Topic
Security Automation
Within the Topic facet, Security Automation topic intelligence connects articles that share a specific subject, signal focus, or monitoring theme. The page gives readers a richer path through related reporting, source evidence, market actors, and infrastructure implications, with enough context to understand why the topic matters across company movements, governance decisions, regional exposure, and operational risk. Readers can compare recurring signals, affected organisations, public evidence, market context, service continuity, procurement, competition, compliance, and strategic planning questions behind the subject instead of stopping at a thin list of matching articles. It explains what the topic covers, which infrastructure actors or policies are involved, what evidence supports the coverage, and why the subject may matter for operators, customers, investors, and policy readers.
CASE FILE
The Zone Went Dark. The Resolver Made the Outage Louder
When authoritative DNS stops answering, the first failure belongs to the zone. The next thousand queries may belong to the resolver. RFC 9520 draws a narrow but consequential line between the two: silence is not proof that a name does not exist, yet a resolver that has exhausted…
CASE FILE
The Block Was Explained. The Policy Was Still a Claim.
The night shift sees an authenticated DNS response that says a name was blocked, identifies a policy category and offers a support route. The explanation is orderly, machine-readable and intact. It still does not reveal whether the upstream classification was right, who had…

Global Cloud Services Trends
ServiceNow Repaid Its US$4bn Armis Loan Mainly With Notes Maturing Through 2056
ServiceNow did not make the cost of Armis disappear when it repaid a six-month acquisition loan. It moved most of that funding onto five unsecured note series whose final maturity sits 30 years after the deal closed. That longer clock gives the company time to integrate the…
CASE FILE
The Proof Verified. The Fork Was Still Private.
Every response on Alice’s device verifies. Every later tree head extends the one before it. Across town, Bob sees the same tidy sequence—except his latest head commits to a different key for Alice. The log has not broken either local proof chain. It has separated the witnesses.
CASE FILE
The Handshake Succeeded. The DNS Question Was Already Exposed
RFC 9539 lets a recursive resolver encrypt its next hop to an authoritative server without waiting for the server to advertise a new policy or present a verifiable identity. That modest bargain can hide many DNS questions from passive observers. It also creates an unusually…
CASE FILE
The Certificate Was Fresh. The Number Authority Had Its Own Clock.
A verifier receives a PASSporT with an intact signature, a valid certificate path and a certificate that will expire in hours. Between issuance and the call, however, control of the calling number has changed. The credential can be fresh in the precise X.509 sense while the fact…
CASE FILE
The Tokens Stayed Server-Side. The Browser Still Spent the Session.
The incident review found no exported access token, no stolen refresh token and no readable session cookie. Yet a state-changing request had crossed the Backend for Frontend and reached the protected service. The missing fact was not secret custody. Compromised code had run…

History
The Green Light That Was Not Yours: How NNTP Separated Group Policy from Posting Permission
A news server marks one group `y`, the old shorthand for posting permitted, and still refuses the person at the keyboard. Another group carries `n`, yet a specially privileged client may pass. NNTP did not contradict itself. It made the catalogue describe the group's ordinary…

History
The Address Seen from Outside: What STUN Could Discover but Not Guarantee
When a client behind a Network Address Translator (NAT) seeks to understand its reachable address from the perspective of an external server, it performs a specific exchange: sending a STUN Binding request. This request, originating from a known local address and port, traverses…
CASE FILE
The Certificate Named an Interface. It Did Not Prove the Device.
The commissioning test produced two honest identifiers. The certificate named the factory address of one Wi-Fi interface. The frame arriving at the access point used a private address chosen for that network. Rejecting the connection would punish a real device for using a privacy…

IETF
Brian Carpenter and the Boundary That Needed Proof
A network diagram can draw a clean perimeter around a campus, cloud overlay or industrial system. A packet cannot rely on the ink. Brian Carpenter and Bing Liu's RFC 8799 asks what must replace that intuition when a protocol has meaning only inside: verifiable membership…
CASE FILE
The Timestamp Got Sharper. The Clock Did Not Gain Authority.
Send one NTP request through ordinary UDP port 123 and its arrival may be timestamped after software and queueing have already left fingerprints on the measurement. Wrap the same logical request in a PTP event message, and a compatible network card can timestamp it at the wire.…

History
The Command Authentication Could Not Resume: How NNTP Made the Client Ask Again
An NNTP client asks for a restricted newsgroup and receives `480`. It authenticates successfully, yet the requested group does not open. The command must be sent a second time. That small repetition preserved a consequential boundary: proving an identity could change the…
CASE FILE
The Message Had Expired. The Mailbox Had Not.
At noon, an offer in the inbox reaches the date chosen by its sender. At 12:01, the mail reader dims it. Search still finds it, the archive still holds it, and no deletion has occurred. That small separation is the point of the IETF’s newly approved work on the email `Expires`…

History
The Birth Record That Could Outlive the Group: How ACTIVE.TIMES Separated Provenance from Availability
One list says a newsgroup can be selected now but remembers nothing about its beginning. Another preserves a group's local creation record after that group has disappeared from the selectable catalogue. NNTP made both answers valid on the same server. The apparent contradiction…

ICANN
ICANN Wrote a 24-Hour Disclosure Clock. Authentication Decides When It Starts
The most consequential sentence in ICANN's new urgent-disclosure rules is not the one containing “24 hours.” It sits lower on the same policy page, in an implementation note: the obligations become effective when ICANN fully implements a Consensus Policy that establishes…

History
The Prefix the Resolver Sent on Someone Else’s Behalf: EDNS Client Subnet
A recursive resolver usually speaks to an authoritative server from its own address. EDNS Client Subnet changed the message: the resolver could send part of a client's network instead, asking the authority to tailor an answer for someone who had not made that upstream query. The…

History
The Layer That Had to Come Last: How NNTP Compression Turned Order into Security
Two clients want the same three things: an encrypted channel, an authenticated account and fewer bytes on the wire. One asks for compression first. The server replies `206`, and two doors close: this connection can no longer begin TLS or accept `AUTHINFO`. The other client…

Global Cloud Services Trends
A Code-Signing Certificate Has Two End Dates
A replacement certificate changes tomorrow's build, but a valid timestamp can preserve yesterday's binary beyond the signer's expiry. The real cutover is therefore an inventory of artifacts, timestamp tokens, revocation time and verifier results—not a closed renewal ticket.

History
The Secure Channel That Had to Forget the Conversation: How NNTP STARTTLS Reset the Session
A news client has already inspected a server's capabilities, selected a newsgroup and positioned an article. Then it asks for TLS. The TCP connection stays open, but the protocol refuses to carry those earlier conclusions into the protected phase. The group selection disappears…
