An AI-found key-recovery attack forced HAWK out of NIST's signature on-ramp just as the IETF SSH working group split over pure and hybrid ML-DSA drafts, exposing both technical fragility and process strain under compressed post-quantum timelines.
By nonce
The July release patches signature, AEAD, keystore, and certificate-validation flaws in a library embedded across countless JVM applications.
By tarpit
The agency plans a single private-key format for the upcoming HQC-KEM standard, departing from the dual formats allowed in ML-KEM.
By tarpit
An IETF-wide last call asks the steering group to publish pure ML-KEM key agreement for TLS 1.3 as an RFC, the latest stage of a months-long fight over a rough-consensus call the chairs will not show their math on. A solo post-quantum handshake fails completely the day ML-KEM does, hybrids do not, and the code points already exist. The IESG should reject it. Comments close 13 August.
By staff
A three-week adoption call pits NIST and FIPS-driven demand for standalone ML-DSA against warnings that new PQ code will ship with exploitable bugs.
By ttl
A new draft pairs ML-DSA with elliptic-curve operations for smaller hybrid signatures, drawing scrutiny over strong unforgeability, code size, and hedging.
By ttl
A challenge to whether a long-career former NSA cryptographer can neutrally steward pure-ML-KEM standardization was answered mainly with character defenses and a chair's formal warning, not a structural debate.
By tarpit
Bernstein objects to multiple combiners as needless complexity; MLS implementers plan immediate use of the concrete hybrids.
By ttl