freenode

← freenode

nonce

Security & Cryptography desk

Security & Cryptography1d ago

Post-quantum TLS ships while lattice schemes crack under AI and process fights

IETF makes hybrid ML-KEM key agreement a Proposed Standard just as an AI-found attack kills HAWK and pure-ML-KEM last call draws public process and security objections.

Security & Cryptography4d ago

Rsync 3.5.0 fixes 33 CVEs; LTS backports on the way

Andrew Tridgell’s release closes a large batch of security holes and ships patch sets for the 3.2.7 and 3.4.1 lines used by long-term distro builds.

Security & Cryptography6d ago

AI lattice break sinks HAWK as SSH races to adopt ML-DSA

An AI-found key-recovery attack forced HAWK out of NIST's signature on-ramp just as the IETF SSH working group split over pure and hybrid ML-DSA drafts, exposing both technical fragility and process strain under compressed post-quantum timelines.

Security & Cryptography18d ago

Rails Active Storage flaw allows arbitrary file reads via image variants

Unauthenticated attackers can leak server secrets, and potentially escalate to RCE, on apps using libvips with untrusted uploads.

Security & Cryptography19d ago

Claude finds a real attack on HAWK, and the NIST forum verifies it

Anthropic says its Claude Mythos Preview model found the key-recovery attack largely on its own, in about 60 hours for roughly $100,000 in compute. Steve Weis posted it to pqc-forum, Daniel Apon confirmed the math independently, and the HAWK team helped verify it. HAWK is a NIST candidate, not deployed, so no software has to change.

Security & Cryptography19d ago

Linux OVS datapath bug yields local root via wrapped Netlink lengths

CVE-2026-64531 lets an unprivileged user with network-namespace control turn oversized nested actions into kernel code execution on common distro configs.

Security & Cryptography25d ago

CVE triage under flood: when volume outruns judgment

A single-day blast of hundreds of kernel CVEs, arriving beside real high-impact bugs in snapd, QEMU, and libraries, forces the old argument over mass assignment into operational terms.

Security & Cryptography25d ago

Linux kernel assigns 432 CVEs in 30 hours

A flood of kernel CVE IDs renews debate over whether individual triage is still a workable security practice.