NB588: Active Threats Target Siemens PLCs; IBM Chills Qubits With Modular Cryogenics
Network Break episode NB588 covers critical security vulnerabilities in Oracle and Cisco products, active threats targeting Siemens PLCs with AI-assisted exploits, IBM's modular cryogenic systems for quantum computing, Marvell's $120 billion custom silicon deal with Google, and NASA's demonstration of non-GPS navigation for spacecraft.
Summary
The episode opens with a sponsor message from Itential about Flow AI for infrastructure automation, then dives into a red alert on Oracle's extensive vulnerability disclosure: 4,397 new CVEs added in the week ending August 20th, with 708 rated as critical (CVSS 9+) and 39 receiving perfect 10 scores. Three specific Oracle vulnerabilities are highlighted—CVE-2026-61-241 in Oracle Internet Directory LDAP allowing unauthenticated takeover, and two Hyperion vulnerabilities (70880 and 70921) permitting complete system compromise with minimal access. Cisco receives runner-up status for five critical vulnerabilities in Secure Workload software discovered during internal testing, possibly using AI models from Project Glasswing. The hosts discuss that Cisco's proactive disclosure and patching is commendable despite the serious nature of the vulnerabilities.
A major news story involves joint warnings from U.S. intelligence and law enforcement agencies about active threats against Siemens S7 series PLCs used in critical infrastructure like wastewater treatment and power plants. Threat actors are scanning for systems with default or minimal authentication and outdated software, with the warning specifically noting that attackers are using AI to generate and iterate exploit scripts—marking what may be the first official U.S. government statement confirming AI-assisted cyber attacks in active use. The hosts emphasize that while the vulnerabilities exist, the primary issue is misconfiguration, particularly the failure to change default passwords, which they note occurs in over 50% of OT deployments. They stress that IT and OT should not be treated as separate domains and advocate for basic security hygiene in often under-resourced municipal facilities.
On the business side, Marvell disclosed a deal signed July 29th with Google to design custom semiconductors for Google's TPU ecosystem, valued at up to $120 billion in revenue through 2033 if all vesting tranches are triggered. The warrant structure ties $12.2 billion in stock options to purchasing milestones, which would make Google Marvell's fifth-largest shareholder. The hosts note this is a significant win for Marvell, whose $8.2 billion in fiscal year 2026 revenue would be dramatically expanded by this partnership.
Google Cloud announced Access Approval functionality for GCP, allowing customers to pre-approve or deny access by Google staff to customer data, building on existing Access Transparency logs. The hosts note this addresses a longstanding enterprise concern about CSP access to customer data, though Google retains emergency access rights for law enforcement or security incidents. IBM announced modular cryogenic systems reaching temperatures below 15 millikelvin that enable multiple superconducting quantum computers to be linked together, potentially enabling quantum systems with 1,000+ qubits. The hosts discuss how this reflects a broader renaissance in cooling technology across AI data centers and quantum systems, noting IBM's historical pattern of building complete ecosystems rather than just chips.
Amazon Web Services added rule hit counts to AWS Network Firewall stateful rules, enabling visibility into how often rules match traffic to identify policy gaps and validate rule changes. The hosts use this to discuss the "survivorship bias" principle from WWII bomber armor plating, cautioning that high rule hit counts don't necessarily indicate effective rules.
In space news, startup Muon Space closed a $250 million Series C funding round, bringing total investment to $386 million. The company has 11 satellites in orbit with two more scheduled for deployment, including a wildfire monitoring satellite for Google. NASA successfully demonstrated Falcon (Fast Autonomous Lost-in-Space Catalog-based Optical Navigation), a non-GPS navigation system that determines spacecraft position by referencing known objects in space rather than GPS signals, developed with Stanford spin-out Iridrive. The Starling mission name references the birds' mysterious migration capabilities, and the hosts note the poetic reference to starling murmurations. The episode concludes with mentions of the Human Infrastructure Newsletter, multiple Packet Pushers podcasts, and an invitation for listener feedback.
About this episode
Take a Network Break! It’s a Red Alert double feature for Oracle’s Internet Directory LDAP server and Cisco’s Secure Workload Software. In tech news, US law enforcement and intelligence agencies release a joint advisory warning of active threats against Siemens PLCs, Marvell wins a deal to make chips for Google that could bring billions in<a class="excerpt-read-more" href="https://packetpushers.net/podcasts/network-break/nb588-active-threats-target-siemens-plcs-ibm-chills-qubits-with-modular-cryogenics/" title="ReadNB588: Active Threats Target Siemens PLCs; IBM Chills Qubits With Modular Cryogenics">... Read more »</a>
Key Insights
- The U.S. government's joint warning about Siemens PLCs represents what may be the first official statement confirming that threat actors are actively using AI to generate and iterate exploit scripts in real-world attacks.
- Over 50% of operational technology deployments retain default passwords, and the hosts attribute this primarily to misconfiguration rather than fundamental vulnerabilities, stemming from artificial IT-OT separation that forces OT operators to relearn decades of IT security lessons.
- Cisco's discovery of five critical vulnerabilities through internal testing may reflect the company's participation in Project Glasswing, providing access to AI models for security testing, demonstrating a proactive approach to vulnerability identification.
- Marvell's deal with Google is structured with warrant vesting tied to purchasing thresholds of $500 million in qualifying revenue increments through 2033, creating an incentive alignment model where Google benefits from Marvell's rising stock price.
- IBM's modular cryogenic systems represent the company's historical DNA of building complete technology ecosystems rather than point solutions, similar to mainframe era practices.
- Cooling technology has transitioned from a 1960s-era solved problem to a 'hot and sexy' field requiring innovation across both AI data centers and quantum computing infrastructure.
- AWS Network Firewall's new rule hit count feature introduces a potential survivorship bias problem where high-hit rules don't necessarily indicate effective security policies, requiring careful interpretation.
- NASA's Falcon navigation system repurposes the long-standing problem of space debris into a solution by using known satellite objects as positional landmarks, similar to sextant navigation but using space-based ephemerides instead of celestial bodies.
Topics
Transcript
Take a network break. I'm Drew Connery-Murray. I'm Jonna Johnson. You'll be glad to know that the PLCs to keep the Packet Pushers donut factory running are locked down and fully patched, so you can help yourself to a virtual confection as we sprint through this week's news. We've got Oracle bugs, a special red alert runner-up to Cisco, U.S. government agencies warning that Siemens PLCs are under threat, IBM has modularized the cryogenic chambers, say that fast, three times kids. They keep its quantum computers cold. Marvel strikes a lucrative deal with Google. Amazon adds new features to its network firewall, plus space news and more. But first, we want to give a shout out to our sponsor. Sponsor…
Full transcript available for MurmurCast members
Sign Up to AccessMore from The Everything Feed - All Packet Pushers Pods
TNO071: The Network Team Is Drowning. Is AI the Life Raft? (Sponsored)
Rekha Shenoy and Irfan Kimji from Backbox discuss how the exponential growth of vulnerabilities (49,000 CVEs annually) has made manual network operations unsustainable, and how AI-powered automation can help network teams manage patches and security updates at scale while maintaining human control and oversight.
HN840: How to Make a Technology Buying Decision
Sean Morgan, a research director at Deloro Group, discusses how technology buying decisions should extend beyond engineering specifications to include business alignment, ROI calculations, and understanding total cost of ownership. Engineers must shift from viewing IT as a cost center to positioning it as a business enabler by connecting technical decisions to revenue impact and organizational objectives.
IPB207: Flying Blind: Monitoring Might Not See IPv6
The IPv6 Buzz hosts discuss critical gaps in IPv6 monitoring across enterprise networks, highlighting that many monitoring platforms lack IPv6 awareness, vendor parity, and advanced analytical capabilities. They emphasize that while basic IPv6 data ingestion has improved, sophisticated features like cross-protocol event correlation, extension header analysis, and device identity tracking remain significant industry challenges.
N4N063: Link Layer Discovery Protocol
Link Layer Discovery Protocol (LLDP) is a standardized Layer 2 protocol that enables network devices to announce information about themselves to directly connected neighbors, facilitating network topology discovery and device identification in multi-vendor environments. The protocol uses Ethernet frames with special multicast destination MAC addresses to ensure frames don't propagate beyond immediate neighbors, and includes mandatory TLVs (Type-Length-Values) like chassis ID, port ID, and TTL alongside optional ones for extended information.
TCG083: Superintelligence for Everyone: Who Actually Holds the Power?
Three technology experts discuss Mark Zuckerberg's manifesto on distributed superintelligence, examining whether his promises of universal access and individual empowerment align with infrastructure realities. They conclude that while decentralized AI is theoretically safer than centralized control, the manifesto fails to account for human complexity, existing inequalities, and the enormous capital requirements that will likely concentrate power rather than distribute it.