NVIDIA’s $20B Groq Deal, Meta Buys Manus, and MongoDB Bleed | TSG Ep. 993
Alan, Mike, Mitch, Jack Poller and Stephen Foskett, president of the Tech Field Day arm of the Futurum Group, dive into a $20 billion licensing agreement that gives NVIDIA access to an artificial intelligence (AI) accelerator developed by Groq AI before delving into why Meta is acquiring Manus to gain access to a set of general purpose AI agents.Then the gang takes a look at MongoDB Bleed, a vulnerability affecting the widely used database that has been actively exploited over the holidays.
Transcript
Hey everyone. I'm Alan Shimmel. You are not, and we're live on Textron Gang.
A little take up on my, well, you gotta be old enough to remember Chevy Chase on Saturday Night Live. Anyway, happy New Year everyone. It is 2026, my God, 2026.
We're trying something new here on the gang. We're actually really, really live. So this isn't edited the day before or anything like this.
Bear with us, you know what happens with live tv? You know, someone's gonna have a mouth full of chocolates here or something, but we'll, we'll figure it out. Um, we hope you like this new format, though.
I'd love to hear any comments or thoughts you have on, on the live versus recorded. Um, as I said, we're a bit in experimental video here as we head into the new year, and why not? It's gonna be that kind of year.
Let me quickly introduce you to our live gang members for the first show of 2026. Couldn't think of a better crew to kick it off with. I've got my friend Steven Fst, fresh off of Caribbean vacation.
Steven, happy New Year. It's great to be here live and I'm glad I got out of there before the airspace was closed, that's for sure. Let's not go there, but, okay, I hear ya.
Um, also joining us. He looks like he's home. Happy New Year, Jack Poller.
Thank you. Happy New Year to the gang. This is wonderful to be here today.
And then, you know, our core, core, some of our court gang boys here, we've got, of course, Mitch Ashley Mitchell. Happy New Year. Happy new.
And the dean, Mike Ard. Mike, happy New Year. I hope you guys had a great Christmas New Year holiday.
I hope all of you out there had a great Christmas New Year holiday and whatever you're celebrating. Um, but we're back to work. And you know, the, the news doesn't stop.
The tech beat is marching on. It's all kinds of stuff going on. Mike, what do we got?
Well, it's been a busy holiday season. Normally things are quiet, but there's been a lot going on for the last two weeks. So let's just dive right in.
Nvidia struck a $20 billion licensing deal to get access to technology from Grock ai. The idea here is that they want to be able to at least either, maybe we're not quite clear, it might be they want to kill this thing like an oil company investing in a solar panel company, or they actually have some concerns that maybe GPUs are not the right answer for everything in the world of ai. And they want to use the gr ai technology and accelerators for different use cases.
Steven, I know you've been tracking this whole area for a while, but what do you make of this thing? 'cause it kind of feels like, I don't know what to call it, an Unac acquisition. Well, I think this is called a clever, uh, acquihire.
Uh, they are, uh, taking over Grock. Uh, those of you who don't know grok, there's actually two things in AI called grock. This is the other thing that's not Elon Musk's GR bot.
Uh, GROQ is a, um, AI startup. They're a hardware startup. Um, also, uh, software services of course.
But, um, you know, grok is a very interesting company. It's one of those, uh, firms that I've been watching closely, like you said, on our utilizing tech and now utilizing AI series of podcasts. Uh, essentially they developed a novel, uh, AI compute platform.
Um, and, and again, this was founded by Google Engineers, I think back in 2016. So they've been working at this for a long time. They have a lot of respect from those of us in the industry who watch the hardware space closely because essentially they're doing what NVIDIA's not doing, rather than developing, um, I don't wanna say NVIDIA's generic because of course they're doing a lot of really amazing stuff with their hardware, but their hardware is sort of general purpose.
Rocks is very special purpose, and that's really what they're trying to do, is to develop, uh, special purpose hardware. And that has mainly been focused lately in the inferencing space by purchasing or acqui hiring gr essentially what NVIDIA's getting access to is all that hardware, um, uh, as well as the employees. Uh, but they're leaving grok, um, purportedly intact in the hands, I believe, of a former CFO, which sounds to me like he's kind of probably wind that company down a little bit, um, while keeping the, uh, grok family over there on the Nvidia side.
Honestly, I don't expect this to be what you expect. You know, what you said about, you know, Nvidia, the big giant coming in here and crushing the competition because frankly GR was already getting crushed by Nvidia in the marketplace. I actually see this as an opportunity or an admission by Nvidia, that that inferencing is on the rise and they need special purpose hardware and software to do that.
And GRS got some of the best out there. And so essentially it's a validation of what GRS been working on more than a, uh, a, a move against them. Alright, you, you know, this, this seems to be a pattern though that we're seeing.
It's almost a new, it's a new, uh, method of acquiring, right? We saw it with, what was it, windsurf? Mm-hmm.
Right? Where they, I think it was Google licensed the technology, not exclusively. Same here.
Not exclusively. Aqua hired a lot of the brains. And Steven, I remember being on the show with you when that deal came out and we said, well, I guess they just left someone to shut the lights.
Lo and behold, about a week or two later, they sold the company for another couple billion dollars. Right? And Maybe, maybe GR will be able to do that With whatever's left.
I think so. I think the key to it is the licensing of the technology does not give Nvidia the exclusive use of it. They could go license or sell that technology to someone else, but you're buying it sort of without the brains.
So you've gotta be able to do a brain transplant to adopt that technology and carry it forward if you are the ultimate acquirer of grok. Right? But, you know, so for $20 billion billion, you gotta ask yourself, well, why didn't they just buy the whole thing?
Well, the whole thing might have cost them 50 billion or Yeah, well look vid 5 trillion, what's 50 billion here or there? But, you know, there's that to it. Is this just an elaborate way to avoid a antitrust review of the acquisition?
I mean, is that what these folks are really after at the end of the Day aspect? Mm-hmm. I think it's, it's the, the risk isn't the antitrust.
The division will say no to the deal. It's that it puts the ti it puts a different timeline on it, right? Once the regulators get involved and say, Hey, we need to look at this, then you can't do anything with it until six months or a year from now.
And at that point you've lost all of your, um, time to market for this. And so by doing it this way, you're getting the people you need and the technology you need immediately, and you get to start developing product with it immediately, which is in the AI field, that speed is pretty critical right now. Oh, well, in a way it's kind of a best of both worlds because they get access to the technology.
They're getting the people that they want to move over, and maybe there's a following deal down the road. Um, you know, for, for that deal, for 20, for $20 billion, you know, that's pretty remarkable that you're gonna pay that much to get ahold of that technology. So maybe, maybe there's a secondary transaction that'll follow.
Maybe it's something that they, they're not as worried about acquiring customers 'cause they're getting going after the same ones, or maybe they are adding some new customers. You have to kind of look at that analysis. So the question I have when you say it's, you know, it's a great deal for Nvidia, but the employees, since it's not a change of control, doesn't trigger their stock valuation and their ability to, to earn any payout from this.
So where does all that, who gets all that money? And do the employees get any of it at all? Right?
Probably not. Steven, is there two separate AI markets kind of evolving here? One is the whole training side of the world, and then the other is this inference side and that inference side might not be as GPU dominated as the training side.
Absolutely, there is. And if you look at, uh, companies like Google Cloud, AWS, Microsoft, um, I think what they're showing us is not only is there another a a whole disparate AI market here for inferencing and applications, but that that market is really, really heating up and that market actually has the possibility of generating, uh, revenue and cash flow. And again, I think that this is an example.
Now again, we don't know the details here, but if I was in charge of Nvidia, what I would be doing is positioning what Grok had built as a competitor to what Google and others are successfully doing on the inferencing and application side in terms of building out cloud-based inferencing as a service for customers and trying to build another revenue stream essentially. Uh, that, that may end up being the real story here. We may see Nvidia competing with the likes of Google and AWS Microsoft as, as opposed to Nvidia just being a big iron supplier to everyone.
Mm-hmm. You know, I, I think we're in the new year, the new era is daunt, I think 2025 in the rear view mirror. We all foretold.
It is the year of Agen ai where 2024, perhaps even 2023 was the years of generative ai. Maybe 2026 is the year of inference computing for ai. Now, keep in mind that it seems we're always a year ahead, right?
We're pushing these things faster than they, they at least A year ahead. Yeah. So, You know, but, but the action and the money and the attention will be on inference computing for 2026.
Mitch, you Think merit to what you're saying, Alan, too, and I, I think this is a consequence of the AI race, right? You, it, it's sometimes irrational behavior, sometimes it all makes sense, but a lot of people are making a lot of moves in, in many directions, acquiring companies, acquiring technology, doing partnerships, doing investments, all of this. And, and the kind of big, big companies, if you will, are really competing to go after the smaller companies that they're getting to acquire a license.
And I think we're gonna see a fevered pitch of this happening throughout this year. This wasn't just a 2025 experience. Mitch, I think though follow that up a little bit further.
I think the, the decision about what inference engine to use shifts and becomes much more of a traditional IT decision rather than the data science team, per se, that trains AI models. And so will we see CIOs and IT teams and DevOps teams playing a much larger role in rolling out those inference engines. Developers already today make a lot of those decisions in part with their operations and platform engineers.
And of course, uh, GitHub and others have talked about having the ability to pick the model for you based on what the inferencing is that you're doing or what the, the prompting is the agent's trying to perform. So at some point that could be automated. The other third wheel in that though is finops, what's the cost effective way to do this?
Or can I groom a prompt in a way that I actually can run it much cheaper on whatever engine that I select? So I think the, there's a lot more intelligence to be added to that, both from a cost savings and performance perspective. To me, it sounds like, you know, it is back driving this car again, but we'll see what happens.
Not going away yet. Not dead yet. Alan, closing thoughts on this one?
You know, I, I, I think I gave you my closing thought. 2026 is the year of inference. It'll be, I I also though look as a corp dev guy for a lot of years in my life, I, I wanna follow this trend of like sucking the brains in a licensing deal rather than doing a a, an outright acquisition.
I think our next segment, Mike, and this is a great segue, is more of a traditional acquisition by the folks at Meta. And you know, Jack, I think you're onto something there. Obviously from a re if you're, if you're a regulatory concerned company, thi this is maybe a little cleaner, easier, shorter time to the finish, though.
There are trade offs involved. Mike, what's the deal with the meta app of the meta acquisition? Excuse me.
All right, well let's shift the gear right now then, and we'll talk about this meta acquisition, which acquired a startup called Manus that has been building some AI agents that are highly thought of. They are general purpose AI agents. And the idea here, I think is that they're gonna talk to other AI agents to execute various tasks, but this will become the central focus of your AI agentic experience.
To me, it, it's an interesting move because for Meta it means that, you know, we're moving beyond just messaging apps and social media. It looks like we're trying to maybe start to take more control of both personal and maybe even business workflows. Mitch, what do you think?
Well, I think Meta is the middle child of the AI race companies. I was talking about the race for AI technologies. They're trying to gain, they're trying to gain credits and so far they're really have fallen quite far behind the top three at least.
And of course, the, the last child being the startups that are the ones that are interesting to acquire. So it's, it's, I'm not sure that this really changes their positioning. It gives them more functionality and maybe it accelerates their ability to, to have, uh, long running or multitask agents that they can populate across their platforms.
I think that's one potential advantage they might have is that, that they can implement Manus in a way that it can be used across Instagram, across Facebook, et cetera. So that you have actually agents that not only work within those environments, but can go cross environment and think of Meta as more of a platform play. But that's kind of a big, big, I'm not predicting that happening.
That would be a big move. I'm not sure. Facebook, excuse me, uh, meta is ready for that.
Um, do you guys think at the end of the day that this might be the first thing that, um, meta has done that's actually gonna make money for them in ai? 'cause everything else that they've done is an open source platform and it's an investment that they're sharing with other folks. But, um, is this, you know, the first revenue stream, Alan, You know, I, I, I hate to be the one to do this right?
On New Year's, but we need, an emperor has no close kind of moment here. Mm-hmm. 9% of these agents suck and they're hard to use.
They don't do what they say they're gonna do. And if they do do it, they don't do it the way we want it to. And for all the talk about Agen ai, it still seems like we're out in front of our skis a little bit on this.
9% of agents out there? There's one reason to think that, and that's that they're actually generating revenue. Um, I, I don't want to be the that guy always, and when we're talking about ai, but, uh, where's the money?
Where's the revenue? Well, Manus, uh, yeah, they took in a bunch of money, but according to what I've read, they're actually generating on the orders of, uh, a hundred million dollars, uh, annual recurring revenue. Now, again, that's not yet gonna get them to the point of break even, but, uh, it's better than a kick in the head as the man said, uh, I'd rather have a hundred million dollars of revenue than negative a hundred million dollars.
Uh, which I guess they kind of do 'cause Well, anyway, point is they're actually, they actually are paying customers. And as, uh, you know, Mike and, and Mitch and so on pointed out, um, this could be a signal that Meta is ready to start making money here instead of just pouring gasoline on this fire In the model business, right? I mean, that's, that's where they've fallen behind and they're really struggling to keep up.
Yeah. And in a way you can argue, do they really need to be in the model business? Why don't they really emphasize their applications, their platforms, the Instagrams, Facebooks, et cetera.
So maybe it's just complete shift. Now, I'm not saying they're gonna go away from models completely, but this could be a pivot for them. But I think you're Right.
And I think, I think you're right, it's a shift, but it's a completely different shift that you guys are missing. This is not an AI story at all. This is an ad story, okay?
Ad revenue is, they look at it and they see ad revenue's gonna go off a cliff because the ad, the search engine business and the ad business is gonna completely be changed by ai. The question is, when's the last time you guys have done a Google search, right? We all now use ai.
And Google's seeing this too, is that the ad business is gonna change completely. And so this has Meta's first attempt at figuring out how to enter the software as a service business and generate revenue and recurring revenue. It's a good way to do it in the AI space rather than traditional SaaS space.
But this is their, their next revenue opportunity. And they all, what happens when the ads die? I like to come back to what Alan said and focus on this $2 billion number for a minute.
So if the first rev of these AI agents truly do suck, does this mean that the cost of for Manis to get to the next generation of these things is gonna be in excess of that $2 billion number? So therefore it makes sense to maybe, um, sell out now to meta versus going to the public markets that may not wanna contribute, you know, the kind of billions of dollars that might be required to make agents ultimately work. Alan, what do you think?
So I, I think we've gotta go not to play soccer here and kick the ball, but we gotta go back to what Steven said, right? Which is yes, man is, is generating a hundred million dollars plus in revenue. But again, not to be the old man on the lounge chair here for New Year saying, go play in front of your own house.
There's a difference between generating revenue and making money. They don't make money. com, most of us on here did too.
We're all not spring chickens anymore. At some point the street says top line's not enough. Show me your bottom line.
Is this a real business? And I don't care if you did a hundred million dollars, if you are losing 20 cents on every dollar you, you take in, it's not a good business. And so that's my, my, my fear here is, you know, and now, you know, from the meta point of view, look, they have already made business to drop this into in terms of s right?
Um, and so maybe they're not as concerned necessarily with the, the financials, if you will, of madness because they view it as, look, they're going to turn this thing on its head given their own position in market and ability to run ads. Jack, I would put forth that Google is an AI search today. It's no longer the Google search that we knew it's AI search.
You know, I don't remember the last time I did a Google search where I didn't just read what Gemma and I said, and that was my starting off point. I'm sure Google's glad to hear that. Well, I'm, what am I, am I wrong, Steven?
Do you, are you in the same boat? Are you still going through the old, like scrolling down? Oh, baby, I use DuckDuckGo.
I'm a weirdo. All right, there you go then. But, But see, Alan, when you do that though, you read the, the, the AI summary.
Yes, they're a search engine, but they're not getting ad money for that placement there, right? That's the business. Right?
But I think that Google made the, the choice of if they don't do that, they're gonna lose it to pre to, uh, open AI and perplexity and, and, and Claude. Absolutely. Which, which is my point that the higher level message here is that the ad business is changing and Google et all, and Meta cannot look at their ad business as the cash cow that funds all of the rest of their activities.
Mm-hmm. That's almost go away over time, Jack. They're kind of, in a way, it, I'm glad you brought up the whole ad part of it.
It's good insight, uh, interesting that it's also pivoting to more of a product placement as opposed to an ad, right? Yes. You can see this in perplexity, which is, yeah, I'll give you some Google, some YouTube videos, but also here's three places you can, three different products you can go buy that does these things, right?
Mm-hmm. Of course, they're making some money on that as well. So it's, it's kind of skipping the ad, going right into here's the answer for what you're looking for.
Here's some options. Yeah. And that's what Google has really successfully done with ai.
To Alan's point, again, I was flippant by, you know, no, I don't do that, but, but everybody else does. They go to Google, they look something up, Google, you know, Gemini gives them an answer ish at the top. And there's no reason now that Google can't use that to promote specific products, specific technologies, specific, you know, revenue generating links.
In fact, they probably already are. I don't know enough about it to know whether they are or not. But you know, if I was, um, you know, I, I feel like the antitrust regulators that, that that went after Google in previous years completely missed that, that Google was able to leverage the search platform just like Microsoft leveraged the operating system in the browser wars.
Google was able to do that and has successfully turned the corner to the point now where Google is in the AI business. To Alan's point, I think that Meta's done the same thing. I think that Microsoft's done the same thing, and many of these companies, I think are leveraging their previous position to be a leader in ai, and now they're looking for revenue, and that's what they're gonna do next.
So I see this slightly differently. I would say that the future user experience for both Facebook and Google and everything else is gonna be some type of AI agent that you're gonna engage with. And then it becomes, well, which of those AI agents is gonna be my dominant user experience?
And then we'll be calling all these other backend services. And I think that Google and now Meta are making a play for that, where they wanna both create AI agents that will sit in front of those summaries and the search and, and, and say, here's what you're looking for and tell me what the next thing you want me to do for you is, and I think Meta wants to be in that same position, not just for their own properties, but maybe for other properties that a lot of this stuff on the internet today that we access is just gonna become some sort of backend service that some agent services up and we're not gonna see 'em anymore. And they might just be, the web is five companies with five agents, and everybody else is an API call away.
You know, there's one other angle to this too, Mike, and that's that this is a Chinese created company. It's parent company is Chinese based. They've actually founded it in China, then moved it to Singapore.
So it will get great, uh, it could get substantial, uh, regulatory scrutiny. It's already kind of drawn the eye of the, uh, European Union around data protection. I guess China has its own export controls.
We'll see what that means. But maybe it's Zuck calling up, you know, Donald, Hey, hey Don, you know, let's make this transaction happen or what. But it could, So you say Don takes 15% off the top.
Well, you know how that's kind of the way those haircuts work and the new hair, the new kind of haircuts in the federal, Otherwise you wind up in the Brooklyn Detention Center. Yeah, I think, I think there's a tick. I think there's a TikTok script that shows how to get around that role.
Well, That's what I'm saying. Yeah. I think, You know what I see we're descending into another level here.
Let me lift this back up. Let's stop talking about AI and politics and let's talk about good old fashioned security. Mike, my friends at MongoDB, I gotta be, I love MongoDB, but I've been covering MongoDB for 15 or 18 years, and there's always this like security shadow, not quite in sync with them.
This is true. And apparently, you know, the bad guys don't take 10 minute time off because during the holidays they were exploiting, I guess it was a known vulnerability within MongoDB, but they just decided to aggressively exploit it in unison. And the next thing you know, it's everywhere.
And there's a patch being provided by MongoDB. And developers are coming in to work to handle and deal with all this stuff. And it's the usual chaos and fun that goes with things.
Now, Jack, you've been on the show multiple times and have said, you know, if it bleeds, it bleeds. So here it is. Mongo bleed.
Yeah. Well, first off, we have to give props to whoever comes up with these, uh, you know, military operation names and the names of, uh, vulnerabilities. Somebody is very creative there.
So yes, it is a Mongo bleed and it is bleeding. Um, interestingly enough, this was not discovered by the bad guys despite it being in existence since 2017 and living in almost every single Mongo release ever. Uh, it, it was discovered by security researchers that were doing a fuzzy attack, which is basically trying to feed in random inputs and see what happens.
And that's a very common thing that security researchers and bad guys do. And it's something that MongoDB, if they're not doing, should be doing. It's a common, you know, security test and validation effort.
Do they discovered that, uh, one of the libraries used to process your network data and do, um, encryption decryption before it ever enters the system, had a bug in it and didn't check the length of the, the, the length return. And so you were able to, uh, overrun buffers and extract data out of MongoDB databases without ever authenticating to the database. So that was, uh, discovered by security researchers was given to Mongo, who created a patch.
And at the same time, somebody created a proof of concept release, that proof of concept in the wild. And now people are using the proof of concept concept to exploit Mongo DBS in the wild. So it is a, uh, rated an eight plus on the CBE E 10 point scale.
Um, it was given a one of the last CBEs, uh, critical vulnerabilities, uh, last year, of which there are almost 15,000, which is just an astounding number in and of itself. And Steven's reaction is, my reaction is like, we gotta get better at this stuff. We've really just gotta get better at it.
Yes. So big problem. Uh, if you have the Mongo db, if you're using the cloud service that Mongo provides, I believe it's called Atlas, then you're not affected.
'cause they patch that immediately. But if you have Mongo embedded in your application, and it's very common to do so, then you need to patch your Mongo asap. Otherwise you're going to lose your data.
Steven, you're shaking your head. What's up my friend? Well, first off, uh, I'm a MongoDB user, So this is concerning to me.
Also, Merry Christmas. Uh, here's a CVE that's being exploited in the wild. Congratulations on your week off.
Um, unfortunately I didn't hear about this until now. I think though that I am not vulnerable to this. And the reason is because my setup, my, you know, web application setup has MongoDB on a private network that is only accessible to the front end web servers.
And so I'm not sure that the vulnerability, if you can't access the MongoDB server, that this vulnerability affects everyone. Now, my question, uh, about that Jack, is, is that your understanding, but also it, it seems to me, I mean, from my reading, it seems to me like what they're doing is because z lib is processed, so compressed data is processed before the authentication steps, then it exploits a z lib compression, um, error in order to get around the authentication steps. Uh, again, if, is this only, is this only, uh, vulnerable if your MongoDB web server is ACT or MongoDB server is actually, um, accessible to outside networks?
Or do you think that this could be ex expressed through, uh, like remote codex Through A a website? Yeah, so through, I'm through an application. My, my under my understanding is this is if your Mongo database is exposed directly to the internet, so somebody is crafting an, uh, a, uh, a transaction directly to MongoDB, it would be very, very difficult, not impossible, but it would be much more difficult to hit your application and force your application to send the bad data to Mongo and then get that all the way back out.
Again, not saying it's not couldn't happen, but I think that's less likely than just, or it's less of a positive issue than if your database is exposed directly to the internet. That being said, it's, you know, all bets are off once you have an exposure. Mitch, is this the new reality?
Because, you know, a bunch of researchers, you know, for whatever reason decided to come up with this attack and then they published it in the quote unquote the best interest of society. And then the next thing you know is getting exploited. Um, is this all the timeline for all this seems much more compressed.
And so basically, you know, we're getting exploits and vulnerability disclosures. Is the time window's collapsing to the point where do I have to be if I'm a developer continuously on guard for this stuff? I mean, you know, is there no such thing as a vacation?
'cause I gotta go figure out how to patch something. What's the future like? This is the low hanging fruit of exploits.
In other words, instead of creating something novel, it's exploits something that already exists that hasn't been patched. If you could discover what that is and then take advantage of it, and, uh, while this is for, this is primarily a internet exposed databases that are, that are, you know, as susceptible to this attack, it can't happen internally as well. Someone breaks in and gets inside the, the, uh, security perimeter, if you will, if there is a perimeter anymore.
But I think this is an example of you could argue that not only because the accessibility of information, but our ability to process it. You know, going back to the AI story, maybe it's something you can aided by AI of finding more of these kind of existing, uh, vulnerabilities that can be exploited. So I, I think if anything, the tax surface doesn't have to necessarily widen.
It's just going after things that haven't exploited yet. Look, I, for 1:00 AM happy to see just a good old fashioned security breach story. Isn't that like napalm in the morning?
Is that what you're saying? Yeah, No, look, the floors, the vulnerabilities been out there forever. Shame on us for not closing it down or making it, well, in Steven's case, it sounds like it is not reachable, um, today, you know, but, um, I mean, this is, this is God and variety security work guys.
Mm-hmm. That it is Jack, Jack who should be in charge of responding to this. And I asked the question because there's been this ongoing conversation about letting security people just patch things and not wait for the developers to fix them.
And then there's still a lot of developers out there who are like, don't you dare touch my application. You're gonna break it. Uh, security is a team sport and there is absolutely no room for walled gardens and security.
If you've got a vulnerability, the first person who has the opportunity to protect it, to protect your kingdom, should do so. Right? The guard at the guard at the front gate doesn't say it's, uh, you know, it's not my turn to check badges, so I'm gonna let everybody in.
Right? That's, that's not the way this works, right? So I don't think, I think everybody has a responsibility, and if the developer says, Hey guys, I can do this much quicker than you, or I need to in making this fix.
I need to make some other fixes. I'll take care of it. That's one thing.
If the IT folks say, Hey, look, we have an easy, quick workaround. We'll take care of this another way we can put a block on this, we can take it off from exposed to the internet, whatever. We'll fix it that way.
Right? That's the right thing to do, is to just fix the problem. If, 'cause it's, it's, it's a known exploit.
It's being exploited, right? It's, it's, it's a problem. So it's hot.
Yeah. I, I, it's, it's hot. I, I don't think it's the developer.
It's not right. But It, but Regardless, you know, it's the IT team. But you know, Mitch, we probably remember this, I'm gonna say around 2005, Mitchell and I go meet with one of the three global CIOs of Citibank, a guy named Peter Fisher.
Man, nice gentleman. Really nice guy. Mm-hmm.
And you know, Peter told us at the time we were trying to sell them vm, the vulnerability assessment of management tool. Mitchell held glad the development of Peter told us it took 'em 90 to 120 days from the time a patch was available to installing that patch at Citi. Why?
Because they had to make sure it didn't break anything else because they were more worried about the patch breaking something that was more valuable than what they were patching. To me, that expressed the, the conundrum of security. Mm-hmm.
Right? Is that we had to play those games. And so though we knew that this was actively being exploited in the wild and we were susceptible, we didn't do anything until we made sure it didn't break anything bigger or more valuable.
Mm-hmm. I think though that, that math is changing 'cause the cost of the breaches keeps going up. And maybe we reached a point where the patch and being applied immediately is probably less explosive than the breach is gonna be, than it would be if I knocked the system offline.
And the odds of that happening is low to medium. Jack, you're, you're insecurity. It has the arithmetic changed Calculus?
I, I think it has. Uh, I, you know, 10 years ago I was working with, uh, some, uh, international multinational biotech companies 10, 15 years ago, and they required a sign off from international headquarters to make any changes to their network configuration. So local facilities couldn't change that, which means you couldn't change a firewall rule to do a block without getting approval and getting it audited and having the whole, you know, documentation and all of that, that's changed because it's now all automated.
You use threat intelligence to do that. So I think we're becoming much more reactive. And very often you can say that the risk of an exposure is much more than just the particular incidents.
Yes, somebody could extract data from my MongoDB, but there's all sorts of financial reputational risk that comes with just having an exposure that companies are very interested in just saying, no, I'm not affected by this. Right? Your data is safe with us no matter what.
And yes, we had three hours downtime or a half hour downtime while we figured this out, but that was more important to us rather than losing your data and your trust. And so I think that equation really is changing. Again, it's somewhat, um, uh, domain specific, right?
Industry specific. I think the financial industries are much more concerned about losing your money and your data or healthcare than say if it was an exposure at a, you know, uh, a manufacturing plant that makes light bulbs, right? Yeah.
The risk is a lot different. So, so there's some additional clarifying information from Steven and Abuntu here. What are you, what are they trying to say here?
Well, You know, it's funny. I I think that based on what Jack was just saying, my experience is that a lot of the time management rushes out, um, sort of, um, not quite ready for primetime messaging about things like this. And among those are sometimes management rushing out messages to customers saying, your data's not affected.
You won't be impacted by this when they may not be sure. And then other times, um, there are incorrect assumptions here. Now, I notice in our article, and also, um, online, there's references to this same, uh, bug affecting syc, which is another tool that I use a lot.
And, um, and in fact I have it running right now. And yet, um, according to AUN two, um, later testing showed that SYC was not vulnerable to this. So I think this is an example of that sort of messaging problem where people get out in front of things, they worry about things, they, they read into things and, and they don't yet know.
Um, you know, it seems horrible to think that it would take months for a company to, uh, deploy a patch to a known CVE, but at the same time, um, you know, we'd all, we don't wanna run around like chickens with our heads cut off here worrying about, you know, oh my gosh, my r sink server is going to be impacted by this, and that is visible to the internet, and I better go out there and find a look, which is exactly what I just did. And instead, um, you know, we should probably hold off a moment and let the experts take a look at it and tell us whether things are vulnerable and whether things aren't, and whether data is safe and whether it's not. Um, I, I guess that's, that's the problem with our democratized internet, right?
We all are out here, um, worrying about things running around, uh, spreading the news, uh, person to person without, you know, having any kind of, um, you know, hierarchy to tell us whether this is really impacting us or not. I'm, I'm gonna take the prerogative to have the last word on this. Sorry.
That's your prerogative. Thank you, Steve. I just interrupted you though, to make it No, no, no.
I, IG listen what you say, and I'm going to, I think one of the issues though, the elephant in the room that we don't acknowledge is still the stigma of a security vendor acknowledging that they have a vulnerability or they were breached or caused a breach. I had a situation just this past Christmas where I was reached out to on, uh, I guess it was New Year's Eve that a, an article on our, one of our sites claimed there was a breach when technically, technically it wasn't a breach according to their technical definition. Well, I will tell you that every it person out there would think of it as a breach when my identity and access credentials are stolen.
We had, we had breach, um, when the URL of IT points somewhere, you had a breach. Whether the information is hashed or encrypted, that was still stolen. Now we need to remove the stigma of being of breached or having a vulnerability.
It happens to all of them. Everyone, all of us have breaches. The best thing for the security industry is to have sort of these blameless postmortems, borrow it from DevOps, blameless postmortems.
It's not about who did what or what, who was wrong or, or what, you know, those consequences are. It's about how do we make things right going forward? How do we handle these things better?
Mm-hmm. And that's what we need to do as an industry, Except for the fact that all those people that you used to be going to school with at St. John's and law school have a, a career to do.
And that first thing they do is we love these things, we're gonna sue you. We breach. Well, maybe we need tort reform.
What did Shakespeare say about lawyers? I don't remember exactly. I remember.
That's why I don't do it. All right. Hey, I hope you've enjoyed this live session of Textron Gang.
It's fun doing it live. A little different, a little. We had to do some stuff here on the fly, but I think all in all, it worked.
It worked primarily 'cause we had such a great gang today, Steve and Jack, Mitch, Mike, thanks for joining in. We're gonna be live tomorrow as well, so check that out. We might even be looking at some predictions.
Speaking of predictions, next week, the 15th, our Predict 2026, join us and the RUM advisory team with our best predictions, guesses, intuition of what 2026 holds in store. com. Um, until tomorrow though, thanks for joining.
This is Alan. We're out.