Latest Quantum Security, PQC, Post-Quantum, Crypto-Agility News
-
Oct- 2026 -2 OctoberQuantum Security & PQC
Germany’s BSI Advises Against New Classic McEliece Deployments After Researchers Estimate Key Recovery Below Its Claimed Security Levels
Less than two months after a new Classic McEliece distinguisher appeared, three research groups estimate key recovery below every claimed security level, and Germany's federal cybersecurity agency wants no new projects built on it. No practical attack exists yet.
Read More » -
Sep- 2026 -23 SeptemberQuantum Security & PQC
China’s Next-Generation Crypto Candidates Drew 104 Public Findings in Three Days. Researchers Broke Five Designs on Day Two
Within three days of China publishing its first-round candidates, public reports listed 104 findings against 65 of them. Saarinen's AI-assisted sweep found code bugs; researchers posting to ICCS's own forums found the design breaks.
Read More » -
21 SeptemberQuantum Security & PQC
FIPS 140-2 Goes Historical Today – What Actually Changes and What Doesn’t
Every remaining FIPS 140-2 certificate moves to the CMVP Historical list on September 21, 2026. The sunset changes procurement, not operations – but the supply-side gap in FIPS 140-3 validated modules makes the transition harder than the seven-year runway implied.
Read More » -
21 SeptemberQuantum Security & PQC
Apple Joins the Merkle Tree Certificate Consensus – and Raises the Bar
Apple's Root Program has committed to Merkle Tree Certificates for TLS with requirements that go beyond Chrome's in key respects, while taking the composite-algorithm path for S/MIME – confirming the two-track PKI fork organizations must plan for.
Read More » -
19 SeptemberQuantum Security & PQC
RSA-896 Factored With Claude on Spare GPUs, 16 Days After RSA-260
Stephen Weis of Anthropic used Claude to port CADO-NFS to GPUs and factored RSA-896 on idle capacity, 16 days after Cognition's RSA-260 record. RSA-2048 remains about 35 billion times harder and needs a quantum computer.
Read More » -
18 SeptemberQuantum Computing
Every Headline RSA-2048 Estimate Assumes Qubits That Work. A Sydney Team Measured What Happens When They Don’t.
On a single IBM chip, a distance-5 surface code lost to a distance-3 even after the defective components were routed around. The headline estimates of what breaking RSA-2048 takes assume they all work.
Read More » -
11 SeptemberQuantum Security & PQC
Cloudflare’s 1.1.1.1 Now Validates Post-Quantum DNSSEC Signatures – And Shows Why PQC Migration Is a Systems Problem
Cloudflare enabled ML-DSA-44 DNSSEC validation on its 1.1.1.1 resolver. No other major public resolver has announced equivalent support. The move exposes transport, downgrade, and chain-of-trust challenges that will define PQC migration beyond TLS.
Read More » -
10 SeptemberResearch
Chip-Based QKD Has a Glow Problem: VOA Luminescence Creates a Side Channel That Standard Security Analyses Miss
A peer-reviewed study finds that variable optical attenuators in integrated QKD chips emit unintended light near 1107 nm. The emission creates a wavelength-resolved side channel that standard BB84 security analyses do not account for, and the modeled impact on key rates is severe.
Read More » -
8 SeptemberQuantum Security & PQC
Altera Ships ML-DSA Secure Boot on Agilex FPGAs – PQC Reaches the Silicon Root of Trust
Altera began shipping ML-DSA secure boot on its Agilex 3 and Agilex 5 FPGAs on September 8, 2026 – the first general-purpose FPGA family with post-quantum firmware authentication as a production feature, not a roadmap item.
Read More » -
8 SeptemberResearch
IonQ Compiles Shor’s Attack on secp256k1 Down to 19,397 Ions and 26 Days per Attempt
IonQ has compiled a full ECDLP-256 attack to a trapped-ion design that does not exist, charging every Clifford, measurement and ion transport. The accounting is the most detailed I have seen. The error rates, cycle time and machine are assumptions.
Read More » -
4 SeptemberQuantum Security & PQC
Cognition’s Devin Built a GPU Number Field Sieve and Factored RSA-260, Cutting the Price of Breaking RSA-1024 to $30 Million
Eric Lu of Cognition had the Devin agent build a GPU version of CADO-NFS and factored the 862-bit RSA-260 on idle cluster capacity, for about $400,000 of GPU time. Factoring RSA-1024 would cost about $30 million, by his estimate.
Read More » -
4 SeptemberQuantum Security & PQC
G7 Tells Every Organization to Start PQC Migration – But the Procurement Signal Matters More Than the Headline
The G7 Cybersecurity Working Group's September 2026 call to action urges all organizations to begin PQC migration. The document is guidance, not regulation, but its procurement and supply chain language carries real consequences for enterprises and their vendors.
Read More » -
Aug- 2026 -29 AugustQuantum Security & PQC
First Quantum-Safe Bitcoin Transaction: What QSB Proves
The first quantum-safe Bitcoin transaction was confirmed on mainnet on 26 August, built by StarkWare's Avihu Levy using hash-based constructions within existing consensus rules. The method protects individual holdings but cannot help the six million BTC with public keys already exposed on-chain.
Read More » -
17 AugustQuantum Security & PQC
An Incomplete FO Check Turned wolfSSL’s ML-KEM Into Key Recovery
A researcher recovered 98% of an ML-KEM-1024 private key from wolfSSL's shipped binaries using a few hundred chosen ciphertexts. The bug was in hand-written SIMD assembly, patched in version 5.9.2.
Read More » -
15 AugustQuantum Security & PQC
The Ethereum Foundation Spent Eight Years on a Hash Its Roadmap No Longer Needs
Binary-field proof systems made standard hashes cheap enough to prove that Ethereum's exotic one lost its reason to exist. Nobody broke it. An eight-year research bet was retired in a single post.
Read More »
