Skip to main content

Topic

Security Automation

Within the Topic facet, Security Automation topic intelligence connects articles that share a specific subject, signal focus, or monitoring theme. The page gives readers a richer path through related reporting, source evidence, market actors, and infrastructure implications, with enough context to understand why the topic matters across company movements, governance decisions, regional exposure, and operational risk. Readers can compare recurring signals, affected organisations, public evidence, market context, service continuity, procurement, competition, compliance, and strategic planning questions behind the subject instead of stopping at a thin list of matching articles. It explains what the topic covers, which infrastructure actors or policies are involved, what evidence supports the coverage, and why the subject may matter for operators, customers, investors, and policy readers.

A single employee workstation sits inside a closed translucent boundary while an irregular stream of blank file-like sheets fades outside it; an intact enterprise and retail network remains separate in the background.

North America Institutional Trends

Five Below Bounded Its Cyber Incident to One Employee Environment. The File Risk Remains Open

Five Below’s July disclosure draws a sharp line around the machine that was reached and a much softer line around the information that left it. The retailer said social engineering enabled access to one employee’s company computer, that the access was contained, and that no other…

Aug 31, 2026
Russ Housley in an AI editorial portrait beside separate certificate, six- and eight-octet address, Layer 2 and local authorization planes.

IETF

Russ Housley and the MAC Address a Certificate Could Name but Not Make Unique

Six bytes can fit cleanly inside a certificate. The difficult part begins after they leave it: who assigned them, what interface is using them now, who observed that use, and why a local network should permit an action.

Aug 31, 2026
Editorial image of one domain signal splitting into amber and blue validation paths, with alias nodes and a pruning gate before one blank certificate endpoint.

CASE FILE

SC101 Closes a Domain-Control Gap. The Transition Still Permits Two Rulebooks

A certificate authority can now point to one current set of TLS Baseline Requirements while legitimately running one of two different domain-control derivation rules. SC101 made the safer order explicit: choose the validation method, follow a permitted CNAME path, then prune…

Aug 31, 2026
An early-1980s parsing bench holds one long amber Ethernet carrier containing a shorter blue IPv4 datagram that stops before a row of blank ivory padding cells; separate trays accept the inner object and inspect the suffix.

History

The Frame Was Longer Than the Datagram: How RFC 894 Kept Ethernet Padding Out of IP

An Ethernet interface could deliver 46 data octets even when the IPv4 datagram inside it ended sooner. RFC 894 did not resolve the mismatch by stretching IP. It assigned two rulers to two layers: Ethernet supplied enough zeroes to satisfy its physical minimum, while the IP Total…

Aug 31, 2026

CASE FILE

The Label Named the Encoding. It Did Not Name the Schema: RFC 9996 and Authority Behind a Protobuf Payload

A gateway accepts `application/protobuf`, the decoder returns a message value, and the request enters the business system. None of those successes establishes that the receiver used the producer's intended message definition. RFC 9996 gives Protocol Buffers a proper outer label.…

Aug 31, 2026

CASE FILE

The Envelope Signed the Digest. It Did Not Deliver the Preimage: RFC 9995 and the Authority Behind a COSE Hash Envelope

A release gate receives a valid signature over the digest of an SBOM. The envelope is small, the cryptography checks out, and the signed location points to a repository. Yet the SBOM itself is absent. Nothing has been downloaded, compared, parsed or judged. RFC 9995 makes the…

Aug 31, 2026
An archive passes an empty glass verification cradle into a compiler while its detached signature foil and public-key ring remain beside the release platform.

Story

LACNIC’s FORT Guide Skips the Signature Published Beside Its Tarball

The guide checks the validator after installation. It never checks the archive before extraction, even though the release already offered a digest, a detached signature and a public keyring.

Aug 31, 2026
Aaron Parecki in an AI editorial portrait beside a browser session path, server-held tokens and a constrained BFF route to a resource gate.

IETF

Aaron Parecki and the BFF That Stops Token Theft but Not Client Hijacking

Putting OAuth tokens behind a server is a material security improvement. It is not the end of the authorization story. RFC 10017 shows why: malicious browser code may be unable to steal a token and still be able to spend the user’s live session through the same Backend for…

Aug 31, 2026
An early-1980s network scene shows a broken satellite path above a single narrow maintenance detour, where a dual-interface host swaps abstract header blocks in both directions over one shared line with two subaddress sockets.

History

The Back Door Was Not a Route: How RFC 831 Reached a Partitioned SATNET

The emergency machine was allowed to behave like a gateway, but it was forbidden to become one. That distinction carried the whole proposal in RFC 831. A multihomed host at UCL could rewrite a chosen maintenance exchange around a broken SATNET path, yet it would send no routing…

Aug 31, 2026
Hannes Tschofenig in an AI editorial portrait beside separate component-authority and enclosing-token signature layers.

IETF

Hannes Tschofenig and the Authority ID That Was Not the Token Signer

A measured component can name the key that signed its firmware and still say nothing about the key that signed the enclosing attestation token. RFC 10013 makes that boundary explicit. The identifier, the measurement, the EAT signature and the relying party’s decision are four…

Aug 31, 2026
Two glass inspection frames examine one registry process: policy tickets on one side and layered system controls on the other, beneath an unfinished control layer.

Story

ARIN's Two Audit Findings Sound Opposite. They Test Different Controls

One ARIN Board record says no audited ticket was out of policy; another says inconsistencies appeared in every area examined. The difference is not a proven reversal in performance. It is a warning that audit findings become misleading when the test, standard and denominator are…

Aug 31, 2026
An editorial workbench contrasts one individually slotted route-authorization tile with a removable tray holding an entire interconnected set, against a subtle map of Latin America and the Caribbean.

Story

LACNIC Calls Postman Its Current API. The Website Still Says ROAs Change by Serial Number

LACNIC gives an API operator two public descriptions of the same control surface. Its Registration API page says Postman holds the most current v3 documentation, while the route table beside that instruction describes modifying or removing one ROA by `serialNumber`. Follow the…

Aug 31, 2026
Corey Bonnell in an AI editorial portrait beside two certified-key paths, only one passing an explicit CRL-signing authorization gate.

IETF

Corey Bonnell and the CRL Signature Whose Key Was Not Authorized

A certificate revocation list can carry a flawless digital signature and still be signed by the wrong certified key. RFC 10007 closes that uncomfortable gap by requiring a version 3 CRL issuer certificate to say, explicitly, that its key may sign CRLs. The change turns a skipped…

Aug 30, 2026

CASE FILE

The Number Named the Enterprise. It Did Not Authenticate the Model: RFC 9997 and Authority Inside a Private SID Block

A network controller receives the integer key it expected, from the numerical territory associated with the vendor it expected. That is enough to avoid a collision. It is not enough to know who made the mapping, which model the integer denotes, or whether the device in front of…

Aug 30, 2026

CASE FILE

Yesterday’s Path Lent the New Flow Its Window. It Did Not Lend Its Capacity: RFC 9959 and the Authority to Reuse Congestion State

A service remembers that yesterday’s connection filled a long, fast path, so today’s connection starts with more confidence than an ordinary new flow. The gain can be real. So can the queue it creates when the same address now reaches another server, route or bottleneck. RFC 9959…

Aug 30, 2026
A large parent network block and smaller child NET joined by three distinct teal and amber paths, a glass boundary and a glowing verification checkpoint.

Story

ARIN's NET Permissions Change With the Lookup Path

One child NET, three ways to identify it, and three different questions about authority. An ARIN community suggestion reported that a direct registrant could reclaim a Detailed Reassignment and retrieve it through an exact address range, but could not use the same API key to GET…

Aug 30, 2026
Eliot Lear in an AI editorial portrait beside separate device-signal, recommendation, enforcement and observed-traffic layers.

IETF

Eliot Lear and the Device Policy That Was Never an Attestation

A limited-purpose device can tell a network which communications it needs without proving what the device is, who currently controls it, or whether it will behave as described. RFC 8520 makes that narrow statement useful through Manufacturer Usage Description, then leaves the…

Aug 30, 2026
Tero Kivinen in an AI editorial portrait beside a dim outgoing control plane, a luminous successor and several uninterrupted abstract data paths.

IETF

Tero Kivinen and the New IKE SA That Inherited Live Child SAs

In IKEv2, the word “rekey” can describe two materially different successions. Replacing the protected control association creates a new IKE SA, yet the Child SAs carrying ESP or AH traffic can remain exactly the ones already in service. The distinction documented in RFC 7296…

Aug 30, 2026

CASE FILE

The Collection Held Every Evidence Item. It Had Not Bound Them to One Machine: RFC 9999 and the Composite Attestation Boundary

A verifier can receive a neat package labelled CPU, SmartNIC and GPU, decode every member and validate several signatures. None of those facts alone proves that the three reports describe the machine requesting access now. RFC 9999 makes remote-attestation messages portable; it…

Aug 30, 2026

CASE FILE

The Envelope Named the Evidence. It Did Not Bind the Device: RFC 9999 and the Authority Inside an Attestation Collection

A server can present signed reports from its CPU, SmartNIC and accelerator in one neat package. The package may be well typed, easy to route and validly encoded while still failing the question that matters: do all three reports describe this device, in this appraisal, under one…

Aug 30, 2026