Topic
Security Automation
Within the Topic facet, Security Automation topic intelligence connects articles that share a specific subject, signal focus, or monitoring theme. The page gives readers a richer path through related reporting, source evidence, market actors, and infrastructure implications, with enough context to understand why the topic matters across company movements, governance decisions, regional exposure, and operational risk. Readers can compare recurring signals, affected organisations, public evidence, market context, service continuity, procurement, competition, compliance, and strategic planning questions behind the subject instead of stopping at a thin list of matching articles. It explains what the topic covers, which infrastructure actors or policies are involved, what evidence supports the coverage, and why the subject may matter for operators, customers, investors, and policy readers.

IETF
The App Kept the User Out of the Browser. It Also Entered the Trust Boundary.
OAuth’s proposed Authorization Challenge Endpoint can keep a native first-party journey inside the app. The saved context switch is real. So is the transfer of credential prompts, session continuity and risk routing into a client whose provenance, presentation and installed…

IETF
The Delegation Counter Reached Zero. The Sensing Policy Could Still Have Been Lost.
A depth counter can stop the next handoff while saying nothing about what happened to the rules carried through the earlier ones. In agentic sensing, a finite graph is not yet a compliant chain of authority.

IETF
The Certificate Expires in 9999. Its Document Binding Can Still Go Unchecked.
A one-signature certificate is designed to accompany one document, one private key and one signing operation. Its proposed X.509 extension narrows scope sharply—but ordinary signature success does not prove that a verifier compared the document with that binding, or that the key…

IETF
The Origin Published a Knowledge Map. It Did Not Authorise the Agent to Obey It.
An agent can discover a file, verify its bytes and still have no permission to act on a sentence inside it. The proposed `knowledge-linkset` well-known URI makes that distinction operationally urgent rather than philosophical.

IETF
The Composite Signature Passed. The Envelope Named a Different Algorithm.
Composite ML-DSA combines post-quantum and traditional signatures behind one interface. Its CMS profile shows why that single verdict still depends on several algorithm identifiers, exact encoded bytes and a content digest agreeing across the envelope.

IETF
The Capsule Recorded a Disagreement. It Had No Right to Block Anything.
A new SCITT profile proposes an immutable third-party comparison between what a subject declared and what an observer found. Its most important design choice is not the hash or the Merkle tree, but the refusal to let measurement quietly become authority.

IETF
The Final Filter Was Correct. The Update Still Leaked a Route.
Revision 03 of an IETF GROW draft turns BGP security from a static configuration question into a transaction question. A router may begin and end with the intended policy while briefly enforcing something else between commands.

IETF
The Tool Knew the SID. It Still Did Not Own the Actuator.
CORECONF-M2M proposes a compact route from YANG models and SID identifiers to MCP tools that an AI agent can call. The route can remove bespoke serialization without removing the harder boundary: who may act, what the device accepted and whether the physical world actually…

IETF
The Issuer Signed the Envelope. It Still Could Not Swap the Agent Key.
Revision 02 of the AIC JSON Web Token profile places a principal-signed delegation inside an issuer-signed credential. The nested design matters because an issuer may certify the carrier without acquiring the right to substitute the agent key chosen by the principal.

IETF
The Agent Signed the Challenge. Its Embedded Key Still Wasn't Authority.
OpenA2A AIP revision 03 separates a mathematically valid response from an authenticated agent. The decisive control is not whether the supplied key verifies the signature, but who is entitled to bind that key to the claimed identity.

IETF
The Agent Went Silent. The Trust Score Punished What the Verifier Could Not See.
The proposed Network Behavioral Trust Protocol turns missing heartbeats and co-silence into score decay, SUSPECT and QUARANTINED states. That may be useful operationally, but an absence first describes a verifier's observation surface—not an agent's character.

History
The Customer Saw a Private Wire. The Operator Held the Hidden Address Pair: RFC 3186
At one edge, customer equipment emitted an ordinary PPP frame. At the other, customer equipment received one. Between them, switches replaced the frame’s first octets, forwarded it through a shared MAPOS fabric, restored the original values and withheld the machinery from view.…

IETF
Every Link Verified. The Timeline Could Still Be Shorter.
AER-1 revision 09 gives an AI-agent job a verifiable internal history. Its more important contribution is admitting why that history still needs a witness outside itself.

History
The Recipient List Shrunk. The Old Key Still Opened the Message: RFC 3185
The second encrypted message named fewer recipients than the first. One omitted member could still open it. Nothing had malfunctioned: RFC 3185 warned that this was the expected consequence of deriving a later key-encryption key from content-key material already delivered to the…

IETF
The Key Changed. The Instance Stayed the Same Because Someone Kept the Ledger.
OAuth attestation can prove that a client instance holds a current key. A new profile tries to preserve that instance's identity when the key changes. The continuity does not live in the identifier string: it lives in an attester's enrollment records, lifecycle rules and custody…

History
The Domain Signed the Message. The Individual Was Still Unnamed: RFC 3183
A recipient could verify that a message had crossed an authenticated organizational boundary and still be unable to display the name of the person who sent it. RFC 3183 made that distinction unusually explicit. Its domain-security machinery did not offer one generic act called…

IETF
The Chain Proved a Clock Was Wrong. It Did Not Name the Culprit.
Roughtime can seal an inconsistency into portable evidence without pretending that cryptography has already decided whom to distrust.

IETF
The ICV Was Valid. The Path Record Could Still Be False.
IOAM can carry a cumulative integrity chain across the network and let a Validator confirm that protected fields were not modified. That is valuable evidence. It is not the same as proving that every expected record arrived, every participating node told the truth, or the…

IETF
No One Reported Progress. Why Did the Task Look Complete?
A task with entities but no progress reports should preserve the absence of evidence, not turn an empty column into a green completion state.

IETF
The Controller Reported Both Directions Done. The Network Had Not Proved Hitless
Fine-grain optical transport can change a low-rate service’s bandwidth without a planned interruption. Yet the green completion event at the multi-domain coordinator is only one controller’s conclusion. It is not a receipt for every direction, domain, protection path, tributary…
