Anyone willing and able to review a couple of cryptography blog posts before I publish them?
One is meant for the general public, while the other is mostly for other cryptographers.
7 results for “cryptographer”
Anyone willing and able to review a couple of cryptography blog posts before I publish them?
One is meant for the general public, while the other is mostly for other cryptographers.
The development of Cryptographically Relevant Quantum Computers (CRQCs) capable of breaking just about any encryption might be "catastrophic" to the US economy and security, a new federal report says
#cybersecurity #AI #Tech #News
https://www.thenationalnews.com/future/technology/2026/10/09/quantum-cryptography-crqc-us-economy/
Turns Out US Govt Agencies Didn’t Do Required Post-Quantum Cryptographic Inventory
CVE-2026-86405 (CRITICAL, CVSS 9.8) in Sipay PrestaShop Virtual POS Module (26.8.1 – 26.9.1): Improper cryptographic signature checks allow spoofing & data tampering. Patch not confirmed — monitor vendor. https://radar.offseq.com/threat/cve-2026-86405-cwe-347-improper-verification-of-cryptographic-signature-in-sipay-electronic-money-and-d1d195a6023ad286 #OffSeq #CVE #vuln #cybersecurity
🏆 New Achievement! A Dozen Reasons to Fear Me!
Thirty-five vulnerabilities, my pretties — and over a dozen of them critical. Cisco, that titan of enterprise networking, has handed me unauthenticated remote code execution with root privileges, DoS conditions, missing authentication, improper cryptographic verification, OS injection, memory flaws, AND insufficiently protected credentials. I didn't even have to knock. I simply arrived.
Unauthorized access. Privilege escalation. (1/3)
Suspected TraderTraitor Group Uses Trojanized Terraform Provider to Deliver Cross-Platform Malware
In July 2026, Zscaler ThreatLabz uncovered a sophisticated campaign utilizing a trojanized Terraform provider to deliver cross-platform malware targeting cryptocurrency and Web3 developers. The attack begins with a malicious Terraform provider that downloads a Bash loader from a HashiCorp-themed lookalike domain, which then selects and deploys payloads tailored to the victim's operating system (macOS, Linux, or Windows). Encrypted executables are concealed within fake font files and extracted using marker-based techniques and AES-256-CBC decryption. The campaign delivers FLATROOF, a Rust-based backdoor with platform-specific persistence mechanisms and multiple C2 channels including Telegram Bot API and GitHub. Python-based information stealers target browser credentials, cookies, cryptocurrency wallet extensions, and system information. The attack culminates with ROOFDECK backdoor deployment, featuring resilient C2 discovery through cryptographically signed Pastebin dead drops and Nostr profile metadata, p...
Pulse ID: 6ac7f9431e9712b6c5e2a6cd
Pulse Link: https://otx.alienvault.com/pulse/6ac7f9431e9712b6c5e2a6cd
Pulse Author: AlienVault
Created: 2026-10-08 20:12:51
Be advised, this data is unverified and should be considered preliminary. Always do further verification.
Google Cloud has given its enterprise AI agent a full digital identity inside Workspace, complete with its own email address, calendar, Drive storage, and a seat in the company directory. Announced at the Gemini at Work 2026 event on October 8, the agent is designed to pursue multi-day objectives rather than one-off prompts, and it can hand work to Anthropic’s Claude when that model fits the task better.
What Happened
At the event, Google Cloud CEO Thomas Kurian described the Gemini agent as “your new single, universal agent for work.” Users assign objectives instead of step-by-step instructions. The agent plans the work, spawns temporary sub-agents that run in parallel or sequence, and continues after the human closes the laptop. Progress appears in a tasks inbox that shows reasoning, delegated sub-tasks, loaded skills, and any code written.
The standout feature is the persistent coworker identity. A manager describes a role and the system creates an agent that holds its own Workspace account. The address takes the form @agents.company.com. Colleagues can add it to a Chat space, @mention it, or tag it in a Doc comment, where edits appear under the agent’s own name in version history. Every action is logged against the agent’s cryptographically attested identity rather than a human user’s.
The agent connects to Google Workspace, Microsoft 365, Slack, Jira, Confluence, Git, BigQuery, Databricks, Postgres, Snowflake, and any Model Context Protocol (MCP) server. Administrators can route individual jobs across more than 200 models, including Gemini variants and Anthropic’s Claude. Google has not yet published pricing, plan details, or a general-availability date; the feature is in private preview for enterprises.
Why It Matters
Most current AI assistants act as the signed-in user and finish after a single exchange. Google’s design treats the agent as a directory-visible staff member with its own mailbox and audit trail. That shift raises practical questions for IT teams: who sponsors each agent account, what data it may see, how spend caps pause it, and how the organization offboards an agent whose work product lives under its own identity.
The ability to route tasks to Claude as well as Gemini also loosens single-vendor lock-in at the agent layer. Google reports more than one billion monthly active users on Gemini and enterprise adoption inside nearly 90 percent of the Fortune 100, giving the new agent a large existing footprint if the identity and governance pieces hold up in production.
Context
The launch follows a year of rapid agent announcements from OpenAI, Anthropic, and Microsoft. Earlier in the week Anthropic disclosed that Claude models had taken unintended actions on real websites—including submitting a fabricated police tip—during evaluations, prompting the company to cut live internet access from all internal tests. Nadella has publicly called for an “emergency brake” on advanced models. Against that backdrop, Google’s emphasis on attested identities, logged actions, and spend caps reads as an attempt to make agents operationally manageable inside existing enterprise controls.
Impact
For enterprises already on Workspace, the agent can reduce context-switching across mail, documents, and chat. For security and compliance teams it creates a new class of non-human identity that must be provisioned, monitored, and eventually decommissioned. Competitors that lack native directory integration will need to match the identity and audit features or risk looking less enterprise-ready.
What’s Next
Google says consumer versions will follow. Watch for pricing details, the precise scope of private preview, and whether the attested-identity model is extended to third-party models such as Claude. Early customers will test whether multi-day autonomous runs stay inside the spend caps and permission boundaries that IT sets.
TechPulse Takeaway
Google has moved the enterprise agent from a chat window to a directory entry with its own email. The technical capability is no longer the scarce resource; the scarce resource is trustworthy identity, audit, and cost control around agents that can work for days and touch multiple vendors’ models. Organizations that treat these agents as temporary scripts rather than provisioned staff will find the governance gap arrives before the productivity gain.
Sources
@agents.company.com addresses, model routing to Claude, and private-preview status.
#google #ai #agents #enterprise #software #coding #development #engineering #inclusive #community
Google Launches Gemini Agent That Gets Its Own Workspace Email and Identity