NB594: Visa Offers AI Security Software Free of Charge; Meta’s 1Pb Subsea Cable Puts Petal to the Metal artwork

NB594: Visa Offers AI Security Software Free of Charge; Meta’s 1Pb Subsea Cable Puts Petal to the Metal

The Fat Pipe - All Packet Pushers Pods

October 5, 2026

Take a Network Break! We discuss listener follow-up on orbital data centers, and hit the Red Alert for a string of Citrix NetScaler vulnerabilities.

Speakers Drew Conry-Murray, Jonna Johnson, Richard Piazzentine

TopicsTechnology

Drew Conry-Murray (0:00)

Take a network break, I'm Drew Connery-Murray.

Jonna Johnson (0:02)

I'm Jonna Johnson.

Drew Conry-Murray (0:03)

All of our virtual donuts have been analyzed by Mythos for vulnerabilities. You can enjoy one Murray free. On today's show, we talk about Visa, releasing AI-driven vulnerability remediation software as open source, new medical device patching capabilities from Gluware, a one petabit per second subsea cable coming from Meta, an Azure maintenance mess, Nokia and AWS supporting sovereignty, and a brand new quantum research facility in Mexico that's going to put top tier national labs and private startups in the same building and more. But first, a message from our sponsor, Itential.

SPEAKER_3 (0:30)

Sponsor Itential's Flow AI delivers agentic operations for infrastructure, meaning easily build AI agents that actually work the way engineers need them to, governed, terministic, and built for production. Add intelligent automations to your network operations without the usual AI chaos. Find out more at itential.com/flowai.

That is itential.com/flowai.

Drew Conry-Murray (0:56)

And we thank Itential for being a sponsor. And also a reminder, we have a TechBytes podcast after the news, where you are invited to the Velocity Room. Velocity Room is a community for IT pros with a focus on infrastructure and security. We'll talk about this community, what kind of events it runs, and whether it might be worth your time. So stick around for that.

John, before we get into the Red Alert, we got a follow up. Last week, we were talking about Google putting some TPUs into space to see if they could be useful for AI data centers. This person wrote in to say, Drew mentioned orbital data centers as Elon Musk's idea. I don't know why Elon gets the credit for the idea because he was responding to a reporter's question in October 2025 Google's paper, as Drew mentioned, came out in November 2025, which means they must have been working on this for a while. The original ideas predate either Google or Musk.

Thank you. I just assumed any kind of wacky idea belongs to Elon, but I appreciate the correction.

Jonna Johnson (1:48)

Well, in fairness, Drew, I mean, that is what Elon does. He puts his name on other people's ideas.

Drew Conry-Murray (1:54)

He really does, doesn't he?

Jonna Johnson (1:55)

That is his thing.

Drew Conry-Murray (1:56)

Yeah, it is. All right.

Jonna Johnson (1:58)

Before we jump into the news, a quick red alert, Citrix NetScaler smuggling problem. There were 3,445 new CVEs created in the week, ending October 1st, and 8,934 updated. Of the new ones, 312 are critical, with CVSS scores of 9 or higher, and 25 got a full 10 out of 10

The red alert this week goes to CVE 202688773, great number there, concerning an HTTP request smuggling vulnerability in Citrix NetScalers. In a nutshell, the NetScalers, in the job of passing HTTP requests and responses in and out of their environment, do not interpret malformed HTTP requests or responses in ways that are consistent with how the messages will be processed by the entities at either end, which opens up those destination devices to web-based attacks. This bug affects NetScaler ADCs and FIPS ADCs and NetScaler gateways of various software versions. See the show notes for details. Guess what? What a surprise. There's updates that resolve the bug, so get updating.

Drew Conry-Murray (2:57)

Yeah. All right, speaking of updating, our first story is that credit card giant Visa is releasing its custom software for AI vulnerability detection and remediation as an open source project called Visa Vulnerability Agentech Harness or VVAH. The software was developed during the card processors experience as part of Project Glasswing. That's a project where an unreleased frontier AI model was provided to large corporations to help them find software vulnerabilities.

Visa notes that participants across Project Glasswing found more than 10,000 high or critical severity vulnerabilities, which a Visa executive called, quote, humbling.

The software, which is available under an Apache 2 license, uses LLMs to find vulnerabilities, assess exploitability, fix them, and then validate the fixes. Visa says its harness can use commercial and open weight models with no hard dependency on a single model provider. The card processor developed the software with the idea that the bottleneck for most organizations isn't actually finding the vulnerabilities, but prioritizing risks and triaging those risks, whether through patches or workarounds. So VVAH is meant to help shrink that time between discovery and fixes.

Jonna Johnson (4:03)

I think it's an interesting idea, but I have to admit that I would worry about using somebody else's code for something that critical, even though there's no guarantee that anyone would do any better than Visa, it still feels a little itchy to me. Maybe listeners may find that otherwise, but it just feels like, look, we built this tool and we think it's useful and we're releasing it as open-source, all I can think of is great how many bugs are embedded in this tool.

32 more minutes of transcript below

Thousands of transcripts fetched by people building searchable podcast archives

Fetch the whole transcript

The demo key returns a sample episode in full, no card needed:

request
curl -H "x-api-key: pt_demo" \
  https://spoken.md/transcripts/1000651996090

Markdown with the speakers named, for your notes, your knowledge base, or anything that makes HTTP calls.

From $0.10 per transcript. No subscription. Credits never expire. Prices exclude VAT, added at checkout for EU customers. Not what you expected? Email us within 14 days with 20 or fewer credits used and we refund the pack in full.

Using your own key:

request
curl -H "x-api-key: YOUR_KEY" \
  https://spoken.md/transcripts/1000793312735