NB589: OpenAI Makes Cyber Mess, Wants World to Clean It Up; Cisco Strategizes Infrastructure Identity
Network Break discusses major tech news including NVIDIA's reported $12.9B acquisition of Hugging Face, OpenAI's call for global cyber defense (criticized as a potential sales pitch), and significant partnerships between major cloud providers and AI/infrastructure companies. The episode highlights strong financial results from NVIDIA and Marvell, reflecting massive growth in GPU and AI chip demand.
Summary
The episode opens with follow-up on Google Chrome's new Device-Bound Session Credentials (DBSC) security feature, a W3C standard that uses TPM or secure enclave keys to prevent session cookie theft by requiring cryptographic signatures. The hosts note this reduces reliance on fragile source IP anchoring. The red alert covers 16 critical CVEs in IBM AIX versions 7.2 and 7.3, involving remote code execution, privilege escalation, and buffer overflows. NVIDIA is reportedly in acquisition talks to purchase Hugging Face for $12.9B, positioning itself at the center of open-source and open-weight AI models as alternatives to expensive proprietary offerings. The hosts see this as part of NVIDIA's broader ecosystem strategy. OpenAI and 100+ companies released a letter calling for increased global cyber defense against AI-enabled attacks, citing longstanding infrastructure problems like unpatched software and weak authentication. Drew and Jonna critique this as somewhat hypocritical—OpenAI identified problems that the industry has known about for decades while also positioning themselves as the solution to sell more AI tools. AWS and NVIDIA expanded their partnership to deploy 2 million additional GPUs on AWS infrastructure and build AI factories up to 100,000 GPUs for U.S. government use. Lumen expanded its multi-cloud gateway service beyond its fiber footprint, and Cloudera announced Cloudera Anywhere Cloud for hybrid AI and data-intensive applications. Cisco is investing in and partnering with Teleport to develop infrastructure identity using just-in-time cryptographic credentials instead of standing secrets—essentially implementing zero-trust principles. Google Cloud and Verizon announced a strategic partnership deploying Gemini across Verizon's operations, from network anomaly prediction to employee productivity to marketing automation. Chinese AI company Moonshot is negotiating with AWS, Azure, and Google Cloud to host its Kimi K3 model (comparable to GPT-4.5 and Claude 3.5) for up to 30% revenue share, though the hosts express serious concerns about using Chinese AI models given data security risks. Marvell reported Q2 FY2027 revenue of $2.7B (up 37% YoY) and raised full-year guidance, boosted by their Google TPU chip deal. NVIDIA reported Q2 FY2027 revenue of $96.2B (up 106% YoY) with net income near $60B, with data center GPU revenue comprising $89B of total revenue. NVIDIA forecasts Q3 revenue over $100B.
About this episode
Take a Network Break! We start with listener followup about how Device Bound Session Credentials could thwart session cookie theft, and then highlight a string of critical vulnerabilities in IBM’s AIX. On the news front, Nvidia has reportedly bought Hugging Face for $12.9 billion, Nvidia and AWS team up on GPUs and physical AI, and<a class="excerpt-read-more" href="https://packetpushers.net/podcasts/network-break/nb589-openai-makes-cyber-mess-wants-world-to-clean-it-up-cisco-strategizes-infrastructure-identity/" title="ReadNB589: OpenAI Makes Cyber Mess, Wants World to Clean It Up; Cisco Strategizes Infrastructure Identity">... Read more »</a>
Key Insights
- NVIDIA's Hugging Face acquisition fits a broader ecosystem strategy to offer enterprises complete soup-to-nuts AI solutions including chips, models, consulting, and support, addressing customer hesitation about internal expertise and operational requirements
- OpenAI's call for increased cyber defense against AI-enabled attacks is criticized as self-serving because OpenAI identified longstanding, well-known infrastructure problems while positioning itself as the solution provider to profit from the crisis
- Organizations are moving away from expensive proprietary AI models toward cheaper open-source and open-weight alternatives due to phenomenal bills from cloud AI usage, creating a significant market opportunity
- Just-in-time cryptographic infrastructure identity (Cisco-Teleport partnership) represents the proper implementation of zero-trust principles by anchoring access to specific tasks rather than maintaining standing credentials
- NVIDIA's single quarter net income of approximately $60B now roughly equals Cisco's entire annual revenue, reflecting a massive shift in technology sector value concentration around GPU manufacturers
- Chinese AI company Moonshot's model negotiation with U.S. cloud providers faces potential barriers due to security concerns about backdoors and data sovereignty, with U.S. regulatory stance remaining uncertain
- The hosts argue that attributing AI-enabled cyber attacks to 'acts of God' rather than corporate responsibility could relieve companies of accountability for inadequate security investments, similar to historical internet reliability issues
- NVIDIA forecasts Q3 revenue exceeding $100B with sustained high revenues for multiple years, suggesting the AI infrastructure boom remains robust despite questions about when the market may saturate
Topics
Transcript
Taking that work break, I'm Drew Connery-Martin. I'm Jonna Johnson. It's almost pumpkin spice time, ugh. So grab a virtual beverage of choice, and my choice will not be pumpkin spice. And we will sprint through today's news items. We've got lots of news about NVIDIA, acquisitions and partnerships and quarterly results. Oh, my. Some new cybersecurity features from Google Chrome, a call to action for cyber defense from OpenAI, some cloud news from Cloudera and Lumen, infrastructure identity from Cisco and Teleport, a Verizon-Google partnership, quarterly results from Marvel, and more. But first, a big thank you to our sponsor, Meter. If your organization is running on gear from multiple vendors with no one really owning the whole thing,…
Full transcript available for MurmurCast members
Sign Up to AccessMore from The Everything Feed - All Packet Pushers Pods
TNO070: Spec Driven Design (SDD) for NetOps and NetEng
Lasse Haugen, a NetOps engineer from Norway, discusses how Spec-Driven Development (SDD) combined with AI tools like Claude has transformed his approach to network automation and infrastructure projects. He shares practical examples of using SDD to build sustainable, maintainable code while leveraging AI as a collaborative partner rather than a code generator.
HN839: Why Flows, Packets, and DDI are All Critical for Operational Effectiveness (Sponsored)
BlueCat Networks, a DDI provider that acquired LiveAction in 2024, discusses how integrating network observability (flows, packets) with DDI capabilities enables faster troubleshooting, improved collaboration between NetOps and SecOps teams, and better automation of network operations. The integration provides context for understanding both network intent (DNS/DHCP rules) and actual network outcomes (traffic behavior).
D2DO310: Developing Efficient AI Workflows
The podcast discusses the evolution and best practices of using AI coding assistants within DevOps workflows, emphasizing token efficiency, agent memory management using Obsidian, and the importance of sandboxing for security. Tyler Lynch shares insights from his experience with AI agents in coding and automation at IBM.
HW085: Designing Wi-Fi for High-Density Events
The podcast discusses strategies for designing Wi-Fi networks for high-density events, emphasizing the importance of thorough planning, questioning, and on-site validation. Key tools and techniques for optimizing performance under these conditions are also highlighted.
PP121: How CYBR.SEC.CON Builds Community for Learning and Professional Development
The episode features a conversation about CyberSecCon, a community-driven security conference in Houston, and explores the origins and growth of both the conference and the Packet Protector podcast. Key insights include how both platforms aim to foster community and collaboration within the cybersecurity and networking fields.