Primary Domain
Security
Within the Primary Domain facet, Security intelligence groups reporting by primary domain so readers can follow a focused area of internet infrastructure, governance, connectivity markets, or digital capital. The page brings together related articles, public evidence, institutions, companies, people, regional exposure, operating dependencies, and market context that may otherwise sit across separate category pages. It explains the domain, the likely actor class, the market or governance context, and the source material readers should use when comparing signals. Operators, analysts, and governance readers can see how the same domain appears across events, profiles, market shifts, public-source evidence, regional dependencies, and longer-cycle infrastructure decisions over time.
IETF
The log line parsed. The authority to read the connection did not: RFC 9850
RFC 9850 gives diagnostic tools a common way to read TLS connection secrets. The grammar is small; the authority it can transfer is not. A usable key-log record proves neither permission nor safe closure.
IETF
The verifier subscribed. The evidence chain still had seven tests
An IETF draft turns device attestation from a polling exercise into a stream. That is a useful change in tempo, but a signed notification is still only one link between a measurement and a decision.
IETF
Fresh Entropy Entered the Session. Recovery Still Needed Proof in Both Directions
TLS 1.3's ordinary KeyUpdate advances a secret already known to the current chain. The active Internet-Draft for Extended Key Update proposes something stronger: rerun the negotiated key exchange inside a live session and mix fresh input into the next traffic secrets. That can…
CASE FILE
The Parameter Set Verified. The Signing State Did Not: RFC 9858
RFC 9858 gives HSS/LMS implementers more hash and security-strength choices. It does not make the stateful part of a stateful signature disappear. The operational question is therefore not only whether a verifier can parse the new typecodes, but whether the signer can prove that…
Global Cloud Services Trends
Let’s Encrypt’s 99.21% Issuance Share Is Not a Deployment Share
A new IP-certificate study makes concentration visible. Its published analysis also shows why a certificate count cannot stand in for the services that depend on it.
Global Cloud Services Trends
Cloudflare Keeps a Post-Quantum API That No Longer Changes the Setting
Automatic Key Exchange separates algorithm selection from algorithm restrictions. A surviving legacy endpoint no longer controls either in the way its old name suggests.

Asia-Pacific National Telecom
TESS, Docomo test security for solar monitoring
The pilot lets TESS block suspicious SIM traffic remotely while testing how solar monitoring continues when a connection is cut.

Europe and Middle East Institutional Trends
ENISA confirms manual CRA reporting at launch
ENISA's CRA platform launches without an API, so manufacturers must submit mandatory cyber reports through its interface from 11 September.
IETF
A CDN must carry a loop warning it cannot authenticate
A cooperative defence can depend on preserving information that remains untrusted. CDN-Loop exposes the division between a customer's configuration freedom, a provider's protective decision and the evidence needed to explain a failed request.
IETF
A captive portal needs an expiry date for its idea of a device
An address can legitimately pass from one terminal to another. The access system has to retire the old association, not merely recognize the address again. That small distinction connects network admission, accounting and privacy.
IETF
A firewall’s speed belongs to a particular configuration
Two reports can describe the same appliance without showing that its protection and performance were achieved together. The missing connection is often the configuration between the tests.

Global Cloud Services Trends
F5 resolves Global Log Receiver degradation
F5 resolved a Global Log Receiver degradation affecting one customer, while application traffic and Distributed Cloud Console services remained operational.

North America Cloud Services Trends
Cloudflare restores R2 after regional 503 errors
Cloudflare restored R2 in Eastern North America after a roughly three-and-a-half-hour incident caused elevated 503 errors for customers in the region.

Story
ARIN Lets You Name a ROA. Its Online Search Still Ignores the Name
ARIN Lets You Name a ROA. Its Online Search Still Ignores the Name intelligence summary explains the development, the public evidence available to readers, the organisations involved, the regional context, market exposure, and the infrastructure consequences that may follow. The…
IETF
The Meeting Operator Still Chooses What Reaches the Screen
SFrame can keep a conferencing relay out of the conversation's plaintext. It does not take away the relay's choice of which streams and quality layers to forward—or make the first usable picture arrive on time.
CASE FILE
Who Gets to Ask the User to Authenticate Again?
An API can reject a perfectly usable token because the user's authentication does not meet the needs of this particular request. RFC 9470 gives that refusal an interoperable language. It does not settle a more consequential question: who may turn a local risk decision into…
CASE FILE
A Private Address Can Be a Familiar Address
A Wi-Fi identifier can be randomly chosen and remain recognizable for years. RFC 9724 makes that distinction explicit. The managerial question is how much continuity a service needs, within which boundary, and who decides when it ends.

Leaders
Daniel Fett and the Issuer Field That Named the Server, Not the Token
An OAuth callback can contain the right state and a real authorization code and still be on its way to the wrong server. RFC 9207 adds one small comparison before that mistake becomes a disclosure: did the server named in the response match the issuer the client recorded when the…

Story
ARIN Plans ROA Impact Warnings for the Web, Not the API
ARIN is building a warning for the moment before a Route Origin Authorization changes what observed routes look like. The warning belongs to its web interface. The registry’s programmatic writer is still expected to assemble the same evidence elsewhere. That is not a difference…

Story
APNIC’s RDAP Blocked About 10% of Requests for Not Looking Like Browsers
For 18 hours in January, a machine-readable registry protocol lost requests because the software introducing itself at the edge did not resemble a common browser. APNIC’s own incident notice supplies the number and the cause. The harder question is what evidence should stand…
