Skip to main content

Topic

Security Automation

Within the Topic facet, Security Automation topic intelligence connects articles that share a specific subject, signal focus, or monitoring theme. The page gives readers a richer path through related reporting, source evidence, market actors, and infrastructure implications, with enough context to understand why the topic matters across company movements, governance decisions, regional exposure, and operational risk. Readers can compare recurring signals, affected organisations, public evidence, market context, service continuity, procurement, competition, compliance, and strategic planning questions behind the subject instead of stopping at a thin list of matching articles. It explains what the topic covers, which infrastructure actors or policies are involved, what evidence supports the coverage, and why the subject may matter for operators, customers, investors, and policy readers.

CASE FILE

The Zone Went Dark. The Resolver Made the Outage Louder

When authoritative DNS stops answering, the first failure belongs to the zone. The next thousand queries may belong to the resolver. RFC 9520 draws a narrow but consequential line between the two: silence is not proof that a name does not exist, yet a resolver that has exhausted…

Aug 28, 2026

CASE FILE

The Block Was Explained. The Policy Was Still a Claim.

The night shift sees an authenticated DNS response that says a name was blocked, identifies a policy category and offers a support route. The explanation is orderly, machine-readable and intact. It still does not reveal whether the upstream classification was right, who had…

Aug 28, 2026
Five copper-lit capital conduits of different lengths extend from a central security-workflow core reached by a short bridge.

Global Cloud Services Trends

ServiceNow Repaid Its US$4bn Armis Loan Mainly With Notes Maturing Through 2056

ServiceNow did not make the cost of Armis disappear when it repaid a six-month acquisition loan. It moved most of that funding onto five unsecured note series whose final maturity sits 30 years after the deal closed. That longer clock gives the company time to integrate the…

Aug 28, 2026

CASE FILE

The Proof Verified. The Fork Was Still Private.

Every response on Alice’s device verifies. Every later tree head extends the one before it. Across town, Bob sees the same tidy sequence—except his latest head commits to a different key for Alice. The log has not broken either local proof chain. It has separated the witnesses.

Aug 28, 2026

CASE FILE

The Handshake Succeeded. The DNS Question Was Already Exposed

RFC 9539 lets a recursive resolver encrypt its next hop to an authoritative server without waiting for the server to advertise a new policy or present a verifiable identity. That modest bargain can hide many DNS questions from passive observers. It also creates an unusually…

Aug 28, 2026

CASE FILE

The Certificate Was Fresh. The Number Authority Had Its Own Clock.

A verifier receives a PASSporT with an intact signature, a valid certificate path and a certificate that will expire in hours. Between issuance and the call, however, control of the calling number has changed. The credential can be fresh in the precise X.509 sense while the fact…

Aug 28, 2026

CASE FILE

The Tokens Stayed Server-Side. The Browser Still Spent the Session.

The incident review found no exported access token, no stolen refresh token and no readable session cookie. Yet a state-changing request had crossed the Backend for Frontend and reached the protected service. The missing fact was not secret custody. Compromised code had run…

Aug 28, 2026
Two early network terminals sit below green, red and amber catalogue lights, while separate brass gates show that group status and client permission are different decisions.

History

The Green Light That Was Not Yours: How NNTP Separated Group Policy from Posting Permission

A news server marks one group `y`, the old shorthand for posting permitted, and still refuses the person at the keyboard. Another group carries `n`, yet a specially privileged client may pass. NNTP did not contradict itself. It made the catalogue describe the group's ordinary…

Aug 28, 2026
A conceptual diagram showing a client's STUN Binding Request packet passing through a NAT, which changes the source address, before reaching a STUN server. The server's response packet travels back, containing the observed public IP and port in the XOR-MAPPED-ADDRESS attribute.

History

The Address Seen from Outside: What STUN Could Discover but Not Guarantee

When a client behind a Network Address Translator (NAT) seeks to understand its reachable address from the perspective of an external server, it performs a specific exchange: sending a STUN Binding request. This request, originating from a known local address and port, traverses…

Aug 28, 2026

CASE FILE

The Certificate Named an Interface. It Did Not Prove the Device.

The commissioning test produced two honest identifiers. The certificate named the factory address of one Wi-Fi interface. The frame arriving at the access point used a private address chosen for that network. Rejecting the connection would punish a real device for using a privacy…

Aug 28, 2026
AI editorial portrait of Brian Carpenter beside nested network domains, verified member nodes and a controlled outbound path.

IETF

Brian Carpenter and the Boundary That Needed Proof

A network diagram can draw a clean perimeter around a campus, cloud overlay or industrial system. A packet cannot rely on the ink. Brian Carpenter and Bing Liu's RFC 8799 asks what must replace that intuition when a protocol has meaning only inside: verifiable membership…

Aug 28, 2026

CASE FILE

The Timestamp Got Sharper. The Clock Did Not Gain Authority.

Send one NTP request through ordinary UDP port 123 and its arrival may be timestamped after software and queueing have already left fingerprints on the measurement. Wrap the same logical request in a PTP event message, and a compatible network card can timestamp it at the wire.…

Aug 28, 2026
A brass-and-glass relay machine shows one blank command card stopped at an amber gate and a separate new card passing after an identity checkpoint toward a news archive.

History

The Command Authentication Could Not Resume: How NNTP Made the Client Ask Again

An NNTP client asks for a restricted newsgroup and receives `480`. It authenticates successfully, yet the requested group does not open. The command must be sent a second time. That small repetition preserved a consequential boundary: proving an identity could change the…

Aug 28, 2026

CASE FILE

The Message Had Expired. The Mailbox Had Not.

At noon, an offer in the inbox reaches the date chosen by its sender. At 12:01, the mail reader dims it. Search still finds it, the archive still holds it, and no deletion has occurred. That small separation is the point of the IETF’s newly approved work on the email `Expires`…

Aug 28, 2026
A cyan live catalogue and an amber history archive show opposite gaps: a current triangular group lacks a retained record, while an archived crescent aligns to an empty live bay.

History

The Birth Record That Could Outlive the Group: How ACTIVE.TIMES Separated Provenance from Availability

One list says a newsgroup can be selected now but remembers nothing about its beginning. Another preserves a group's local creation record after that group has disappeared from the selectable catalogue. NNTP made both answers valid on the same server. The apparent contradiction…

Aug 28, 2026
An unnumbered clock mechanism pauses at a luminous verification gate before the path divides into several independent decision chambers.

ICANN

ICANN Wrote a 24-Hour Disclosure Clock. Authentication Decides When It Starts

The most consequential sentence in ICANN's new urgent-disclosure rules is not the one containing “24 hours.” It sits lower on the same policy page, in an implementation note: the obligations become effective when ICANN fully implements a Consensus Policy that establishes…

Aug 28, 2026
EDNS Client Subnet diagram showing a recursive resolver sending a truncated client-network prefix to an authoritative DNS server, whose returned scope partitions cached answers for later clients.

History

The Prefix the Resolver Sent on Someone Else’s Behalf: EDNS Client Subnet

A recursive resolver usually speaks to an authoritative server from its own address. EDNS Client Subnet changed the message: the resolver could send part of a client's network instead, asking the authority to tailor an answer for someone who had not made that upstream query. The…

Aug 28, 2026
Two protocol conduits show opposite orders: the successful path passes through a blue protection tunnel, an amber identity seal and compression rollers, while compression-first is blocked from the later stations.

History

The Layer That Had to Come Last: How NNTP Compression Turned Order into Security

Two clients want the same three things: an encrypted channel, an authenticated account and fewer bytes on the wire. One asks for compression first. The server replies `206`, and two doors close: this connection can no longer begin TLS or accept `AUTHINFO`. The other client…

Aug 28, 2026
Two timestamped software artifacts cross a verification boundary into mirrors, update systems and endpoint devices.

Global Cloud Services Trends

A Code-Signing Certificate Has Two End Dates

A replacement certificate changes tomorrow's build, but a valid timestamp can preserve yesterday's binary beyond the signer's expiry. The real cutover is therefore an inventory of artifacts, timestamp tokens, revocation time and verifier results—not a closed renewal ticket.

Aug 28, 2026
One continuous conduit crosses a transparent TLS chamber while old state tiles stop at the boundary, a fresh capability set appears beyond it and a credential waits at a separate authentication checkpoint.

History

The Secure Channel That Had to Forget the Conversation: How NNTP STARTTLS Reset the Session

A news client has already inspected a server's capabilities, selected a newsgroup and positioned an article. Then it asks for TLS. The TCP connection stays open, but the protocol refuses to carry those earlier conclusions into the protected phase. The group selection disappears…

Aug 28, 2026