
Network Break · 2026-08-10 · 30 min
Key moments - from our scoring
Substance score
48 / 100
Five dimensions, 20 points each
This episode delivers rapid-fire coverage of network and security industry developments with particular focus on AI-related initiatives and regulatory pressures. The hosts discuss Cisco's proactive disclosure of 5 bundled SD-WAN CVEs with scores up to 9.9, achieved through internal security reviews - a best practice in vulnerability management. The broader AI security landscape gets examined through the newly formed Open Secure AI Alliance, a 100+ member coalition including Amazon, Microsoft, Nvidia, Cloudflare, CrowdStrike, and others consolidating projects like Nvidia's NOAA, Hugging Face SafeTensors, IBM Lightwell, and Microsoft M-dash. The hosts note ongoing questions about governance structure and decision-making authority. A detailed breakdown of the Kymik3 'jailbreak' story reveals it as a configuration issue rather than model escape - the framework explicitly warns about Internet access, making this less about a flaw and more about how evaluation environments are set up. The conversation then shifts to European telecom operators' resistance to Huawei/ZTE equipment replacement mandates, with GSMA citing potential €40 billion costs. The hosts balance this against real geopolitical threat vectors, though note Salt Typhoon's penetration of Cisco gear suggests replacement alone won't guarantee security. Cato Networks launches agentic threat prevention focusing on AI-assisted attack prediction and automated mitigation. Financial results from Extreme Networks and Arista close the segment, with particular emphasis on Arista's Q2 performance boost.
Cisco released 5 bundled CVEs with CVSS scores from 7.7 to 9.9, each addressing multiple bugs of the same type including improper input validation. All were discovered internally and patched concurrently with no workarounds available.
Over 100 AI, cybersecurity, and technology companies formed the alliance to provide open tools for securing AI and using AI in cybersecurity. Founding members include Amazon, Microsoft, Nvidia, Cloudflare, CrowdStrike, F5, Zscaler, Linux Foundation, Mozilla, Dell, HPE, IBM, SAP, and ServiceNow.
No - the UK AI Security Institute's framework explicitly documents that Internet access depends on sandbox configuration. Frontier Security configured the environment with outbound network access, allowing the model to use GitHub to solve its challenge, making this a configuration choice rather than a model escape.
GSMA Intelligence estimates replacement costs could reach €40 billion across European telcos, with additional concerns about reduced competition and higher customer costs or reduced network maintenance investment.
It deploys autonomous agents to predict likely attack paths using network telemetry and customer-specific threat modeling, then continuously adapts protections across Cato's entire mesh of points of presence without service chaining.
Our reviewer’s read on each dimension, with quotes from the episode.
The episode delivers a rapid-fire summary of industry news with moderate insight density. It covers multiple topics (Cisco patches, AI security alliances, N Scale/Anyscale, Huawei policy, Cato threat prevention, financial results, Starlink) but most receive surface-level treatment without deep analysis. The hosts occasionally push back on narratives (e.g., debunking the Qwen-3 'jailbreak' as a configuration issue, questioning the Open Secure AI Alliance governance) but these moments are brief. The financial results section is especially light on substance - mostly just reporting numbers without strategic context.
Various cybersecurity organizations create the Open Secure AI Alliance. More than 100 AI and cybersecurity companies and other organizations have formed the the Open Secure AI alliance
You know, that is an excellent set of questions and I think those are the questions that listeners should be asking themselves because we don't have an answer for that either.
The episode largely reports conventional industry narratives without contrarian insight. Hosts acknowledge standard tropes (Cisco proactively finding bugs is good; Huawei/ZTE replacement is expensive but perhaps necessary for security; AI infrastructure is driving revenue) but don't challenge underlying assumptions or offer first-principles analysis. The one fresher moment - noting that Chinese state actors hacked non-Huawei equipment (Salt Typhoon) to undermine the 'just swap the gear' premise - is quickly passed over. Most takes are predictable consensus.
Come buy my scary model before somebody else's scary model gets you.
It really comes down to whether high risk is a politically designated, uh, term that has nothing to do with reality or whether these vendors are in fact high risk.
This is a news show with only two hosts (both journalists/analysts) discussing industry announcements and reports. There are no guest interviews. While the hosts appear knowledgeable, they are reporters synthesizing public information rather than practicing operators or subject-matter experts who have built and shipped systems at scale.
I'm Drew Conrey Murray
I'm Jonna Johnson
The episode includes concrete numbers and named companies throughout (Cisco's 2,533 CVEs, 396 critical; Arista's $3.036B Q2 revenue, up 38% YoY; Nokia's optical business up 20%; Extreme's subscription revenue at $474M). However, specificity is weakened by the absence of deeper data: no detail on *which* CVEs are most exploited, *why* Arista is outperforming competitors, or the actual technical mechanics of Cato's agent-based threat prevention. Financial results are quoted but barely analyzed.
There were 2,533 CVEs created in the week ending August 6th and 7991 updated. Um, big numbers getting bigger each week. Of the new ones, 396 are critical with a CVSS score of higher and 30 scored 10 out of 10.
For Q2 2026, Arista posted its first ever $3 billion quarter with revenue coming in at $3.036 billion. So they just squeaked it over, uh, up almost 38% uh, versus this time last year.
The hosts ask clarifying follow-up questions and occasionally push back on narratives (e.g., asking whether the Qwen-3 incident was truly a model 'breakout' or a config flaw; questioning the Open Secure AI Alliance's governance). However, many segments lack depth - financial results are recited without probing why companies succeeded or failed, and interesting topics (like the EU Huawei ban's economic impact) are mentioned but not thoroughly explored. The conversation is friendly and competent but rarely ventures into productive disagreement or demanding evidence.
So is N Scale essentially a NEO cloud? Is that the bucket you would put it in? Uh, I don't know, Drew.
Does it need to be an agent to predict these likely paths? If they're obviously, you know, you're running your traffic through them, they're also seeing everything that you're running through it.
Computed from the transcript - who did the talking, and the words that came up most.
Take a Network Break! Cisco takes center stage in our Red Alert after the network giant discovered a bunch of high-severity bugs in its Catalyst SD-WAN platform. It has rolled out software upgrade and there are no other workarounds. On the news front, NVIDIA assembles other tech bigwigs to form the Open Secure AI Alliance ... Read more
Transcribed and scored by The B2B Podcast Index.
Speaker A: Take a network break. I'm Drew Conrey Murray.
Speaker B: I'm Jonna Johnson. Grab a frosty beverage and we'll hop to it with the technology news of the week. We've got a major cybersecurity patch from Cisco, some industry attempts to enable AI security, some more industry concerns about the cost of mandated Huawei replacement, an acquisition by N scale, new capabilities from Cato, and quarterly results from Extreme, Arista, uh, and Nokia, as well as Starlink's attempt to bring space networking to earth. Quite a full show for you today.
Speaker A: Yeah, but before we kick off, we do have a sponsor we want to thank.
Speaker B: We are sponsored by Curvium, an industry leading systems integrator that offers strategic IT consulting, professional engagements, automation and AI. Curvium takes the time to understand your infrastructure needs and how best to support your business objectives. Curvium skilled professionals put your needs first. From rapid designs to full scale architectural planning, and from short term project completion to multi year support, Curvium provides the know how and vendor connections you need to succeed. Find out more@curvium.com that's C-U-R V as in Victor I u m m.com curvium.com and while you're there, check out their Secure Campus Network architecture blueprint. That's curvium.com.
Speaker A: all right, John, I kick us off with a red alert.
Speaker B: Okay, so today is a big or actually last week was a big SD WAN patch day for Cisco. There were 2,533 CVEs created in the week ending August 6th and 7991 updated. Um, big numbers getting bigger each week. As you know. Of the new ones, 396 are critical with a CVSS score of higher and 30 scored 10 out of 10. The red alert this week goes to five CVEs issued by Cisco for its SD WAN software, with scores that go from 7.7 up to 9.9. These are noteworthy because they don't have to do with a single bug. Instead, each collects a whole selection of bugs of the same type, including improper input, validation bugs. Uh, and Cisco doesn't tell us how many bugs are covered under hcve. They affect all Catalyst SD WAN software, regardless of device configuration or deployment type. Uh, Cisco released these CVEs concurrently with the update to resolve all the bugs, so no workarounds. So patch now. Um, for reference, the language from Cisco Security Advisory reads, as part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Catalyst SD WAN software engineering team has conducted a comprehensive internal security review. This resulted in software hardening releases that address multiple internally discovered vulnerabilities.
Speaker A: Okay, so Cisco found these vulnerabilities themselves then?
Speaker B: That's what they're saying. And quite frankly it smells to me like they were uh, using some of that, that Mythos those Mythos tokens to fire harden their gear, which is a good thing. That's what they were supposed to be doing.
Speaker A: Absolutely. That's what they're there for. Uh, and glad that this is exactly what those kind of tools should be used for. So. And good on Cisco for finding stuff proactively and rolling it out.
Speaker B: Yeah, and I think it does make sense to just, you know, do it all in one giant trench like that instead of trickling them out, because that allows people to just go in, do one round of patching and be done with it.
Speaker A: Yeah, hopefully the patches work.
Speaker B: Hopefully the patches work, but I suspect they do. Um, moving on to more cybersecurity stuff. AI and cyber. Various cybersecurity organizations create the Open Secure AI Alliance. More than 100 AI and cybersecurity companies and other organizations have formed the the Open Secure AI alliance with a, uh, stated mission to ensure defenders everywhere have open frontier tools they can trust and control for securing AI and using AI in cybersecurity. 2 different things, but both important. Uh, founding members include folks like Amazon, Microsoft, Nvidia, CyberSecurity folks like Cloudflare, CrowdStrike, F5 and Zscaler. Major open source initiatives like the Linux foundation and Mozilla. Plus major uh, players across the board. Dell HPE, IBM, SAP ServiceNow. Uh, new and pre existing open source projects are getting sucked in under the OSAIA umbrella. One new one is the Nvidia Labs Object Oriented Agent noaa aimed at making available advanced AI security capabilities to test, trace, audit and govern agent and model behavior. Also this initiative encompasses more mature projects including Spiff Spire for cryptographically verifying AI agent identities. A critical piece of agent security. Hug Face has offered Safe Tensors, which is a safe format to store AI model weights. IBM and Red Hat's got Lightwell, which we've talked about multiple times on the show, for issuing digitally signed patches. And Microsoft's Mdash, which orchestrates specialized AI agents to discover, debate and prove exploitable bugs.
Speaker A: So just a bit, are these all now being moved under this new body, Things like Spiffy and Lightwell, or are those. You're just saying there's a bunch of other initiatives that have happened as well.
Speaker B: No, no, they are all being moved under it. And I think the main, the main step on this is we are bringing, we're bringing this all together in a coordinated approach so that, so that enterprises and other folks can get better security.
Speaker A: That's interesting because I felt like particularly IBM and Red Hat's light, well was so IBM focused. Uh, okay, so that's interesting. So this is when this first came out it seemed to me to be just more like essentially a lobbying effort to make sure the US government didn't ban open weight models, including Chinese open weight models. Um, which we'll talk about shortly. Right, yeah, yeah. But this does sound like maybe there is more going on here.
Speaker B: Yeah, I think this is an attempt by the industry to show that it's responsible, it's addressing the concerns and it's worth noting that this announcement is going hand in hand with uh, just a drumbeat of vendors announcing that their models have gone rogue and done things that oh, the horrors we never expected.
Speaker A: Right.
Speaker B: Obviously Mythos made that first splash way back in the spring, but now you're seeing the same thing from everybody all over. So I think this is an attempt by the industry to show that it takes these things seriously and not just as headlines to generate, generate semi positive news about their, the power of their models.
Speaker A: So when this first came out I looked at it and it seemed there wasn't really a lot there besides sort of like a press announcement. Uh, I don't know if there's more details around like what kind of governing structure, whether there's a board, how people can join and participate, that kind of thing.
Speaker B: You know, that is an excellent set of questions and I think those are the questions that listeners should be asking themselves because we don't have an answer for that either. So it's interesting. Um, at the very least there's certainly the press announcement, but I think there's also the fact that they're trying to get ah, all these companies working together to deliver agreed upon security measures. That said, working together covers an awful lot of ground and one wants to know who makes the decisions and one does not yet know that.
Speaker A: Right, for sure, for sure. Yeah. Because we do need this seems in some ways like it would be perfect for like the Linux foundation which already has an existing structure, um, and some assurance that you know, results are generally made available to the broader community as opposed to just, you know, individual actors. So uh, we'll see what happens. But it's an interesting initiative.
Speaker B: Well, and I think, and this will be a point we'll make on Our next news item. I think part of the problem is that existing groups of organizations are by definition too small. Um, so in a lot of cases these efforts have been made before. The problem is they weren't as broad reaching. So I think the whole, the big takeaway from this initial effort is to show that, look, we've got chip vendors, we've got software vendors, we've got systems vendors, we've got everybody. It's not just a narrow set of folks or one of the pre existing organizations, whether it's going to be effective or not. I mean, I think you raised some excellent questions about who's running it and how do they release, you know, what are they releasing to whom and under what circumstances and all those great things. Yeah, but I think the fact that it's bigger than any one industry or any one segment of the industry is key.
Speaker A: Yeah, for sure. Yeah. And the fact that it's not just an Nvidia special project, I guess, makes me feel a little bit better about it. But we do need to see some kind of like governance structure and so on to make sure this is an actual ongoing thing and not just a press release. All right, moving on. Uh, there were headlines that the Chinese Open weight model Kimik3 broke out of an evaluation environment. And those headlines sort of echoed other headlines about anthropic and OpenAI and so on, um, breaking containment. And so it might sound alarming because it's like, oh, it's the Chinese open weight model. But, uh, there is more to the story here. A security startup called Frontier Security was assessing a cybersecurity evaluation framework which was developed by an organization called the UK AI Security Institute, which is backed by the UK government and institute set up to provide a whole lot of resources for folks who are training, testing, uh, uh, AI models and model security, along with a whole bunch of other things. Uh, so in this evaluation that Frontier Security did, the model did have outbound network access. So it used that access to go to GitHub to find the answer to the challenge it had been given. Uh, the security researchers claim that the framework thus has a leak. Uh, but I did look at the side branch framework and it clearly says as one of its warnings, that the model will have Internet access depending on how the sandbox is configured. So to my mind it's not a leak per se, it's a configuration choice on how you set up the sandbox. So this is less about a model breaking out of its environment and more about, I think Frontier Security was trying to make a critique of various cybersecurity evaluation frameworks. Meaning that, uh, be careful about the framework you use and the configurations in it. Uh, you're not necessarily getting a real test of the model's capabilities if you leave open a huge backdoor like public Internet access.
Speaker B: Yeah, I think that's a very relevant point, Drew. And once again, it's interesting that we've got yet other organizations that are jumping into the breach when it comes to uh, AI and cybersecurity.
Speaker A: Ah.
Speaker B: I'm reminded of an earlier framework, the Harm Bench framework, which is less technical but broader in goals. And I think this sort of backs up my contention on the previous news item that uh, basically we don't yet know who runs this kind of stuff. So who is the framework of choice and uh, who should we be following is still a little up in the air because each group has uh, its own approach. That said, uh, I just want to highlight the point that you raised, which is it's not about the framework's flaw, it's about a configuration flaw, if you will. If you set up your model so it has Internet access, it will use that Internet access. So that's not even a flaw, that's just a configuration issue, right?
Speaker A: Absolutely. And it's a configuration choice because as I mentioned, the framework says like, hey, just so you know, the way we've set this up, it can get out to the Internet. Uh, so you can configure not to do that if that's part of the thing you want to test.
Speaker B: So uh, um, that said, though, I do wonder, um, how easy it is to avoid to turn off the Internet access because I'm reminded of all the Microsoft stuff where you, uh, know there isn't actually a security flaw in Microsoft. It's just a configuration flaw because when it arrives it's default configured badly. And you know, if this I would hope that the, the instructions require you to set up a default no Internet access and that has to be a proactive choice. It may not be the case.
Speaker A: Right. And I just. The main reason I wanted to bring this up is because the way the headlines were slanted, it made it seem like this was akin to the, you know, OpenAI and Anthropic. And I think now Meta has also said it's AI.
Speaker B: I was going to say, yeah, uh,
Speaker A: uh, it's not really that at all.
Speaker B: Yes, I mean at this point, uh, uh, we could basically issue those press releases ourselves. Scary model got out and did scary things. Come buy more powerful models from us.
Speaker A: Right. Come buy my scary model before somebody else's scary model gets you.
Speaker B: Exactly. All right. In a rare detour to non AI related news, uh, N scale buys anyscale. Nscale announced on July 30 that it has entered into a definitive agreement to acquire Anyscale. N Scale is okay, AI focused infrastructure as a service provider, but it's not directly AI. It's got data centers with requisite GPUs and power, as well as software layers to provide, quote, a unified cloud platform for running AI training and inference. End quote. Anyscale is a software layer that AI teams use to distribute, run and manage workloads. Uh, Anyscale will continue to operate under its existing brand and serve its existing customers who can run it on whatever infrastructure they choose. They will gain the additional option of running the Anyscale software on top of nscale. All of anyscale staff, approximately 200 people across the United States, Europe and India, are moving over to N Scale.
Speaker A: So is N Scale essentially a NEO cloud? Is that the bucket you would put it in? Uh, I don't know, Drew.
Speaker B: I have not heard that term before. So do do elaborate.
Speaker A: Neoclouds. Mhm. I mean, they're essentially companies that buy a bunch of GPUs and then rent them out.
Speaker B: Okay, I, um, had not heard that before. So, uh, there you go. Uh, yes, they are.
Speaker A: Okay. Okay. I'm surprised.
Speaker B: Yeah, I'm surprised too. But there you go.
Speaker A: And N Scale and Any scale. Not a lot of brand change that has to happen there, I guess.
Speaker B: Yeah, right. Just add the A, take off the
Speaker A: A. Updating the T shirts should be easy.
Speaker B: Exactly.
Speaker A: Uh, moving on. The gsma, that's a global lobbying and advocacy group for the mobile communications industry, is warning of the potentially high costs that European mobile operators could face if they are compelled to replace telecom gear from Chinese vendors Huawei and zte. Uh, and I feel like I have just jumped in a time machine Back to like 2009, 2010, when we were having this discussion. Uh, in any case, GSMA Intelligence, this is a research arm of the lobbying group, released a new report saying the replacement costs could reach as high as 40 billion for European telcos. It also says that banning these vendors will reduce competition and drive up costs, which could in turn result in higher costs for customers or less investment by the telcos in maintenance and upgrades. According, uh, to reporting by the Register, the research report was prompted by a proposed EU Cybersecurity act that would require, quote, member states to rip out and replace critical equipment supplied by designated high risk Vendors in their telecoms infrastructure. And obviously Huawei and CTE are among the vendors listed as high risk. Um, thoughts, Jonna?
Speaker B: I don't know. I mean, on the one hand, I know everybody is dead against more onerous government regulations, blah, blah, blah, but this smells a lot to me like, uh, the old Ford Pinto analysis. It's like, oh, well, replacing this part, which costs 49 cent, is going to cost us 53 cents. And if you use, if you spread that across all the Ford Pintos, we'd rather just explode a few Pintos and kill a few people. It's cheaper that way. I mean, it really comes down to whether high risk is a politically designated, uh, term that has nothing to do with reality or whether these vendors are in fact high risk. If it's a purely political play, then, yes, this makes no sense whatsoever. But if they really are high risk, I'm not sure why. What the, what the sense. Why anyone would respond with, well, it's really expensive. You know, it's really expensive to take the rat poop out of our food. Food production. Well, yeah, it is, but spend the money.
Speaker A: I mean, it comes down to that argument that we've been talking about forever, which is, are how connected are companies like Huawei and ZTE to the Chinese, uh, government? Are these companies building in backdoors, uh, to their equipment that could be exploited, uh, you know, for national security or hack purposes? Um, and could China, if we get into some kind of war, decide to press the magic button that shuts down, you know, European telecommunications companies? Uh, I think those are essentially very simplified arguments that anti Huawei and ZTE people are making.
Speaker B: Yeah. And I don't think they're. I don't think they're wrong. Obviously I have no way of knowing this, but my dad was in the military during the Cold War and pretty much everything that people said was a scary threat to turned out to be true and not going far enough. Um, there's some really wonderful books about how, for example, the Soviet Union bugged the Russian embassy, um, many years ago and the effectiveness with which they did it. Still, you know, this is decades on. They did a fantastic job and really went undetected. So these things. Uh, sorry, it was the US Embassy, excuse me, but these things may sound far out, but they actually are not a lot of real world geopolitics. So I guess it comes down to the degree to which you believe these things are a real threat.
Speaker A: Yeah, Yeah, I agree. Frankly, I can't say for sure either whether Huawei and ZTE pose a threat. Um, but the potential does seem to be there. $40 billion spread across every European country's telecom, uh, sector doesn't really sound like that much. Um, yes, of course it is extra spending that they don't want to have to spend. Maybe they could find way to help minimize the costs and the disruption. I will also say on the flip side though, Western companies don't have a great track record. Just pointing back to Salt Typhoon, where Chinese state actors penetrated multiple American telecom companies which weren't using Huawei equipment. They just hacked into Cisco gear. So.
Speaker B: Yeah, but that's an interesting counter example there, Drew, because if you're using it to back up the idea that the Chinese don't have nefarious attack plans, it kind of fails at that.
Speaker A: Just saying. I guess I'm saying is just because you're swapping out the gear doesn't make you any safer. Maybe you've, you, you've made it one remove harder for them to get in. But they can get in.
Speaker B: Well, arguably, yes, but it is hugely easier to embed vulnerabilities from the get go. And uh, by the way, uh, with the red alert that we kicked off, uh, today's show with, at least we know that Cisco is making a very good faith effort to get rid of those vulnerabilities as opposed to leaving them baked in for future use.
Speaker A: Yes, yes, exactly. If you've got feelings about this, packetpushers.net FU, uh, FU is for follow up. Uh, we'd love to get your feedback if you have an opinion on this issue or anything else that we're covering in the show. Um, and if you want us to use it on the air in a subsequent episode, we're happy to do that. But, um, let's pause for a message from our sponsor, Curvium. All right, we'll pause, uh, for a message from our sponsor, Curveium. As a systems integrator in var, Curvium doesn't just sell to you. They consult with you to pick the best technology to accelerate success, always putting trust and your organization's unique needs first. Whether you need a quick design critique or a full scale architectural planning, Curvium's experts provide the oversight and vendor connections that you need to succeed. And Curvium doesn't just plan, they execute. They use powerful industry standard automation tools to handle everything from initial rack and stack to the final operator cutover. They even train your team to work more efficiently along the way. And Curvium can help you enter the age of AIOps with its curvium curve OS. This is a centralized AI powered platform to manage all your infrastructure from a single point point. It's not just an afterthought, it's a stress reducing, sleep saving control layer designed to give you total visibility and peace of mind. Find out how Curvium can help you@curvium.com c u r v I u m curvium m.com and we thank Curvium for being a sponsor.
Speaker B: All right and moving right along. Uh, CATO is now offering agentic threat prevention. Uh, on July 3rd, SASE service provider Cato Networks added Cato Agentic Threat Prevention to its portfolio. That's a service that automatically deploys autonomous agents to predict likely attack paths in a customer environment and tailors protections for each customer environment. So uh, if you have multiple environments, the goal is to prevent breaches before AI assisted attacks can advance. The new service bases its actions on the combination of network and security telemetry from each environment, including customer specific activity. It does customer specific threat modeling to anticipate how attacking AIs might chain techniques and vulnerabilities as we know they do and exploit gaps to evade that client's controls. It continuously adapts the customer's protections, which are enforced globally across cato's entire mesh of points of presence without service chaining. The Agentic threat protection service joins Cato's Agentix CVE mitigation service which autonomously assesses new CVEs and applies protections to mitigate them in as little as 45 minutes, which is pretty darn fast. But we don't yet know whether it's fast enough to protect against the attackers, which are also pretty darn fast. Anyway, it's a good, uh, it's a good addition to the portfolio and um, interesting that cato's done this.
Speaker A: Does it need to be an agent to predict these likely paths? If they're obviously, you know, you're running your traffic through them, they're also seeing everything that you're running through it. If you're, you know, using the security capabilities in their pops because they're decrypting traffic to analyze that traffic for malicious, potentially malicious stuff before they send it on. Like I don't, I guess I'm not really clear what the agentic element is bringing other than potentially more risk. But now that we're seeing how agents can go rogue.
Speaker B: So I think the agentic applies to the attacker, not the defender here. Ah, this is a service that protects against agentic attacks. Is the way to think about it.
Speaker A: I see. Okay.
Speaker B: Um, and it does use agents to do this as well. But, uh, basically the idea is that you've got lots of agent intelligence, looking at where the attacks are going to come from and combining the telemetry data with customer specific data to sort of respond to those attacks.
Speaker A: All right, yeah, uh, Cato always right. Uh, on top of things, particularly with AI related, uh, tools and techniques. Uh, moving on, some financial results. We'll start with Extreme Networks. They reported some positive results for Q4 and their full fiscal year 2026. Uh, for the quarter, revenue was 338.6 million dol million, up 10% year over year with net income of 18 million. For the full year, revenue was 1.3 billion, up 12.6% year over year with net income Of 42 million. Last year the company posted a net loss of 7.5 million. So a much better outcome this year. Uh, for the year, product, uh, revenues accounted for 809 million, with subscription and support bringing in 474 million. Any thoughts, Jonathan?
Speaker B: Uh, I find it interesting, probably the biggest one is that the subscription is still roughly just over half of the product, which I find it's interesting. As you know, I'm kind of bullish on Extreme generally and it's good to see that they're continuing their upward trajectory. I'm surprised, as I said, that the subscription is still lagging behind as they were, like a lot of vendors in this space, kind of doing that full transition to, to subscription based.
Speaker A: Yeah, I mean, I think they would definitely like to see that number go up. Um, and I would love to see more of a breakout in that product revenue about, you know, WI fi versus switching. Um, because I think of them doing very well in WI fi. But uh, I'd love to see more about, you know, how much penetration they're making on the Ethernet switching side as well.
Speaker B: Yeah. And you know, let's, let's reiterate again. Hey, last year we had a loss. This year we had, you know, net net positive. So that's definitely good. I guess I would be more surprised by it if I hadn't been privy to some of the work that they've been doing for the past several years to make this happen. So I'm quite happy to see it.
Speaker A: Yeah, well done. Extreme. Uh, Nokia also reported results for its Q2 2026. Net sales were 4.8 billion euros, up 8% year over year, with a profit of 5 million euros. The company cited AI and cloud sales doubling from this Time last year. Its optical network business is up 20% year over year. IP networking is up 16%. Mobile infrastruct grew 7%. Uh, so as with other vendors, the AI, uh, infrastructure buildout uh, is really helping generate revenue for Nokia, particularly at a higher rate than its mobile infrastructure business.
Speaker B: Yeah, I was interested in the optical stuff and I kind of looked at that and said I hope they double down on that because I know Nokia is also doing. Yes, they're surfing the AI wave rather well. Uh, but they're also doing interesting stuff when it comes to quantum and I think their optical capabilities will, will help them there uh, in the future. So it's interesting that they're growing fastest in optical surfing the AI wave today but preparing them for the quantum wave tomorrow.
Speaker A: Yeah, I think the AI infrastructure buildout is. Optical is very expensive but with so much being poured into AI data centers and performance being so high that might be less of an issue than it used to be. Um, so not surprised that optical is up 20%. Uh, it also occurred to me that if this EU law does go through where customers have to telcos have to get rid of high uh, risk vendors, that could be very good for Nokia being a European vendor.
Speaker B: Yes, uh, that was an excellent observation. I hadn't thought of that. Very clever.
Speaker A: Uh, last but not least financial results is Arista. The good times keep rolling. For Q2 2026, Arista posted its first ever $3 billion quarter with revenue coming in at $3.036 billion. So they just squeaked it over, uh, up almost 38% uh, versus this time last year. Net income was 1.2 billion, a uh, 36% increase over last year. So Arist a very efficient ship. Uh, looking ahead, Arista forecasts another 3 billion in revenue for Q3. Uh just five years ago, Arista's total annual revenue was 2.9 billion. Total four quarters. Uh, so they are from five years ago just going gangbusters.
Speaker B: Yeah, yeah. And uh, when you said they just squeaked by. I have a strong suspicion that there was a lot of last minute tweaking around the edges because that's how it happens in big companies with major milestones. But we are certainly happy to see that. And yeah, that is eye popping. Five years ago. So 2021, the entire company didn't make as much money as the company did in one quarter in 2026.
Speaker A: Yeah. And it just goes to show how well Arista is doing with the AI infrastructure build out. Um, they're not. Is there something you do More than just surf the wave. They are, I don't know, they're doing it.
Speaker B: Whatever it is.
Speaker A: Whatever it is.
Speaker B: Yep. Okay, well, wrapping things up, we've got an inversion on our usual space networking, which is Starlink is coming to Earth, or at least trying to. Uh, on the August 4th space SpaceX earnings call, company leaders talked up plans for building out a terrestrial mobile data network as a component of this planned Starlink Mobile. So instead of mobile companies adding, um, satellite services to their portfolio, they're planning to build in the terrestrial service. As I will say, an afterthought, so to speak. The main approach for Starlink Mobile is still to go to direct to device from orbit. But company president Gwynne Shotwell and Elon Musk both discussed the idea of equipping Starlink dishes with femtocell mobile global arrays to allow them to be small scale base stations. They suggested this will be considerably less expensive than building out large cellular base stations and just using small ones to fill gaps and extend ranges. You don't necessarily have to spend many billions of dollars in low band spectrum all up front before you deploy your system. According to Shotwell. They also mentioned utilizing the spectrum they've already purchased from EchoStar, which has a terrestrial component. Okay, um, and that's one way to go about it, I guess.
Speaker A: So is the idea that they would essentially be competing with Verizon AT&T and T Mobile by offering a mobile service but they're just relying on primarily satellites but using some dishes on the ground as base stations?
Speaker B: Uh, no, I think the idea is to more cheaply deliver ubiquitous connectivity everywhere to the Starlink customers. So in other words, you aren't going to suddenly wake up one morning and decide that you want, you know, SpaceX services as opposed to Verizon services. Um, you are, you are signing up for Starlink Mobile and you suddenly discover that, oh, sometimes the traffic is being transported over cellular network to save the company money. Of course they will not pass those savings on to you.
Speaker A: But maybe it would also help with performance. Um, particularly like for if you don't have to send that signal all the way to space, that could be better for your traffic.
Speaker B: Uh, could be, could be. Um, but it sounds like they're really focusing on it for cost, which makes lots of sense.
Speaker A: Sure.
Speaker B: I mean there's nothing wrong with the idea, it's just kind of funny.
Speaker A: Well, links in the show notes if you want to dig into it yourself. Uh, that does wrap up the episode. Jonna, where can folks find you online?
Speaker B: Hit me up@numertis substack.com I'm Drew Con Murray.
Speaker A: I'm on Blue sky at Drew CM, and I'm blogging@pack of pushers.net uh, thanks to our sponsor, Curvy Mitt, and as always, thanks to you for listening. Uh, by the way, uh, there's much more you can find@packer pushers.net More than a dozen podcasts, two weekly newsletters, our community Slack group, a YouTube channel, even an IR IRC group. All free, no login required@packetpushers.net thanks for listening.
Other episodes covering the same guests and topics, from across The B2B Podcast Index.