You're reading the Sunday, October 11, 2026 edition. Today's briefing →
Toronto
Sunday, October 11, 2026No. 119

Digital Plumber

Plumbing the information age

AI-curated intelligence for people who run networks. Daily coverage of AIOps, network automation, agentic operations, AI infrastructure, security and the vendors shaping them.

Today's 3 things that matter

Picked by the AI editor
  1. Security·Industry news

    Ransomware crews exploit Palo Alto GlobalProtect authentication bypass

    Ransomware groups including Qilin and Settra are actively exploiting CVE-2026-0257, an authentication bypass in Palo Alto Networks PAN-OS GlobalProtect and Prisma Access, to create unauthorized VPN sessions and enter internal networks through trusted remote access services.

    Why it matters The vulnerability affects firewalls with GlobalProtect portal or gateway when authentication override cookies are enabled, requiring immediate audit of cookie-based authentication configurations on all PAN-OS deployments.

  2. Security·Analysis

    Cisco and SonicWall edge zero-days land in CISA KEV

    Cisco CVE-2026-76504 and SonicWall CVE-2026-102255 were added to CISA's Known Exploited Vulnerabilities catalog within weeks of disclosure, both scoring near-maximum CVSS and affecting network edge devices that serve as preferred entry points for ransomware crews.

    Why it matters VPN gateways and SD-WAN controllers remain prioritized ransomware targets because they are internet-facing, upstream of internal networks, and often subject to extended patch-window schedules that create exploitation windows lasting weeks or months.

  3. Routing·Primary source

    Cloudflare makes BGP over IPsec and GRE generally available

    Cloudflare released general availability of BGP peering over IPsec and GRE tunnels for Unified Routing, enabling dynamic route exchanges without manual static route management.

    Why it matters Simplifies SD-WAN routing: operators can now use BGP as control plane over encrypted transport tunnels, eliminating tedious static route provisioning when network topology changes.

Today's briefing

What happened, and why it matters

8 stories · 4 topics · Updated 12:20 PM ET

Philippines-Singapore subsea cable cut disrupts regional traffic for days

SubTel Forum · Oct 5, 2026 · Industry news

A fiber-optic submarine cable segment connecting the Philippines to Singapore was severed on October 2, causing intermittent connectivity across the region. Telecommunications companies including Converge and Globe restored services within days by rerouting through redundant cable systems.

Why it matters Demonstrates real-time subsea cable resilience: redundant routing prevented total outage, but shows concentration risk in Asia-Pacific regional connectivity and the operational value of diverse cable routing.

On Friday October 2, users in the Philippines experienced slow and intermittent connectivity after the Philippines-Singapore submarine cable segment went down, with the Hong Kong link also affected. The Department of Information and Communications Technology (DICT) investigated; possible causes included natural fiber cuts, equipment failure, or sabotage, but full details remained undetermined as repairs continued. Critically, Converge ICT Solutions deployed its new subsea cable to Singapore as backup routing, preventing full outage for its customers and demonstrating the operational ROI of diversified international cable paths. Globe Telecom also restored services quickly but noted repairs would take several weeks. The incident highlights that even single-cable cuts in critical chokepoints can cascade regionally, making multi-path BGP routing and carrier diversification essential operational practices for Asia-Pacific network operators.

Read the original at subtelforum.com ↗

Cloudflare makes BGP over IPsec and GRE generally available

Cloudflare Changelog · Oct 7, 2026 · Primary source

Cloudflare released general availability of BGP peering over IPsec and GRE tunnels for Unified Routing, enabling dynamic route exchanges without manual static route management. Available to all WAN and Magic Transit customers.

Why it matters Simplifies SD-WAN routing: operators can now use BGP as control plane over encrypted transport tunnels, eliminating tedious static route provisioning when network topology changes.

BGP over IPsec and GRE tunnels is now GA for production workloads on Cloudflare's Unified Routing platform. The feature allows BGP speakers to dynamically exchange routes between customer devices and Cloudflare's virtual routing table over encrypted tunnels, removing the need for manual static route configuration when sites come online or topology shifts. This operational improvement matters because traditional SD-WAN deployments often require manual intervention to update static routes as networks expand or failover; BGP automation eliminates that friction. BGP peering exchanges routes dynamically, so any network change propagates automatically. The feature is available to all accounts using Unified Routing; BGP over CNI (container native interface) remains in closed beta. No explicit enablement required.

Read the original at developers.cloudflare.com ↗

BGP flapping at Qrator Labs breaks Russian proxy forwarding

debuglies.com · Oct 9, 2026 · Analysis

A major October 8 incident in Russian digital infrastructure involved BGP flapping at Qrator Labs causing upstream reverse-proxy nodes to cease packet forwarding. Analysis notes potential BGP hijacking or volumetric saturation attacks against Qrator's advertising infrastructure concurrent with kinetic events.

Why it matters Real-world case study in routing control plane degradation under stress: demonstrates how BGP instability isolates origin servers from public internet even when backends remain operational.

On October 8, 2026, Russian digital infrastructure including national banking and media services experienced outages driven by BGP flapping at Qrator Labs, a major DDoS mitigation and routing security provider. Origin servers in multiple availability zones remained operationally healthy but became unreachable via public DNS and anycast resolution because reverse-proxy nodes failed to forward traffic. Analysis indicates upstream BGP route advertisements from Qrator may have experienced targeted hijacking or volumetric saturation attacks. The incident underscores a critical operational reality: control-plane failures (BGP flapping, route withdrawal, path instability) can render healthy infrastructure completely invisible to the internet. Even with redundancy and healthy backends, if BGP announcements collapse or become unstable, clients cannot reach services. The incident also raises questions about whether Russia's telecommunications monitoring center (TsMU SSOP) issued centralized routing overrides during concurrent kinetic operations in the Ryazan region.

Read the original at debuglies.com ↗

Ransomware crews exploit Palo Alto GlobalProtect authentication bypass

CyberSecurityNews · Oct 11, 2026 · Industry news

Ransomware groups including Qilin and Settra are actively exploiting CVE-2026-0257, an authentication bypass in Palo Alto Networks PAN-OS GlobalProtect and Prisma Access, to create unauthorized VPN sessions and enter internal networks through trusted remote access services.

Why it matters The vulnerability affects firewalls with GlobalProtect portal or gateway when authentication override cookies are enabled, requiring immediate audit of cookie-based authentication configurations on all PAN-OS deployments.

CVE-2026-0257 is a high-severity authentication bypass in Palo Alto's GlobalProtect VPN portal and gateway that allows unauthenticated attackers to forge authentication override cookies and establish fully authorized VPN sessions without credentials. The vulnerability stems from improper certificate configuration where the same certificate used for HTTPS services is reused for encrypting authentication override cookies, combined with lack of signature verification during cookie decryption. Attackers extract the public key from the server's TLS certificate and forge valid authentication override cookies, gaining network access that appears to be from a legitimate remote user.

Active exploitation began in May 2026, but has accelerated with multiple ransomware-as-a-service operations now weaponizing the flaw. ReliaQuest's October 2026 threat intelligence confirms Qilin and Settra ransomware groups using CVE-2026-0257 to bypass remote access controls and move laterally through internal networks. Organizations must verify whether Authentication Override is enabled on GlobalProtect deployments (deployments without the vulnerable configuration remain unaffected) and either disable it or implement the recommended mitigations: using a dedicated certificate exclusively for signing authentication override cookies with secure key management.

The vulnerability does not affect Panorama or Cloud NGFW deployments, and patch versions are available across PAN-OS 10.2 through 12.1.x releases. Affected products include PA-Series and VM-Series firewalls and Prisma Access with GlobalProtect enabled and authentication override cookies configured.

Read the original at cybersecuritynews.com ↗

Cisco and SonicWall edge zero-days land in CISA KEV

Tech Insider · Oct 10, 2026 · Analysis

Cisco CVE-2026-76504 and SonicWall CVE-2026-102255 were added to CISA's Known Exploited Vulnerabilities catalog within weeks of disclosure, both scoring near-maximum CVSS and affecting network edge devices that serve as preferred entry points for ransomware crews.

Why it matters VPN gateways and SD-WAN controllers remain prioritized ransomware targets because they are internet-facing, upstream of internal networks, and often subject to extended patch-window schedules that create exploitation windows lasting weeks or months.

Cisco and SonicWall have released critical vulnerabilities affecting their remote access and SD-WAN edge products, both added to CISA's Known Exploited Vulnerabilities catalog within weeks of disclosure. The Cisco vulnerability (CVE-2026-76504) and SonicWall's SMA 1000 flaw (CVE-2026-102255) both carry near-maximum CVSS scores and affect devices positioned at the network perimeter, making them high-value targets for initial compromise in ransomware campaigns.

SonicWall's advisory carefully scopes damage to SMA 1000 models (6210, 7210, 8200v) across physical and virtual deployments running vulnerable platform-hotfix versions 12.4.3-03526 or 12.5.0-02952. The flaws do not affect SMA 100 series or the separate SSL-VPN functionality built into SonicWall's firewall line. This represents a second maximum-severity flaw in five weeks for SonicWall's portfolio, indicating systemic issues with edge device security.

Network and security operations teams must prioritize patching these edge devices immediately, recognizing that the brief window between patch release and active exploitation (often less than 24 hours for VPN gateway flaws) leaves minimal reaction time. The structural reason VPN gateways and SD-WAN controllers remain ransomware's preferred attack surface is that they are internet-facing, positioned upstream of internal networks, and frequently subject to extended patch-window schedules. Federal agencies received a deadline of October 21, 2026 to apply fixes, but private sector organizations should treat these as zero-day equivalent threats and prioritize emergency patching over normal change-control procedures.

Read the original at tech-insider.org ↗

Mistral releases trillion-parameter open-weight Large 4 in preview

Distilling Intelligence · Oct 9, 2026 · Industry news

Mistral AI released Mistral Large 4, a trillion-parameter open-weight multimodal model with Mixture-of-Experts architecture and 1M context window, available in public preview with full weights coming October 27.

Why it matters Open-weight deployment flexibility and MoE efficiency reduce inference costs for coding and agent workloads while offering alternatives to closed-model providers.

Mistral Large 4 (nicknamed 'Le Chonk') is Mistral's first major model announcement in five months, designed for cybersecurity and coding tasks. The trillion-parameter model uses a Mixture-of-Experts architecture enabling selective parameter activation per task, reducing inference costs compared to dense models. With a 1M context window and multimodal capabilities, it supports both long-context reasoning and multi-modal inputs. The open-weight release on Hugging Face allows deployment on private infrastructure without API dependencies—critical for organizations with data residency requirements or high-volume inference cost constraints. Mistral partnered with Loft Orbital on a $1 billion satellite data-analysis program, signaling infrastructure expansion beyond model development. For production teams, this eliminates vendor lock-in for inference and enables fine-tuning on proprietary data. The timing directly addresses European regulatory push for digital sovereignty and positions Mistral competitively against closed-model leaders and Chinese open-weight alternatives.

Read the original at distillintelligence.com ↗

AI political spending passes $300M as FTC probes safety claims

TechTimes · Oct 9, 2026 · Industry news

AI industry political spending has surpassed $300 million in the 2026 midterms, while the Federal Trade Commission opens a formal inquiry into OpenAI and Anthropic examining whether public safety claims match actual deployment practices.

Why it matters Enterprise AI adoption strategies now operate under federal safety scrutiny; regulatory alignment will shape vendor selection and procurement processes in Q4 2026.

The Federal Trade Commission opened a formal inquiry into OpenAI and Anthropic on October 1, examining whether the companies' public safety claims align with their actual deployment practices. Simultaneously, the artificial intelligence industry has poured more than $300 million into congressional races through competing super PACs. The three dominant AI political networks operating in 2026 have collected more combined spending than the Club for Growth — the previous record-holder for single-sector midterm PAC spending, with $69 million in 2022. This creates direct conflict: major AI vendors are simultaneously funding candidates who will determine regulatory oversight while operating under active federal safety investigations. For enterprise teams, this signals regulatory volatility ahead—the post-election AI policy landscape will depend partly on which candidates the industry successfully funded. The FTC inquiry itself creates immediate compliance exposure: organizations need to audit vendor safety claims against actual deployment practices, particularly for any systems handling sensitive enterprise data.

Read the original at techtimes.com ↗

Bloomberg documentary ties AI capital flood to economic strain

Crypto Briefing · Oct 8, 2026 · Industry news

A Bloomberg Originals documentary released on October 8, 2026, argues that the flood of capital into AI is creating problems for the US government, developing nations and the global economy at large.

Why it matters Geopolitical capital concentration in US AI vendors affects enterprise procurement strategy, sovereign AI requirements, and international regulatory divergence shaping deployment decisions.

The world's money has a favorite destination right now, and it's a short list of American tech companies building artificial intelligence. The documentary highlights structural issues: concentrated AI investment flows to a handful of US-based vendors, creating macroeconomic pressure on US fiscal policy while marginalizing developing-nation AI ecosystems. This directly impacts enterprises: it accelerates regional regulatory responses and sovereign AI mandates, as evidenced by Microsoft's $10 billion Japan commitment to build domestic AI infrastructure. The capital concentration also affects vendor leverage in procurement negotiations—major US AI vendors control disproportionate capital access, shaping enterprise choices. For multinational organizations, this reinforces divergent deployment patterns: US/Western enterprises rely on concentrated vendor solutions, while Asian and European markets increasingly pursue localized alternatives driven by geopolitical and regulatory pressure. CIOs should expect tighter regional data residency requirements and rising infrastructure capex as governments respond to perceived dependency on US vendors.

Read the original at cryptobriefing.com ↗
Nothing in today's briefing matches that.

Vendor Radar

Last 7 days · arrows compare with the 7 before

What changed this week

Last 7 days vs the 7 before

Biggest moves

Trending topics

agent · MCP · SRE · automation · observability · Agentic AI · RAG · OpenTelemetry · AIOps · LLM · Kubernetes · inference

Get the daily briefing

Today's 3 things that matter and every story with why it matters, in your inbox each morning. Free, and you can unsubscribe at any time. Prefer a reader? Follow the RSS feed.