Palo Alto walks through a 3-zero-day chain on Siemens ROX II, from file read to persistent root, because one bug was too mainstream.
trending30
01 02 Paper on SPiRiT, a verifiable contact-tracing protocol for privacy and safety, because even pandemics need audits.03 ε-Indistinguishability In Moving Target Defense: Framework, Algorithms, And Cloud Case Studies arxiv.orgAnonymity turns into a densest-window query here, and two cloud case studies show deployment noise wrecks the nice math.04 TEE plus secret sharing plus MPC for outsourced ML training, because apparently one trust model was too simple.05 Separable generalized integral properties get matrix/MILP and Gaussian-elimination solvers for automated distinguisher search.06 Multi-party quantum PSI with verifiability and collusion resistance, built on qFHE and threshold FHE, not the usual 2-party toy.07 Unbounded-depth ABE on a new doubly circular assumption, because ordinary assumptions apparently needed more circles.08 Paper on Reed-Solomon MCA bounds past the Johnson radius, with polynomially many bad lines, because the radius needed one more paper.09 Survey of secure ranked e-voting designs, from mix-nets to ZKPs, and yes, every privacy guarantee has a leak somewhere.10 Docs page on Asentum's Tendermint-style BFT PoS, rotating ~100 validators, stake quorums, and ML-DSA-65/BLAKE3 choices.11 wolfSSL post on ML-DSA for PKCS#7/CMS SignedData, because even S/MIME now needs a quantum-resistance badge.12 CMALU: Compact Fault-Tolerant Modular Arithmetic Logic Unit for Post-Quantum Cryptography eprint.iacr.orgCan a compact modular arithmetic unit for PQC catch faults without turning into a bloated side project? CMALU says yes.13 PUFs still have a pulse: this paper benchmarks Arbiter vs hybrid oscillator designs for low-power wearable key gen.14 Quantum resource estimates for Rijndael/AES under MAXDEPTH, with verified ProjectQ oracles, because even ciphers need a spreadsheet.15 Is External Database Protection Static in Retrieval-Augmented Generation? Rethinking Privacy Preservation under Dynamic Queries arxiv.orgRAG privacy is query-dependent, so this paper proposes PA-HDP to replace entities and pick safer text.16 Rust NTRU+, SMAUG-T, HAETAE, and AIMer with SIMD, then measures speed and memory against C refs and a naive Rust port.17 Is RainHash2.0 the new ZK hash sweet spot? Paper claims better arithmetization and FPGA speed for binary-field proofs.18 Benchmarks security agents by cost per success, showing red-team and blue-team tasks scale very differently.19 OASIS Approves Two Public-Key Cryptography Standards to Advance Post-Quantum Security and Interoperability oasis-open.orgOASIS ratifies PKCS#11 v3.2 and profiles, finally adding PQC support to the HSM API everyone already ships around.20 bc-rust 0.1.2alpha release notes, with ML-KEM/ML-DSA, low-memory variants, suspendable APIs, and less secret-data footguns.21 Practical consistent broadcast encryption with linear ciphertext and linear work per recipient, from two generic schemes.22 Surprise: a banking app negotiated TLS_RSA_WITH_AES_128_CBC_SHA, and Corrata walks through catching it on-device.23 Can secure aggregation work with one server and no secret forwarding? This paper says yes, via two-layer secret sharing.24 Automated Template-free Synthesis of Instruction-Centric Leakage Contracts for Black-Box CPUs arxiv.orgTemplate-free synthesis of instruction-centric leakage contracts for black-box CPUs, so the hand-written folklore can retire.25 CT-KAT: A Multilayer Analysis Platform for Automated Screening of Constant-Time Risks in PQC C Implementations eprint.iacr.orgePrint paper on CT-KAT, a CT-risk screening pipeline for PQC C code, because apparently one check was too easy.26 [PRÉSENTATION] Outils numériques : Devenir invisible sur l’Internet avec NymVPN / Becoming Invisible on the Internet with NymVPN | Le Steki lesteki.beEvent page for a talk on NymVPN, mixnets, cover traffic, and the SDK, because privacy networking needed another acronym.27 Paper on sublinear-communication layered MPC from HSS, with dynamic participation and fewer online servers, naturally.28 Shuffled-ArgMax: Securing ArgMax Decisions Against Side-Channel-Guided Fault Injection in Edge-AI IoT Devices eprint.iacr.orgTurns out you can steer voltage faults with side-channel leaks to flip ArgMax, so they randomize traversal and verify loops.29 Beyond Size: Do Hybrid PQC Certificates Actually Enforce the Classical–PQC Binding? A Cost-and-Security Study eprint.iacr.orgFinally measures whether hybrid certs actually bind classical and PQC signatures in real TLS stacks, and the ranking changes.30 Seven open problems, handpicked by 11 isogeny experts, because apparently post-quantum crypto still needs homework.