Topic
Security Automation
Within the Topic facet, Security Automation topic intelligence connects articles that share a specific subject, signal focus, or monitoring theme. The page gives readers a richer path through related reporting, source evidence, market actors, and infrastructure implications, with enough context to understand why the topic matters across company movements, governance decisions, regional exposure, and operational risk. Readers can compare recurring signals, affected organisations, public evidence, market context, service continuity, procurement, competition, compliance, and strategic planning questions behind the subject instead of stopping at a thin list of matching articles. It explains what the topic covers, which infrastructure actors or policies are involved, what evidence supports the coverage, and why the subject may matter for operators, customers, investors, and policy readers.
CASE FILE
The Route Reflector Hid the Choice: BGP ADD-PATH and the Authority to Expose Alternatives
A route reflector can make a large network easier to operate by showing each client only the route it selected. That economy also removes choices. ADD-PATH creates a way to carry several paths for one prefix, but the protocol does not decide which alternatives deserve exposure…
CASE FILE
The Route Was Valid. The Reflector Called It a Loop: BGP Cluster IDs and the Authority to Discard Reachability
Every BGP session was Established. The customer prefix was valid at its source. Yet a regional reflector refused the route because a four-octet value in `CLUSTER_LIST` matched its own. The protocol had done exactly what it was told: an identity meant to stop loops had been reused…
CASE FILE
The Policy Changed; the Routes Did Not: BGP Route Refresh and Re-evaluation Authority
Editing an inbound BGP policy changes a rule, not the routes already judged under the old one. To apply the new rule, a router needs the inputs again. Route Refresh lets it ask a capable neighbor to re-advertise the neighbor's current export set without destroying the session—but…
CASE FILE
The Route Carried a Request, Not a Restraint: BGP NO_EXPORT and the Authority to Propagate
A route can arrive carrying `NO_EXPORT`, a name that sounds like a lock. It is nothing of the kind. The community tells a receiving network where the route is meant to stop, but the receiver's running policy still decides whether the value survives and whether the route leaves…
CASE FILE
The Neighbor Suggested a Door; We Chose Whether to Enter: BGP MED and Advisory Authority
The Neighbor Suggested a Door; We Chose Whether to Enter: BGP MED and Advisory Authority intelligence summary explains the development, the public evidence available to readers, the organisations involved, the regional context, market exposure, and the infrastructure consequences…
CASE FILE
The Route Chose Three Times, the Neighbor Heard Once: BGP MRAI and Temporal Authority
A BGP router can change its mind several times while saying nothing new to one neighbor. The silence is not indecision. MRAI deliberately separates local route selection from external disclosure, trading the peer's freshest possible view for bounded UPDATE traffic and processing…
CASE FILE
The Server That Remembered Nothing: SYN Cookies and Stateless Admission
A listening server usually spends memory after the first knock and before it knows whether anyone can hear the answer. A SYN cookie changes that order. The server places a compact receipt for the unfinished connection inside its own sequence number, then waits for the requester…
CASE FILE
The Key Installed Twice: KRACK and the Authority of a Retransmission
Wireless loss made retransmission necessary. KRACK exposed the hidden assumption that arrived with it: an authentic copy of a handshake message could be treated as fresh authority to install an already-active key. The password held. The key stayed secret. The state around the key…
CASE FILE
The Failure That Chose the Cipher: POODLE and the Authority Hidden in Fallback
A failed TLS handshake should have been evidence of one thing: this connection attempt did not work. Compatibility code turned it into a much larger claim - that the server needed an older protocol. POODLE showed what happens when an attacker who can cause failure is also allowed…
CASE FILE
The Header That Became a Program: Shellshock and the Authority Hidden in an Environment
Shellshock did not require an exotic packet or a new network protocol. It needed two familiar interfaces to compose badly: one that placed remote request data in a process environment, and one that treated a specially shaped environment value as code. The incident remains a hard…
CASE FILE
The Patch Had Six Months. Slammer Needed Ten Minutes.
On 25 January 2003, the useful unit of incident response stopped being the working day. A 376-byte program could arrive in one UDP datagram, seize an unpatched database service and begin sending copies without waiting for a reply. The repair had already been published. The…
CASE FILE
The Cache That Answered 51,000 Times: Memcached and the Bandwidth Nobody Meant to Delegate
A reflector attack begins with a peculiar transfer of authority: one machine lies about who asked, another machine believes the return address, and a third party pays for the answer. In February 2018, public memcached servers made that transfer large enough to move GitHub's…

Creators
Jakub Kicinski: How Linux makes network features supportable
A new network card can arrive with an impressive capability and a commercial deadline. Linux has to ask a slower question: can the feature be expressed in a way that other hardware can understand, operators can observe, tests can reproduce and maintainers can still support years…
CASE FILE
The Answer That Won the Race: Kaminsky's DNS Poisoning and the Entropy Behind Trust
The dangerous answer did not need a signature or a privileged route; it only had to resemble one outstanding question closely enough and arrive first. The 2008 DNS crisis turned that narrow acceptance rule into a renewable race—and showed why a patch can buy safety without…
CASE FILE
The Rule That Reached Every Edge Before Anyone Priced It: Cloudflare's 2019 WAF Outage
Cloudflare's distributor needed seconds to place one approved security rule around the world; the incident lasted because approval had established what the rule should catch, not how much computation every request could make it consume.

Global Institutional
NTT DATA, Palo Alto set US$1bn alliance target
NTT DATA and Palo Alto Networks are expanding joint engineering and managed security services under a global alliance targeting US$1bn in business by 2029.
CASE FILE
The Page That Borrowed Another Customer's Memory: Cloudbleed and the Boundary of a Shared Edge
A malformed page triggered Cloudflare's parser, but the escaped bytes could belong to somebody else entirely; Cloudbleed showed that stopping a leak and recovering what had already crossed the boundary are different acts of control.
CASE FILE
The Certificate That Was Valid for the Wrong Job: Flame and the Authority Hidden in Purpose
The Flame malware did not need Microsoft's root private key. It found a licensing certificate path whose mathematics, issuance habits and inherited trust could be rearranged into software-signing authority.
CASE FILE
The Request That Vanished but Kept Working: What Rapid Reset Revealed About Cancellation
HTTP/2 let a client withdraw one request without closing the connection; Rapid Reset exposed the moment when that valid cancellation stopped being a courtesy and became an unlimited claim on somebody else’s queues.
CASE FILE
The Patch That Could Not Retire a Key: Debian's OpenSSL Entropy Failure and the Afterlife of Weak Credentials
The repaired library stopped minting predictable keys. It did not find the old ones, remove them from remote authorization files, revoke their certificates or persuade a single relying party to refuse them.
