< ciso
brief />
Tag Banner

All news with #encryption in transit tag

59 articles · page 2 of 3

Cloudflare Enables Post-Quantum IPsec with ML-KEM Standard

🔒 Cloudflare has made post-quantum encryption generally available for Cloudflare IPsec using hybrid ML‑KEM (FIPS 203), implementing draft-ietf-ipsecme-ikev2-mlkem. The rollout enables site-to-site WAN tunnels protected against harvest-now-decrypt-later attacks and has been tested interoperably with Cisco and Fortinet branch connectors. This brings post-quantum IPsec closer to Internet-scale deployment and supports Cloudflare’s goal of full post-quantum security by 2029.
read more →

AWS Managed Microsoft AD: Kerberos Encryption Logs

🔒 AWS Managed Microsoft AD can now forward Kerberos Encryption audit event logs (Event IDs 201–209) to Amazon CloudWatch Logs. These logs provide visibility into whether clients and services negotiate RC4 or AES encryption, helping you decide whether to upgrade clients for stronger protection or retain compatibility. Enable log forwarding from the directory's Network and Security tab in the Directory Service console. This feature is available in all AWS Regions offering the service except UAE and Bahrain.
read more →

Google Brings Client-Side Gmail E2EE to Mobile for Orgs

🔐 Google has extended client-side encryption (CSE) for Gmail to Android and iOS for organizations using the Enterprise Plus with Assured Controls edition. Messages and attachments are encrypted on-device with customer-managed keys and require admins to enable the mobile clients in the CSE admin console. The feature is opt-in, requires premium licensing, and disables some Gmail capabilities (including AI features and full search) for encrypted content. Non-Gmail recipients receive a secure web portal to read and reply.
read more →

Google enables Gmail end-to-end encryption on mobile

🔐 Google has rolled out native end-to-end encryption for Gmail on Android and iOS, allowing enterprise users to compose and read encrypted emails without installing extra apps. The capability uses client-side encryption (CSE) and is available to organizations with Enterprise Plus licenses plus the Assured Controls add-on after admins enable mobile clients. Encrypted messages and attachments are encrypted on the device and delivered as regular emails, and recipients using other services can read them in a web browser.
read more →

Amazon SES Mail Manager Adds mTLS, TLS Options and Actions

📧 Amazon Simple Email Service Mail Manager now supports optional TLS (including STARTTLS) and certificate-based mutual TLS (mTLS) on Ingress Endpoints, plus two new rule actions: Invoke Lambda function and Bounce. These additions let organizations preserve compatibility with legacy email systems while implementing stronger authentication and custom processing workflows. The Invoke Lambda action enables direct serverless email processing and automation, and the Bounce action issues RFC-compliant SMTP responses to senders. The features are available today in all Regions offering SES Mail Manager except the Middle East (UAE and Bahrain).
read more →

AWS Launches VPC Encryption Controls in GovCloud US

🔒 AWS VPC Encryption Controls is now available in AWS GovCloud (US-East) and GovCloud (US-West). The feature lets security teams enable monitoring and enforcement of encryption in transit across existing VPCs, automatically identifying flows that permit plaintext. It transparently activates hardware-based AES-256 encryption across VPC resources (including Fargate, NLB, and ALB) and produces audit logs to help demonstrate compliance with standards such as HIPAA, PCI DSS, FedRAMP, and FIPS 140-2.
read more →

Proton launches Meet: E2EE privacy-focused conferencing

🔒 Proton has launched Meet, a privacy-focused video conferencing service offering end-to-end encrypted calls as an alternative to mainstream platforms. Meet supports free one-hour meetings with up to 50 participants and offers a Pro tier starting at $7.99/month for longer sessions. The service uses the open-source MLS protocol, WebRTC with SFUs, and client-side encryption; authentication relies on SRP. Meetings are created via links containing an ID and locally held passwords, and Proton says it retains only non-sensitive meeting IDs, minimizing exposure even in server compromises.
read more →

Post-Quantum Roadmap for US Enterprises Targeting 2030

🔒 US organizations should begin operationalizing post-quantum cryptography now to protect long-lived secrets and meet an emerging 2030 readiness horizon. With NIST finalizing initial PQC standards in 2024 and agencies like NSA and CISA aligning guidance, a pragmatic hybrid strategy—pairing existing classical algorithms (ECDHE/TLS) with post-quantum primitives such as ML-KEM—reduces long-term confidentiality risk while preserving interoperability. Start with a comprehensive crypto inventory tied to data value, pilot internal mTLS, VPN and code-signing migrations in a lab, improve crypto agility, add telemetry for rollout metrics, and add PQC requirements into procurement to buy time and avoid last-minute disruption.
read more →

AWS Direct Connect: New Equinix SY5 location in Sydney

📡 AWS has opened a new AWS Direct Connect location at Equinix SY5 in Sydney, Australia. From this site you can establish private, direct network access to all public AWS Regions (except China), AWS GovCloud Regions, and AWS Local Zones. The location supports dedicated 10 Gbps and 100 Gbps connections and offers MACsec encryption. This is the fourth Direct Connect site in Sydney and the tenth in Australia, providing a more consistent private networking option than the public internet.
read more →

Meta to End Instagram End-to-End Encryption Support

🔒 Meta will discontinue support for end-to-end encryption for Instagram chats after May 8, 2026, and says affected users will receive instructions to download any messages or media they wish to keep. The company notes some users may need to update older versions of the app before downloading impacted chats. The encrypted-direct-messaging feature was first tested in 2021 and remains available only in select regions and not enabled by default.
read more →

AWS Pricing for VPC Encryption Controls Moves to Paid

🔒 AWS is introducing pricing for VPC Encryption Controls, a regional capability that audits and enforces encryption-in-transit for traffic within and across Virtual Private Clouds. The feature supports Monitor mode to detect unencrypted flows and Enforce mode to prevent the creation or operation of resources that allow unencrypted traffic. Beginning March 1, 2026, AWS will apply a fixed hourly charge to every non-empty VPC with Encryption Controls enabled; empty VPCs enabled with the feature are not charged. When encryption is enabled on a Transit Gateway, standard VPC Encryption Controls charges apply to all VPCs attached to that Transit Gateway regardless of each VPC's mode or whether they are empty.
read more →

Android 17 Beta Adds Secure-by-Default Architecture

🔐 Android 17 public beta introduces a secure-by-default architecture that tightens app protections and refines developer workflows. The release deprecates the android:usesCleartextTraffic attribute and will block cleartext by default for apps targeting API level 37 without a network security configuration. It also adds a public SPI for HPKE hybrid cryptography, enables certificate transparency by default and introduces install-time permissions for localhost interactions. Large-screen behavior changes, a lock-free MessageQueue and generational garbage collection in ART target performance, while Google replaces the traditional Developer Preview with a continuous Canary channel for earlier feature access and streamlined testing.
read more →

Apple beta adds RCS E2EE and expanded Memory Integrity

🔐 Apple has released an iOS and iPadOS 26.4 developer beta that introduces end-to-end encryption (E2EE) for RCS conversations between compatible Apple devices, with a wider rollout planned for iOS, iPadOS, macOS and watchOS in a future update. The feature is currently in beta and limited to Apple devices and supported carriers. The update also expands Memory Integrity Enforcement (MIE), allowing applications to opt in to full protections beyond Soft Mode. Additionally, iOS 26.4 is expected to enable Stolen Device Protection by default and the SDK is available via Xcode 26.4.
read more →

Apple Tests End-to-End Encrypted RCS in iOS 26.4 Beta

🔒 Apple has introduced end-to-end encryption for RCS messaging in the iOS and iPadOS 26.4 developer beta, enabling encrypted conversations between Apple devices during testing. The feature remains in beta and is not available for all devices or carriers, and it currently does not extend to non-Apple platforms such as Android. The release also introduces an opt-in for full Memory Integrity Enforcement and signals forthcoming Stolen Device Protection defaults.
read more →

Preparing for the Quantum Era: A Call to Secure PQC

🔐 Google issues a call to action to protect digital systems against quantum threats, outlining its post-quantum cryptography (PQC) work and policy recommendations. The company warns that large-scale quantum computers could break current public-key cryptography and cautions about 'store now, decrypt later' harvesting of encrypted data. Google commits to research transparency, completing PQC migrations within NIST guidelines, and strengthening crypto agility, critical shared infrastructure, and ecosystem readiness.
read more →

Amazon CloudFront Adds Mutual TLS Authentication for Origins

🔐 Amazon CloudFront now supports mutual TLS (mTLS) for origins, allowing origin servers to cryptographically verify that incoming requests originate from authorized CloudFront distributions. This certificate-based approach replaces custom solutions like shared-secret headers and IP allow-lists, reducing operational overhead and improving security for public and externally hosted origins. Customers may use client certificates issued by AWS Private Certificate Authority or third-party private CAs imported through AWS Certificate Manager, and can configure origin mTLS via the Console, CLI, SDK, CDK, or CloudFormation. Origin mTLS works with AWS-supported mutual TLS origins such as Application Load Balancer and API Gateway, as well as on-premises and custom origins, and is available at no additional charge.
read more →

Microsoft Fixes Outlook Bug Blocking Encrypted Emails

✅ Microsoft has issued a fix for a known issue that prevented Microsoft 365 customers from opening Encrypt Only messages in classic Outlook after a December update. Impacted users saw a message_v2.rpmsg attachment instead of readable content and a 'restricted permission' notice in the Reading Pane. Microsoft says the repair is available in the Beta Channel now and will roll to Current Channel and Current Channel Preview in February. Temporary workarounds are provided for users who cannot upgrade immediately.
read more →

Classic Outlook bug prevents opening encrypted emails

🔒 Microsoft is investigating a bug in the classic Outlook client introduced by Current Channel Version 2511 (Build 19426.20218) that prevents recipients from opening messages encrypted with Encrypt Only permissions. Impacted users may see a reading pane error asking them to verify credentials or encounter a message_v2.rpmsg attachment instead of readable content. The Outlook Team is working on a fix but has not provided an ETA. Microsoft recommends two temporary workarounds: have senders save encrypted messages before sending, or roll back to build 16.0.19426.20186.
read more →

AWS Direct Connect Opens First Hanoi Location in CMC Tower

🔌 AWS opened a new AWS Direct Connect location at the CMC Tower in Hanoi, Vietnam, enabling private, dedicated network access to all public AWS Regions (except China), AWS GovCloud Regions, and AWS Local Zones. The site offers dedicated 1 Gbps, 10 Gbps, and 100 Gbps connections, with MACsec encryption available for 10 Gbps and 100 Gbps links. This is the first Direct Connect location in Vietnam and is designed to deliver a more consistent network experience than internet-based connections. Organizations can use this location to establish private, physical connections between AWS and their data centers, offices, or colocation environments.
read more →

Implementing HSTS Across AWS Services for Cloud Apps

🔒 This AWS Security Blog post explains how to implement HTTP Strict Transport Security (HSTS) consistently across distributed AWS architectures using Amazon API Gateway, Application Load Balancers, and Amazon CloudFront. It presents concrete, service-specific configuration steps, example mappings and code snippets, and recommended curl commands to validate header delivery. The guidance highlights centralized header enforcement options to reduce fragmentation and align with the AWS Well-Architected Framework security principles. Practical advice covers testing, header override behaviors, and phased rollout using conservative max-age values before enabling preload in production.
read more →