< ciso
brief />
Tag Banner

All news with #post quantum cryptography tag

151 articles

Most Medical Devices Unready for PQC Transition

🔒 A Forescout investigation across 50+ healthcare delivery organizations found most medical devices cannot be upgraded to post-quantum cryptography, leaving sensitive healthcare data at risk of future quantum-enabled decryption. Only 6% of IoMT and 16% of medical OT devices use SSH implementations that could support PQC, compared with around 50% of traditional IT devices. The report highlights exposed systems holding EMRs and PACS and urges immediate inventory, segmentation, TLS 1.3 enforcement and vendor engagement to prepare for quantum threats.
read more →

Cloudflare Birthday Week 2026: Platform and Security

🎉 Cloudflare recapped its 16th Birthday Week, detailing 46 announcements spanning open source, application security, developer tools, monetization, data platforms, and observability. Highlights include a new cf CLI and Forge pipeline, EmDash CMS, post-quantum cryptography efforts, plans to become a certificate authority, Monetization Gateway and Pay Per Use, and GA launches for Basin and K2. The company emphasized support for agents, developer ecosystems, intern contributions, and commitments to open tools and civic programs.
read more →

Sovereign AI Choice: One Year Later

🎉 Cloudflare announces two public models—EuroLLM and Apertus—now available via Workers AI, plus hands-on workshops to help government cyber agencies build model-agnostic AI defenses. EuroLLM covers 35 languages including all 24 EU official languages, while Apertus is Switzerland's fully open multilingual model trained on over 15 trillion tokens. The company emphasizes choice and open standards to avoid vendor lock-in and strengthen national AI resilience.
read more →

Cloudflare Workers adds ML-KEM and ML-DSA support

🔒 Cloudflare Workers now exposes post-quantum primitives in Web Crypto, enabling developers to experiment with ML-KEM and ML-DSA via new APIs like encapsulateBits(), decapsulateKey(), getPublicKey(), and SubtleCrypto.supports(). Available behind the webcrypto_modern_algorithms compatibility flag, this runtime-level support reduces the need to bundle third-party crypto implementations and lets libraries delegate operations to the native environment. The initial implementation on workerd uses BoringSSL and includes ML-KEM-768 and ML-DSA-44 with additional variants provisioned for testing.
read more →

Cloudflare adds TLS post-quantum visibility tools

🔒 Cloudflare has added post-quantum (PQ) cryptography visibility into its Application Security and Logs products, enabling customers to inspect TLS key exchange algorithms in Logpush, Log Explorer, and HTTP Traffic Analytics. The update surfaces the negotiated key exchange per incoming request so teams can audit PQ adoption, assess compliance, and identify cryptographic gaps across domains. Cloudflare highlights X25519MLKEM768 as the primary TLS 1.3 PQ key-exchange and provides guidance for enabling TLS 1.3 and collecting PQ telemetry.
read more →

Cloudflare adds IPsec downgrade protection extension

🔒 Cloudflare and the IETF developed and implemented a mitigation for downgrade attacks against IPsec to guard against quantum-capable adversaries. The company has rolled out beta support across IPsec products including Cloudflare WAN and Magic Transit, enabling customers to request an ipsec_downgrade_protection flag. The upgrade helps ensure post-quantum key agreement is not bypassed by active attackers during protocol negotiation.
read more →

Cloudflare announces PQ-capable CA using MTCs

🔐 Cloudflare outlines its plan to operate a post‑quantum capable Certificate Authority (CA) that supports Merkle Tree Certificates (MTCs) to enable scalable, efficient PQ authentication. The post explains how MTCs integrate issuance and transparency, reducing the cost of PQ signatures and improving auditability with cosigners and mirrors. Cloudflare will offer MTC issuance for free, build ACME tooling, and target Chrome inclusion in early 2027.
read more →

Cloudflare announces intent to become a public CA

🔒 Cloudflare today announced its intent to become a public certificate authority (CA), detailing milestones including applications to major root programs and an agreement to acquire a trusted root from GlobalSign. The company plans ACME-first automation, support for post-quantum and Merkle Tree Certificates, and transparency through reproducible builds and public dashboards. Cloudflare emphasizes reliability, redundancy, and gradual adoption while continuing partnerships with existing CAs.
read more →

Cloudflare’s AI-Driven Cryptography Discovery Effort

🔍 Cloudflare describes its internal effort to achieve full post-quantum (PQ) readiness by 2029, focusing on discovering and classifying cryptographic uses across its centralized codebase. The company developed an AI-assisted tool, CryptoLabe, to map repositories, identify cryptography in source, configs, and docs, and generate actionable reports for product and engineering teams. CryptoLabe runs two-stage scans—discovery and analysis—assigning cautious classifications and surfacing prerequisites when ecosystem support is lacking. The system runs on Cloudflare Workers, Durable Objects, Workflows, and an AI Gateway to manage model requests and resource limits.
read more →

Amazon RDS Adds Post‑Quantum TLS for PostgreSQL

🔐 Amazon RDS for PostgreSQL now supports post-quantum TLS (PQ-TLS) key exchange to provide post-quantum cryptography options for data in transit. RDS for PostgreSQL versions 18 and higher allow modification of the ssl_groups parameter so administrators can pick cryptographic groups from the RDS allow list. Customers can deploy or update managed PostgreSQL instances through the Amazon RDS Console or the AWS CLI to enable these options.
read more →

Sovereign AI and Quantum-Ready Defense with FortiNDR

🛡️ Fortinet expands its NDR portfolio with FortiNDR Cloud and on‑prem FortiNDR, adding dynamic deception, a post‑quantum cryptography (PQC) dashboard, and an on‑premises AI investigation capability. The PQC dashboard surfaces quantum‑vulnerable encryption from network traffic without new agents, while dynamic deception integrates with FortiDeceptor and Fortinet Automation Service to misdirect attackers. FortiAI Sovereign provides AI‑driven investigation fully within air‑gapped environments, eliminating cloud dependence.
read more →

FedRAMP Moderate for Quantum-Safe Security

🔒 Palo Alto Networks has earned FedRAMP Moderate authorization for its Quantum-Safe Security (QSS) Automated Cryptography Discovery and Inventory solution, enabling immediate federal deployment. The authorization confirms QSS meets stringent federal security requirements and helps agencies protect sensitive, unclassified data while accelerating post-quantum cryptography (PQC) transition. QSS provides continuous cryptographic discovery, risk assessment, and actionable transition capabilities without requiring new hardware.
read more →

Cloudflare Enables ML-DSA-44 Validation on 1.1.1.1

🔒 Cloudflare’s 1.1.1.1 resolver now validates DNSSEC signatures created with the post-quantum algorithm ML-DSA-44, a NIST-standardized scheme. This step lets Cloudflare test large signature transport and downgrade-resilience at Internet scale while planning full post-quantum DNSSEC support by 2029. The update is automatic for users when zones publish the requisite DNSSEC records.
read more →

Planning for post-quantum cryptography migration

🔒 This article argues that post-quantum cryptography (PQC) is an immediate planning priority because adversaries can harvest and store ciphertext now to decrypt later. It reviews NIST and national guidance with concrete dates, highlights Mosca’s theorem to set timelines based on migration time and data confidentiality needs, and stresses crypto-agility and comprehensive discovery across systems. Vendor coordination and prioritized migration of long-lived sensitive data and public TLS endpoints are emphasized as practical starting points.
read more →

Post-Quantum Cryptography and National Security Risks

🔒 Quantum computing advancements are turning theoretical cryptographic vulnerabilities into imminent threats, prompting an urgent shift to post-quantum cryptography (PQC). The technology will likely remain concentrated within nation-states and large corporations, creating adoption gaps among smaller organizations and critical infrastructure. This disparity could be exploited for intelligence collection, economic espionage, or prepositioning for conflict.
read more →

Amazon RDS Adds Latest Community MariaDB Minors

🆕 Amazon RDS for MariaDB now supports community minor versions 10.6.28, 10.11.19, 11.4.13, 11.8.9, and 12.3.3, which include operational improvements and post-quantum TLS (PQ-TLS) key exchange support for in-transit encryption. AWS recommends upgrading to gain CVE fixes, bug fixes, performance improvements, and new features. You can upgrade via Blue/Green deployments, in-place upgrades, or snapshot restores, and automate rollouts with automatic minor upgrades and the AWS Organizations Upgrade Rollout Policy. Migration from external MariaDB sources is supported via AWS Database Migration Service.
read more →

Cloudflare Enables Automatic Key Exchange for Origins

🔐 Cloudflare introduces Automatic Key Exchange, extending Automatic SSL/TLS to probe origin servers and choose the optimal TLS 1.3 key agreement on the first ClientHello. This measurement-driven approach replaces a static X25519 guess, dramatically reducing HelloRetryRequests and lowering handshake latency while enabling broader post-quantum hybrid key usage. The feature is active by default and includes compliance filters for operators who need to restrict allowable algorithms.
read more →

G7 urges accelerated shift to quantum-safe encryption

🔒 The G7, led by France's ANSSI during the 2026 Presidency, has issued a call to action urging governments and organizations to begin transitioning to post-quantum cryptography (PQC). The document reframes quantum threats as near-term risks and recommends a phased, risk-based approach: inventory cryptographic assets, map dependencies, and prioritize protection of critical systems. It also urges procurement of PQC-integrated products and early migration to lower costs, and sets five priorities including awareness, national strategies, R&D, public–private partnerships, and integrating PQC into cybersecurity requirements.
read more →

Amazon Aurora MySQL 8.4.8: PQ‑TLS and replication

🔒 Amazon Aurora MySQL-Compatible Edition 8.4 now supports MySQL 8.4.8, introducing security enhancements and bug fixes plus features such as post-quantum TLS (PQ-TLS) key exchange, transaction timeout, multi-source replication, and delayed replication. These additions strengthen in-transit encryption options and improve operational resilience by preventing long-running transaction impacts and enabling consolidated or lagged replicas for recovery and reporting. Upgrades are available via automatic minor version upgrades during scheduled maintenance and supported across all AWS Regions where Aurora MySQL is offered.
read more →

Google donates ZKP library to Linux Foundation Europe

🔒 Google has donated its Longfellow Zero-Knowledge Proof (ZKP) library, open-sourced last year, to the Post-Quantum Cryptography Alliance under Linux Foundation Europe. This transfer establishes vendor-neutral, open stewardship to enable global trust, auditability, and adoption as a quantum-safe standard for digital identity applications. Google will continue developing and supporting the library openly and collaborating with experts worldwide to scale interoperable digital credential solutions across devices and browsers.
read more →