Sep 29: CISA flags exploited Check Point, Arista and F5 flaws
Today's 3 things that matter
- CISA flags exploited Check Point, Arista and F5 flaws
VPN gateways, SD-WAN orchestrators, and management platforms whose compromise expose credentials, policies, and downstream devices represent the highest-risk attack surface for enterprise networks. - Forward Networks ships change validation for agentic NetOps
Forward Predict provides the verification and guardrails Agentic NetOps requires for network operations teams deploying autonomous agents. - CloudWatch Omni reaches general availability with cross-cloud observability
Omni's cross-cloud and cross-region aggregation reduces NOC tool sprawl; warm-up/wall clock evaluation directly addresses alert noise during deployments—a core operational efficiency metric for SREs.
Full stories below, grouped by topic.
Network Automation
When to pick Ansible, Nornir or Netmiko
OneUptime · Sep 26, 2026 · Analysis
What happened: Practitioner guide comparing three network automation tools by mapping workflows to state management, orchestration, transport, testing, and operational ownership. Covers when to use each tool and provides decision framework based on real requirements.
Why it matters: Helps NetDevOps practitioners avoid tool selection based on popularity and instead match tools to actual operational workflows and scaling constraints.
This guide by Nawaz Dhandala addresses the fundamental question practitioners face: which automation tool fits your workflow? Rather than comparing tools in isolation, the article maps three categories—Ansible, Nornir, and Netmiko—against five dimensions: state management (declarative vs. imperative), orchestration (scheduling, retries, partial failures), transport layer, testing coverage, and operational ownership. A key insight: these tools sit at different layers. Netmiko provides device-oriented CLI connections; Nornir adds Python-native inventory and parallel task execution; Ansible layers on declarative configuration management. The article walks through a concrete example (maintaining interface descriptions on 200 switches) showing how requirements evolve: a one-off script works initially, but at scale you need scheduling, error handling, and consistency—at which point Ansible or Nornir becomes necessary. Testing gets its own section: validate against representative devices per platform and release, including offline devices and malformed responses. The guidance concludes that a useful default is Ansible for well-supported configurations, Nornir for complex logic requiring Python control, and recognizes that Nornir can use Netmiko as its transport, so selecting one doesn't always exclude the other. This is practitioner wisdom, not marketing.
Read the original at oneuptime.com
Making NetBox the real source of truth for inventories
OneUptime · Sep 26, 2026 · Analysis
What happened: Technical guide on establishing NetBox as a true network source of truth (SoT) by separating three concerns: device selection, data validation, and inventory format translation. Shows contract-driven integration pattern for both Ansible and Nornir.
Why it matters: Addresses the gap between having a SoT API and actually consuming it reliably; essential for practitioners trying to eliminate hand-edited inventory files.
The core problem this article solves: replacing a static inventory file with an API query doesn't magically establish a source of truth. Missing management addresses, ambiguous device names, and unsupported platform slugs still produce incomplete or incorrectly targeted jobs—silent failures that break automation. The author separates three concerns: (1) Device Selection—define what devices qualify: active, tagged, physical only, etc. (2) Data Validation—require unique device name, primary management IP, recognized platform slug. (3) Format Translation—render NetBox records into Ansible inventory.yml or Nornir inventory.yaml format. Operationally, the integration records export metadata: time, source URL, selection filters, and a digest of the records. This enables you to detect when NetBox is unavailable and fail a new deployment explicitly rather than silently falling back to a stale cache—critical for safety. Testing covers edge cases: duplicate names, missing IPs, unsupported platforms, empty selections, and multi-page API responses. The boundary is validated before any device connection is attempted. Once established, Ansible and Nornir can share the same operational view without maintaining competing hand-edited host files. This shifts SoT from aspirational architecture to operational practice.
Read the original at oneuptime.com
Bounding automation concurrency and reporting partial failures
OneUptime · Sep 26, 2026 · Analysis
What happened: Deep technical guide on safely scaling parallel network automation by identifying concurrency bottlenecks (AAA, jump hosts, WAN bandwidth) and implementing result tracking that fails gracefully on partial execution.
Why it matters: Prevents common gotchas when scaling from serial to parallel automation: exhausted AAA capacity, connection storms, and loss of visibility into which targets failed.
Parallel network automation can turn a thirty-minute collection into a short job, but it can also exhaust an AAA service, open too many sessions through a jump host, or send a burst of expensive commands to a small branch network. The article's framework starts with modest global concurrency limits (e.g., 10 workers), then identifies shared bottlenecks: device session limits, TACACS+/RADIUS request rates, jump-host connection capacity, and WAN bandwidth/latency at branch sites. Each bottleneck requires different mitigations—some need threading limits, others need adaptive request queueing. The key safety principle: fast execution is only useful when the job can still identify every target that failed, was skipped, or never ran. This means tracking per-device results, not just aggregate success/failure. The article covers implementation patterns in both Ansible (async module with poll strategy) and Nornir (ThreadPoolRunner with result aggregation). Failure handling is crucial: partial failures must be visible, not masked by overall success. This is operational maturity—moving from 'did it work?' to 'what percentage worked and where did we lose visibility?'
Read the original at oneuptime.com
AIOps & Network Observability
CloudWatch Omni reaches general availability with cross-cloud observability
AWS Cloud Operations Blog · Sep 26, 2026 · Primary source
What happened: Amazon CloudWatch Omni reached general availability with AI-first, app-centric observability across AWS accounts, Regions, and Azure workloads. New features include alarm warm-up periods, wall clock evaluation windows, expanded database observability, and native journald support for log collection.
Why it matters: Omni's cross-cloud and cross-region aggregation reduces NOC tool sprawl; warm-up/wall clock evaluation directly addresses alert noise during deployments—a core operational efficiency metric for SREs.
Amazon CloudWatch Omni, now generally available in August-September 2026, introduces an AI-powered observability experience organized around teams and applications rather than resources. Key operational improvements for NOCs include: (1) Alarm warm-up periods and wall clock evaluation windows that eliminate spurious alerts from startup gaps and rolling-window edge cases—a significant source of alert fatigue in traditional monitoring; (2) Unified telemetry ingestion across AWS accounts, Regions, and Azure workloads in a single space, reducing context-switching and tool fragmentation; (3) Expanded database observability covering self-managed PostgreSQL and Aurora DSQL alongside managed offerings; (4) AI-powered investigation via Amazon Q Console for CloudTrail events, enabling plain-language root cause queries over access logs; (5) Enhanced log collection with native journald support, GeoIP/RDS/XML pipeline processors, and tag propagation for centralized log correlation. The release signals Amazon's move toward event correlation and causal analysis—moving beyond passive metric collection to active incident investigation. Integration with OpenTelemetry across the portfolio enables vendor-neutral instrumentation, addressing long-standing NetOps concerns about lock-in.
Read the original at aws.amazon.com
Network Security
Check Point patches management server zero-day used in attacks
The Hacker News · Sep 22, 2026 · Industry news
What happened: CVE-2026-93616 allows unauthenticated attackers to run scripts on Check Point management servers via path traversal; Check Point released a fix on September 22. A separate CVE-2026-91843 was patched via LivePatch on September 16.
Why it matters: Firewall management server compromise gives attackers policy control and credential access across all managed gateways, exposing the entire network infrastructure.
CVE-2026-93616 is a path traversal vulnerability allowing unauthenticated remote code execution on Check Point management servers controlling firewall policies. Check Point released a fix on September 22. Attackers exploited the flaw to escalate privileges using certificate validation bypasses to access administrative functions. The vulnerability affects Security Management, Multi-Domain Management, Log, and SmartEvent servers, with directory traversal and file upload enabling arbitrary script execution. Smart-1 Cloud deployments are already protected, while on-premises systems require the specific fix released on September 22. Check Point explicitly states that LivePatch Take 28 or 29 does not address this issue—a critical operational detail for patch verification. This is the central control plane for Check Point deployments; compromise means attackers have both network topology visibility and the ability to modify firewall configurations across all managed devices.
Read the original at thehackernews.com
CISA flags exploited Check Point, Arista and F5 flaws
Aviatrix Threat Research Center · Sep 22, 2026 · Industry news
What happened: CISA added four critical vulnerabilities to Known Exploited Vulnerabilities catalog on September 22: Check Point CVE-2026-85102/93616, Arista VeloCloud CVE-2026-93952, and F5 BIG-IP CVE-2026-94127—all actively exploited in the wild with CVSS 9.0+.
Why it matters: VPN gateways, SD-WAN orchestrators, and management platforms whose compromise expose credentials, policies, and downstream devices represent the highest-risk attack surface for enterprise networks.
CISA added four critical KEV entries affecting Check Point gateways (certificate validation bypass and path traversal), Arista VeloCloud Orchestrator (input validation), and F5 BIG-IP APM (buffer overflow). Attack chains achieve remote code execution on exposed appliances, then escalate to administrative access, move laterally through network infrastructure to cloud environments, and establish encrypted command-and-control channels bypassing traditional perimeters. The fundamental problem: patches exist but attackers are moving faster than patch cycles, targeting edge network appliances. F5's BIG-IP flaw (CVE-2026-94127) was exploited as a zero-day before the fix existed, exposing the gap between discovery and vendor response. This signals a structural shift where perimeter infrastructure—not endpoints—drives breach speed.
Read the original at aviatrix.ai
Six exploited edge and identity flaws added last week
about InfoSec · Sep 28, 2026 · Analysis
What happened: Four newly cataloged exploited edge and identity vulnerabilities led the week's defender queue, with CISA adding six actively exploited flaws affecting F5 BIG-IP APM, Check Point gateways/management, Arista VeloCloud Orchestrator, WSO2, and Adobe Commerce. Citrix separately disclosed two NetScaler zero-days patched on September 27.
Why it matters: Edge and management infrastructure—VPN gateways, SD-WAN orchestrators, OAuth servers, security-management platforms—are the perimeter's real high-value targets; their compromise exposes credentials, policies, and configuration across downstream infrastructure.
CVE-2026-94127 (F5 BIG-IP APM, CVSS 9.8) is a heap-based buffer overflow in Access Policy Manager allowing unauthenticated RCE when OAuth is configured, affecting APM 17.1.0–17.1.3, 17.5.0–17.5.1, and 21.1.0. Check Point reports active exploitation of CVE-2026-85102 on Spark Firewalls since September 12, with systems using certificate-based VPN authentication requiring the current LivePatch or Jumbo Hotfix. Two Citrix NetScaler zero-days (CVE-2026-88771 and CVE-2026-88772) were patched on September 27 after watchTowr disclosure; all eight disclosed flaws scored CVSS 9.0 or higher and are actively exploited with fixes available. The operational priority is clear: fix confirmed exploitation paths now, verify whether attackers already arrived first through forensics, then plan durable control-plane isolation to prevent lateral movement.
Read the original at aboutinfosec.com
Agentic AI & MCP
Forward Networks ships change validation for agentic NetOps
PR Newswire · Sep 29, 2026 · Vendor release
What happened: Forward Networks announced Forward Predict, a capability for safe Agentic NetOps now generally available, which deterministically shows the impact of proposed network changes before production using a mathematically accurate digital twin to give AI agents proof of connectivity, security, and compliance effects at design time.
Why it matters: Forward Predict provides the verification and guardrails Agentic NetOps requires for network operations teams deploying autonomous agents.
Forward announced Forward Predict is now generally available as a critical enabler of safe Agentic NetOps. The tool deterministically shows the impact of proposed network changes before they touch production, built on Forward Enterprise's mathematically accurate digital twin to give AI agents and human teams proof of how a change will affect network connectivity, security, and compliance at design time. Since its beta launch in May, organizations across financial services, media, and technology have used Forward Predict to reduce change risk and accelerate delivery. This addresses a core operational requirement for teams deploying autonomous agents in NetOps: before agents can safely execute changes at scale, they need deterministic validation that changes won't degrade service. Digital twins provide that guardrail without requiring lab testing, reducing change risk from hours of manual review to seconds of simulation.
Read the original at prnewswire.com
AI Model Providers
Anthropic releases faster Claude Sonnet 5.5 at same price
9to5Mac · Sep 28, 2026 · Industry news
What happened: Anthropic upgraded Claude Sonnet, replacing Sonnet 5 with Sonnet 5.5 as its best medium-sized model. Sonnet 5.5 generates output more than 30% faster than Sonnet 5 while maintaining identical pricing at $2 input / $10 output per million tokens.
Why it matters: Better performance at unchanged pricing means lower per-token costs for API workloads; first Sonnet with Opus-level cybersecurity safeguards expands secure deployment options.
Anthropic released Claude Sonnet 5.5 on September 28, 2026, replacing Sonnet 5 as the best medium-sized model. The new version generates output 30% faster than Sonnet 5 while using fewer tokens for equivalent work. Pricing remains unchanged: $2 per million input tokens, $10 per million output tokens, and $0.20 per million cache reads. Notably, Sonnet 5.5 is the first Sonnet model to launch with cybersecurity safeguards and fallbacks comparable to Opus 5, previously reserved for Anthropic's flagship models. This release came just 90 minutes before OpenAI's competing Sol and Luna launch on September 22, demonstrating the acceleration in release cadence between the two labs. For infrastructure and MLOps teams, the combination of faster inference, unchanged costs, and expanded security capabilities makes Sonnet 5.5 a direct productivity upgrade for medium-tier workloads without requiring cost optimization efforts.
Read the original at 9to5mac.com
AI Industry & Policy
False AI intelligence report nearly triggered US-China incident
p4sc4l (Substack) · Sep 27, 2026 · Analysis
What happened: A false AI-assisted intelligence report brought the U.S. military close to boarding a Chinese vessel before error was caught. Report documents broader trends in AI governance hardening into operational controls, training-data conflicts expanding beyond copyright, and geopolitical competition over AI as national-security infrastructure.
Why it matters: Military institutions deploying AI for intelligence now face demonstrable risks of AI failures in high-consequence situations; governance and safety controls moving from advisory to mandatory.
A false AI-assisted intelligence report brought the U.S. military close to boarding a Chinese vessel before the error was caught, exemplifying risks of AI systems operating at scale with insufficient vetting. Simultaneously, the training-data conflict is widening from copyright into consent, provenance, hidden human labor, and auditability across the entire AI supply chain. Meta's Muse was reported to opt users into data collection while soliciting sensitive information, OpenAI contractors were fired for using AI to perform AI-training work, and Meta's supposedly automated calling feature relied partly on human call-center agents. AI governance is hardening from principles into operational controls covering model safety, infrastructure, competition, attribution, and platform accountability, while technology companies increasingly contest those rules through litigation. For infrastructure practitioners and policy teams, this signals that voluntary AI safety standards are transitioning to enforceable requirements, and that supply-chain visibility into training data and human labor is becoming a compliance mandate rather than an aspirational best practice.
Read the original at p4sc4l.substack.com
Google challenges EU AI and search competition orders
Rio Times · Sep 29, 2026 · Industry news
What happened: Google filed challenges at the General Court in Luxembourg against two EU orders requiring it to open up to AI rivals and search competitors, arguing the measures undermine privacy and would cause irreversible harm. Filing marks direct test of EU enforcement authority over AI interoperability and competitive access.
Why it matters: EU AI Act enforcement is moving from regulatory guidance to court proceedings; outcomes will set precedent for how regulators can mandate AI platform interoperability and may affect data governance strategies globally.
Google filed challenges at the General Court in Luxembourg against two EU orders requiring it to open up to AI rivals and search competitors, arguing privacy risks and irreversible harm. This legal action represents the first major test of the EU's enforcement mechanisms under its AI governance framework. Luxembourg's General Court now holds the AI-search fight, with interim relief or its absence marking the first critical ruling. The case directly addresses how regulators can mandate interoperability and competitive access in AI-driven search and recommendation systems—a pattern other jurisdictions including the US are monitoring. For enterprise operators, the immediate outcome—whether Google obtains interim relief—will signal the speed and scope of EU competition intervention in AI and may force similar architectural decisions in other regulated markets.
Read the original at riotimesonline.com
Read this edition on the web · The week in network intelligence · Vendor Radar
Digital Plumber is AI-curated and AI-summarized, with no human review before publishing. Verify before acting on anything here. How it works.