Visualização normal

Ontem — 7 de Setembro de 2026Stream principal
  • ✇Firewall Daily – The Cyber Express
  • G7, CISA Urge Urgent Shift to Post-Quantum Cryptography Samiksha Jain
    Some of the world's leading democracies are pushing governments and companies to start preparing for post-quantum cryptography before quantum computers become powerful enough to break the encryption systems that protect global digital infrastructure today. In a joint advisory released Thursday, the G7 Cybersecurity Working Group and the U.S. Cybersecurity and Infrastructure Security Agency (CISA) said organizations should begin their transition to post-quantum cryptography now, rather than wait
     

G7, CISA Urge Urgent Shift to Post-Quantum Cryptography

7 de Setembro de 2026, 03:51

post-quantum cryptography

Some of the world's leading democracies are pushing governments and companies to start preparing for post-quantum cryptography before quantum computers become powerful enough to break the encryption systems that protect global digital infrastructure today.

In a joint advisory released Thursday, the G7 Cybersecurity Working Group and the U.S. Cybersecurity and Infrastructure Security Agency (CISA) said organizations should begin their transition to post-quantum cryptography now, rather than waiting until cryptographically relevant quantum computers (CRQCs) are available to threat actors.

Why the Post-Quantum Cryptography Shift Cannot Wait

The publication, titled "Preparing for the Post-Quantum Era: A Call to Action," warns that the quantum computing threat is no longer a distant concern. While the exact timeline for CRQC development remains uncertain, the working group said recent technological advances suggest such machines could emerge sooner than expected, putting widely used public-key cryptography mechanisms at risk.

One of the most immediate dangers is a tactic known as "harvest now, decrypt later," where malicious actors intercept and store encrypted data today with the intention of decrypting it once a CRQC becomes available. This poses a serious risk to governmental records, sensitive personal data, and trade or business secrets that require long-term confidentiality.

The advisory also cautions that CRQCs could eventually be used to target authentication mechanisms, allowing bad actors to impersonate trusted entities, forge data, or compromise equipment. Because supply chain vulnerabilities can cascade, a single organization's delay in adopting post-quantum cryptography could expose entire sectors to compromise.

According to the report, organizations that fail to act may also face business consequences beyond security risk, including exclusion from public procurement contracts and loss of competitive advantage.

Five Priorities for the PQC Transition

The G7 Cybersecurity Working Group outlined five priority areas to guide the global shift toward post-quantum cryptography:

  1. Raising awareness — Many organizations still view the quantum threat as a distant or purely technical issue. The group called for awareness campaigns, technical guidance, and workforce upskilling to reframe it as an economic and business risk.
  2. Developing national strategies — Countries are encouraged to build strategies that ensure an adequate supply of quantum-safe hardware and software while encouraging adoption, integrating the effort into broader digital privacy and security policies.
  3. Advancing research and development — Governments should fund research programs and support pilot projects and testbeds to help organizations test and refine their transition to post-quantum cryptography.
  4. Building public-private partnerships — Collaboration between government, industry, and academia is seen as key to developing domestic expertise, lowering transition costs, and sharing playbooks and case studies across sectors.
  5. Integrating PQC into cybersecurity requirements — The group recommends treating post-quantum cryptography adoption as a natural evolution of cryptographic best practice, and embedding requirements into public procurement to push both vendors and organizations toward quantum-safe systems.

The advisory emphasizes that the shift to post-quantum cryptography cannot be solved by individual organizations in isolation. Instead, it calls for early engagement, coordinated planning, and informed decision-making across public and private sectors worldwide.

Tackling the risks that the impending quantum computing era poses to current cryptographic systems... requires a coordinated global effort to transition to PQC," the report states, adding that public and private organizations must act now to safeguard confidential data, supply chains, and critical systems.

The document was jointly published by cybersecurity authorities from Canada, Germany, Italy, Japan, the United Kingdom, the United States, and France's ANSSI, with participation from the European Commission and support from the EU Agency for Cybersecurity (ENISA).

Antes de ontemStream principal
  • ✇Schneier on Security
  • Python Now Has a Post-Quantum Encryption Library Bruce Schneier
    This is good: Post-quantum cryptography is now one pip-install away for the entire Python ecosystem. With funding from the Sovereign Tech Agency, we implemented support for ML-KEM, the NIST-standard key-establishment primitive, and ML-DSA, the NIST-standard digital-signature primitive, in pyca/cryptography. Remember, the reason to do this now is because there’s no emergency. And because you will make your systems crypto agile, which is always a good idea.
     

Python Now Has a Post-Quantum Encryption Library

10 de Agosto de 2026, 08:02

This is good:

Post-quantum cryptography is now one pip-install away for the entire Python ecosystem. With funding from the Sovereign Tech Agency, we implemented support for ML-KEM, the NIST-standard key-establishment primitive, and ML-DSA, the NIST-standard digital-signature primitive, in pyca/cryptography.

Remember, the reason to do this now is because there’s no emergency. And because you will make your systems crypto agile, which is always a good idea.

  • ✇Firewall Daily – The Cyber Express
  • Q-Day Could Arrive by 2029, Raising Global Encryption Security Fears Ashish Khaitan
    For decades, cybersecurity researchers and computer scientists have warned about a future moment known as “Q-Day” — the point at which quantum computing becomes powerful enough to break the encryption systems that currently protect the world’s digital infrastructure. What once sounded like a distant theoretical concern is now being treated as an increasingly urgent reality. According to recent projections from Google, Q-Day could arrive as early as 2029, significantly earlier than many exper
     

Q-Day Could Arrive by 2029, Raising Global Encryption Security Fears

Q-Day

For decades, cybersecurity researchers and computer scientists have warned about a future moment known as “Q-Day” — the point at which quantum computing becomes powerful enough to break the encryption systems that currently protect the world’s digital infrastructure. What once sounded like a distant theoretical concern is now being treated as an increasingly urgent reality. According to recent projections from Google, Q-Day could arrive as early as 2029, significantly earlier than many experts had previously estimated.  The accelerated timeline has intensified concerns across governments, technology companies, and cybersecurity agencies, all of which now face mounting pressure to prepare for the disruptive impact quantum computing could have on global data security. 

What Is Q-Day in Quantum Computing? 

Q-Day refers to the hypothetical moment when quantum computers gain enough computational power, resources, and stability to crack modern cryptographic systems. Most online security today relies on encryption methods that are considered practically impossible for classical computers to break within a reasonable timeframe. However, advances in quantum computing could change that equation entirely.  Unlike traditional computers, which process information in binary bits represented as zeros and ones, quantum computing systems use quantum-mechanical properties to process information in fundamentally different ways. This allows quantum computers to solve highly complex calculations far more efficiently than even today’s most advanced supercomputers.  One of the biggest concerns surrounding Q-Day involves RSA cryptography, a widely used encryption method based on the mathematical difficulty of factoring large prime numbers. RSA encryption currently protects everything from online banking and email communication to medical records and cryptocurrency wallets. Experts fear that sufficiently advanced quantum computing systems could eventually crack RSA encryption not over billions of years, but potentially within hours or days. If Q-Day arrives before organizations transition to safer encryption standards, the consequences could be severe. Financial transactions, personal emails, medical data, location histories, and sensitive government information protected by today’s cryptographic algorithms could become vulnerable to exposure. 

Why the Timeline for Q-Day Has Shifted 

For many years, the consensus within the cybersecurity community was that Q-Day remained decades away. That assumption gave governments and private companies time to develop and implement stronger protections before quantum computing capabilities matured. However, Google’s recent assessment suggesting Q-Day may emerge by 2029 has significantly altered that outlook. The revised estimate has prompted warnings that organizations may have far less time than expected to prepare for the transition to quantum-resistant cybersecurity systems. The growing concern has drawn comparisons to Y2K, also known as the millennium bug, when programmers feared that computer systems worldwide could malfunction after Dec. 31, 1999. While Y2K ultimately caused limited disruption due to extensive preparation efforts, cybersecurity experts believe Q-Day could pose a far more complex and enduring challenge because it directly threatens the encryption systems underpinning modern digital communication. Some researchers are also worried about a strategy known as “harvest now, decrypt later.” Under this scenario, malicious actors may already be collecting encrypted information today with the intention of decrypting it once quantum computing becomes sufficiently advanced. Even if current encryption cannot yet be broken, sensitive information stolen now could become readable in the future after Q-Day arrives.

The Push Toward Post-Quantum Cryptography 

As fears surrounding quantum computing grow, cybersecurity experts are urging organizations to begin transitioning toward post-quantum cryptography. These newer encryption methods are specifically designed to resist attacks from quantum computers. Google has been advocating for broader adoption of quantum-resistant algorithms and has introduced guidelines intended to accelerate digital security upgrades across the technology industry. The goal is to help companies prepare their infrastructure before Q-Day becomes reality. At the same time, cryptographers have been developing alternative encryption algorithms based on mathematical problems that quantum computers are not believed to solve efficiently. Several of these proposed standards have already advanced through evaluation processes conducted by the National Institute of Standards and Technology (NIST), which has identified multiple algorithms currently considered secure against quantum computing threats. Despite these efforts, experts caution that no encryption system can be viewed as permanently secure. As one assessment noted, encryption functions more like a “time-locked safe” than an impenetrable barrier — secure only until someone eventually discovers the combination.

Governments Are Accelerating Quantum Readiness Plans 

Government agencies have also begun preparing for the possibility of Q-Day. In 2022, the National Security Agency (NSA) announced plans aimed at improving national quantum readiness throughout the 2030s. More recently, both the Biden and Trump administrations issued executive orders emphasizing the importance of preparing U.S. infrastructure for quantum computing risks. The NSA is currently working toward a 2031 deadline for strengthening systems against potential quantum-based cybersecurity threats. However, officials acknowledge that the timeline remains fluid as advancements in quantum computing continue to evolve rapidly. Whether those estimates ultimately prove accurate or not, the growing momentum behind quantum computing research has made one thing increasingly clear: Q-Day is no longer viewed as a distant science-fiction scenario. Instead, it is becoming a serious cybersecurity challenge that governments, corporations, and researchers are racing to address before current encryption systems become obsolete.

The Race to Quantum-Proof the Internet Has Already Begun

The race to quantum-proof the internet is underway as experts warn of “harvest now, decrypt later” risks and slow migration to post-quantum security.

Google Wants to Transition to Post-Quantum Cryptography by 2029

6 de Abril de 2026, 07:52

Google says that it will fully transition to post-quantum cryptography by 2029. I think this is a good move, not because I think we will have a useful quantum computer anywhere near that year, but because crypto-agility is always a good thing.

Slashdot thread.

  • ✇Security Boulevard
  • Inventors of Quantum Cryptography Win Turing Award Bruce Schneier
    Charles Bennett and Gilles Brassard have won the 2026 Turing Award for inventing quantum cryptography. I am incredibly pleased to see them get this recognition. I have always thought the technology to be fantastic, even though I think it’s largely unnecessary. I wrote up my thoughts back in 2008, in an <a href+https://www.schneier.com/essays/archives/2008/10/quantum_cryptography.html”>essay titled “Quantum Cryptography: As Awesome As It Is Pointless.” Back then, I wrote: While I like the
     

Inventors of Quantum Cryptography Win Turing Award

31 de Março de 2026, 08:05

Charles Bennett and Gilles Brassard have won the 2026 Turing Award for inventing quantum cryptography.

I am incredibly pleased to see them get this recognition. I have always thought the technology to be fantastic, even though I think it’s largely unnecessary. I wrote up my thoughts back in 2008, in an <a href+https://www.schneier.com/essays/archives/2008/10/quantum_cryptography.html”>essay titled “Quantum Cryptography: As Awesome As It Is Pointless.”

Back then, I wrote:

While I like the science of quantum cryptography—my undergraduate degree was in physics—I don’t see any commercial value in it. I don’t believe it solves any security problem that needs solving. I don’t believe that it’s worth paying for, and I can’t imagine anyone but a few technophiles buying and deploying it. Systems that use it don’t magically become unbreakable, because the quantum part doesn’t address the weak points of the system...

The post Inventors of Quantum Cryptography Win Turing Award appeared first on Security Boulevard.

  • ✇Security Boulevard
  • Will Your Organization Take the Quantum Leap in 2026? Read This First David McNeely
    Explore how organizations can prepare for the quantum age by developing quantum security intelligence, establishing governance plans, and prioritizing system updates. Learn strategies for building resilience without exorbitant investments as quantum computing technology advances The post Will Your Organization Take the Quantum Leap in 2026? Read This First appeared first on Security Boulevard.
     
  • ✇Security Intelligence
  • 2024 trends: Were they accurate? Jennifer Gregory
    The new year always kicks off with a flood of prediction articles; then, 12 months later, our newsfeed is filled with wrap-up articles. But we are often left to wonder if experts got it right in January about how the year would unfold. As we close out 2024, let’s take a moment to go back and see if the crystal balls were working about how the year would play out in cybersecurity. Here are five trends that were often predicted for 2024. 1. The use of artificial intelligence in cybersecurity will
     

2024 trends: Were they accurate?

23 de Dezembro de 2024, 14:00

The new year always kicks off with a flood of prediction articles; then, 12 months later, our newsfeed is filled with wrap-up articles. But we are often left to wonder if experts got it right in January about how the year would unfold. As we close out 2024, let’s take a moment to go back and see if the crystal balls were working about how the year would play out in cybersecurity.

Here are five trends that were often predicted for 2024.

1. The use of artificial intelligence in cybersecurity will increase

As the year began, there was no doubt that artificial intelligence (AI) would be a main character in the year’s events — and that was right on the money. Many organizations began to use or continue using AI in their cybersecurity operations in a wide range of ways. For example, Microsoft’s internal response teams use a large language model to manage requests and tickets based on how they were handled previously, saving 20 hours per person each week.

As the world turned its attention over the summer to the Paris Olympics, the team responsible for keeping the Paris Olympics data, apps, systems and even physical buildings protected turned to AI. While 140 cyberattacks were linked to the Olympics, the teams’ efforts resulted in no disruption of the competitions.

Throughout the entire life cycle of the games, from before the opening ceremony to after the torch left Paris, cybersecurity teams used AI to secure critical information systems, protect sensitive data and raise awareness within the games’ ecosystem. Additionally, algorithmic video surveillance based in AI scanned video to detect abandoned bags, the presence of weapons, unusual crowd movements and fires.

2. Organizations will see more AI-based threats and attacks

Unfortunately, experts were right about cyber criminals also turning to AI technology to more effectively conduct attacks. Threat actors are using AI in a wide range of ways for data breaches and cyberattacks, including improved reconnaissance, better target profiling and lowering expertise required for conducting an attack. Because AI can automate many processes required for an attack, such as vulnerability scanning, exploitation and data exfiltration processes, more cyber criminals now have the skills for even more damaging attacks.

“Since the release of gen AI, attackers are increasingly employing tools along with large language models to carry out large-scale social engineering attacks, and Gartner predicts that by 2027, 17% of total cyberattacks/data leaks will involve generative AI,” wrote Gartner in an August 2024 press release.

IBM distinguished engineer Jeff Crume has no doubt that the trend of cyber criminals using AI for attacks will continue in 2025. He says that cyber professionals do a better job of authentication because attackers are finding it easier to log in than to hack in. While looking for bad grammar and spelling errors now works to spot phishing attacks, he expects that this will no longer work as AI-based phishing attacks hit mass distribution.

Explore cybersecurity services

3. An increase in deepfakes and deceptions

While experts correctly predicted that deepfakes would become more of a threat in 2024, it’s likely no one expected the scale of arguably the most shocking deepfake story of the year. At the beginning of 2024, attackers created a deepfake video call that led to an employee giving the cyber criminals $25 million, which showed the power and damage that deepfakes can cause. But the World Economic Forum expects that the trend will only increase, even declaring that over the next two years, AI-fueled disinformation will be the number one threat in the world.

Throughout the year, other deepfake incidents made headlines. Quantum AI, an AI company, was suspected by the Securities and Exchange Commission of using AI to generate deepfakes on social media to deceive the public that Elon Musk developed the company’s technology. Even the well-received Paris Olympics were not immune to deepfakes, with Russian Group Storm-1679 suspected of creating AI content to discredit the International Olympic Committee. As the year closed out, German citizens saw an increase in AI-based propaganda regarding the upcoming German elections in 2025, including text, images and video.

4. A growing impact of quantum computing on cybersecurity

Ray Harishankar, IBM Fellow, IBM Quantum Safe, predicted that in 2024, “harvest now, decrypt later” attacks would become more common. As the year moved forward, quantum computing became an increasingly top concern, especially the harvest-now attacks. In July, the Office of Management and Budget released the Report on Post-Quantum Cryptography, which urged organizations to prepare their systems and processes for advancements in quantum computing.

During the fall of 2024, the predictions of the quantum’s impact became even more urgent, as symmetric cryptography would be unsafe by 2029, with even asymmetric cryptography fully breakable by quantum technology by 2034.

“That does not mean, however, that the risks are five years away. The prospect of harvest-now, decrypt-later attacks is already a concern, making the post-quantum cryptography transition an urgent priority,” wrote Gartner.

 5. Recession of ransomware attacks

John Dwyer, former Head of Research at IBM X-Force, predicted we might face a ransomware recession as more companies pledged not to pay the ransom. While we wish we could declare this came true, the jury is still out, and likely, we won’t know for sure until all the data is collected from 2024.

However, Wired declared in the summer of 2024 that “ransomware showed no signs of slowing down in 2024 — despite increasing police crackdowns.” In December, Heather Wishart-Smith wrote in her Forbes article The Persistent Ransomware Threat: 2024 Trends and High-Profile Attacks about the increasing dual extortion technique of cyber criminals as an increasing trend in 2024.

All in all, the experts were largely on target with their 2024 predictions. And in the next few weeks, we will start the prediction game all over again as we wonder what’s in the cards for cybersecurity in 2025.

The post 2024 trends: Were they accurate? appeared first on Security Intelligence.

❌
❌