FR
live
section

Networking

Arista EOS exposes unauthenticated code execution through P4Runtime and gNPSI

Arista published four security advisories for Arista EOS on September 9, including an unauthenticated RCE rated CVSS 10.0 via P4Runtime (CVE-2026-73453) and two code-execution flaws in the gNPSI telemetry interface. No active exploitation is documented yet, but patching must come before the control plane is ever exposed.

OpenSSL 4.1 adds DTLS 1.3 and GREASE to the network crypto stack

On September 9, 2026, the first OpenSSL 4.1 alpha enabled DTLS 1.3 — shorter handshakes, forward secrecy and built-in post-quantum crypto — plus GREASE, the mechanism that stops middleboxes from ossifying TLS. For anyone running gateways, IoT fleets or UDP-based services, it is the signal to start planning the migration.

MikroTik patches routers hijacked over internet-exposed SSH

CERT Polska warns that attackers are taking full administrative control of MikroTik routers whose SSH service is reachable from the internet, without authentication. Update RouterOS and audit the configuration before putting any device back into service.

A backdoor compiled into HAProxy intercepts traffic and vanishes from the load balancer’s counters

Rapid7 Labs documents “ted”, an implant compiled directly into HAProxy 2.8.12 at two South Korean companies that intercepts web traffic and erases its own connections from the load balancer’s counters. It requires a prior compromise of the host — verify the integrity of your edge binaries and watch connection counters instead of waiting for an HAProxy patch.

Cisco ships seven IOS XR hardening CVEs, two reach CVSS 9.8

On September 2, 2026, Cisco bundled seven internally discovered IOS XR vulnerabilities into seven CVEs grouped by CWE class, including two at CVSS 9.8 that affect every release of the core-router operating system. Apply the SMUs in your maintenance windows rather than waiting for releases 26.2.2 and 26.3.1.

A CVSS 9.8 flaw opens a remote root shell on ten Cisco Nexus 9000 switches

On 2 September 2026 Cisco disclosed CVE-2026-20212, a CVSS 9.8 flaw that leaves TCP ports 43210 and 43211 on ten Nexus 9000 switches reachable for unauthenticated remote code execution as root. Apply an iACL on both ports and the Live Protect lp00031 shield now, then check your release in the Software Checker.

Wi-Fi 8 stops chasing raw speed and goes after reliability

Wi-Fi 8 (IEEE 802.11bn) is the first wireless generation that no longer tries to break a throughput record: with the same theoretical top speed as Wi-Fi 7, it targets bounded latency and “ultra-high reliability” in dense environments. The first Qualcomm and Broadcom products land in late 2026, but most users can ignore them until 2028.

A Moscow fire exposes the Russian internet’s single point of failure

On 18 August 2026, a fire at a Moscow power plant cut electricity to MMTS-9, the building that hosts the core of MSK-IX, Russia’s main internet exchange point; Discord, Steam, Telegram and the country’s mobile carriers went down with it. The incident confirms a twenty-one-year-old warning: concentrating interconnection in one place is fragile design.

DOJ and FBI dismantle the GRU’s DNS hijacking network

The US Justice Department and FBI announced the takedown of a network of SOHO routers compromised by Russia’s GRU, which was hijacking DNS lookups to intercept credentials and encrypted email. The lesson in one line: the home router has become the intelligence services’ preferred interception point, and it must be defended like an attack surface.

The FBI takes down QScan and QTRouter, the obfuscation network hiding China’s intrusions

On August 26, 2026, the U.S. Department of Justice and the FBI seized the domains of QScan and QTRouter, two platforms run by a Chinese group that concealed the origin of intrusions against U.S. critical infrastructure. The lesson outlives the news cycle: network obfuscation is now an industrialized service, and it breaks where the attacker has the least redundancy.

A field report prices the IPv4 tax on EKS: about $143 a month per environment

On August 14, 2026, a RIPE NCC member published a field report on an IPv6-first EKS deployment on AWS: roughly $143 a month per environment saved, against a dated list of dependencies still stuck on IPv4. Teams standing up a new cluster now have an objective criterion for choosing IPv6-first over dual-stack.

Cavern picks its C2 channel via a DNS query and hides inside Google Apps Script and Microsoft 365 calendars

The Iranian Cavern C2 framework has added a module that queries DNS to choose between a direct HTTPS channel and a Google Apps Script relay, plus another that turns Microsoft 365 calendars into a dead-drop. For network detection, indicator blocklists are no longer enough: you have to watch for anomalous DNS queries and abuse of legitimate services.

Evooo1Bot turns exposed routers into monetized SOCKS5 traffic relays

The Mirai-derived modular botnet Evooo1Bot has been recruiting internet-exposed gateways — Alcatel, NETGEAR, Tenda, D-Link — into resellable SOCKS5 relay nodes since July. Fortinet documents a full arsenal whose economic novelty, the residential relay, should push every operator to inventory their internet-facing routers.

HPE closes its $14 billion Juniper acquisition after two and a half years

On August 13, 2026 a federal judge approved the settlement between HPE and the US Department of Justice, ending a two-and-a-half-year regulatory saga over Juniper Networks. For network teams, the HPE–Aruba–Juniper combination redraws the enterprise switching and Wi-Fi market against Cisco and Arista.

Cisco Hardens IOS XE and SD-WAN — 12 Flaws Including Three CVSS 9.9s Found With AI-Assisted Auditing

On August 5, 2026, Cisco shipped a massive hardening release for IOS XE and SD-WAN, bundling fixes for 12 vulnerabilities uncovered during an internal AI-assisted security review. Three reach CVSS 9.9. The era of AI-accelerated vulnerability discovery has hit the network hardware industry — and Cisco just showed what that looks like in production.

NatJack hijacks TCP sessions and spoofs DNS by manipulating NAT tables — Black Hat 2026 exposes a universal design flaw

On August 6, 2026, researcher Malcolm Stagg presented NatJack at Black Hat USA — a new attack class that manipulates NAT connection state to hijack active TCP sessions, spoof DNS responses, expose mapped ports, and exhaust NAT tables. Windows, Linux, and consumer routers are all vulnerable — because the flaw is in the concept of NAT itself, not any one implementation.

CISA Issues Urgent Alert After 30 Minnesota Water Systems Were Paralyzed — 4,100 Exposed Rockwell PLCs Await the Next Assault

On August 3, 2026, CISA issued an urgent alert after attackers disrupted more than 30 community water systems in Minnesota within 48 hours. The attackers targeted internet-exposed programmable logic controllers (PLCs), changed passwords, and disconnected equipment from the network. Censys counts over 10,000 Rockwell, Siemens, and Schneider PLCs publicly accessible.

Your APIs are the front door of your business — an API Gateway protects, measures, and accelerates them

Your APIs aren’t internal plumbing anymore — they’re your products. An API Gateway centralizes the rate limiting, authentication, caching, and analytics that every microservice would otherwise have to reinvent in its own code. Kong, Traefik, and Tyk embody three distinct architectures: here’s how to pick the one that won’t slow you down.

Nmap Finds Your Open Ports Before Attackers Do

Nmap 7.99, masscan, and RustScan represent three distinct network scanning philosophies. A pentester doesn’t pick one: they combine all three to map their attack surface before someone else does it for them.

Your MPLS costs $2,000 per site per month — SD-WAN does the same job over a $35 fiber line

The MEF published the MEF 70 standard in July 2019, Broadcom acquired VMware VeloCloud in November 2023, and FlexiWAN crossed 4,000 accounts in 2025 with open-source SD-WAN. The SD-WAN market hit $3.4 billion in 2024 and is projected to reach $13.7 billion by 2028 according to Gartner — here is why your MPLS contract is becoming a subscription to a horse-drawn carriage.

Your office Wi-Fi is the bottleneck — the 6 GHz band removes it

Wi-Fi 7 certification was finalized in January 2024, enterprise access points from every major vendor have been shipping since early 2026, and the 6 GHz spectrum delivers 1,200 MHz of untouched bandwidth. If your office runs more than thirty devices on Wi-Fi 5 or 6, the bottleneck isn’t your fiber connection — it’s the air between the access point and the desk.

Type at least two characters.

navigate open esc dismiss