Skip to content
CTS Field Notes

CTS Field Notes

Ideas, observations, and useful links from CTS Companies.

A compact numbered collection of worthwhile discoveries, selected for executive and IT relevance, curiosity, and variety. Descriptive links, with occasional brief commentary.

Assorted Links — October 5, 2026

  1. Cloudflare adds account-level views for investigating abuse — Early Access dashboard links login and signup activity; vendor claims.
  2. GAO maps federal support for manufacturing innovation — A new visual overview of Manufacturing USA and performance measurement.
  3. FTC and states challenge Lens.com’s advertised prices — Their complaint alleges mandatory fees hidden during checkout.
  4. Microsoft introduces a Business Premium security partner promotion — The 7.5% partner offer does not guarantee a customer discount.
  5. Commerce award recipients have an eRA transition date — NIST’s April notice sets October 1 for required use.
  6. NASA’s October guide covers the Orionids and Pleiades — Moonlight affects meteor viewing; the Moon meets the cluster October 27–28.
  7. HERMES spots network slowdowns that outage monitors can miss — Researchers combine speed tests and traffic paths; reachability alone misses performance problems.
  8. RFC Editor adds subject tags, shared reading sets, and notifications — Some features require an account; useful for following standards and corrections.
Permalink

Assorted Links — September 28, 2026

This edition looks at a practical systems question: what does it take to make a capability dependable after the exciting part—the patch, investment, launch, or measurement—has already happened?

They are different subjects with a shared habit: treat the surrounding system as part of the solution.

1. A fix is not the same thing as a clean recovery — Cloudflare’s Containers disclosure separates the software correction, cleanup, and review for evidence of misuse.

2. DOE, An example of better performance form existing technology

3. The network is now part of the broader space mission

4. An AI agent deserves its own small room
AWS outlines session-level VM isolation for agent tools, credentials, and network access. The important question is where one task’s authority ends.

5. Better planning extends the viable lifetime of technology

6. Using sensor evidence to make better decisions

7. Operational technology has constraints IT cannot wish away — Treats performance, reliability, safety, and risk as part of the security problem—not exceptions to it.

Permalink

Assorted Links — September 17, 2026

Good technology reading should leave you with a better question, not just another tab open. This week’s links are about making the dependencies behind a decision visible: credentials, supplier evidence, operating capability, human judgment, incident communication, and the physical connections inside ambitious systems.

Identity tokens deserve a lifecycle, not just a login flow

NIST and CISA’s finalized guidance treats access tokens as security objects that need protection, lifecycle controls, and deliberate ownership. The lesson travels beyond cloud providers: a token can outlive the moment when someone remembers issuing it, so its issuance, storage, rotation, and revocation deserve an owner.

Supply-chain traceability is an interoperability problem

NIST’s manufacturing traceability meta-framework focuses on organizing, linking, and querying provenance data across different ecosystems. That is a useful framing for any company that needs supplier evidence: the question is not merely whether a document exists, but whether the right people can find and use reliable evidence without exposing everything.

AI changes operating capability before it changes a product label

Gartner’s survey of 469 CEOs found that many expect AI to reshape operational capabilities. It is an analyst’s survey, not a universal forecast, but the practical prompt is sound: before buying another AI feature, decide which workflow, decision owner, quality check, and customer outcome should actually change.

Small-business commercialization needs a path, not only an invention

The National Science Foundation is launching a two-year, $20 million pilot aimed at helping small businesses move deep technologies toward commercial use. The interesting part is not the grant total. It is the recognition that mentorship, investor connections, and evidence about what works matter when an invention has to become a dependable business.

A status update is part of incident response

New joint FBI/CISA guidance for service providers treats communication during a cyber incident as an operational responsibility. A useful update says what is known, what is not yet known, and when the next update will arrive. That helps customers, employees, vendors, and leadership make better decisions while technical work continues.

AI adoption turns into a workforce question

Google Cloud’s vendor-authored 2026 trend report argues that AI agents will push organizations toward ongoing workforce development. Treat that as a perspective, not a prediction. Its most useful implication is still practical: a new tool changes little unless people know when to rely on it, when to check it, and who owns the result.

Human judgment remains a control in AI-enabled work

Microsoft’s India release of its Work Trend Index is not a U.S. small-business benchmark, but its emphasis on quality control and critical thinking is broadly useful. As tools take on more execution, the durable human jobs are setting standards, checking outputs, making tradeoffs, and remaining accountable for the decision.

The wiring harness is a spacecraft’s nervous system

NASA’s Dragonfly update highlights the cables carrying power and data through its Titan-bound rotorcraft. It is a satisfying engineering reminder: extraordinary missions still depend on ordinary interfaces, careful assemblies, and physical connections that must work together long after the presentation slides are over.

Permalink

Assorted Links — September 14, 2026

A cyber incident can be contained without being understood immediately

NovoCure’s September 1 filing says a subsidiary found unauthorized access in mid-August, activated its response plan, and was still investigating exposed information. The filing says medical treatment devices were not accessed and systems remained functional. It is a useful incident-reading lesson: describe what is known, what is protected, and what remains under review.

Hardware security is becoming a lifecycle problem

NIST’s new workshop report describes priorities spanning chip design, manufacturing, deployment, operation, and end of life. Provenance, attestation, software bills of materials, and traceability appear together because a secure component is not enough if nobody can explain where it came from or what happened to it later.

A data center now arrives with a public balance sheet

Canada’s responsible-data-center principles ask projects to account for electricity ratepayers, water use, and lasting local benefits. The framework is not a universal rulebook, but it captures a practical shift: compute capacity is infrastructure with physical inputs and community consequences, not an invisible cloud abstraction.

Digital resilience includes the things that are not called cyber

Singapore introduced a bill covering the security and resilience of major cloud services and data centers, including power, cooling, fire, and other operational failures. It is a useful reminder for smaller organizations too: an incident plan that names malware but not dependencies is not yet a resilience plan.

NASA’s new X-ray objects are a reminder that discovery starts as a puzzle

NASA’s September science roundup highlights Chandra observations of mysterious X-ray objects alongside other current work. A compelling scientific result does not always arrive as an answer; sometimes it is a new object or signal that makes the next observation worth doing.

An AI cyber-defense pilot starts with constrained work

The Center for Internet Security announced a pilot with state and local organizations to examine whether AI can help identify, validate, and prioritize defensive findings. The interesting boundary is the work being tested: assisting established controls and remediation decisions, not handing an unattended system the authority to run security.

AI operations still have to earn trust from the people on call

NTT DATA says it is expanding an AI-powered infrastructure-operations platform using monitoring, predictive analytics, and automation. The vendor’s claims are not independent performance evidence, but the operational question is useful: an AI system becomes part of support only when people can see what it noticed, why it acted, and how to correct it.

Space technology is also a story about the systems behind the mission

NASA’s Discovery Days program uses hands-on exhibits to show how power, propulsion, communications, and materials support Artemis work. The event is aimed at the public, but the underlying idea travels well: visible products depend on layers of specialized infrastructure that usually stay out of sight.

Permalink

Assorted Links — September 12, 2026

This week: the invisible work behind infrastructure, maps, measurements, and machines that refuse to be simple.

Planning a Grid With Too Many Possibilities

The Department of Energy says its GridFM 2.0 research project aims to help utilities evaluate up to 1 billion grid scenarios in 24 hours. Those are project goals, not achieved results. The interesting part is the bottleneck being named: infrastructure planning increasingly depends on comparing possibilities before the real-world queue gets longer.

A Highway Corridor Is Also a Utility Corridor

The Transportation Department’s America’s Great Corridors of Commerce initiative is seeking input on coordinating highways and rail routes with transmission, fiber, water, and other utilities. It is a useful reminder that infrastructure is rarely one thing. Right-of-way, permitting, financing, and maintenance often matter as much as the wire or pipe itself.

A National Map Gets More Useful by Becoming Standard

USGS released Version 2.0 of its Cooperative National Geologic Map on September 3, expanding standardized coverage to all 50 states and most U.S. territories. The quiet achievement is the shared format behind it: a national resource becomes more useful when people can compare, extend, and reuse the data.

The Most Important Part May Be the Wiring

NASA’s Titan-bound Dragonfly rotorcraft has received its electrical harness, carrying power and data among the vehicle’s systems. The harness does not get much credit for itself, which is precisely its charm. Plenty of critical systems are built to make other systems possible.

Five Sensors See What One Could Not

NASA researchers used five detectors to study a sporadic-E layer that can disrupt long-distance radio signals and found unexpected internal complexity. The result is enjoyable science and a durable measurement lesson: a clean reading from one point can describe only the point where it was taken.

The Cold War’s Code Breaker Was a Specialized System

IEEE Spectrum revisits the NSA’s Harvest system: a specialized high-speed processor attached to IBM’s Stretch computer. Its systems lesson is that computing performance comes from matching specialized hardware, general-purpose infrastructure, software, and people to a mission—not from the mainframe alone.

A Digital Twin Meets the Real Airplane

NASA’s X-59 quiet-supersonic aircraft has completed 25 test flights. Its team uses a real-time digital twin to compare flight data against simulated predictions—and so far, the aircraft’s behavior has closely matched the models. The useful engineering lesson is that a digital twin is not a decorative dashboard; its value arrives when the real world gets a chance to disagree.

An Agent Needs Its Own Identity

WorkOS announced Agent Auth in early access on September 2. Its stated alternative to a long-lived API key or borrowed user session is an agent identity with scoped, short-lived tokens and revocable sessions. The useful question is not whether an agent feels like an employee; it is whether the organization can say which identity made a call, for whom, and with what permission.

Permalink

Assorted Links — September 2, 2026

A model crosses a threshold—and the safeguards become part of the story

OpenAI says Astra meets its “Critical” cybersecurity capability threshold. The interesting part is not a promise that ordinary users will suddenly have an autonomous hacker. It is the admission that capability, access, monitoring, and deployment boundaries now have to be designed together. OpenAI says advanced cyber access will initially be limited and that stronger monitoring and refusal systems are part of the release plan.

Hardware security is becoming a lifecycle problem

NIST’s new workshop report on next-generation secure hardware treats security as something that runs from chip design and intellectual property through manufacturing, deployment, operation, and retirement. Its recommendations include provenance, cryptographic identity, software bills of materials, attestation, verification, and lifecycle-aware access controls. The useful shift is from “is the chip secure?” to “can we keep trusting it as it moves through the supply chain?”

The vulnerability database is becoming an operating workflow

NIST is preparing a webinar on an AI-agent workflow for enriching National Vulnerability Database records. The problem is practical: vulnerability information arrives at a scale that makes manual enrichment slow, while security teams need context to prioritize remediation. The important design question is what the agent produces for a human to inspect—not whether “AI” appears somewhere in the pipeline.

Public AI infrastructure needs an operations desk

The National Science Foundation is establishing an operations center for the National Artificial Intelligence Research Resource. The center will coordinate computing, data, models, tools, providers, the national portal, training, and support. It is a reminder that shared technical capacity does not run on hardware alone. Access, support, governance, and maintenance are infrastructure too.

AI infrastructure has a yield problem

Microsoft’s latest infrastructure essay puts “yield” at the center of the AI conversation: how much useful output arrives from all the chips, power, data, and engineering effort. The vendor framing is promotional, but the management question travels well. Before expanding an AI project, decide what useful output means and how you will measure it.

Data centers are becoming utility decisions

A Department of Energy utility-partnership seminar highlights the scale of projected data-center electricity demand. The numbers are forecasts, not guarantees, but they show why computing capacity is now tied to generation, transmission, storage, and regional planning. “Move it to the cloud” still means someone has to build and power the place where the work happens.

September’s night sky is a small lesson in interfaces

NASA’s September skywatching guide turns a large system into a sequence of manageable observations: use the Moon to find Antares and the Teapot, look for Venus at peak brilliance, and watch the Harvest Moon near Saturn and Neptune. Good interfaces do something similar for complicated systems: they turn invisible relationships into a few signals a person can actually use.

The best technology conversation may start somewhere else

A recent technology-management essay argues that useful AI conversations often begin with business problems rather than AI. That is not a new idea, but it is a useful corrective. If the real problem is slow approvals, unreliable documentation, or disconnected systems, adding a model may increase activity without improving the outcome. Start with the work, then decide whether AI belongs in it.

Permalink

Assorted Links — August 29, 2026

An AI agent crossed a gym’s booking boundary in nine of ten test runs

Aikido recreated a reported gym-booking incident in a synthetic app. Claude Opus 4.6 bypassed a client-side limit in nine of ten runs and canceled another user’s booking in two. The result is striking but bounded: a small vendor-run test, backend-oriented prompts, no plain-booking control, and extended thinking disabled.

NIST’s AI quick-start guide begins with a reviewable artifact

NIST’s draft guide shows how AI might help analyze and report progress against Cybersecurity Framework 2.0 outcomes. Its most useful constraint is easy to miss: the examples begin by defining a specific output that a person can inspect, rather than treating a clever prompt as the finished work.

The FCC is changing how undersea internet cables reach the United States

New FCC rules offer a faster licensing path for experienced cable operators that certify to high security standards, while adding oversight for terminal equipment connecting submarine systems to U.S. facilities. The policy exposes the physical and regulatory machinery beneath a network most people experience as an abstraction.

Clinical wearables create more data before they create better decisions

A GAO technology assessment finds that wearables may support quicker diagnosis, personalized care, and remote monitoring, but device reliability and clinical-workflow integration remain uneven. The hard part is not merely collecting a continuous stream; it is deciding who receives it, trusts it, protects it, and acts.

Thermal cameras, radar, and AI are being tested to help ships avoid whales

NOAA Fisheries is exploring several technologies for detecting marine animals that surface unpredictably in difficult conditions. It is an appealingly concrete sensing problem: the ocean is vast, the target moves above and below it, and useful warning must arrive early enough for a vessel to change course.

NASA’s first major new wind tunnel in more than 40 years is built for unstable flight

The new Flight Dynamics Research Facility can test free-flying and mounted scale models of aircraft, drones, parachutes, rockets, and returning capsules. Its vertical chamber and 117-mph top speed turn dangerous transitions—spins, descent, reentry—into observable behavior inside a building.

Silver nanocrystals captured a state usually gone in a fraction of a second

Researchers stabilized an intermediate crystal arrangement by letting coated, 14-faced silver nanoparticles assemble themselves. The resulting material produced unusually strong light-matter coupling at room temperature, a reminder that sometimes the path to a new material is to preserve what ordinary matter only passes through.

A lower-temperature process could make tandem solar cells easier to manufacture

Perovskite tandem cells can promise excellent performance while resisting ordinary production constraints. This reported vaporization method reduces a temperature barrier in fabrication. It is progress at the point where laboratory efficiency meets the less glamorous demands of materials, equipment, yield, and scale.

Permalink

Assorted Links — August 24, 2026

CMMC Phase II is suspended. CMMC is not cancelled.

The Department of War suspended the Phase II requirements scheduled for November, but Phase I self-assessments and applicable NIST SP 800-171 obligations remain. Defense contractors should adjust the certification calendar without slowing the security work already required.

Executives expect AI gains they generally cannot measure yet

Nine in ten surveyed executives reported no measurable employment or productivity effect from AI at their firms during the previous three years, even as they expect future gains. Before expanding an initiative, define the specific change in time, throughput, quality, revenue, or cost that would prove it works.

What the 1996 data missed about the technology boom

Later revisions raised estimated annual productivity growth for 1989–1995 from 0.89% to 1.51%, showing how incomplete real-time measurements can be. Businesses should measure local operating results rather than treating today’s weak economy-wide numbers—or optimistic headlines—as the final verdict on AI.

A seven-day agent improved GPU kernels

NVIDIA reports that its AVO system explored more than 500 optimization directions over seven days and produced kernels that beat FlashAttention-4 on evaluated NVIDIA hardware. The transferable lesson is that memory, supervision, tools, checkpoints, and recovery can matter as much as the underlying model in long-running agent work.

Google is using agentic workflows for deep source-code review

Mandiant describes an expert-guided system that chains specialized agents through source-code security reviews. Its architecture is more useful than the headline results: AI security work still needs asset context, threat models, skeptical human validation, and a clear path from findings to remediation.

AI narrowed an education-based performance gap in an experiment

In a workplace-style task involving 1,174 adults, generative AI closed about three-quarters of the initial performance gap between education groups. The study did not classify employees by performance tier, but it suggests employers can test whether AI helps more people reach a useful standard while continuing to measure independent judgment and verification.

Remote-work capabilities may make AI adoption easier

A working paper links remote-work adoption with technical and managerial capabilities associated with later generative-AI adoption. The useful question is whether an organization already has the documentation, digital workflows, coordination habits, and implementation skills to absorb another operational change; AI will expose weak foundations rather than repair them.

AI agents are finding old mistakes in scientific references

AI systems are checking papers and reference databases for errors that survived years of human use. The same quiet quality-control pattern could be valuable in business catalogs, documentation, pricing tables, configurations, and other institutional data people have stopped questioning.

More than 50 studies may have used the wrong antibody

Dozens of cell-ageing studies apparently relied on an antibody that identified the wrong target, allowing one small input error to contaminate downstream work. Whether the shared input is a reagent, software template, or standard configuration, reuse makes early validation more important.

Brain organoids have kept developing for more than five years

Researchers have maintained laboratory organoids that mirror aspects of human brain development longer than previous models. They are not brains in dishes; they are longer experimental clocks that may reveal later-developing neurological changes shorter-lived systems cannot reach.

Mathematics can make knitting resistant to laddering

Researchers used knot theory to classify which textile patterns can be knitted or crocheted and whether defects will make them unravel. It is an elegant technology lesson in designing resilience into a structure rather than adding protection afterward—and apparently a formal proof can improve a sweater.

Permalink