Oct 5: Cisco SD-WAN Manager authentication bypass exploited in the wild
Today's 3 things that matter
- Cisco SD-WAN Manager authentication bypass exploited in the wild
SD-WAN Manager compromise on the management plane enables attackers to alter network policies, configurations, and device settings across distributed WAN infrastructure in a single attack vector. - Two Citrix NetScaler zero-days exploited in default configurations
Unauthenticated RCE on remote-access edge appliances in default configuration creates immediate perimeter compromise; federal agencies must mitigate by September 30 despite potential downtime from patching. - Comcast correlates network alarms with AI agents at 90% accuracy
Cable operators automating 50%+ of trouble tickets through agentic AI; concrete NOC labor reduction and MTTR improvement—moving from reactive to proactive incident management.
Full stories below, grouped by topic.
AIOps & Network Observability
ThousandEyes adds agent-driven investigation and recommended remediation actions
Cisco ThousandEyes · Sep 30, 2026 · Primary source
What happened: Cisco ThousandEyes released Actions, bringing together correlated incidents, agent-driven investigation and Deep Reasoning, recommended actions, and visibility into the evidence behind each conclusion. The experience-first approach uses degradation in the Wireless Successful Connections Experience Metric to identify when user experience is being affected for supported wireless incidents.
Why it matters: Transitions ThousandEyes from alert-centric to action-centric incident response, enabling correlated investigation and validated recommendations for network operations teams through agentic automation.
Cisco ThousandEyes Actions represents a maturation of its agentic AI capabilities, moving beyond fragmented alerts to coordinated incident investigation. The system correlates network incidents using Deep Reasoning, surfaces evidence-backed recommendations, and enables operator validation before automated actions execute. Experience metrics drive incident detection—for wireless use cases, the system identifies when connection success rates degrade and correlates to root causes. The release bridges ThousandEyes' network observability with Cisco's broader Assurance suite, including Cloud Control and AI Canvas. Actions builds on ThousandEyes' OpenTelemetry integration with Splunk and Dynatrace, ensuring network context flows into full-stack platforms where APM and infrastructure teams operate. This enables cross-domain correlation where network issues surface alongside application latency and infrastructure impact, critical for NOC-to-DevOps collaboration in hybrid environments.
Read the original at thousandeyes.com
Routing & Internet
Philippines subsea cable cut rerouted within hours without full outage
Rappler / GMA Network · Oct 2, 2026 · Industry news
What happened: October 2 subsea cable cut between Philippines and Singapore caused intermittent connectivity and reduced international bandwidth for multiple telcos. PLDT and Converge rerouted traffic through alternate cables within hours; Globe fully restored service by October 5. Cable segment handled ~300Gbps of traffic; rerouting capacity proved sufficient to avoid complete outage.
Why it matters: Real-world case study of subsea cable failure recovery; demonstrates multi-path redundancy and rapid failover limit blast radius and enable recovery without prolonged service loss.
On October 2, internet users across Philippines experienced slow and intermittent connectivity after a fiber cut in a subsea cable linking Philippines to Singapore. Impact affected major telcos: PLDT, Globe, and Converge ICT Solutions reported nationwide service degradation. PLDT quickly confirmed the cut removed ~300Gbps of international capacity but assured customers sufficient redundancy existed to cover the loss. Within hours, PLDT and Converge rerouted data traffic destined for Singapore through alternative submarine cables, restoring most service. Globe tapped backup capacity and alternative international links the same evening but warned repairs could take weeks. By October 4, Globe announced full restoration of services after subsea cable repair completion. Customers experienced residual intermittency and elevated latency on international routes while rerouting was active, but local services remained unaffected. The incident illustrates how operator investments in diverse cable paths and rapid traffic engineering procedures limit outage scope—what could have been a complete international disconnect became a temporary capacity constraint managed through existing redundancy.
Read the original at rappler.com
Network Security
Fortinet FortiMail zero-day exploited with federal fix deadline
The Register · Oct 2, 2026 · Industry news
What happened: Fortinet warned customers to lock down FortiMail after attackers started exploiting a critical CVSS 9.8 bug allowing unauthenticated file writes via crafted HTTP/HTTPS requests. CISA added it to KEV on October 1 with federal mitigation deadline of October 4, 2026.
Why it matters: Email gateway compromise enables mail scanning bypass, communication exfiltration, persistent backdoors, and lateral network pivot—critical for organizations managing perimeter security and incident response.
CVE-2026-104286, disclosed October 1, 2026, combines path traversal with improper null-byte handling in FortiMail's web interface, allowing unauthenticated arbitrary file writes. Affected versions: FortiMail 8.0.0–8.0.1, 7.6.0–7.6.6, 7.4.0–7.4.8, and 7.2.0–7.2.9. Fortinet confirmed active exploitation in the wild but fixed builds remain pending; interim mitigation requires disabling IBE (Identity-Based Encryption) via CLI and restricting management interface access. CISA's KEV entry requires forensic triage under BOD 26-04 for federal agencies. The web-facing attack surface and arbitrary file-write primitive make this a gateway-level compromise risk; attackers can disable threat scanning, harvest archived mail, or establish persistence for lateral movement. Organizations must assume potential compromise and conduct forensic investigation even where mitigation is applied, as the vulnerability existed before disclosure and patches became available.
Read the original at theregister.com
Two Citrix NetScaler zero-days exploited in default configurations
Security Boulevard · Sep 28, 2026 · Industry news
What happened: CISA added two Citrix NetScaler zero-days (both CVSS 9.5) to KEV after confirming active global exploitation: CVE-2026-88771 is an unauthenticated RCE in default configurations affecting ADC and Gateway, and CVE-2026-88772 is a DTLS VPN memory buffer overflow enabling RCE or denial of service.
Why it matters: Unauthenticated RCE on remote-access edge appliances in default configuration creates immediate perimeter compromise; federal agencies must mitigate by September 30 despite potential downtime from patching.
Both CVE-2026-88771 and CVE-2026-88772 are CVSS 9.5 and confirmed under active global exploitation as of September 28, 2026. CVE-2026-88771 allows unauthenticated remote code execution on NetScaler ADC and Gateway systems running default configurations; CVE-2026-88772 is a memory buffer overflow in DTLS-enabled VPN virtual servers that can result in RCE or denial of service. The vulnerabilities target edge and remote-access products typically internet-exposed; unauthenticated RCE on such devices enables immediate lateral movement into protected networks without credential requirement. Citrix advised organizations to review advisories, perform compromise assessments, and prioritize patching despite potential downtime. The federal agency deadline of September 30 reflects the severity and evidence of weaponization. Organizations relying on traditional VPN gateways rather than SASE or zero-trust network access should treat these as emergency priorities given the gateway role in perimeter defense.
Read the original at securityboulevard.com
Cisco SD-WAN Manager authentication bypass exploited in the wild
IPSIP Vietnam · Oct 4, 2026 · Industry news
What happened: Cisco released a fix September 30, 2026 for CVE-2026-76504, a CVSS 9.8 authentication bypass in Catalyst SD-WAN Manager allowing unauthenticated remote attackers to gain administrator-level access via crafted HTTP requests. Active exploitation confirmed during September 2026.
Why it matters: SD-WAN Manager compromise on the management plane enables attackers to alter network policies, configurations, and device settings across distributed WAN infrastructure in a single attack vector.
CVE-2026-76504 is rated CVSS 9.8 and allows unauthenticated remote attackers to obtain administrator-level access to Cisco Catalyst SD-WAN Manager through specially crafted HTTP requests. Cisco PSIRT confirmed active exploitation during September 2026. The vulnerability impacts the management plane rather than edge forwarding, meaning compromise of a central orchestrator can propagate policy changes, disable security controls, or redirect traffic across the entire SD-WAN fabric. Network operators must verify immediate patching and enforce network segregation of SD-WAN management interfaces. The risk is amplified for organizations in hybrid SD-WAN/MPLS migrations or early-stage SASE deployments where the SD-WAN controller serves as a critical control point. Unlike edge vulnerabilities that affect a single appliance, management-plane compromise can affect hundreds of branch devices and thousands of user sessions with a single authenticated action by an attacker.
Telco & Cable AI
Comcast correlates network alarms with AI agents at 90% accuracy
Light Reading · Oct 2, 2026 · Industry news
What happened: Cable operators Comcast and Charter demonstrated agentic AI for network operations at SCTE TechExpo, with Comcast using AI agents to correlate alarms into single tickets and perform root-cause analysis at over 90% accuracy. Charter deployed GPU infrastructure across 1,000+ edge hubs, delivering sub-10ms latency to 500 million devices.
Why it matters: Cable operators automating 50%+ of trouble tickets through agentic AI; concrete NOC labor reduction and MTTR improvement—moving from reactive to proactive incident management.
Comcast demonstrated agentic AI handling the operational challenge of alarm overload: high-volume network telemetry generates thousands of alerts daily, overwhelming NOC teams. AI agents now correlate related alarms into single trouble tickets and perform root-cause analysis with over 90% accuracy (targeting 99% within a year). Data from resolved incidents continuously reflows into the AI model to improve analysis. Comcast reports deconflicting more than 50% of incoming trouble tickets, effectively halving manual triage burden. Charter Communications deployed Edge Compute Infrastructure (ECI) across 1,000+ hubs and headends, repurposing physical space and power/cooling capacity for GPU clusters. This distributed edge architecture positions Charter (post-Cox merger) to deliver sub-10 millisecond latency to roughly 500 million devices in US homes and businesses, enabling low-latency AI inference at the network edge. For cable operators, this represents transition from DAA (distributed access architecture) infrastructure toward AI-informed network operations—leveraging existing hub/headend real estate for edge compute and correlating distributed telemetry through agentic systems.
Read the original at lightreading.com
Bell Canada and Cisco build sovereign AI infrastructure offering
Rallies · Sep 29, 2026 · Industry news
What happened: Bell Canada signed an MOU with Cisco to develop a sovereign AI infrastructure offering combining Bell's data centers, networks and operations with Cisco modular AI PODs. The offering targets Canadian government and regulated industries requiring data residency, with flexible commercial models for AI workload deployment.
Why it matters: Telcos repositioning from connectivity providers to AI infrastructure operators; sovereign offerings unlock higher-margin enterprise segment (government, healthcare) with data residency and operational control requirements.
Bell Canada and Cisco are jointly developing an AI infrastructure offering for organizations demanding data sovereignty—government agencies, regulated industries, sensitive workloads requiring Canadian data residency and operational control. The architecture combines three elements: Bell's existing datacenters (BC, Saskatchewan, Manitoba facilities), high-performance connectivity infrastructure, and Cisco's modular AI appliances (Cisco AI PODs). The commercial model is flexible—customers align costs with infrastructure usage rather than fixed capacity purchases, lowering entry barriers for organizations uncertain about AI workload requirements. This MOU complements Bell's existing AI Fabric strategy (Groq, Cohere partnerships in British Columbia and Saskatchewan) by adding Cisco's standardized modular appliances, enabling faster deployment and lower total cost of entry. For network operators, this signals a strategic shift: infrastructure-as-a-service (IaaS) centered on AI compute and connectivity is becoming a distinct revenue stream separate from consumer broadband and enterprise connectivity services. Bell's positioning targets segments where public cloud options (AWS, Azure, GCP) face regulatory barriers or data residency concerns—a higher-margin enterprise market unlocked by telco infrastructure assets.
Read the original at rallies.ai
AI Industry & Policy
Collibra buys Trail ML as agent governance demand grows
Artiverse · Oct 5, 2026 · Industry news
What happened: Collibra acquired Munich-based AI governance company Trail ML, while Cohere introduced North 2 with tighter controls for agents and automations on October 5, 2026. Both moves signal enterprise demand for comprehensive agent governance at scale.
Why it matters: Enterprises need tools that manage agents across their full lifecycle while scaling without leaving governance, security, spending, and permissions behind.
On October 5, 2026, Collibra announced its acquisition of Trail ML, a Munich-based AI governance company, while Cohere released North 2 with enhanced controls for agents and automations. These announcements reflect a core enterprise pressure: AI systems need to scale without leaving governance, security, spending, and permissions behind, with companies seeking tools to manage agents across their full lifecycle—from assessing requirements to controlling actions in production. The timing is critical as agentic AI usage is poised to rise sharply in the next two years, but oversight is lagging with only one in five companies having a mature model for governance of autonomous AI agents. The acquisitions and product launches address the documented 47-point gap between adoption rates (74%) and governance controls (47%), a gap driving projected 25% budget increases in AI governance technology. For infrastructure and AIOps teams, this means procurement reviews for agentic systems now require explicit governance checkpoints.
Read the original at artiverse.ca
AI unit costs collapse while frontier labs absorb record capital
p4sc4l substack · Oct 4, 2026 · Analysis
What happened: AI economics are bifurcating as unit costs collapse while frontier development demands unprecedented capital, with OpenAI seeking $30B at $1.4T valuation and Anthropic's IPO materials pointing to $2T valuation. Competitive advantage is shifting toward distribution and proprietary data.
Why it matters: AI is being absorbed into national-security, defense and industrial policy, binding governments, hyperscalers, defense companies, critical minerals and data infrastructure into a single strategic ecosystem.
AI unit costs are collapsing at roughly 13x per year according to Epoch AI, even as frontier labs require massive capital—OpenAI seeking $30B at $1.4T valuation and Anthropic's IPO materials pointing to $2T valuation. This creates a two-tier market: frontier labs competing on compute and talent moats, while application-layer companies compete on distribution, workflow integration, and proprietary data. Simultaneously, AI is being absorbed into national-security, defense and industrial policy, binding governments, hyperscalers, defense technology companies, critical minerals and data infrastructure into a single strategic ecosystem. For enterprise and infrastructure leaders, this means the venture market is consolidating toward either frontier infrastructure plays backed by sovereigns or acquisition targets with defensible vertical applications. The geopolitical integration of AI with defense and critical infrastructure creates new compliance, data residency, and supply-chain risks for enterprises operating internationally.
Read the original at p4sc4l.substack.com
Read this edition on the web · The week in network intelligence · Vendor Radar
Digital Plumber is AI-curated and AI-summarized, with no human review before publishing. Verify before acting on anything here. How it works.