< ciso
brief />
Tag Banner

All news with #post quantum cryptography tag

129 articles · page 3 of 7

FortiOS 8.0: Unified Security for AI and Quantum Era

🔒 FortiOS 8.0 delivers a unified operating system to simplify security and networking across hybrid, multi-cloud, and IT/OT environments. The release consolidates controls through the Fortinet Security Fabric and adds features such as SASE Outpost, Sovereign SASE, unified SD‑WAN, and multipath IPsec for resilient connectivity. It also extends OT support and compliance with standards like NERC CIP and IEC 62443. Key risk-focused updates include MCP observability, image OCR in FortiGuard DLP, agentic AI automation, and FIPS 204/205 hybrid cryptography to mitigate quantum risk.
read more →

Google Aims to Shift to Post-Quantum Cryptography by 2029

🔒 Google announced a plan to complete a transition to post-quantum cryptography across its services by 2029. Security expert Bruce Schneier welcomes the decision, arguing the primary benefit is improved crypto-agility rather than an imminent quantum threat. The timeline allows Google to test implementations, assess performance and interoperability impacts, and coordinate with evolving standards. Early adoption can reduce the risk of retrospective decryption and signals leadership that may accelerate broader industry migration.
read more →

Turing Award Honors Inventors of Quantum Cryptography

🔬 Charles Bennett and Gilles Brassard have been awarded the 2026 Turing Award for inventing quantum cryptography. Bruce Schneier welcomes the recognition but reiterates his view that, while scientifically impressive, the technology is largely unnecessary for most practical security problems. In a 2008 essay, he argued that quantum key exchange doesn’t address the usual weak points of systems and that effort is better spent on system-level security and crypto agility.
read more →

Google Warns: Quantum Threat to Encryption by 2029

🔒 Google warns that advances in quantum computing could render widely used public-key cryptography vulnerable as early as 2029, increasing the risk of store-now-decrypt-later attacks. The company points to progress in quantum hardware, error correction and factoring resource estimates that compress migration timelines. To reduce exposure, Google will include post-quantum digital signature protection in Android 17, aligned with NIST recommendations. It urges organizations to treat post-quantum cryptography migration as an immediate operational priority rather than a distant compliance task.
read more →

Google Accelerates Post-Quantum Migration Deadline to 2029

🔒Google announced it is accelerating its post-quantum cryptography migration, setting 2029 as the new target to phase out quantum-vulnerable algorithms and prioritizing PQC for authentication services. The company cites rapid improvements in quantum hardware, error correction and algorithmic estimates that drastically reduce the qubit requirements to break common asymmetric encryption. Google urged other engineering teams and hyperscalers to follow suit, warning that adversaries may already be collecting encrypted data for future decryption.
read more →

ThreatsDay Bulletin: PQC Push, AI Bugs, Pirated Backdoors

🔔 This week’s ThreatsDay Bulletin captures a quieter, sneakier cadence: big-picture progress on cryptography and AI set against a steady churn of pragmatic abuse. Google accelerated a PQC migration to 2029 and GitHub is bringing AI-powered detections into the PR workflow, while threat actors keep innovating around trust — using pirated ISOs, fake extensions, firmware implants and clever phishing to scale backdoors, credential theft and fraud. The common thread is operational efficiency: takedowns and disruptions are temporary, but the workflows keep returning.
read more →

Android 17 Adopts NIST Post-Quantum Standards Platform

🔒 Google is introducing post-quantum cryptography support in Android 17, integrating NIST’s lattice-based standards into boot, keystore, and app signing to establish a quantum-resistant chain of trust. The release adds ML-DSA to Android Verified Boot and migrates KeyMint certificate chains and Remote Attestation toward PQC compliance. Developers gain native support for ML-DSA-65 and ML-DSA-87 via the KeyPairGenerator API, and Google Play will offer hybrid APK signing with keys managed by Google Cloud KMS to preserve compatibility during migration.
read more →

Google Sets 2029 Timeline for Post-Quantum Migration

🔐 Google announces a company-wide timeline targeting 2029 for migration to post-quantum cryptography (PQC) to protect against future quantum threats. The timeline reflects advances in quantum hardware, error correction, and factoring estimates, and prioritizes PQC for authentication services to guard digital signatures. Google cites ongoing integrations — including Android 17 using ML-DSA, Chrome support, and Cloud offerings — as concrete commitments and urges other teams and organizations to accelerate their own migrations.
read more →

Cryptographic Reset: Operational Shifts in Trust Now

🔐 The cryptographic foundation of the internet is undergoing a rapid operational reset driven by shorter certificate lifecycles and the transition to quantum-resistant algorithms. The CA/Browser Forum reduced public TLS validity to 200 days on March 15, 2026, with further reductions planned to 100 days in 2027 and 47 days by 2029, dramatically increasing renewal velocity. Manual certificate processes and spreadsheets will not scale; organizations need network-native discovery, continuous certificate visibility, and fully automated lifecycle management. Palo Alto Networks' Next-Generation Trust Security brings certificate lifecycle controls into the network to automate discovery, renewal, deployment and governance.
read more →

Post-Quantum Roadmap for US Enterprises Targeting 2030

🔒 US organizations should begin operationalizing post-quantum cryptography now to protect long-lived secrets and meet an emerging 2030 readiness horizon. With NIST finalizing initial PQC standards in 2024 and agencies like NSA and CISA aligning guidance, a pragmatic hybrid strategy—pairing existing classical algorithms (ECDHE/TLS) with post-quantum primitives such as ML-KEM—reduces long-term confidentiality risk while preserving interoperability. Start with a comprehensive crypto inventory tied to data value, pilot internal mTLS, VPN and code-signing migrations in a lab, improve crypto agility, add telemetry for rollout metrics, and add PQC requirements into procurement to buy time and avoid last-minute disruption.
read more →

China Plans National Post‑Quantum Cryptography Standards

🔒China is planning to develop national post-quantum cryptography standards within three years, prioritizing finance and energy for early migration. Chinese experts say they favor structureless lattice algorithms over the algebraic lattice designs adopted elsewhere, arguing better long-term security. Organizations should begin hybrid deployments now to reduce 'harvest now, decrypt later' risk and to maintain flexibility for future compliance.
read more →

Possible Quantum Speedup for Factoring: Skeptical View

🔬 The author expresses skepticism and notes they are not qualified to fully evaluate a newly announced claim of improved quantum factoring. If validated, the finding would represent a theoretical improvement in the speed of factoring large integers with a quantum computer. The post emphasizes that the result is currently unverified and that practical consequences for deployed cryptography remain uncertain. Further expert review, replication, and analysis are necessary to determine any real-world impact.
read more →

Infosecurity Europe 2026 unveils keynote line-up and panels

🎤 Infosecurity Europe 2026 has revealed a major keynote programme for its 2–4 June event at ExCeL London, featuring industry founders, former intelligence leaders and elite-sport figures. Shlomo Kramer and Cynthia Kaiser headline Tuesday with sessions on technology trends and the ransomware economy, respectively, while Jason Fox will open Thursday with a resilience and decision-making keynote. Technical talks will address AI-driven cloud threats and preparations for post-quantum cryptography.
read more →

AWS IAM Roles Anywhere Adds Post-Quantum ML-DSA Support

🔐 AWS Identity and Access Management (IAM) Roles Anywhere now supports the FIPS 204 Module-Lattice Digital Signature Standard (ML-DSA), a NIST-standardized, quantum-resistant digital signature algorithm. Customers can register ML-DSA-signed CA certificates as IAM Roles Anywhere trust anchors or reference AWS Private Certificate Authority instances, and issue end-entity X.509 certificates bound to ML-DSA keys. The capability is available in all Regions where IAM Roles Anywhere operates, including AWS GovCloud (US), the AWS European Sovereign Cloud (Germany), and China Regions.
read more →

Vendors Race to Define Post-Quantum Cryptography Roadmap

🔐 Security vendors are reframing post-quantum cryptography (PQC) from a theoretical concern into an operational priority, emphasizing discovery, inventory, and crypto-agility across enterprise environments. Companies such as Palo Alto Networks, Cisco, and Cloudflare are packaging visibility, assessment, and compensating-controls while specialist firms like SandboxAQ deliver continuous monitoring via AQtive Guard. With NIST standards finalized and a 2030 readiness horizon, vendors stress phased migration and prioritization for long-lived sensitive data. The market is competitive as providers position to guide enterprises through complex modernization and legacy constraints.
read more →

U.S. Cyber Strategy Prioritizes Offensive Operations

⚔️ The White House released a concise seven-page cybersecurity strategy developed by the Office of the National Cyber Director that places offensive cyber operations at the center of U.S. policy while also pushing deregulation and accelerated AI adoption. It articulates six implementation pillars including shaping adversary behavior, modernizing federal networks with AI and zero-trust, securing critical infrastructure, and building workforce capacity. Industry responses were broadly positive from vendors emphasizing AI and quantum-safe security, but defenders warn the emphasis on proactive offense and deregulatory moves could raise escalation and resilience concerns.
read more →

National Cyber Strategy: Securing America's Digital Future

🔐 The U.S. National Cyber Strategy offers a clear, action-oriented agenda to protect the digital way of life by emphasizing disruption of hostile actors, streamlined regulation, federal network modernization, and the security of AI and quantum technologies. Palo Alto Networks endorses the strategy and highlights practical measures—such as reciprocity for government software certifications, a four-stage quantum-safe framework, and its Secure AI by Design Policy Roadmap—to help operationalize these priorities through public–private collaboration.
read more →

Preparing for the Quantum Era: Post-Quantum Strategies

🔒 Security leaders face a growing threat from harvest now, decrypt later attacks as quantum computing progresses. A webinar will outline practical steps—identify long-term sensitive data, map encryption use, and adopt hybrid cryptography such as ML-KEM alongside existing algorithms—to begin transitioning without operational disruption. The session also covers post-quantum traffic inspection and Zero Trust integration to maintain policy enforcement at scale.
read more →

GCOT Issues Security and Resilience Principles for 6G

🛡️ The Global Coalition on Telecoms (GCOT) has released voluntary 6G Security and Resilience Principles to guide the early development of next-generation mobile networks. Founded by Australia, Canada, Japan, the UK and the US, and joined by Finland and Sweden at Mobile World Congress 2026, the framework was published with industry partners including AT&T, Ericsson, NVIDIA and Nokia. The guidelines define four security and four resilience objectives—covering containment, confidentiality, integrity, resilience and regulatory compliance—to inform standards, supply-chain practices and network architectures ahead of anticipated 6G rollouts in 2029–2030.
read more →

Google unveils Merkle Tree Certificates for Post‑Quantum TLS

🔐 Google is developing Merkle Tree Certificates (MTCs) in Chrome to make HTTPS certificates resilient to future quantum attacks while avoiding the bandwidth cost of adding post‑quantum algorithms to traditional X.509 chains. Working with Cloudflare and the PLANTS working group, Chrome proposes a model where a CA signs a single tree head and browsers receive lightweight proofs of inclusion. Google is running a feasibility study (Phase 1), plans to invite compatible Certificate Transparency logs in Q1 2027 (Phase 2), and aims to finalize requirements and launch a Chrome Quantum‑resistant Root Store (CQRS) and MTC-only root program by Q3 2027.
read more →