Oct 2: FortiMail zero-day exploited for unauthenticated arbitrary file writes
Today's 3 things that matter
- FortiMail zero-day exploited for unauthenticated arbitrary file writes
Active exploitation of unauthenticated file write flaw on internet-facing Fortinet email gateway requires immediate workaround deployment or isolation pending vendor patches across different FortiMail versions. - Eleven years of data test whether RPKI destabilises BGP
RPKI is BGP's primary hijack defence, but growing deployment may paradoxically increase control-plane churn and impact routing stability through validation-induced changes. - Philippines subsea cable cuts strip 300 Gbps of capacity
Damage on dual critical SEA routes forces rerouting, increasing latency for intra-Asian cloud services, gaming, and video calls. Real-time case study of subsea infrastructure fragility and BGP re-convergence across regional ASes.
Full stories below, grouped by topic.
Network Automation
NetBox 4.7.2 rebuilds cable paths and scopes VLAN groups
GitHub · Sep 29, 2026 · Primary source
What happened: NetBox v4.7.2 released September 29, 2026 with Cable.update_dependent_objects() hook to rebuild cable paths after writes, VLAN group site scoping, and form validation error focus improvements.
Why it matters: Fixes cable management consistency issues and improves VLAN filtering by site; operationally relevant for teams managing large cabled infrastructure via API or bulk operations.
NetBox v4.7.2, released September 29, 2026, addresses cable path consistency and VLAN group scoping. The primary enhancement introduces Cable.update_dependent_objects() hook to rebuild dependent cable paths and related attributes after writes that bypass the normal save() method—important for teams performing bulk cable management or integration via direct ORM calls. VLAN group scoping now includes VLANs assigned via VLAN groups scoped to a site or its site group among the site's related objects, improving hierarchical VLAN management for operators managing multiple sites. Form validation UX improvement: when a form fails validation, the browser now focuses and scrolls to the first field with an error, reducing user friction. These are maintenance-level improvements but address real operational pain points: cable drift in large cabling databases and VLAN visibility inconsistencies across site boundaries. Part of the v4.7 minor release cycle that shipped September 2, 2026, with broader data model enhancements (cooling infrastructure, channelized subinterfaces, module bay types, background API processing).
Read the original at github.com
Routing & Internet
Eleven years of data test whether RPKI destabilises BGP
APNIC Blog · Oct 2, 2026 · Primary source
What happened: As more address space becomes protected by RPKI and networks deploy Route Origin Validation, RPKI-related routing activity increases. Analysis of 11+ years of RPKI and BGP data measures how routing activity correlates with RPKI-related changes.
Why it matters: RPKI is BGP's primary hijack defence, but growing deployment may paradoxically increase control-plane churn and impact routing stability through validation-induced changes.
APNIC's latest analysis questions whether expanded RPKI protection uniformly improves stability. The research quantifies routing activity correlated with RPKI events—not just hijack prevention but also ROV filtering, ROA updates, and path changes driven by validation logic. This matters operationally because as ROV adoption climbs past 27% globally (APNIC Labs February 2026), the interaction between RPKI-protected prefixes and validation-induced withdrawals creates measurable control-plane load. The study covers 11+ years of BGP data, giving practitioners longitudinal visibility into whether RPKI deployment curves track with increased route instability. Key concern: if ROV filtering across tier-1 networks triggers cascading re-announcements or path exploration when a prefix flips between valid/invalid/not-found states, that represents a new class of operational risk. Findings suggest RPKI adoption strategy needs to account for validation logic coherence and coordinated ROV deployment, not just coverage percentage.
Read the original at blog.apnic.net
Philippines subsea cable cuts strip 300 Gbps of capacity
DICT/GizGuide · Oct 2, 2026 · Industry news
What happened: DICT investigating subsea fiber-optic cable outage affecting Philippines on October 2, 2026. Damage to Philippines-Singapore and Philippines-Hong Kong links cost approximately 300 Gbps capacity; ISPs claim sufficient redundancy to cover loss.
Why it matters: Damage on dual critical SEA routes forces rerouting, increasing latency for intra-Asian cloud services, gaming, and video calls. Real-time case study of subsea infrastructure fragility and BGP re-convergence across regional ASes.
The October 2 cable outage affecting Philippines-Singapore and Philippines-Hong Kong routes provides operational insight into subsea infrastructure dependencies. 300 Gbps capacity loss appears contained due to redundancy, but this masks an underlying risk: most SEA carriers depend on 2-3 major international cables rather than full mesh. A cut on Singapore route forces rerouting through Hong Kong, changing AS path diversity and creating cascading latency spikes across multiple regional BGP communities. Converge ICT and PADECO issued coordinated ISP advisories, showing industry monitoring is in place but redundancy options are limited. DICT investigation still determining root cause (natural cut, equipment failure, or external damage), reflecting typical deep-sea repair coordination timelines. For NetDevOps: submarine cable outages do not isolate single markets cleanly. Expected impact includes increased ping/latency for intra-Asian traffic, buffering on regional media services, and BGP instability from re-convergence across dozens of ASes as carriers execute backup path logic.
Read the original at gizguide.com
Network Security
FortiMail zero-day exploited for unauthenticated arbitrary file writes
The Hacker News · Oct 2, 2026 · Industry news
What happened: Fortinet disclosed a path traversal and NULL byte vulnerability allowing unauthenticated attackers to write arbitrary files via crafted HTTP/HTTPS requests to FortiMail systems. The vulnerability is being exploited in the wild; Fortinet issued immediate workarounds including disabling IBE feature and restricting management interface access from the internet.
Why it matters: Active exploitation of unauthenticated file write flaw on internet-facing Fortinet email gateway requires immediate workaround deployment or isolation pending vendor patches across different FortiMail versions.
Fortinet acknowledged a critical path traversal vulnerability (CWE-22) combined with improper NULL byte handling (CWE-158) in FortiMail that allows unauthenticated remote attackers to write arbitrary files to the underlying system through crafted HTTP or HTTPS requests. The vulnerability is confirmed exploited in the wild; Fortinet directed customers to disable the IBE (Internet-Based Enrollment) feature via CLI command and to restrict or completely disable FortiMail management interface internet exposure pending version-specific patches. The flaw was discovered and reported by Gwendal Guégniaud of Fortinet's own Product Security team. For network security operations, this affects perimeter email gateway deployments: immediately apply the CLI workaround across all FortiMail instances, audit recent file system activity for unauthorized writes, and monitor Fortinet advisories for patch timelines. This is a common attack vector for initial access before lateral movement into corporate networks.
Read the original at thehackernews.com
SASE vendors move toward agents that write policy
The Network DNA · Oct 1, 2026 · Analysis
What happened: SASE (Secure Access Service Edge) converged SD-WAN and security services into cloud-delivered platforms; the next evolution is AI-operated SASE where agents autonomously tune paths, write policy, hunt threats, and resolve incidents without human intervention.
Why it matters: AI-driven policy automation and autonomous threat hunting in converged SASE architectures represent the operational shift from manual zero-trust policy tuning to self-healing network access fabric.
SASE platforms have unified SD-WAN networking with security services (SWG, CASB, ZTNA, FWaaS) into single cloud-delivered architectures; the next phase involves AI agents that continuously observe traffic and user behavior to autonomously tune network paths, dynamically write zero-trust policies, perform threat hunting, and resolve security incidents without human intervention. This represents an operational maturity leap beyond static policy frameworks: instead of security teams manually adjusting SASE rules and ZTNA access policies in response to observed threats, AI agents baseline normal user and application behavior across identity, location, and device context, then dynamically enforce policy exceptions and isolation when behavioral anomalies suggest compromise. For network operations teams currently deploying or managing SASE stacks, this shift means future architecture decisions should prioritize platforms with open policy engines supporting vendor-neutral policy formats and API-first automation hooks. Teams will transition from reactive access-policy reviews to oversight roles: validating AI-generated policy decisions, reviewing threat-hunting hypotheses, and tuning the behavioral baselines that drive autonomous response.
Read the original at thenetworkdna.com
Telco & Cable AI
Verizon puts reasoning agents across RAN and transport
RCR Wireless · Oct 1, 2026 · Industry news
What happened: Verizon is moving beyond rule-based automation towards AI systems that can reason about problems and act across RAN, transport, and other network domains. Sub-domain agents investigate individual problems before findings are compiled to determine final deterministic actions, with the operator retaining control of intent and guardrails.
Why it matters: The shift from scripted automation to reasoning AI agents across network domains represents a fundamental change in autonomous network architecture that operators must architect for orchestration and governance.
Verizon's positioning clarifies the distinction between automation (rule-based scripts around known conditions) and autonomy (reasoning about unknown problems). The operator's approach involves sub-domain agents that investigate root causes across RAN, transport, and other infrastructure, then compile findings to determine corrective actions while Verizon retains control of intent, outcomes and guardrails. This contrasts with vendor-supplied RAN agents operating in isolation. Verizon argues only the operator has network topology and institutional knowledge to arbitrate between competing agent recommendations and coordinate action across domains. With thousands of KPIs and interdependencies between transport and environmental factors, agents must predict and act dynamically in real time. This architectural philosophy—distributing reasoning authority while centralizing governance—reflects Level 4 autonomy where networks become truly self-managing rather than executing conditional rules. The approach addresses the core NetOps challenge: how to enable multi-vendor agentic systems while maintaining operational control across complex, interdependent infrastructure.
Read the original at rcrwireless.com
Vodafone and Ericsson run call translation in the network
TelecoomTV · Sep 28, 2026 · Industry news
What happened: Vodafone and Ericsson demonstrated real-time language translation and noise cancellation for voice calls running on the network layer without requiring customer app changes. Liberty Global partnered with Sierra to deploy multi-channel agentic AI for customer service across 80 million European connections.
Why it matters: Network-embedded voice AI and multi-channel agentic customer engagement represent new operator revenue streams and shift telcos from connectivity-only to AI service providers.
Vodafone and Ericsson successfully tested instant translation across English, Spanish, Italian, French and German voice calls with capability to expand to additional languages. The real-time noise cancellation intelligently identifies and removes background noise in loud environments like public transport and construction sites. Both services run at the network level without requiring modified smartphones or separate apps—a significant differentiation from device-side implementations. Separately, Liberty Global signed a three-year agreement with Sierra to deploy conversational AI agents across Belgium, Ireland, Netherlands and UK operations (approximately 80 million fixed and mobile connections). The partnership enables a common approach to deploy AI agents across chat, voice and text channels with the stated goal of handling routine customer interactions while freeing human teams for complex cases. This reflects broader telco shift from infrastructure-only models toward direct monetization of embedded AI services, moving from service providers toward what industry calls AICOs (AI infrastructure companies operating at network proximity).
Read the original at telecomtv.com
AI Model Providers
OpenAI ships GPT-6.1 Sol at a fifth of Astra cost
Layer3Labs / CodersEra · Sep 29, 2026 · Industry news
What happened: OpenAI launched GPT-6.1 Sol on September 29, 2026, as a multimodal point-release upgrade to the GPT-6 Sol series. The model costs $2 per million input tokens and $10 per million output tokens, has a 1.05M-token context window, and nearly matches GPT-6 Astra on agentic coding at about one-fifth the price.
Why it matters: GPT-6.1 Sol targets agentic software engineering, desktop tool manipulation, and complex document processing, offering significant cost savings for production AI ops workloads.
GPT-6.1 Sol is OpenAI's mid-tier model launched 29 September 2026 at DevDay as a replacement for GPT-6 Sol, arriving one week after the initial GPT-6 Sol release on September 22. The architecture maintains multimodal support with text and image inputs, supporting reasoning controls from low through maximum effort. Pricing stands at $2.00/M input, $0.100/M cached input, and $10.00/M output with a 1.1M-token context window. Key performance gains include halving cached input token rates to ten cents per million while lifting performance across technical benchmarks, with scores 4.8 points higher on Business Workflow Automation at medium reasoning and a 7.7% factual error rate versus 11.4% for GPT-6 Sol. Software engineering performance beats GPT-6 Sol by 6.4 percentage points on DeepSWE v1.1 at lower compute expense, making it practical for scaling production AI agents without exponential cost growth.
Read the original at layer3labs.io
AI Industry & Policy
BIS finds 55% of AI investment flows between AI firms
Universal Asset Owners · Oct 2, 2026 · Analysis
What happened: The Bank for International Settlements measured circular financing in AI for the first time: 55.2% of investment value flowing into AI firms came from other AI firms between 2021 and 2025. The RBA sized obligations at US$1 to 1.5 trillion with 20-30 year debt financing hardware against uncertain economic lives.
Why it matters: Infrastructure spending concentration and circular financing creates systemic risk and potential debt service pressure if AI hardware ROI assumptions fail.
The October 2 BIS analysis reveals a structural stability concern in AI funding that goes beyond typical venture concentration. When 55.2% of investment flowing into AI firms originates from other AI firms—not customer revenue or diversified capital sources—the ecosystem becomes self-referential and increasingly fragile. The RBA's sizing of off-balance-sheet financing vehicles at $1–1.5 trillion magnifies this risk. More critically, hardware debt is being structured with 20–30 year terms against assets (GPUs, compute) with much shorter economic lives and uncertain ROI horizons. This maturity mismatch, combined with geopolitical constraints on energy access and supply-chain fragility for batteries and semiconductors, creates a trigger for cascading defaults if major AI infrastructure projects fail to hit deployment or revenue targets. For infrastructure teams and AIOps leaders, this signals that vendor stability during the 2027–2028 period is a material risk factor—many AI infrastructure providers may face refinancing pressure or balance-sheet stress before business models mature.
Read the original at universalassetowners.com
OpenAI seeks $30 billion at $1.4 trillion valuation
Bloomberg · Sep 29, 2026 · Industry news
What happened: OpenAI aims to raise at least $30 billion at a $1.4 trillion valuation while pushing back IPO plans. CEO Sam Altman tied public listing timing to safety claims rather than business fundamentals, signaling extended private-market governance.
Why it matters: Extended private status means reduced SEC-mandated transparency; enterprises cannot rely on public disclosure for vendor due diligence on frontier AI safety and governance.
OpenAI's September 29 funding announcement consolidates private capital dominance in frontier AI development at a time when regulatory governance is fragmenting across jurisdictions. The $1.4 trillion post-money valuation—up from prior estimates of $1.2 trillion—reflects sustained demand from institutional investors despite the company's explicit deferral of public markets. Altman's framing ties IPO timing to safety claims, not business fundamentals, introducing regulatory-adjacent uncertainty into a major AI vendor's governance roadmap. For enterprise practitioners, this creates two operational consequences. First, OpenAI's extended private status means fewer disclosure requirements around model safety, red-teaming depth, or governance structure—enterprises deploying OpenAI models cannot rely on SEC-mandated transparency for vendor due diligence. Second, the raise's scale and timeline acceleration suggest aggressive deployment targets in 2027; enterprises should expect accelerated deprecation of older OpenAI API versions and potential commercial pressure on custom deployment agreements as OpenAI pursues revenue velocity to justify valuation.
Read the original at bloomberg.com
Read this edition on the web · The week in network intelligence · Vendor Radar
Digital Plumber is AI-curated and AI-summarized, with no human review before publishing. Verify before acting on anything here. How it works.