freenode

← digests

HAWK withdrawn from NIST PQC after lattice attack

Security & Cryptography2026-08-04

An AI-assisted lattice attack forced the withdrawal of the HAWK signature scheme from NIST post-quantum standardization. The same period brought a Linux kernel local privilege escalation, Apache NiFi fixes, GNOME security process changes, and further PQC format discussion.

HAWK withdrawn after dimension-halving lattice attack

Anthropic researchers described an AI-assisted lattice attack that reduces HAWK key recovery to an SVP instance in dimension n/2 + 1. The result prompted the scheme's official withdrawal from the NIST PQC signatures round. Developers following post-quantum standardization must drop HAWK and reassess remaining lattice candidates.

XFS reflink race yields local privilege escalation

Qualys disclosed CVE-2026-64600, a local privilege escalation in the Linux kernel caused by an XFS reflink direct-I/O race, and supplied a proof of concept. Red Hat and the XFS maintainer examined mitigations and the bug's reach under NFS. Systems running XFS should apply the forthcoming kernel updates.

Apache NiFi lets read users validate parameter contexts

CVE-2026-62354 is a high-severity incorrect-authorization flaw in Apache NiFi that lets users holding only read permission submit Parameter Context validation requests. The defect is corrected in NiFi 2.11.0. Operators should upgrade to restore the intended authorization boundary.

GNOME shortens embargo and revises report handling

GNOME cut its security embargo to 30 days, ceased forwarding reports to projects that ban AI-generated content, and saw a key security coordinator step down. The shifts triggered discussion of AI-assisted reports and maintainer load. Downstream consumers of GNOME components will encounter faster public disclosure.

Bouncy Castle 1.85 closes 32 CVEs

The Bouncy Castle 1.85 release fixes 32 CVEs. A follow-up message asked whether AI or automated tooling had surfaced the issues. Applications that embed the library should move to the new version.

NIST proposes seed-only keys for FIPS 207

NIST signaled that the forthcoming FIPS 207 (HQC-KEM) will use a seed-only private-key format and invited feedback relative to the dual-format choice made in FIPS 203. Implementers of post-quantum KEMs need to evaluate the impact on key storage and interchange. Discussion continues on the pqc-forum.

New isogeny work examined for SQIsign impact

Daniel J. Bernstein analyzed a recent isogeny paper for its concrete effect on SQIsign parameters under ongoing NIST PQC evaluation. The review helps determine whether parameter adjustments are required. Parties tracking isogeny-based signatures are watching the resulting security margins.

Apache NiFi gzip decompression exhausts memory

CVE-2026-68981 is a high-severity uncontrolled-resource-consumption flaw in Apache NiFi that arises from gzip decompression of HTTP requests and can exhaust memory. The issue is fixed in version 2.11.0. Administrators should upgrade exposed NiFi instances.