< ciso
brief />
Tag Banner

All news with #post quantum cryptography tag

151 articles · page 5 of 8

GCOT Issues Security and Resilience Principles for 6G

🛡️ The Global Coalition on Telecoms (GCOT) has released voluntary 6G Security and Resilience Principles to guide the early development of next-generation mobile networks. Founded by Australia, Canada, Japan, the UK and the US, and joined by Finland and Sweden at Mobile World Congress 2026, the framework was published with industry partners including AT&T, Ericsson, NVIDIA and Nokia. The guidelines define four security and four resilience objectives—covering containment, confidentiality, integrity, resilience and regulatory compliance—to inform standards, supply-chain practices and network architectures ahead of anticipated 6G rollouts in 2029–2030.
read more →

Google unveils Merkle Tree Certificates for Post‑Quantum TLS

🔐 Google is developing Merkle Tree Certificates (MTCs) in Chrome to make HTTPS certificates resilient to future quantum attacks while avoiding the bandwidth cost of adding post‑quantum algorithms to traditional X.509 chains. Working with Cloudflare and the PLANTS working group, Chrome proposes a model where a CA signs a single tree head and browsers receive lightweight proofs of inclusion. Google is running a feasibility study (Phase 1), plans to invite compatible Certificate Transparency logs in Q1 2027 (Phase 2), and aims to finalize requirements and launch a Chrome Quantum‑resistant Root Store (CQRS) and MTC-only root program by Q3 2027.
read more →

Chrome adopts Merkle Tree Certificates for quantum HTTPS

🔐 Chrome has launched an initiative to protect HTTPS from future quantum threats by redesigning certificate mechanics with Merkle Tree Certificates (MTCs). Rather than enlarging X.509 certificates, MTCs use compact Merkle proofs and a single signed tree head to authenticate sites, reducing TLS handshake data and embedding transparency into issuance. Chrome is testing MTCs with Cloudflare and plans a phased rollout through 2027.
read more →

Chrome: Merkle Tree Certificates for quantum-safe HTTPS

🔐 Chrome announces a staged program to support quantum-resistant HTTPS by adopting Merkle Tree Certificates (MTCs), which replace long X.509 signature chains with compact Merkle inclusion proofs. The approach reduces bandwidth costs and decouples cryptographic strength from transmitted size, preserving TLS performance. Chrome is testing MTCs with Cloudflare and plans phased deployment with a new Chrome Quantum-resistant Root Store.
read more →

Cloudflare Radar: origin PQ, Key Transparency, ASPA

🔐 Cloudflare Radar is adding three security-focused datasets and tools: origin-facing post-quantum (PQ) monitoring, a Key Transparency dashboard for E2EE messaging logs, and enhanced RPKI ASPA adoption tracking. The origin feature reports support for X25519MLKEM768 using an automated TLS scanner and provides an on-demand hostname tester that performs real TLS handshakes via Cloudflare Containers. Key Transparency publishes auditor verification status and APIs for independent proof checks, while routing pages gain global, country, and per-AS ASPA views together with API access for integrations.
read more →

Prepare Now for Post-Quantum Cryptography Migration

🔐 The article warns that patient adversaries follow a "Harvest Now, Decrypt Later" strategy and urges organizations to begin Post-Quantum Cryptography (PQC) migration immediately to protect long-lived data. It prescribes a five-phase migration framework—Preparation, Diagnosis, Planning, Execution, and Continuous Monitoring—and recommends hybrid deployments to retain compatibility. Practical guidance covers asset inventories, risk prioritization (Mosca's Theorem), vendor engagement, and adopting cryptographic agility with references to ML-KEM, TLS, and NIST/CISA guidance.
read more →

Cloudflare One delivers post-quantum SASE with ML-KEM

🔐 Cloudflare One is the first SASE platform to deliver standards-compliant post-quantum encryption across Secure Web Gateway, Zero Trust, and WAN services. It implements hybrid ML-KEM across TLS, MASQUE and IPsec on- and off-ramps and upgraded the Cloudflare One Appliance (v2026.2.0 GA). Cloudflare IPsec support for hybrid ML-KEM is in closed beta—contact pq-wan@cloudflare.com for access.
read more →

Cybersecurity Priorities for 2026: Resilience by Design

🧭In 2026 cybersecurity shifts from episodic defense to continuous operational resilience. Regulation, geopolitics and AI now shape architecture and controls, forcing cryptographic agility, continuous Zero Trust decisioning and lifecycle security across cloud and supply chains. Organizations must make attacker intelligence unreliable through deception, Automated Moving Target Defense and Continuous Threat Exposure Management while embedding AI into detection, response and governance.
read more →

Resilience in the AI Era: Google's Call at MSC 2026

🔒 At the 62nd Munich Security Conference, Kent Walker (President, Google & Alphabet) argued that fragmented defenses are inadequate against AI-accelerated cyber threats and the near-term risk from cryptographically relevant quantum computing. Google highlighted GTI findings that adversaries are automating reconnaissance and producing hyper-realistic phishing, and showcased the Ukrainian startup LetsData, which uses AI to scan multilingual media and detect InfoOps at scale. To scale defender advantages, Google launched the Gemini Startup Forum: Cybersecurity and promotes deployment options such as Google Distributed Cloud Air-Gapped for sovereign, secure use of its infrastructure. Walker urged governments, industry, and vendors to adopt a full-stack, collaborative approach—breaking silos and modernizing procurement—to build shared digital resilience.
read more →

BSI Sets Deadlines to Phase Out Classical Encryption

🔒 The Federal Office for Information Security (BSI) has updated its technical guideline TR-02102, establishing concrete deadlines to end the sole use of classical asymmetric encryption: from 2031 generally and for high-security systems from the end of 2030. The guideline mandates hybrid configurations that combine traditional algorithms with post-quantum cryptography and schedules deprecation of conventional signature algorithms for sole use by 2035. TR-02102 is divided into parts addressing algorithm/key guidance, TLS, IPsec/IKEv2, and SSH, and is a reference for developers and mandatory for certain classified-product deployments.
read more →

Why Key Management Is the Weakest Link in Crypto Operations

🔐 Key management — the lifecycle discipline governing key generation, storage, rotation and destruction — has become the weakest operational link as organizations race toward post-quantum and AI-driven systems. While public debate centers on algorithms, real failures stem from long-lived keys, unclear ownership, manual rotation and untested recovery. AI pipelines and autonomous agents amplify these risks, so teams must adopt short-lived, purpose-bound keys, automated rotation and practiced cryptographic incident response.
read more →

Helping Democracies Stay Ahead of Digital Threats Now

🛡️ This week at the Munich Security Conference, Google Cloud released a whitepaper, "Staying Ahead of the Shadows: Digital Resilience in the Era of AI," that outlines current digital threats and recommends a unified, full‑stack defense to help democracies. It highlights supply‑chain targeting, employee‑focused manipulation, and sustained China‑nexus espionage. The paper prescribes a five‑layer resilience model — Infrastructure, Architecture, Models, Applications, and Security — supported by technologies such as Gemini, Workspace, CodeMender, SAIF, and post‑quantum cryptography.
read more →

CISOs: Move Beyond Compliance to Anticipate Risk in 2026

🔒 CISOs entering 2026 should treat compliance as a baseline, not a destination. While frameworks like HIPAA, SOC 2 and ISO 27001 provide essential controls, relying solely on checklists breeds complacency and misses evolving threats such as AI-enabled attacks, third-party failures and future quantum risks. Adopt longer time horizons, scenario-based risk assessments and financial impact modelling to align security with business priorities and secure board support.
read more →

Gartner: Six Cybersecurity Trends Shaping 2026 Priorities

🔒 Gartner identifies six priority cybersecurity trends for 2026 that demand immediate attention from security and risk leaders. Key risks include uncontrolled agentic AI proliferation, global regulatory volatility, and the urgent need to plan for post-quantum cryptography. Gartner advises stronger governance to detect and control both approved and shadow AI agents, evolve identity and access management for machine actors, modernize SOCs with human-in-the-loop processes, and shift awareness programs toward task-focused, AI-specific behavioral training.
read more →

Preparing for the Quantum Era: A Call to Secure PQC

🔐 Google issues a call to action to protect digital systems against quantum threats, outlining its post-quantum cryptography (PQC) work and policy recommendations. The company warns that large-scale quantum computers could break current public-key cryptography and cautions about 'store now, decrypt later' harvesting of encrypted data. Google commits to research transparency, completing PQC migrations within NIST guidelines, and strengthening crypto agility, critical shared infrastructure, and ecosystem readiness.
read more →

AI Meets Quantum Computing: The Next Security Battlefield

⚛️ Quantum computing paired with AI promises transformative gains in processing speed and machine learning capacity, enabling tasks—such as real-time climate modelling and instant financial simulations—that classical infrastructure struggles to deliver. At the same time, the article warns that quantum-enabled attacks could undermine widely used cryptosystems like RSA, ECC and AES, creating a disruptive Q-Day when encrypted confidentiality is at risk. Governments and enterprises are already staging migrations to post-quantum cryptography and updating governance and observability, but the piece stresses that building trust, ethical AI oversight and resilient frameworks will be essential to preserve digital privacy and integrity.
read more →

ThreatsDay: Small Shifts, Big Cybersecurity Risks Ahead

🔎 This week's ThreatsDay bulletin highlights quiet but meaningful shifts where familiar tools and trusted platforms are repurposed to breach access, steal data, or launder funds. Law enforcement seized the RAMP forum while threat actors pivot to alternatives, creating operational churn and new exposures. Guidance from CISA on post‑quantum cryptography and urgent patches for Linux and Dormakaba systems underscore near‑term priorities amid rising phishing, supply‑chain, and ransomware activity.
read more →

Palo Alto Introduces Quantum-Safe Security to Mitigate Risk

🔒 Palo Alto Networks unveiled Quantum-Safe Security to help organizations transition to post-quantum cryptography without disrupting operations. It provides continuous, real-time cryptographic visibility by collecting telemetry from PAN-OS NGFW, Prisma Access and third-party tools to catalog certificates, algorithms, key exchanges and libraries. The solution prioritizes harvest now, decrypt later risks, guides staged remediation including hybrid algorithms and real-time encryption translation for legacy systems, and automates governance and compliance. Integration with SIEM, EDR and other systems supports gradual migration across complex environments.
read more →

Public Sector Cyber Outlook 2026: Identity and AI Trust

🔒 AI integration has shifted public-sector cybersecurity in 2026, forcing agencies to adopt AI-native detection and autonomous response, continuous identity verification, and secure-by-design AI deployments. Nation-state actors now automate intrusion, deception, and tailored malware, expanding risk to IT, OT and research environments. Agencies must consolidate platforms, accelerate post-quantum planning, and govern AI at mission scale.
read more →

Palo Alto Networks Introduces Quantum-Safe Security

🔐 Palo Alto Networks announced Quantum-Safe Security, a continuous solution to discover, assess and remediate enterprise cryptographic risk as organizations migrate to post-quantum standards. The offering ingests telemetry from PAN-OS NGFW, Prisma Access and third-party systems to build a real-time Cryptographic Bill of Materials (CBOM), prioritize harvest-now, decrypt-later exposure, and automate remediation—including cipher translation at the network edge. General availability is expected on January 30, 2026.
read more →