< ciso
brief />
Tag Banner

All news with #post quantum cryptography tag

129 articles · page 2 of 7

US issues post-quantum crypto deadlines, launches quantum push

🔒 The White House signed two executive orders to accelerate federal migration to post-quantum cryptography and expand investment in quantum technologies. The crypto order sets firm deadlines for replacing vulnerable algorithms, requires cryptographic inventories and a CBOM, and signals future procurement rules for contractors. The companion order creates a coordinated federal quantum initiative to drive research, commercialization, workforce development, and defenses for sensitive research.
read more →

U.S. Executive Order Accelerates PQC Adoption

🔒 On June 22, 2026, President Trump signed Executive Order 14409, setting federal deadlines to adopt post-quantum cryptography: key establishment by December 31, 2030, and authentication by December 31, 2031, with contractors required to comply by 2030. Cloudflare supports the EO, noting federal procurement has historically driven industry adoption and highlighting that post-quantum encryption deployment is already widespread across its services while authentication work continues. The EO focuses on NIST-standardized PQC, excludes National Security Systems, and directs OMB and agencies to plan and report migration progress.
read more →

U.S. Sets 2030–2031 Deadlines for PQC Migration

🔐 President Trump signed an executive order on June 22 directing federal agencies to migrate high-value assets to post-quantum cryptography with key establishment required by December 31, 2030 and digital signatures by December 31, 2031. The EO accelerates the federal timeline by four to five years and aligns agency schedules with NIST's 2024 FIPS for ML-KEM and ML-DSA/SLH-DSA. Agencies must name migration leads, inventory cryptographic assets, and submit plans; OMB, NIST, CISA and FAR will issue guidance to enforce timelines and contractor requirements.
read more →

US Executive Order Accelerates PQC Migration by 2031

🔐 The US has issued Executive Order 14409 requiring federal agencies to migrate to post-quantum cryptography (PQC) for key establishment by December 31, 2030 and for digital signatures by December 31, 2031. The EO mandates a Commerce-led PQC pilot to finish by December 31, 2027 and directs OMB and the National Cyber Director to accelerate a nationwide transition while coordinating with other agencies and international partners. It also tasks agencies to find cost efficiencies and ensures contractors meet federal cybersecurity standards by 2030.
read more →

Preparing for quantum-era threats to current encryption

🔒 The article explains the growing reality of “harvest now, decrypt later” attacks, where adversaries steal encrypted data today to decrypt later with quantum computers. It summarizes industry and government perspectives, noting that most organizations underprioritize the risk despite emerging standards like NIST’s 2024 post-quantum algorithms and EU transition roadmaps. The piece reviews mitigation options — PQC, QKD, and the need for cryptoagility — and highlights examples from Spain and financial institutions planning phased transitions.
read more →

Raise security procurement and prepare for quantum

🔐 At Infosecurity Europe, Forescout's Rik Ferguson urged organisations to accelerate transition plans to post-quantum cryptography (PQC), warning that only 8% of SSH servers support PQC. He cited NSA warnings about harvest-now-decrypt-later (HNDL) attacks and evidence from surveillance programs indicating encrypted data is already being hoovered for future decryption. Ferguson recommended urgent inventorying of encrypted assets, embedding quantum readiness into procurement, and building crypto-agility such as adopting TLS 1.3.
read more →

Swiss team claims certifiable perfect randomness

🔬 Researchers at ETH Zurich report creating a device that generates provably perfect random numbers using two superconducting qubits, a 30-meter microwave guide, and specialized software. The setup leverages quantum entanglement and an amplification algorithm to remove bias common in classical and many quantum sources. The team says the output can be certified and could serve cryptographic key generation or public randomness services.
read more →

GCHQ warns businesses: urgent cyber action on AI

⚠️ Anne Keast-Butler, director of GCHQ, urged UK businesses to treat cybersecurity as national defence during the agency's first annual lecture at Bletchley Park on May 27. She warned that rapid AI development narrows the window to stay ahead of threats and called on boardrooms to act now. GCHQ plans a machine-speed national cyber defence using agentic AI within five years while urging adoption of basic controls and quantum-resistant cryptography.
read more →

Automating PQC Readiness for AWS TLS Endpoints with Config

🔒 The PQC Readiness Scanner automates inventory and continuous monitoring of AWS-terminated TLS endpoints — Application Load Balancer (ALB), Network Load Balancer (NLB), and Amazon API Gateway — to evaluate TLS policies for Post-Quantum Cryptography (PQC) readiness. It classifies endpoints into a three-tier framework (Tier 1: PQ-ready, Tier 2: PQ-ready with backward compatibility, Tier 3: not PQ-ready) and returns COMPLIANT/NON_COMPLIANT results with policy recommendations. Built as an AWS Config conformance pack with custom rules and Lambda functions, it supports organization-wide deployment via CloudFormation StackSets and S3-hosted artifacts. The scanner reduces manual review, tracks migration progress across accounts, and helps prioritize upgrades to TLS 1.3 with PQC key exchange.
read more →

April 2026 AWS Security Digest: Features and Alerts

🔒 The April 2026 AWS Security monthly digest highlights new features, hands-on samples, and security bulletins across identity, AI security, data protection, and detection. Notable posts include IAM Identity Center session tags for ABAC, guidance for securing agentic AI via the Model Context Protocol, and practical steps to adopt hybrid post‑quantum TLS for Secrets Manager. The edition also summarizes April CVEs and ships 16 runnable code samples and workshops to validate recommended controls.
read more →

Cloudflare Enables Post-Quantum IPsec with ML-KEM Standard

🔒 Cloudflare has made post-quantum encryption generally available for Cloudflare IPsec using hybrid ML‑KEM (FIPS 203), implementing draft-ietf-ipsecme-ikev2-mlkem. The rollout enables site-to-site WAN tunnels protected against harvest-now-decrypt-later attacks and has been tested interoperably with Cisco and Fortinet branch connectors. This brings post-quantum IPsec closer to Internet-scale deployment and supports Cloudflare’s goal of full post-quantum security by 2029.
read more →

AWS Leverages Nitro, Crypto, and S3 Lessons for AI/Quantum

🔒AWS says long-standing infrastructure and cryptographic choices position it to address emerging AI and quantum threats. The company highlights the Nitro hardware platform — enabled by a 2015 semiconductor acquisition and deployed from 2017 — to provide strong isolation, confidential compute, and a 'zero humans' maintenance model. By favoring symmetric cryptography in KMS (launched 2013) and adding S3 controls like an 'active defense' that returns 'Bucket not found', AWS argues most customer data will not require immediate mass re-encryption while it pursues public-certificate post-quantum authentication by 2028–2029.
read more →

AWS Secrets Manager Enables Hybrid Post-Quantum TLS

🔐 AWS Secrets Manager now prefers hybrid post-quantum TLS (ML‑KEM) for supported clients to reduce harvest-now, decrypt-later risk. Customers using the listed clients and SDK versions can get ML‑KEM key exchange without code changes; secrets at rest remain encrypted with AWS KMS and symmetric algorithms are considered quantum-resistant. Verify client negotiation via CloudTrail tlsDetails.keyExchange == X25519MLKEM768 and check SDK/OpenSSL requirements (for example, OpenSSL 3.5+ for Python). CRYSTALS‑Kyber support is being phased out in 2026, so upgrades are recommended to avoid fallback to traditional TLS.
read more →

Fortinet 2025 Sustainability Report: Security and Impact

🔒 Fortinet released its 2025 Sustainability Report, outlining progress in securing the digital world, reducing environmental impact, expanding cybersecurity education, and strengthening governance. The company expanded AI-driven threat protection across its portfolio and introduced quantum-safe capabilities in FortiOS. It also improved product energy efficiency—up to a 62% reduction for select models—and has trained over 914,800 people toward its 1M goal.
read more →

Kyber Ransomware Uses Kyber1024 Post-Quantum on Windows

🔒 Rapid7 analyzed two Kyber ransomware variants discovered in March 2026 that were deployed on the same network: one targeting VMware ESXi and one targeting Windows file servers. The ESXi build advertises post‑quantum Kyber1024 but instead uses ChaCha8 for file encryption and RSA‑4096 for key wrapping. The Windows variant, written in Rust, implements Kyber1024 and X25519 to protect symmetric keys while using AES‑CTR for bulk file encryption, and includes destructive routines such as service termination, backup deletion and an experimental Hyper‑V shutdown.
read more →

Building a Cryptographic Inventory for Quantum Readiness

🔐 Post-quantum cryptography is imminent, and Microsoft emphasizes that the biggest challenge is locating every use of cryptography across applications, devices, networks, and services. Building a comprehensive, ongoing cryptographic inventory enables risk-based decisions, crypto agility, and regulatory compliance. The article outlines a practical Cryptography Posture Management lifecycle and recommends Microsoft tools—GitHub Advanced Security, Defender suites, Azure Key Vault—and partner integrations to discover, normalize, assess, prioritize, and remediate cryptographic risks.
read more →

AWS Secrets Manager Adds Hybrid Post‑Quantum TLS Support

🔐 AWS Secrets Manager now supports hybrid post-quantum TLS key exchange using ML-KEM (a module-lattice-based KEM) to secure secret retrieval. The capability is automatically enabled in Secrets Manager Agent (v2.0.0+), Lambda Extension (v19+), and Secrets Manager CSI Driver (v2.0.0+); supported SDKs include Rust, Go, Node.js, Kotlin, Python (OpenSSL 3.5+), and Java v2 (v2.35.11+). No code or configuration changes are required for up-to-date clients except Java v2. You can verify hybrid key exchange in CloudTrail GetSecretValue events by checking the tlsDetails field for the X25519MLKEM768 algorithm.
read more →

World Quantum Day 2026: Preparing for PQC Migration

🛡️ Quantum computing is moving from theoretical risk to an imminent threat that undermines current cryptographic protections. Advances in algorithms and reduced qubit requirements mean timelines once measured in decades are now years, prompting Gartner in late 2025 to elevate Post-Quantum Cryptography migration to a board-level priority ahead of 2030. Organizations must inventory sensitive assets, prioritize store-now-decrypt-later risks, and begin crypto-agility planning immediately.
read more →

Cloudflare Actively Adjusts Post-Quantum Priorities

🔐 Cloudflare says it is “actively adjusting” its post-quantum cryptography priorities after Google moved its PQC migration deadline up to 2029, citing algorithmic advances. The company reports that more than half of its traffic is already protected against harvest-now/decrypt-later using ML-KEM (a PQC standard ratified in 2024), and plans to deploy post-quantum certificates in 2027 to guard against active attacks. Bas Westerbaan noted Google demonstrated a breakthrough with a zero-knowledge proof while withholding key details.
read more →

Cloudflare Targets Full Post-Quantum Security by 2029

🔒 Cloudflare is accelerating its post-quantum roadmap and now targets 2029 to achieve full post-quantum security, explicitly including post-quantum authentication. The company already enabled post-quantum encryption for the majority of human traffic to mitigate harvest-now/decrypt-later risks, but new algorithmic and hardware advances (notably Google’s reported speedups and Oratomic’s neutral-atom estimates) make authentication the urgent priority. Cloudflare will enable PQ defaults for customers at no extra cost.
read more →