Russian Subs Trained Near Arctic Cables, Plus 4 Tech Stories
Russian submarines trained near critical Arctic undersea cables
Today’s lead starts a couple of kilometers underwater, which is a useful reminder that “the internet” is not actually floating around in a cloud. A remarkable amount of the digital world still depends on very physical cables lying on the seafloor. Reuters reports that NATO allies confronted Russian submarines this spring near two critical fiber-optic cables connecting Svalbard to mainland Norway.
The public and newly reported parts of this story need to stay separate. Britain disclosed on April 9 that the UK, Norway and other allies had spent more than a month tracking an Akula-class submarine and two specialized vessels from Russia’s Main Directorate for Deep-Sea Research, better known by its Russian acronym GUGI. Britain said those vessels operate around critical underwater infrastructure and are designed to survey it in peacetime and potentially sabotage it during a conflict.
What’s new comes from two Western officials speaking anonymously to Reuters. They say the operation was near Svalbard, involved the United States, and included GUGI submersibles practicing deployment of a sophisticated technology intended to disable subsea cables without leaving obvious evidence of what caused the failure. NATO forces tracked and confronted the vessels, and the exercise ended without any cables being damaged. Russia’s Defense Ministry did not respond to Reuters, while the Kremlin has consistently denied plans to sabotage NATO infrastructure or seek a confrontation with the alliance.
That last paragraph is the part I don’t want to casually promote from intelligence reporting into established fact. Britain has publicly confirmed the Russian operation, the GUGI vessels, the tracking effort and the concern about underwater infrastructure. The specific Svalbard location and secret cable-disabling technology are Reuters’ reporting from unnamed Western officials.
Even with that qualification, the underlying infrastructure problem is real enough. Two roughly 1,400-kilometer fiber cables link Svalbard to Norway, descending as deep as 2,700 meters and carrying satellite data from SvalSat, the world’s largest satellite ground station and part of NASA’s Near Space Network. More broadly, Britain says 99% of its international telecommunications and data traffic crosses undersea infrastructure.
The cloud has an ocean floor. Protecting it is becoming part of cybersecurity.
Technology is rarely just about the technology
Some of the most important technology stories aren’t product launches at all. They’re about health, privacy, education, law, accessibility, work, and what happens when technology reaches ordinary people. Browse more Raymond Tec News for the stories worth understanding without the hype.
Cisco firewall managers have an actively exploited root-level flaw
If your organization runs Cisco Secure Firewall Management Center on-premises, this one belongs ahead of whatever was on the maintenance calendar.
Cisco updated its advisory September 9 to confirm that CVE-2026-20079 is being actively exploited. The vulnerability carries a CVSS score of 10.0 and affects the web interface of Secure FMC. An unauthenticated remote attacker can send crafted HTTP requests, bypass authentication, execute scripts and commands, and ultimately obtain root access to the underlying operating system.
That is especially ugly on a firewall management appliance. A security tool with administrative control over the devices protecting a network is not just another server if somebody else gets root.
Cisco has released hot fixes for supported FMC 7.0, 7.2, 7.4, 7.6, 7.7 and 10.0 branches and recommends moving to fixed software. There is no workaround that fully addresses the vulnerability. Cisco also publishes an indicator administrators can check in system logs, but there’s an important catch: the hot fix prevents future exploitation. It does not clean up a device that was already compromised. Cisco says customers who see the indicator should contact its Technical Assistance Center for recovery guidance.
Cisco says the attack surface is reduced when the FMC management interface is not exposed to the public internet. Reduced is good. Patched is better.
A flight-data failure shows what “resilience” actually costs
Hundreds of thousands of people got a much more practical lesson in infrastructure resilience this week when a systems failure at Britain’s NATS air-traffic-control provider disrupted about 2,000 flights Tuesday and Wednesday.
The UK government says it does not believe the outage was a cyberattack. NATS says the failure affected its flight-data system, and Transport Minister Heidi Alexander told Parliament she does not believe the incident was unavoidable. NATS now has a week to report what happened, while the Civil Aviation Authority will conduct a separate review expected to take six months.
The immediate failure lasted hours. The mess did not. Aircraft and crews ended up in the wrong places, which meant cancellations and delays continued after the underlying system came back. That is the part of resilience planning that gets lost when we reduce an outage to “uptime.” A system can be technically available again while the business process wrapped around it is still trying to put itself back together.
This is also the second major NATS failure in three years. A 2023 outage caused by a problematic flight plan cost airlines about £100 million, and another technical issue affected airports in July 2025. Tuesday’s failure affected about 30% of scheduled UK departures that day, according to aviation analytics firm Cirium.
For stranded passengers, UK airlines still have obligations to provide refunds or rebooking and reasonable expenses such as meals and accommodation, even though the disruption will generally be treated as an extraordinary circumstance that does not trigger ordinary compensation.
Technical discovery & auditing
The public page doesn’t tell you much about the machinery behind it. Raymond Tec audits inherited and long-running projects to uncover the plugins, integrations, data, dependencies, and old decisions that determine what the next change will really involve.
AI shopping agents are getting something like an ID card
Visa, Mastercard and Ant International are now working together on what they call a Know-Your-Agent interoperability framework. The name is a play on “Know Your Customer,” but the problem behind it is very real: if software shows up at a checkout saying it is authorized to spend my money, how does the merchant, payment network or bank know who that agent is and what I actually told it to do?
The companies want card networks, digital wallets, AI platforms and marketplaces to recognize trusted agents across different payment ecosystems while keeping their own approval and risk controls. The proposal builds on systems the companies have already developed separately, including Visa’s Trusted Agent Protocol and Mastercard’s Verifiable Intent.
Those existing approaches use cryptography to carry more than a generic “trusted bot” label. Visa’s protocol can identify the agent and communicate its purchase intent. Mastercard’s Verifiable Intent is designed to create a tamper-resistant record linking the consumer, the authorization given to the agent and the resulting transaction.
That audit trail matters when something goes wrong. “The AI bought it” is not a useful answer to a charge dispute. Did I tell the agent to buy that exact item? Did I approve a maximum price? Was the agent still operating inside those instructions when it paid? Who is liable if it wasn’t?
India is wrestling with the same issue from another direction. Reuters reports that the National Payments Corporation of India is developing a registry to verify AI agents making transactions over UPI as it prepares to introduce agentic payments. The plan reportedly starts with frequent, low-value purchases before moving toward more complicated instructions. Liability for erroneous or unauthorized transactions remains unresolved.
Good. That is exactly the boring question worth solving before autonomous shopping becomes exciting.
Turning on AI is the easy part
Deciding what an AI tool should be allowed to see, who should use it, what work it should perform, and what happens when it gets something wrong is the more interesting problem. Raymond Tec helps businesses connect and automate the tools they actually use without treating every new feature like a button that obviously needs to be switched on.
Microsoft and teachers put actual contract terms behind school AI privacy
There is also a useful follow-up to last week’s move by New York City schools to limit student-facing AI. The American Federation of Teachers, its New York City affiliate and Microsoft have negotiated a National AI Safety & Privacy Standard that U.S. school districts can incorporate into Microsoft customer agreements.
The significant word there is “agreements.” This is not Congress passing a national school-AI law, and the title “National Standard” should not be read that way. The protections become enforceable because a school district puts them into its contract with Microsoft.
The terms say student and educator data will not be used to train AI models, sold or repurposed; schools retain control over how the data is used, retained and deleted; AI systems cannot make consequential decisions without human oversight; and families are supposed to receive understandable information about what data is collected and how AI is being used. The agreement also calls for safeguards against harmful or manipulative AI experiences.
That does not settle every argument about whether, when or how children should use AI in school. It does something more immediately useful: it turns a set of privacy promises into terms a district can enforce.
For school leaders, the question is whether those protections belong in the next Microsoft agreement. For parents, there is an equally simple question to ask: when the school says an AI tool is “safe,” what does the contract actually require the vendor to do?
Still in a reading mood? The Raymond Tec News archive covers security, AI, small-business technology, policy, and the places technology collides with ordinary life — without requiring a computer-science degree to get through it.
Sources / Further Reading
- Reuters: NATO allies foil Russian subsea cable sabotage plot
- UK Ministry of Defence: April 9 operational update on Russian submarine activity
- Cisco: CVE-2026-20079 Secure FMC authentication bypass advisory
- Reuters: UK air-traffic systems failure and investigation
- Reuters: Visa, Mastercard and Ant International launch Know-Your-Agent initiative
- Visa: Trusted Agent Protocol
- Mastercard: Verifiable Intent
- AFT: National AI Safety & Privacy Standard for schools
- Microsoft: school AI safety and privacy agreement
