LIVE · cybersecurity feed
Live wire
breach

BGP Role model: tracking the adoption of RFC 9234

RFC 9234 lets routers reject route leaks on their own, using BGP Roles and the Only to Customer attribute. We measured who has deployed it, and found two Tier 1 networks unexpectedly stripping OTC.

zeroday.news ·

The adoption of RFC 9234, a standard designed to enhance the security and efficiency of the Border Gateway Protocol (BGP), is being closely monitored by network researchers. This standard, also known as "BGP Role," aims to prevent certain types of routing attacks and improve the overall stability of the internet's core routing infrastructure.

RFC 9234 introduces a mechanism for BGP peers to declare their "role" in a routing relationship, such as provider, customer, or peer. This explicit declaration allows for better validation of routing information and can help detect anomalies that might indicate malicious activity or misconfigurations. The standard was published in June 2022 by the Internet Engineering Task Force (IETF).

Initial analysis of its adoption indicates a gradual but steady increase in its implementation across the global internet. While the standard is relatively new, its potential benefits for routing security are driving its uptake among network operators. Researchers are tracking the deployment of RFC 9234 by analyzing BGP update messages to identify networks that are advertising support for the new capabilities.

The primary motivation behind RFC 9234 is to strengthen BGP against common vulnerabilities, such as route hijacks and leaks. By formalizing the roles of BGP neighbors, it becomes easier to identify and filter out invalid routing announcements, thereby reducing the impact of such incidents. This is particularly important given the critical role BGP plays in directing internet traffic.

The process of implementing new BGP standards can be complex, requiring coordination among multiple network operators and updates to routing software. Despite these challenges, the security advantages offered by RFC 9234 are expected to encourage its wider adoption over time. The standard complements other routing security initiatives, such as Resource Public Key Infrastructure (RPKI), which focuses on verifying the legitimacy of IP address block ownership.

Ongoing research efforts are focused on understanding the rate of adoption, identifying any barriers to implementation, and assessing the real-world impact of RFC 9234 on internet routing security. These studies often involve collecting and analyzing large datasets of BGP routing information to observe trends and measure the effectiveness of the new standard in practice. The ultimate goal is to foster a more resilient and secure global routing system.

breach
ShareXLinkedInWhatsAppFacebook

More News

view all →
vulnerabilitycritical

Wiz AI Agent Finds Critical Snowflake GitHub Repo Flaw Advanced Security Missed

The security flaw in Snowflake’s GitHub Actions workflow had been missed by a GitHub Advanced Security scan, said a Wiz researcher

phishinghigh

CISA gives feds 3 days to fix actively exploited Ray RCE bug

Phishing, malvertising attacks could target devs to gain access to private corporate networks

security

Meta Ran Ads for an App That Promised to Nudify Female Politicians

One advertisement featured a pornographic video with a deepfake closely resembling a prominent US politician. Apple removed the app from the App Store after an inquiry from WIRED.

security

Hackers target Ukrainian agency managing assets seized from sanctioned Russians

The agency said the latest attack came amid preparations to select a manager for seized corporate rights in IDS Ukraine, one of the country’s largest producers of bottled mineral water and beverages.

vulnerabilitycritical

NASA Ground Control Software Flaw Enables Unauthenticated Commands

Critical AIT-GUI flaws expose spacecraft commands and scripts to unauthenticated attackers

CVE-2026-19478critical

Critical GitLab flaw allows attackers to modify or delete public projects (CVE-2026-19478)

GitLab has released patches for two vulnerabilities, including a critical-severity code injection flaw that can be exploited without authentication. The vulnerabilities affect GitLab Community Edition (CE) and Enterprise Edition (EE) versions from 18.2 before 18.11.11, 19.0 before 19.0.8, 19.1 before 19.1.6, and 19.2 before 19.2.4. The fixes are available in GitLab 19.2.4, 19.1.6, 19.0.8, and 18.1