OpenSSH 10.4 lands with 8 security fixes and experimental ML-DSA 44 + Ed25519, because crypto entropy wasn't enough.
trending30
31 32 DigiCert's Quantum Central is a PQC readiness tool for crypto inventory, discovery, and migration tracking, because audits are fun.33 RustMizan: A Compilable, Contamination-Aware Benchmarking Framework for Rust Vulnerabilities arxiv.orgRustMizan is a Rust vuln benchmark with compilable variants, CWE labels, and contamination tests, since folklore needed CI.34 BIS Bulletin on why permissionless consensus keeps spawning L1s, L2s, and the usual fragmentation of liquidity and assets.35 Notre Dame faculty profile for Taeho Jung, with his crypto, blockchain, privacy work, papers, awards, and lab info.36 Beyond Gradient-Based Attacks: Adversarial Robustness and Explainability Stability in Cybersecurity Classifiers arxiv.orgPaper measures how cyber classifiers can stay right while their explanations drift, via ESI on Random Forest and XGBoost.37 Can you fingerprint the embedding model from unordered retrieval results? Apparently yes, and the paper tests rerankers and RAG too.38 Paper proposes EvoVuln, which evolves smart-contract vuln rules from a few labels instead of touching model weights.39 Most PQC car talk stops at firmware, this one wants it in TPMs, HSM IP, chiplets, and a future QASIC.40 Trump's crypto EO talk, not new crypto, just policy and deployment handwringing over PQC rollout.41 When do agencies and contractors have to ditch RSA, and what PQC deadlines did the White House just set?42 NIST's PQC migration FAQ covers threat timing, crypto inventories, risk, planning, testing, and validation.43 Trust Boundary Semantic Gaps: A Multi-dimensional Analysis and Mitigation for Security-by-Design arxiv.orgHow do you catch stuff that validates but still fails the receiver’s security model? This paper calls it TBSGs and splits it 4 ways.44 Extends the usual block-withholding story: under PPS, the best attack is to withhold everything and let difficulty do the rest.45 Ledger’s AI tools docs, for wallet CLI runtime ops and DMK build-time signing, with hardware as the last human veto.46 Deep dive on Windows revocation providers and trust validation, for when CRL/OCSP's good enough is apparently not.47 A Non-Line-of-Sight, Multi-Modality-based Side-Channel IP Theft Attack on Additive Manufacturing Using Dual Smartphones arxiv.orgTwo smartphones do off-axis acoustic plus magnetic G-code theft from 3D printers, because confidentiality is optional.48 Quantum Readiness: A Practical Primer for Financial Services and Digital Assets Companies and Projects ashurstperkinscoie.comPractical primer on quantum readiness and PQC for finance and crypto stacks, now with the usual inventory, vendors, and board angst.49 Paper on Hema, a formally verified mutual attestation protocol for same or mixed TEEs, since one attestation stack was not enough.50 zkSecurity's zkao v1 is a deep-research bug finder for crypto codebases, still KYB-gated because apparently scanners need adult supervision.51 Red Hat Delivers Post-Quantum Readiness and AI-Powered Automation with Latest Versions of Red Hat Enterprise Linux redhat.comRed Hat's RHEL 10.2/9.8 pitch adds post-quantum crypto, confidential computing, and AI-assisted admin to the usual distro churn.52 Taiko says its chain-state verifier is compromised, so bridges on Taiko are now trusting a broken oracle.53 How did a deprecated zk-rollup get drained? This postmortem blames a proof/settlement mismatch, not the setup, and says Aztec Network was...54 An informal threat-modeling guide with E2EE, key transparency, and PQC examples, since guessing attackers is apparently a hobby.55 End-to-end confidential AI for CPU+GPU TEEs, with attestation and benchmarks, not the usual single-box secure inference demo.56 Shows a forgery attack on Block.co's credential system, where valid-looking certificates can be minted by exploiting its trust-associatio...57 Microsoft says critical products and services should be on post-quantum crypto by 2029, plus the usual TLS 1.3 cleanup.58 Paper benchmarks prompt-injection defenses and finds the usual fix, stripping instructions, also breaks translation and editing; SecFid f...59 Probe Choice Changes Canary-Memorization Verdicts: Three Post-Hoc Disagreement Case Studies in a Text-Dominant LoRA-Tuned Autoregressive Testbed arxiv.orgPrefix-window mean-NLL, meet reality: this canary paper shows it can disagree with full-span secret NLL and exact recall.60 MySecurityTV talk on post-quantum migration and quantum-safe security, because apparently RSA isn't forever.