Topic
Security Automation
Within the Topic facet, Security Automation topic intelligence connects articles that share a specific subject, signal focus, or monitoring theme. The page gives readers a richer path through related reporting, source evidence, market actors, and infrastructure implications, with enough context to understand why the topic matters across company movements, governance decisions, regional exposure, and operational risk. Readers can compare recurring signals, affected organisations, public evidence, market context, service continuity, procurement, competition, compliance, and strategic planning questions behind the subject instead of stopping at a thin list of matching articles. It explains what the topic covers, which infrastructure actors or policies are involved, what evidence supports the coverage, and why the subject may matter for operators, customers, investors, and policy readers.
CASE FILE
The Key Became Portable. Custody Did Not: RFC 9964, ML-DSA and the AKP Boundary
Post-quantum migration often arrives in a deceptively tidy form: choose a new algorithm, register an identifier, put a key in the familiar container, and continue signing. RFC 9964 does something more useful and more limited. It defines how ML-DSA keys and signatures can travel…
CASE FILE
A Completed SCIM Request Is Not a Completed Cross-Domain Decision: RFC 9967
An asynchronous identity request is easy to over-read. A provider accepts a SCIM change, returns 202, and later emits a Security Event Token that carries the same transaction value. The trail is valuable: it gives two parties something specific to correlate. But it does not…
CASE FILE
The Legacy Code Point Reached the Client. It Did Not Reauthorise the Server: RFC 9963
An IANA code point can look like a broad permission slip when it appears in a migration review. RFC 9963 is deliberately narrower. It gives TLS 1.3 three legacy RSASSA-PKCS1-v1_5 signature values, but only for a client proving possession of a client-certificate key after a server…
CASE FILE
The Reverse Socket Arrived. The Device Had Not Yet Identified Itself: RFC 10011 and RESTCONF Call Home
A controller can receive a connection from the direction it expected, on a listener it deliberately opened, after a device has been configured to call home. That is useful evidence. It is not yet the same thing as knowing which device has arrived, establishing a RESTCONF session…

North America Cloud Services Trends
CrowdStrike Disclosed US$2.9bn Beyond Its US$4.1bn Purchase Table
CrowdStrike's purchase-obligation note contains a number that does not belong to the date printed above its table. At 31 July 2026 the table totalled US$4.141527 billion. After quarter-end, the company committed to an additional US$2.9 billion, running from fiscal 2027 to fiscal…

CASE FILE
W3C’s WebAppSec Charter Draft Gives 16 of 17 Deliverables No Completion Date
W3C’s proposed Web Application Security charter is unusually candid about time: almost every normative deliverable says its expected completion is undetermined. That is not evidence that sixteen specifications are late. It is evidence that the charter maps authority better than…
CASE FILE
The Quantum-Safe Key Was Added. The Classical Recipient Still Opened the Mail: RFC 9980
RFC 9980 gives OpenPGP a post-quantum vocabulary, including composite encryption keys that combine ML-KEM with X25519 or X448. That is an important interoperability step. It is also easy to overstate. A message can carry a genuinely PQ/T-capable recipient key and still be…
CASE FILE
The Model Could Explain the Network. It Could Not Authorize the Change: NEMOPS and the Boundary Between Visibility and Control
The NEMOPS workshop report asks for better models, observability, tooling and verification in network management. Those are valuable improvements in what an operator can see and test. They do not decide whose service may be changed, which risk is acceptable, or who bears the cost…
CASE FILE
The Fast Packet Kept the Session Up. It Did Not Authorise the Change: RFC 9985
RFC 9985 offers a disciplined answer to an awkward operational fact: a protocol can need frequent authenticated liveness packets at a rate that makes identical expensive authentication hard to sustain. Its answer is a split, not a blank cheque. Stronger-in-cost authentication…

IETF
Bas Westerbaan and the Hybrid TLS Handshake That Did Not Make the Certificate Post-Quantum
A browser can report `X25519MLKEM768`, derive a session secret from classical and post-quantum components, and still authenticate the server with a classical certificate signature. Both observations can be true in the same TLS 1.3 connection. Calling the whole service…
CASE FILE
An OAM Requirement Was Written Down. It Did Not Prove a Working Diagnostic: RFC 9974 and BIER Evidence
A requirements catalogue can sharpen an engineering question. It cannot, on its own, answer whether a particular network can run the test, what the test observed, or who may act on it.
CASE FILE
The Signed Time Saved a Transfer. It Did Not Prove a Moment: RPKI, RFC 9589 and the Switchover Boundary
A RPKI relying party can keep validating useful repository material after its preferred delivery path fails without pretending that a signed timestamp is a trustworthy clock. RFC 9589 makes that distinction operational: one CMS attribute can align filesystem comparison across…
CASE FILE
Four Thousand Was a Prefix Claim, Not a Rate-Limit Mandate: RFC 9977 and the Evidence Boundary
A prefix file can make an address range easier to group. It cannot convert a count of end sites into a command to relax a local risk control.

IETF
Daniel Fett and the QR Context That MFA Never Authenticated
The password was right, the second factor was real and the authorization server behaved as designed. The attacker still received the session, because the ceremony proved who the user was without proving whose request the user had approved.
CASE FILE
The Certificate Verified the Peer. The External PSK Still Needed a Custodian: RFC 9973 and TLS Authority
A security review can make an unusually comforting statement: the client validated the certificate, the server selected an external pre-shared key, the handshake finished, and the traffic was encrypted. Every clause may be true. None answers the question a security owner…
CASE FILE
The BFD Counter Rose. The Service Path Was Still Unproven: RFC 9978 and Stability Evidence
A BFD session can stay Up while control packets disappear inside its Detection Time. RFC 9978 makes that early deterioration observable. It does not turn a control-packet counter into proof of data-plane loss, a failed route, or a customer-facing outage.
CASE FILE
The Flag Said Several Routers Meant This Prefix. It Did Not Name a Working One: RFC 9983 and Anycast Evidence
An OSPF control plane can state that a prefix is meant to be advertised by several routers. That is useful coordination. It is not a statement that any particular replica is reachable, selected, healthy, authorised to serve, or able to complete the transaction a packet…
CASE FILE
A Cookie Matched the Request. It Did Not Prove the Decision: RFC 10025 and Ambient Authority
A browser can attach the right-looking cookie to the right-looking request at the exact moment a consequential button is pressed. That still leaves four questions open: who caused the request, whether the server still accepts the session, whether this action is allowed now, and…
CASE FILE
A Ciphertext Reached the Key. It Did Not Name Its Sender: RFC 9180 and the Authority Missing from HPKE Base Mode
A team can receive an HPKE ciphertext, open it with the intended private key and still be unable to say who sent it, what outer request it belonged to, whether it is fresh, or whether anyone was entitled to act on its plaintext. RFC 9180 makes the cryptographic transition…
CASE FILE
An MPLS Action Is Not an Admission Decision: RFC 9994
A packet can arrive with a perfectly formed MPLS Network Action Sub-Stack, an opcode that an engineer can name and ancillary data that a parser can read. That packet has not yet proved that the next node supports the action, that the action belongs on this path, that its data…
