the show notes. All right, jumping into news. A networking startup called EVA Networks or EVA Networks has emerged from stealth to sell the concept of ephemeral network connectivity and the big idea is that instead of trying to monitor and protect persistent connections between things like workloads or applications or cloud services or AI agents, EVA Networks only spins up those connections as needed and then tears them down again when the job is done. The press release says, quote, The approach is designed to reduce unnecessary standing connectivity, attack service, significant costs, and the operational burden associated with maintaining long-lived tunnels, routes, circuits, and firewall policies, end quote.
38 more minutes of transcript below
Thousands of transcripts fetched by people building searchable podcast archives
Fetch the whole transcript
The demo key returns a sample episode in full, no card needed:
curl -H "x-api-key: pt_demo" \
https://spoken.md/transcripts/1000651996090Markdown with the speakers named, for your notes, your knowledge base, or anything that makes HTTP calls.
From $0.10 per transcript. No subscription. Credits never expire. Prices exclude VAT, added at checkout for EU customers. Not what you expected? Email us within 14 days with 20 or fewer credits used and we refund the pack in full.
Using your own key:
curl -H "x-api-key: YOUR_KEY" \
https://spoken.md/transcripts/1000790979069