Topic
Security Automation
Within the Topic facet, Security Automation topic intelligence connects articles that share a specific subject, signal focus, or monitoring theme. The page gives readers a richer path through related reporting, source evidence, market actors, and infrastructure implications, with enough context to understand why the topic matters across company movements, governance decisions, regional exposure, and operational risk. Readers can compare recurring signals, affected organisations, public evidence, market context, service continuity, procurement, competition, compliance, and strategic planning questions behind the subject instead of stopping at a thin list of matching articles. It explains what the topic covers, which infrastructure actors or policies are involved, what evidence supports the coverage, and why the subject may matter for operators, customers, investors, and policy readers.

Story
RIPE NCC's New CTO Inherits a €12.2m Estimate, Not a Mandate
Sjoerd Wolthers becomes RIPE NCC's permanent chief technology officer on 1 September. The appointment settles who will lead the technology function. It does not settle a separate question left open in the latest public Board minutes: whether, how and on what evidence RIPE NCC…
CASE FILE
The Token Was Bound to a Key. The Action Was Still Unauthorized: DPoP and the Authority of a Sender Constraint
DPoP can stop a copied OAuth token from becoming a portable credential. It cannot decide whether the key holder is the right client, whether the token still carries the right audience and scope, or whether today's resource state permits the requested effect.

History
The Mask Was Public. The Bytes Were Not Predictable: How WebSocket Protected Old Proxies
A WebSocket client places its 32-bit masking key beside the payload it disguises. The server can reverse the operation immediately, and so can anyone watching the path. That apparent contradiction reveals the rule's real purpose: the key was not meant to hide a message. It was…

Global Cloud Services Trends
Zscaler Had No 10% Revenue Customer. One Partner Held 12% of Receivables
Zscaler’s latest filing draws two concentration maps over the same quarter. On the revenue map, no customer reached the 10% reporting line. On the collection map, one anonymous channel partner held 12% of net accounts receivable. Neither number is alarming on its own. Together…

Story
LACNIC's Four-Vendor BGP Claim Needs the Configuration Column
One malformed Prefix-SID attribute reportedly met three different actions as it crossed the Internet: discard, propagation and session reset. LACNIC's new routing-security article makes the divergence visible. To make it reproducible, the comparison now needs to name the release…
CASE FILE
The Error Returned as a New Question: DNS Report-Channel and the Authority of Feedback
An authoritative server can announce where it wants to hear about failures it cannot see. It cannot make a resolver diagnose, report or believe anything. DNS Error Reporting turns one local validation failure into a second DNS query, then leaves transport, caching and human…

Story
At ARIN, Resource-Level Tech Authority Stops Before the ROA
ARIN's records can give a Technical Point of Contact authority over one network resource while routing-security actions remain organized around the containing organization. A newly confirmed suggestion asks ARIN to bridge that gap. The hard part is not adding another permission…
CASE FILE
The Signature Verified. The Command Was Still Unauthorized: HTTP Message Signatures and the Authority of Covered Components
RFC 9421 can prove that selected parts of an HTTP message survived in a defined semantic form. It cannot decide whether the signer was entitled to issue the command, whether an omitted field changed its meaning, or whether a valid request has already been used.
CASE FILE
The Packet Hid Its Exact Length. The Pattern Still Spoke: EDNS Padding and the Limits of DNS Privacy
An encrypted DNS message can conceal its names and answers while leaving a surprisingly useful silhouette. EDNS Padding changes that silhouette by adding bytes. The difficult question is not whether the packet became larger, but whether client, server, transport and path made…
CASE FILE
The Record Bound the Options. The Client Still Chose the Connection: DNS SVCB, HTTPS and Service Authority
A domain owner can authenticate a list of preferred endpoints, protocols and connection parameters before the first application exchange. That does not make the first preference a command, turn a routing target into the origin, or prove which path a real client can securely…
CASE FILE
The Counter Hit Its Ceiling. The Filename Opened a New Epoch: RPKI Manifests and Recovery Authority
A correctly signed RPKI manifest can become unusable because a relying party remembers an impossible predecessor. RFC 9981 gives the issuer a narrow way out: change the manifest filename, start a new comparison epoch and preserve every other freshness, location and integrity…
CASE FILE
The Feed Was Valid. The Answer Was Local: DNS Response Policy Zones and the Authority to Rewrite Resolution
An authenticated threat feed can tell a resolver what a publisher recommends. It cannot decide which users lose a name, whether the answer should disappear or be replaced, or who owns the damage when a correct transfer produces the wrong operational result.
CASE FILE
The Digest Matched. The Zone Was Still Wrong: ZONEMD and the Limits of Cryptographic Integrity
A whole-zone checksum can expose truncation, corruption and substitution. It can also authenticate a mistake with perfect precision. The decision for infrastructure leaders is not whether to trust cryptography, but how narrowly to interpret what it has proved.
CASE FILE
The Signal Was Signed. The Delegation Was Not Yet Secure: CDS/CDNSKEY and the Authority to Publish DS
A child zone can publish a perfectly signed request for a new DNSSEC secure entry point and still lack the one chain that would validate it. CDS/CDNSKEY makes parent coordination machine-readable; it does not collapse operational control, registrant authority, parent admission…
CASE FILE
The Catalog Was Valid. The Deletion Was Not: DNS Catalog Zones and the Authority to Provision
An authenticated DNS transfer can deliver a perfectly formed catalog whose operational consequence is to remove every zone from a secondary fleet. The transport may be trustworthy and the syntax impeccable while the decision encoded inside it is still wrong. DNS Catalog Zones…
CASE FILE
The Answer Had Expired. The Failure Had Not: DNS Serve-Stale and the Authority Beyond TTL
A DNS answer can outlive its ordinary freshness without becoming current again. Serve-stale is the resolver's narrow authority to prefer a known old answer over a fresh failure, but only after the source has been consulted, the failure has been bounded and the age of the…

Story
AFRINIC’s Trust Anchor Still Runs to 2030. The NRO Roadmap Said “Short-Lived” by the End of 2025
A roadmap can name a destination and a date. It cannot prove that a live trust anchor has crossed the line. AFRINIC’s retrievable certificate shows why RPKI commitments need an implementation receipt rather than a silently ageing table.

North America Cloud Services Trends
US$127.9m of Varonis's SaaS ARR Sits in the Conversion Layer
Varonis ended June with US$726.0 million of SaaS ARR, up 52%. Strip out contracts moved from its self-hosted base and the balance was US$598.1 million, growing 25%. Both figures are valid; they measure different engines.

North America Institutional Trends
Axon's $15.1bn Contracted-Bookings Headline Includes $5.3bn Outside GAAP RPO
Axon ended June with two views of future business. Its broad operational ledger held $15.1 billion; the accounting ledger held about $9.8 billion. The $5.3 billion difference is not a rounding error or hidden revenue. It is the price of admitting different kinds of commercial…

North America Cloud Services Trends
Rapid7 Is Cutting Costs Against a Shrinking ARR Base
Rapid7 can make its adjusted operating result improve before its recurring-revenue engine does. The company is cutting roughly 12% of its workforce, guiding to higher non-GAAP operating income, and expecting ARR to fall again. Those statements are not contradictory. They belong…
