#nist — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #nist, aggregated by home.social.
-
NVD Modernization: NIST Seeks Public Input on an AI-Ready National Vulnerability Database - https://www.redpacketsecurity.com/nist-seeks-public-input-on-ai-ready-nvd-modernization/
-
NVD Modernization: NIST Seeks Public Input on an AI-Ready National Vulnerability Database - https://www.redpacketsecurity.com/nist-seeks-public-input-on-ai-ready-nvd-modernization/
-
NVD Modernization: NIST Seeks Public Input on an AI-Ready National Vulnerability Database - https://www.redpacketsecurity.com/nist-seeks-public-input-on-ai-ready-nvd-modernization/
-
NVD Modernization: NIST Seeks Public Input on an AI-Ready National Vulnerability Database - https://www.redpacketsecurity.com/nist-seeks-public-input-on-ai-ready-nvd-modernization/
-
THIS WEEKEND! Lockdown Systems will be at HOPE 26! 🌐🐢
Our collective member @redshiftzero will be giving a talk about post-quantum encryption and where we are in the post-quantum transition!
The arrival of a cryptographically relevant quantum computer means that encrypted data collected now could be at risk of getting decrypted later. This is why we need to prepare now! 🔒️
Harvest Now, Decrypt Later
When: Sunday, August 16th at 10am
Where: New York City (USA), New Yorker Hotel, Gramercy Park Suitehttps://schedule.hope.net/hope26/talk/3E3DUJ/
#HOPE26 #LockdownSystems #Encryption #PostQuantumEncryption #QuantumComputer #NIST
-
THIS WEEKEND! Lockdown Systems will be at HOPE 26! 🌐🐢
Our collective member @redshiftzero will be giving a talk about post-quantum encryption and where we are in the post-quantum transition!
The arrival of a cryptographically relevant quantum computer means that encrypted data collected now could be at risk of getting decrypted later. This is why we need to prepare now! 🔒️
Harvest Now, Decrypt Later
When: Sunday, August 16th at 10am
Where: New York City (USA), New Yorker Hotel, Gramercy Park Suitehttps://schedule.hope.net/hope26/talk/3E3DUJ/
#HOPE26 #LockdownSystems #Encryption #PostQuantumEncryption #QuantumComputer #NIST
-
THIS WEEKEND! Lockdown Systems will be at HOPE 26! 🌐🐢
Our collective member @redshiftzero will be giving a talk about post-quantum encryption and where we are in the post-quantum transition!
The arrival of a cryptographically relevant quantum computer means that encrypted data collected now could be at risk of getting decrypted later. This is why we need to prepare now! 🔒️
Harvest Now, Decrypt Later
When: Sunday, August 16th at 10am
Where: New York City (USA), New Yorker Hotel, Gramercy Park Suitehttps://schedule.hope.net/hope26/talk/3E3DUJ/
#HOPE26 #LockdownSystems #Encryption #PostQuantumEncryption #QuantumComputer #NIST
-
THIS WEEKEND! Lockdown Systems will be at HOPE 26! 🌐🐢
Our collective member @redshiftzero will be giving a talk about post-quantum encryption and where we are in the post-quantum transition!
The arrival of a cryptographically relevant quantum computer means that encrypted data collected now could be at risk of getting decrypted later. This is why we need to prepare now! 🔒️
Harvest Now, Decrypt Later
When: Sunday, August 16th at 10am
Where: New York City (USA), New Yorker Hotel, Gramercy Park Suitehttps://schedule.hope.net/hope26/talk/3E3DUJ/
#HOPE26 #LockdownSystems #Encryption #PostQuantumEncryption #QuantumComputer #NIST
-
NIST запретил плановую смену паролей. У ФСТЭК она теперь обязательна
NIST в июле 2025-го запретил требовать плановую смену паролей: SHALL NOT, раздел 3.1.1.2 финальной SP 800-63B. ФСТЭК в апреле 2026-го сделала её обязательной для госсистем и КИИ: 90 дней в системе, 30 на мобильных, с запретом на 12 последних паролей. Разбираем три документа дословно: почему в самом приказе 117 слова «пароль» нет, где живёт требование, чем оно обернётся на оценке Кзи (штрафное обнуление группы показателей) и кого всё это не касается. Плюс таблица: парольные требования NIST и ФСТЭК рядом. Расходятся они меньше, чем принято думать.
https://habr.com/ru/articles/1068448/
#ротация_паролей #парольная_политика #ФСТЭК #приказ_117 #NIST #ИАФ3 #методические_документы_ФСТЭК #ГИС #КИИ #Кзи
-
NIST запретил плановую смену паролей. У ФСТЭК она теперь обязательна
NIST в июле 2025-го запретил требовать плановую смену паролей: SHALL NOT, раздел 3.1.1.2 финальной SP 800-63B. ФСТЭК в апреле 2026-го сделала её обязательной для госсистем и КИИ: 90 дней в системе, 30 на мобильных, с запретом на 12 последних паролей. Разбираем три документа дословно: почему в самом приказе 117 слова «пароль» нет, где живёт требование, чем оно обернётся на оценке Кзи (штрафное обнуление группы показателей) и кого всё это не касается. Плюс таблица: парольные требования NIST и ФСТЭК рядом. Расходятся они меньше, чем принято думать.
https://habr.com/ru/articles/1068448/
#ротация_паролей #парольная_политика #ФСТЭК #приказ_117 #NIST #ИАФ3 #методические_документы_ФСТЭК #ГИС #КИИ #Кзи
-
NIST запретил плановую смену паролей. У ФСТЭК она теперь обязательна
NIST в июле 2025-го запретил требовать плановую смену паролей: SHALL NOT, раздел 3.1.1.2 финальной SP 800-63B. ФСТЭК в апреле 2026-го сделала её обязательной для госсистем и КИИ: 90 дней в системе, 30 на мобильных, с запретом на 12 последних паролей. Разбираем три документа дословно: почему в самом приказе 117 слова «пароль» нет, где живёт требование, чем оно обернётся на оценке Кзи (штрафное обнуление группы показателей) и кого всё это не касается. Плюс таблица: парольные требования NIST и ФСТЭК рядом. Расходятся они меньше, чем принято думать.
https://habr.com/ru/articles/1068448/
#ротация_паролей #парольная_политика #ФСТЭК #приказ_117 #NIST #ИАФ3 #методические_документы_ФСТЭК #ГИС #КИИ #Кзи
-
📰 NIST Publishes Final Cybersecurity Framework Profile for Transit Sector
NIST has released the final version of its Transit Cybersecurity Framework Profile (NIST IR 8576). The guide helps U.S. transit agencies manage cybersecurity risks across their IT and operational technology (OT) systems. #NIST #Cybersecurity #OT #ICS
-
Centralize logs to meet NIST 800-53 AU-2/AU-6. This config sets up an rsyslog server with TLS on TCP 6514, using imtcp and self-signed certs for encrypted client logs on Ubuntu/Debian/RHEL. #nist #rsyslog #logging
https://www.valtersit.com/vault/nist-80053-au2-centralized-log-aggregation-with-rsyslog-and--7e1e30/
-
Centralize logs to meet NIST 800-53 AU-2/AU-6. This config sets up an rsyslog server with TLS on TCP 6514, using imtcp and self-signed certs for encrypted client logs on Ubuntu/Debian/RHEL. #nist #rsyslog #logging
https://www.valtersit.com/vault/nist-80053-au2-centralized-log-aggregation-with-rsyslog-and--7e1e30/
-
Fact-checked the quantum sections of WEF's Top 10 Emerging Technologies 2026.
Three errors: NIST PQC took 8 years, not 2. IBM/Moderna was mRNA structure prediction, not protein folding. "Hybrid classical-quantum cryptography" is wrong terminology.
Also missing: TNFL, key-establishment/signature distinction, all NIST algorithm names.
https://postquantum.com/industry-news/wef-top-10-emerging-technologies-2026-pqc-quantum/
#infosec #PQC #postquantum #cryptography #NIST #cybersecurity
-
Fact-checked the quantum sections of WEF's Top 10 Emerging Technologies 2026.
Three errors: NIST PQC took 8 years, not 2. IBM/Moderna was mRNA structure prediction, not protein folding. "Hybrid classical-quantum cryptography" is wrong terminology.
Also missing: TNFL, key-establishment/signature distinction, all NIST algorithm names.
https://postquantum.com/industry-news/wef-top-10-emerging-technologies-2026-pqc-quantum/
#infosec #PQC #postquantum #cryptography #NIST #cybersecurity
-
Fact-checked the quantum sections of WEF's Top 10 Emerging Technologies 2026.
Three errors: NIST PQC took 8 years, not 2. IBM/Moderna was mRNA structure prediction, not protein folding. "Hybrid classical-quantum cryptography" is wrong terminology.
Also missing: TNFL, key-establishment/signature distinction, all NIST algorithm names.
https://postquantum.com/industry-news/wef-top-10-emerging-technologies-2026-pqc-quantum/
#infosec #PQC #postquantum #cryptography #NIST #cybersecurity
-
... et une autre faille dans #HAWK : un candidat #NIST #post - #quantique... (oups..)
C'est une première... et ça change tout... -
... et une autre faille dans #HAWK : un candidat #NIST #post - #quantique... (oups..)
C'est une première... et ça change tout... -
01net.com: #Claude #Mythos a trouvé 2 #failles #mathématiques #zéro-day dans des #algorithmes #mathématiques jugés #indestructibles, dont une #faille dans le protocole #AES , référéce mondiale de la cybersecurite pour les achats en ligne, et une autre faille dans #HAWK : un candidat #NIST #post - #quantique... (oups..)
C'est une première... et ça change tout...
-
01net.com: #Claude #Mythos a trouvé 2 #failles #mathématiques #zéro-day dans des #algorithmes #mathématiques jugés #indestructibles, dont une #faille dans le protocole #AES , référéce mondiale de la cybersecurite pour les achats en ligne, et une autre faille dans #HAWK : un candidat #NIST #post - #quantique... (oups..)
C'est une première... et ça change tout...
-
01net.com: #Claude #Mythos a trouvé 2 #failles #mathématiques #zéro-day dans des #algorithmes #mathématiques jugés #indestructibles, dont une #faille dans le protocole #AES , référéce mondiale de la cybersecurite pour les achats en ligne, et une autre faille dans #HAWK : un candidat #NIST #post - #quantique... (oups..)
C'est une première... et ça change tout...
-
01net.com: #Claude #Mythos a trouvé 2 #failles #mathématiques #zéro-day dans des #algorithmes #mathématiques jugés #indestructibles, dont une #faille dans le protocole #AES , référéce mondiale de la cybersecurite pour les achats en ligne, et une autre faille dans #HAWK : un candidat #NIST #post - #quantique... (oups..)
C'est une première... et ça change tout...
-
The US National Vulnerabilities Database https://nvd.nist.gov/ the centralized repository of digital security holes, recorded 45,207 flaws between January and Monday, so we are looking at more than double the number of flaws reported in all of 2025.
The good news - a very large percentage of the reported flaws are coming from internal security teams presumably using AI powered cyber-security tools.
Example: of the 433 vulnerabilities reported in Chrome in July, 401 were “reported by Google” internally, according to the company.
There has been no rise in the number of exploits this year despite the uptick in discovered flaws. https://www.bloomberg.com/news/articles/2026-07-27/ai-hunts-for-cyber-flaws-finding-record-numbers-in-tech-sector?accessToken=eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJzb3VyY2UiOiJTdWJzY3JpYmVyR2lmdGVkQXJ0aWNsZSIsImlhdCI6MTc4NTE3ODM1OSwiZXhwIjoxNzg1NzgzMTU5LCJhcnRpY2xlSWQiOiJUSVVETlBUOU5KTFQwMCIsImJjb25uZWN0SWQiOiI0OEFDOEE5MkEwNTM0MkQ4OEIyRjkwQjhDMTgzMTdDMyJ9.z3BDvCQbIyLyRcRQgIsKejrHduNgHbyS9TXTJZhVFi0&leadSource=article-gifting #AI #AISecurity #NVD #Security #Software #CyberSecurity #SecurityFlaws #Vulnerabilities #SoftwareExploits #Hackers #VulnerabilityDataBase #NIST
-
The US National Vulnerabilities Database https://nvd.nist.gov/ the centralized repository of digital security holes, recorded 45,207 flaws between January and Monday, so we are looking at more than double the number of flaws reported in all of 2025.
The good news - a very large percentage of the reported flaws are coming from internal security teams presumably using AI powered cyber-security tools.
Example: of the 433 vulnerabilities reported in Chrome in July, 401 were “reported by Google” internally, according to the company.
There has been no rise in the number of exploits this year despite the uptick in discovered flaws. https://www.bloomberg.com/news/articles/2026-07-27/ai-hunts-for-cyber-flaws-finding-record-numbers-in-tech-sector?accessToken=eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJzb3VyY2UiOiJTdWJzY3JpYmVyR2lmdGVkQXJ0aWNsZSIsImlhdCI6MTc4NTE3ODM1OSwiZXhwIjoxNzg1NzgzMTU5LCJhcnRpY2xlSWQiOiJUSVVETlBUOU5KTFQwMCIsImJjb25uZWN0SWQiOiI0OEFDOEE5MkEwNTM0MkQ4OEIyRjkwQjhDMTgzMTdDMyJ9.z3BDvCQbIyLyRcRQgIsKejrHduNgHbyS9TXTJZhVFi0&leadSource=article-gifting #AI #AISecurity #NVD #Security #Software #CyberSecurity #SecurityFlaws #Vulnerabilities #SoftwareExploits #Hackers #VulnerabilityDataBase #NIST
-
The US National Vulnerabilities Database https://nvd.nist.gov/ the centralized repository of digital security holes, recorded 45,207 flaws between January and Monday, so we are looking at more than double the number of flaws reported in all of 2025.
The good news - a very large percentage of the reported flaws are coming from internal security teams presumably using AI powered cyber-security tools.
Example: of the 433 vulnerabilities reported in Chrome in July, 401 were “reported by Google” internally, according to the company.
There has been no rise in the number of exploits this year despite the uptick in discovered flaws. https://www.bloomberg.com/news/articles/2026-07-27/ai-hunts-for-cyber-flaws-finding-record-numbers-in-tech-sector?accessToken=eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJzb3VyY2UiOiJTdWJzY3JpYmVyR2lmdGVkQXJ0aWNsZSIsImlhdCI6MTc4NTE3ODM1OSwiZXhwIjoxNzg1NzgzMTU5LCJhcnRpY2xlSWQiOiJUSVVETlBUOU5KTFQwMCIsImJjb25uZWN0SWQiOiI0OEFDOEE5MkEwNTM0MkQ4OEIyRjkwQjhDMTgzMTdDMyJ9.z3BDvCQbIyLyRcRQgIsKejrHduNgHbyS9TXTJZhVFi0&leadSource=article-gifting #AI #AISecurity #NVD #Security #Software #CyberSecurity #SecurityFlaws #Vulnerabilities #SoftwareExploits #Hackers #VulnerabilityDataBase #NIST
-
The US National Vulnerabilities Database https://nvd.nist.gov/ the centralized repository of digital security holes, recorded 45,207 flaws between January and Monday, so we are looking at more than double the number of flaws reported in all of 2025.
The good news - a very large percentage of the reported flaws are coming from internal security teams presumably using AI powered cyber-security tools.
Example: of the 433 vulnerabilities reported in Chrome in July, 401 were “reported by Google” internally, according to the company.
There has been no rise in the number of exploits this year despite the uptick in discovered flaws. https://www.bloomberg.com/news/articles/2026-07-27/ai-hunts-for-cyber-flaws-finding-record-numbers-in-tech-sector?accessToken=eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJzb3VyY2UiOiJTdWJzY3JpYmVyR2lmdGVkQXJ0aWNsZSIsImlhdCI6MTc4NTE3ODM1OSwiZXhwIjoxNzg1NzgzMTU5LCJhcnRpY2xlSWQiOiJUSVVETlBUOU5KTFQwMCIsImJjb25uZWN0SWQiOiI0OEFDOEE5MkEwNTM0MkQ4OEIyRjkwQjhDMTgzMTdDMyJ9.z3BDvCQbIyLyRcRQgIsKejrHduNgHbyS9TXTJZhVFi0&leadSource=article-gifting #AI #AISecurity #NVD #Security #Software #CyberSecurity #SecurityFlaws #Vulnerabilities #SoftwareExploits #Hackers #VulnerabilityDataBase #NIST
-
WEBINAR 28 JUL 15:00 UTC - INTC - Transitioning to Quantum-Safe cryptography
Third talk in the INTC Quantum Series: an overview of the post-quantum encryption and digital signature primitives standardized by NIST, the algorithms still in the pipeline, and the challenges of migrating more complex protocols to quantum-safe. With Dr. Vadim Lyubashevsky, Principal Research Scientist, IBM Research Zurich.
-
WEBINAR 28 JUL 15:00 UTC - INTC - Transitioning to Quantum-Safe cryptography
Third talk in the INTC Quantum Series: an overview of the post-quantum encryption and digital signature primitives standardized by NIST, the algorithms still in the pipeline, and the challenges of migrating more complex protocols to quantum-safe. With Dr. Vadim Lyubashevsky, Principal Research Scientist, IBM Research Zurich.
-
WEBINAR 28 JUL 15:00 UTC - INTC - Transitioning to Quantum-Safe cryptography
Third talk in the INTC Quantum Series: an overview of the post-quantum encryption and digital signature primitives standardized by NIST, the algorithms still in the pipeline, and the challenges of migrating more complex protocols to quantum-safe. With Dr. Vadim Lyubashevsky, Principal Research Scientist, IBM Research Zurich.
-
The fact that we can now build a public service that generates verifiably unpredictable numbers is a powerful, real-world demonstration that at its most fundamental level, the universe is inherently probabilistic. It's not just a theoretical debate anymore—it's the basis for practical technology that can help secure elections, run fair lotteries, and create unbreakable encryption #nist #random number factory
-
The fact that we can now build a public service that generates verifiably unpredictable numbers is a powerful, real-world demonstration that at its most fundamental level, the universe is inherently probabilistic. It's not just a theoretical debate anymore—it's the basis for practical technology that can help secure elections, run fair lotteries, and create unbreakable encryption #nist #random number factory
-
The fact that we can now build a public service that generates verifiably unpredictable numbers is a powerful, real-world demonstration that at its most fundamental level, the universe is inherently probabilistic. It's not just a theoretical debate anymore—it's the basis for practical technology that can help secure elections, run fair lotteries, and create unbreakable encryption #nist #random number factory
-
Cuando hablamos de un roadmap de ciberseguridad, casi siempre la conversación empieza igual:
Zero Trust.
ISO 27001.
NIST.
EDR.
SIEM.Pero... ¿y si estuviéramos empezando por el lugar equivocado?
Hace más de cincuenta años, James P. Anderson propuso algo sorprendentemente actual: antes de pensar en controles o tecnologías, primero hay que entender qué estamos protegiendo, de quién y bajo qué supuestos.
El problema no siempre es elegir un framework incorrecto. Muchas veces el problema es intentar aplicar cualquier framework sin haber comprendido primero el entorno.
Quizás por eso seguimos resolviendo problemas modernos con herramientas cada vez mejores... mientras repetimos errores que ya habían sido identificados décadas atrás.
En este artículo
https://medium.com/@jack.of.all.trades/primer-roadmap-de-ciberseguridad-86f23567ac20analizo por qué un roadmap de ciberseguridad debería comenzar mucho antes de hablar de Zero Trust, ISO 27001 o NIST.
#CyberSecurity #InfoSec #ZeroTrust #ISO27001 #NIST #Architecture #RiskManagement #JamesAnderson
-
Cuando hablamos de un roadmap de ciberseguridad, casi siempre la conversación empieza igual:
Zero Trust.
ISO 27001.
NIST.
EDR.
SIEM.Pero... ¿y si estuviéramos empezando por el lugar equivocado?
Hace más de cincuenta años, James P. Anderson propuso algo sorprendentemente actual: antes de pensar en controles o tecnologías, primero hay que entender qué estamos protegiendo, de quién y bajo qué supuestos.
El problema no siempre es elegir un framework incorrecto. Muchas veces el problema es intentar aplicar cualquier framework sin haber comprendido primero el entorno.
Quizás por eso seguimos resolviendo problemas modernos con herramientas cada vez mejores... mientras repetimos errores que ya habían sido identificados décadas atrás.
En este artículo
https://medium.com/@jack.of.all.trades/primer-roadmap-de-ciberseguridad-86f23567ac20analizo por qué un roadmap de ciberseguridad debería comenzar mucho antes de hablar de Zero Trust, ISO 27001 o NIST.
#CyberSecurity #InfoSec #ZeroTrust #ISO27001 #NIST #Architecture #RiskManagement #JamesAnderson
-
Cuando hablamos de un roadmap de ciberseguridad, casi siempre la conversación empieza igual:
Zero Trust.
ISO 27001.
NIST.
EDR.
SIEM.Pero... ¿y si estuviéramos empezando por el lugar equivocado?
Hace más de cincuenta años, James P. Anderson propuso algo sorprendentemente actual: antes de pensar en controles o tecnologías, primero hay que entender qué estamos protegiendo, de quién y bajo qué supuestos.
El problema no siempre es elegir un framework incorrecto. Muchas veces el problema es intentar aplicar cualquier framework sin haber comprendido primero el entorno.
Quizás por eso seguimos resolviendo problemas modernos con herramientas cada vez mejores... mientras repetimos errores que ya habían sido identificados décadas atrás.
En este artículo
https://medium.com/@jack.of.all.trades/primer-roadmap-de-ciberseguridad-86f23567ac20analizo por qué un roadmap de ciberseguridad debería comenzar mucho antes de hablar de Zero Trust, ISO 27001 o NIST.
#CyberSecurity #InfoSec #ZeroTrust #ISO27001 #NIST #Architecture #RiskManagement #JamesAnderson
-
Cuando hablamos de un roadmap de ciberseguridad, casi siempre la conversación empieza igual:
Zero Trust.
ISO 27001.
NIST.
EDR.
SIEM.Pero... ¿y si estuviéramos empezando por el lugar equivocado?
Hace más de cincuenta años, James P. Anderson propuso algo sorprendentemente actual: antes de pensar en controles o tecnologías, primero hay que entender qué estamos protegiendo, de quién y bajo qué supuestos.
El problema no siempre es elegir un framework incorrecto. Muchas veces el problema es intentar aplicar cualquier framework sin haber comprendido primero el entorno.
Quizás por eso seguimos resolviendo problemas modernos con herramientas cada vez mejores... mientras repetimos errores que ya habían sido identificados décadas atrás.
En este artículo
https://medium.com/@jack.of.all.trades/primer-roadmap-de-ciberseguridad-86f23567ac20analizo por qué un roadmap de ciberseguridad debería comenzar mucho antes de hablar de Zero Trust, ISO 27001 o NIST.
#CyberSecurity #InfoSec #ZeroTrust #ISO27001 #NIST #Architecture #RiskManagement #JamesAnderson
-
New analysis: How Much Can AI Actually Help With PQC Migration?
A hypothesis paper in MDPI Cryptography claims frontier AI (Mythos-class) compresses enterprise PQC migration from 12-15 years to 2-4 years. The paper models AI as both defender accelerator and adversary destabilizer through six feedback loops, and that dual-use framing is sound.
The timeline estimate is not.
I've led PQC migration programs generating 120,000+ discrete tasks. AI genuinely helps with the technical analysis fraction: crypto discovery triage (months to days), migration strategy automation across 100K+ instances, code diff generation (hours to minutes), test scenario creation.
That accounts for maybe 15-20% of total program effort.
The other 80%:
- Getting executive mandate and multi-year budget (3-12 months)
- Standing up program governance (3-6 months)
- Negotiating access to production segments across business units (this is the bottleneck in discovery, not analysis speed)
- Change advisory board approvals for every production change
- Vendor firmware/certification timelines entirely outside your control
- Interoperability testing with real counterparties on their schedules
- FIPS 140-3 module validation cycles
- CBOM and crypto-agility as organizational transformations, not technology deployments
Key analytical distinction: effort compression ≠ schedule compression. 20% of effort off the critical path saves zero calendar time. The institutional dependencies dominate the critical path in every large program I've observed.
The paper assigns 8 years to AI-compressible work and 2 years to the institutional floor. In my experience, those proportions are reversed.
EO 14412 (signed June 22, 2026) sets Dec 31, 2030 for PQC key establishment and Dec 31, 2031 for digital signatures in federal high-value systems. CNSA 2.0 requires new NSS acquisitions to be compliant from January 2027.
The correct response to AI-accelerated adversary capability is not "compress the timeline from 15 years to 4." It's: start the program now and use AI within it.
https://postquantum.com/post-quantum/ai-pqc-migration-how-much-help/
#infosec #cybersecurity #PQC #postquantum #cryptography #quantumcomputing #NIST #migration
-
New analysis: How Much Can AI Actually Help With PQC Migration?
A hypothesis paper in MDPI Cryptography claims frontier AI (Mythos-class) compresses enterprise PQC migration from 12-15 years to 2-4 years. The paper models AI as both defender accelerator and adversary destabilizer through six feedback loops, and that dual-use framing is sound.
The timeline estimate is not.
I've led PQC migration programs generating 120,000+ discrete tasks. AI genuinely helps with the technical analysis fraction: crypto discovery triage (months to days), migration strategy automation across 100K+ instances, code diff generation (hours to minutes), test scenario creation.
That accounts for maybe 15-20% of total program effort.
The other 80%:
- Getting executive mandate and multi-year budget (3-12 months)
- Standing up program governance (3-6 months)
- Negotiating access to production segments across business units (this is the bottleneck in discovery, not analysis speed)
- Change advisory board approvals for every production change
- Vendor firmware/certification timelines entirely outside your control
- Interoperability testing with real counterparties on their schedules
- FIPS 140-3 module validation cycles
- CBOM and crypto-agility as organizational transformations, not technology deployments
Key analytical distinction: effort compression ≠ schedule compression. 20% of effort off the critical path saves zero calendar time. The institutional dependencies dominate the critical path in every large program I've observed.
The paper assigns 8 years to AI-compressible work and 2 years to the institutional floor. In my experience, those proportions are reversed.
EO 14412 (signed June 22, 2026) sets Dec 31, 2030 for PQC key establishment and Dec 31, 2031 for digital signatures in federal high-value systems. CNSA 2.0 requires new NSS acquisitions to be compliant from January 2027.
The correct response to AI-accelerated adversary capability is not "compress the timeline from 15 years to 4." It's: start the program now and use AI within it.
https://postquantum.com/post-quantum/ai-pqc-migration-how-much-help/
#infosec #cybersecurity #PQC #postquantum #cryptography #quantumcomputing #NIST #migration
-
New analysis: How Much Can AI Actually Help With PQC Migration?
A hypothesis paper in MDPI Cryptography claims frontier AI (Mythos-class) compresses enterprise PQC migration from 12-15 years to 2-4 years. The paper models AI as both defender accelerator and adversary destabilizer through six feedback loops, and that dual-use framing is sound.
The timeline estimate is not.
I've led PQC migration programs generating 120,000+ discrete tasks. AI genuinely helps with the technical analysis fraction: crypto discovery triage (months to days), migration strategy automation across 100K+ instances, code diff generation (hours to minutes), test scenario creation.
That accounts for maybe 15-20% of total program effort.
The other 80%:
- Getting executive mandate and multi-year budget (3-12 months)
- Standing up program governance (3-6 months)
- Negotiating access to production segments across business units (this is the bottleneck in discovery, not analysis speed)
- Change advisory board approvals for every production change
- Vendor firmware/certification timelines entirely outside your control
- Interoperability testing with real counterparties on their schedules
- FIPS 140-3 module validation cycles
- CBOM and crypto-agility as organizational transformations, not technology deployments
Key analytical distinction: effort compression ≠ schedule compression. 20% of effort off the critical path saves zero calendar time. The institutional dependencies dominate the critical path in every large program I've observed.
The paper assigns 8 years to AI-compressible work and 2 years to the institutional floor. In my experience, those proportions are reversed.
EO 14412 (signed June 22, 2026) sets Dec 31, 2030 for PQC key establishment and Dec 31, 2031 for digital signatures in federal high-value systems. CNSA 2.0 requires new NSS acquisitions to be compliant from January 2027.
The correct response to AI-accelerated adversary capability is not "compress the timeline from 15 years to 4." It's: start the program now and use AI within it.
https://postquantum.com/post-quantum/ai-pqc-migration-how-much-help/
#infosec #cybersecurity #PQC #postquantum #cryptography #quantumcomputing #NIST #migration
-
New analysis: How Much Can AI Actually Help With PQC Migration?
A hypothesis paper in MDPI Cryptography claims frontier AI (Mythos-class) compresses enterprise PQC migration from 12-15 years to 2-4 years. The paper models AI as both defender accelerator and adversary destabilizer through six feedback loops, and that dual-use framing is sound.
The timeline estimate is not.
I've led PQC migration programs generating 120,000+ discrete tasks. AI genuinely helps with the technical analysis fraction: crypto discovery triage (months to days), migration strategy automation across 100K+ instances, code diff generation (hours to minutes), test scenario creation.
That accounts for maybe 15-20% of total program effort.
The other 80%:
- Getting executive mandate and multi-year budget (3-12 months)
- Standing up program governance (3-6 months)
- Negotiating access to production segments across business units (this is the bottleneck in discovery, not analysis speed)
- Change advisory board approvals for every production change
- Vendor firmware/certification timelines entirely outside your control
- Interoperability testing with real counterparties on their schedules
- FIPS 140-3 module validation cycles
- CBOM and crypto-agility as organizational transformations, not technology deployments
Key analytical distinction: effort compression ≠ schedule compression. 20% of effort off the critical path saves zero calendar time. The institutional dependencies dominate the critical path in every large program I've observed.
The paper assigns 8 years to AI-compressible work and 2 years to the institutional floor. In my experience, those proportions are reversed.
EO 14412 (signed June 22, 2026) sets Dec 31, 2030 for PQC key establishment and Dec 31, 2031 for digital signatures in federal high-value systems. CNSA 2.0 requires new NSS acquisitions to be compliant from January 2027.
The correct response to AI-accelerated adversary capability is not "compress the timeline from 15 years to 4." It's: start the program now and use AI within it.
https://postquantum.com/post-quantum/ai-pqc-migration-how-much-help/
#infosec #cybersecurity #PQC #postquantum #cryptography #quantumcomputing #NIST #migration
-
Yes, were elected to reinvent the wheel, and oh by the way, we are not very good at it!
US Government looks to centralize software vulnerability management with 'Gold Eagle' cybersecurity clearinghouse. https://www.techradar.com/pro/security/white-house-launches-gold-eagle-cybersecurity-clearinghouse-to-share-and-patch-ai-discovered-software-flaws
We already have this NOW - its called NIST NVE and CVE processes coordinated by MITRE. https://nvd.nist.gov/general #CyberSecurity #Security #NIST #MITRE #CVE #NVE #Software #AI #GoldEagle #CyberAttack #USGov #CyberThreat #DataSecurity #ReinventtheWheel
-
Yes, were elected to reinvent the wheel, and oh by the way, we are not very good at it!
US Government looks to centralize software vulnerability management with 'Gold Eagle' cybersecurity clearinghouse. https://www.techradar.com/pro/security/white-house-launches-gold-eagle-cybersecurity-clearinghouse-to-share-and-patch-ai-discovered-software-flaws
We already have this NOW - its called NIST NVE and CVE processes coordinated by MITRE. https://nvd.nist.gov/general #CyberSecurity #Security #NIST #MITRE #CVE #NVE #Software #AI #GoldEagle #CyberAttack #USGov #CyberThreat #DataSecurity #ReinventtheWheel
-
Yes, were elected to reinvent the wheel, and oh by the way, we are not very good at it!
US Government looks to centralize software vulnerability management with 'Gold Eagle' cybersecurity clearinghouse. https://www.techradar.com/pro/security/white-house-launches-gold-eagle-cybersecurity-clearinghouse-to-share-and-patch-ai-discovered-software-flaws
We already have this NOW - its called NIST NVE and CVE processes coordinated by MITRE. https://nvd.nist.gov/general #CyberSecurity #Security #NIST #MITRE #CVE #NVE #Software #AI #GoldEagle #CyberAttack #USGov #CyberThreat #DataSecurity #ReinventtheWheel
-
Yes, were elected to reinvent the wheel, and oh by the way, we are not very good at it!
US Government looks to centralize software vulnerability management with 'Gold Eagle' cybersecurity clearinghouse. https://www.techradar.com/pro/security/white-house-launches-gold-eagle-cybersecurity-clearinghouse-to-share-and-patch-ai-discovered-software-flaws
We already have this NOW - its called NIST NVE and CVE processes coordinated by MITRE. https://nvd.nist.gov/general #CyberSecurity #Security #NIST #MITRE #CVE #NVE #Software #AI #GoldEagle #CyberAttack #USGov #CyberThreat #DataSecurity #ReinventtheWheel
-
This is a great distillation of some important points about risk, cybersecurity, and the NIST CSF. If your work touches on any of those, this is worth a read.
https://cyberriskbook.com/ai-wont-save-you-from-weak-cybersecurity-fundamentals/
-
This is a great distillation of some important points about risk, cybersecurity, and the NIST CSF. If your work touches on any of those, this is worth a read.
https://cyberriskbook.com/ai-wont-save-you-from-weak-cybersecurity-fundamentals/
-
This is a great distillation of some important points about risk, cybersecurity, and the NIST CSF. If your work touches on any of those, this is worth a read.
https://cyberriskbook.com/ai-wont-save-you-from-weak-cybersecurity-fundamentals/
-
This is a great distillation of some important points about risk, cybersecurity, and the NIST CSF. If your work touches on any of those, this is worth a read.
https://cyberriskbook.com/ai-wont-save-you-from-weak-cybersecurity-fundamentals/
-
NIST: NIST Launches Center to Drive the Manufacture of Quantum Technologies. “The U.S. Department of Commerce’s National Institute of Standards and Technology (NIST) has announced an agreement with SRI International, a nonprofit research and development institution, to help advance U.S. quantum research, development and manufacturing capabilities.”
https://rbfirehose.com/2026/07/01/nist-nist-launches-center-to-drive-the-manufacture-of-quantum-technologies/ -
NIST: NIST Launches Center to Drive the Manufacture of Quantum Technologies. “The U.S. Department of Commerce’s National Institute of Standards and Technology (NIST) has announced an agreement with SRI International, a nonprofit research and development institution, to help advance U.S. quantum research, development and manufacturing capabilities.”
https://rbfirehose.com/2026/07/01/nist-nist-launches-center-to-drive-the-manufacture-of-quantum-technologies/ -
NIST: NIST Launches Center to Drive the Manufacture of Quantum Technologies. “The U.S. Department of Commerce’s National Institute of Standards and Technology (NIST) has announced an agreement with SRI International, a nonprofit research and development institution, to help advance U.S. quantum research, development and manufacturing capabilities.”
https://rbfirehose.com/2026/07/01/nist-nist-launches-center-to-drive-the-manufacture-of-quantum-technologies/ -
NIST: NIST Launches Center to Drive the Manufacture of Quantum Technologies. “The U.S. Department of Commerce’s National Institute of Standards and Technology (NIST) has announced an agreement with SRI International, a nonprofit research and development institution, to help advance U.S. quantum research, development and manufacturing capabilities.”
https://rbfirehose.com/2026/07/01/nist-nist-launches-center-to-drive-the-manufacture-of-quantum-technologies/ -
Квантового компьютера нет, а ваш трафик уже собирают
TLS 1.3 с прямой секретностью - это правильный выбор. Если завтра скомпрометируют серверный ключ - прошлые сессии не расшифруются. Эфемерные ключи уничтожены. Все продумано. Проблема в том, что это защита от одного сценария. Не от того, о котором идет речь.
https://habr.com/ru/articles/1053538/
#постквантовая_криптография #hndl #tls #алгоритм_шора #crystalskyber #квантовые_вычисления #nist #pqc #signal #прямая_секретность
-
Квантового компьютера нет, а ваш трафик уже собирают
TLS 1.3 с прямой секретностью - это правильный выбор. Если завтра скомпрометируют серверный ключ - прошлые сессии не расшифруются. Эфемерные ключи уничтожены. Все продумано. Проблема в том, что это защита от одного сценария. Не от того, о котором идет речь.
https://habr.com/ru/articles/1053538/
#постквантовая_криптография #hndl #tls #алгоритм_шора #crystalskyber #квантовые_вычисления #nist #pqc #signal #прямая_секретность
-
Квантового компьютера нет, а ваш трафик уже собирают
TLS 1.3 с прямой секретностью - это правильный выбор. Если завтра скомпрометируют серверный ключ - прошлые сессии не расшифруются. Эфемерные ключи уничтожены. Все продумано. Проблема в том, что это защита от одного сценария. Не от того, о котором идет речь.
https://habr.com/ru/articles/1053538/
#постквантовая_криптография #hndl #tls #алгоритм_шора #crystalskyber #квантовые_вычисления #nist #pqc #signal #прямая_секретность
-
量子コンピュータが完成してからでは遅い。「今盗んで、後で解読する」脅威と、耐量子暗号(PQC)移行の最前線
https://qiita.com/d94231/items/4059669676c350b5dcba?utm_campaign=popular_items&utm_medium=feed&utm_source=popular_items -
#Cyberangriffe aus dem Kühlschrank:
Nicht nur hierzulande und in der #EU werden die Anforderungen an vernetzte digitale Geräte immer strenger.
Jüngst hat das #US #NIST einen aktualisierten Leitfaden für die #Cybersicherheit von #IoT-Produkten als öffentlichen Entwurf veröffentlicht, der bis Ende August zur Kommentierung offen steht und fachlich auf eigentlich nahezu jede Organisation, die IoT-Produkte in sicherheitskritische Infrastrukturen einbettet, anwendbar ist:
https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-213r1.ipd.pdf
-
#Cyberangriffe aus dem Kühlschrank:
Nicht nur hierzulande und in der #EU werden die Anforderungen an vernetzte digitale Geräte immer strenger.
Jüngst hat das #US #NIST einen aktualisierten Leitfaden für die #Cybersicherheit von #IoT-Produkten als öffentlichen Entwurf veröffentlicht, der bis Ende August zur Kommentierung offen steht und fachlich auf eigentlich nahezu jede Organisation, die IoT-Produkte in sicherheitskritische Infrastrukturen einbettet, anwendbar ist:
https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-213r1.ipd.pdf
-
#Cyberangriffe aus dem Kühlschrank:
Nicht nur hierzulande und in der #EU werden die Anforderungen an vernetzte digitale Geräte immer strenger.
Jüngst hat das #US #NIST einen aktualisierten Leitfaden für die #Cybersicherheit von #IoT-Produkten als öffentlichen Entwurf veröffentlicht, der bis Ende August zur Kommentierung offen steht und fachlich auf eigentlich nahezu jede Organisation, die IoT-Produkte in sicherheitskritische Infrastrukturen einbettet, anwendbar ist:
https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-213r1.ipd.pdf