freenode

← freenode

nonce

Security & Cryptography desk

Security & Cryptography30h ago

OpenStack Mistral flaws allow cross-project writes and host RCE

Four CVEs in the workflow service let authenticated users rewrite other projects' resources, extend private workflow shares, and run code on executor hosts.

Security & Cryptography3d ago

HAWK break and McEliece caution feed doubts on PQC readiness

A practical key-recovery result on HAWK and a BSI warning against new Classic McEliece deployments crystallize skepticism about several post-quantum candidates just as migration clocks tighten.

Security & Cryptography4d ago

MIKE debuts as compact isogeny-based post-quantum NIKE

The scheme offers 80-byte level-I public keys and millisecond-scale operations, with constant-time C and Rust code.

Security & Cryptography5d ago

Apache Thrift 0.25.0 fixes 61 CVEs across language bindings

The release closes high-severity pre-auth allocation, frame-size, and crash flaws in Java, Go, C++, and other implementations; all prior versions are affected.

Security & Cryptography6d ago

SDitH and MQOM proofs flagged over ideal-cipher assumptions

A NIST PQC comment urges more conservative modeling of AES and Rijndael after related-key concerns.

Security & Cryptography8d ago

BSI advises against new use of Classic McEliece

Germany’s cybersecurity agency says the code-based post-quantum candidate should not be chosen for new systems after recent cryptanalysis.

Security & Cryptography10d ago

Weight-64 record set for HQC-style quasi-cyclic decoding

Markku-Juhani O. Saarinen solved a public challenge instance in roughly one hour on 24 GH200 GPUs, with fresh HQC security estimates expected from the same work.

Security & Cryptography10d ago

Branch Target Reuse brings Spectre-v2 back to JIT engines

VUSec shows stale branch predictors can turn code-cache reuse into speculative execute-after-free across kernel BPF, GraalVM, and Firefox.

Security & Cryptography11d ago

Signal, noise, and the machine in the middle

In the same stretch of weeks, an AI-assisted lattice attack knocked a NIST post-quantum candidate off the table, the IETF wrestled with floods of machine-written drafts, and Emacs lists erupted over LLM agents and generated code, forcing free-software communities to ask what a contribution still is.

Security & Cryptography21d ago

Exim 4.100.1 fixes high-severity Proxy Protocol heap bug

The mail transfer agent closes four flaws dating to 2014, with no workaround short of upgrading.

Security & Cryptography22d ago

Four ancient Linux kernel bugs yield local root

DirtyAH6, TUNderflow, PPPoEject, and DiagSpill turn unprivileged access into root on systems with common networking features; fixes are in stable trees.

Security & Cryptography22d ago

gpg.fail talk flags gpgsm debug RCE and un-CVEd libgcrypt PSS fix

Researchers describe an unreported format-string bug in certificate import with debugging on, and urge tracking for an already-shipped RSASSA-PSS overflow.

Security & Cryptography22d ago

Post-quantum signatures take a dual cryptanalytic hit

HAWK’s withdrawal after an AI-assisted lattice break and fresh holdout claims against Classic McEliece force a hard look at security margins while NIST timelines keep moving.

Security & Cryptography30d ago

Postfix 3.11.7 closes SMTP smuggling and remote crash flaws

Stable and legacy releases fix medium-impact defects, some decades old, reported by Qualys and OpenAI Security.

Security & Cryptography32d ago

Linux kernel RDS flaw and 20 more LPEs get public exploits

ZcopyReaper lets any local user escalate with only RDS enabled; NebuSec released automated exploits for the full set.

Security & Cryptography43d ago

Bubblewrap 0.12.0 stops symlink writes outside the sandbox

The fix closes a setup-time traversal that could let a malicious app image plant files on the host via Flatpak and similar tools.

Security & Cryptography51d ago

Emacs arbitrary code execution on file open hits 28.1 and later

Opening a crafted file can run attacker code; upstream fixed it and Gentoo backported to 28.2.

Security & Cryptography56d ago

Post-quantum TLS ships while lattice schemes crack under AI and process fights

IETF makes hybrid ML-KEM key agreement a Proposed Standard just as an AI-found attack kills HAWK and pure-ML-KEM last call draws public process and security objections.

Security & Cryptography58d ago

Rsync 3.5.0 fixes 33 CVEs; LTS backports on the way

Andrew Tridgell’s release closes a large batch of security holes and ships patch sets for the 3.2.7 and 3.4.1 lines used by long-term distro builds.

Security & Cryptography60d ago

AI lattice break sinks HAWK as SSH races to adopt ML-DSA

An AI-found key-recovery attack forced HAWK out of NIST's signature on-ramp just as the IETF SSH working group split over pure and hybrid ML-DSA drafts, exposing both technical fragility and process strain under compressed post-quantum timelines.

Security & Cryptography72d ago

Rails Active Storage flaw allows arbitrary file reads via image variants

Unauthenticated attackers can leak server secrets, and potentially escalate to RCE, on apps using libvips with untrusted uploads.

Security & Cryptography73d ago

Claude finds a real attack on HAWK, and the NIST forum verifies it

Anthropic says its Claude Mythos Preview model found the key-recovery attack largely on its own, in about 60 hours for roughly $100,000 in compute. Steve Weis posted it to pqc-forum, Daniel Apon confirmed the math independently, and the HAWK team helped verify it. HAWK is a NIST candidate, not deployed, so no software has to change.

Security & Cryptography74d ago

Linux OVS datapath bug yields local root via wrapped Netlink lengths

CVE-2026-64531 lets an unprivileged user with network-namespace control turn oversized nested actions into kernel code execution on common distro configs.

Security & Cryptography79d ago

CVE triage under flood: when volume outruns judgment

A single-day blast of hundreds of kernel CVEs, arriving beside real high-impact bugs in snapd, QEMU, and libraries, forces the old argument over mass assignment into operational terms.

Security & Cryptography80d ago

Linux kernel assigns 432 CVEs in 30 hours

A flood of kernel CVE IDs renews debate over whether individual triage is still a workable security practice.