login sign up

Blog

by @pubkey · 17 nodes · curated
untagged
OpenSSH 10.6: LZ77 compression disabled over cross-channel plaintext recovery, GSSAPI and sftp path fixes openssh.com · Oct 6 openssh.com · Oct 6
1 person saved or upvoted this
Smashing the token limit: CSS-injection exfil of long tokens via overlapping fragments portswigger.net · Oct 5 portswigger.net · Oct 5
1 person saved or upvoted this
Too Small to Hide: single-trace key recovery from ML-KEM keygen eprint.iacr.org · Oct 4 eprint.iacr.org · Oct 4
1 person saved or upvoted this
Recovering SNOVA secret keys from biased vinegar sampling eprint.iacr.org · Oct 3 eprint.iacr.org · Oct 3
1 person saved or upvoted this
Incomplete FO ciphertext compare in ML-KEM: IND-CCA2 break to key recovery eprint.iacr.org · Oct 2 eprint.iacr.org · Oct 2
1 person saved or upvoted this
OpenSSL Security Advisory (29 Sep 2026): DTLS heap disclosure, EC/SM2 timing leaks openssl-library.org · Oct 1 openssl-library.org · Oct 1
1 person saved or upvoted this
MAMBA-Frost: lattice KEM from Learning With Quantization eprint.iacr.org · Sep 29 eprint.iacr.org · Sep 29
1 person saved or upvoted this
Breaking the Gómez-Torrecillas–Lobillo–Navarro cryptosystem with LLL eprint.iacr.org · Sep 28 eprint.iacr.org · Sep 28
1 person saved or upvoted this
Forging 1024-bit RSA signatures in nearly SNFS time eprint.iacr.org · Sep 27 eprint.iacr.org · Sep 27
1 person saved or upvoted this
Factoring "short-sleeve" RSA keys with polynomials blog.trailofbits.com · Sep 26 blog.trailofbits.com · Sep 26
1 person saved or upvoted this
Automatic Key Exchange: post-quantum origin TLS without the HelloRetryRequest tax blog.cloudflare.com · Sep 26 blog.cloudflare.com · Sep 26
2 people saved or upvoted this
pyca/cryptography: duplicate self-signed certs cause exponential path-building DoS github.com · Sep 23 github.com · Sep 23
1 person saved or upvoted this
TLS 1.3 client skips server auth on unsolicited PSK (Erlang/OTP) github.com · Sep 23 github.com · Sep 23
1 person saved or upvoted this
Fiat-Shamir bugs: how one missing line breaks a proof system blog.zksecurity.xyz · Sep 21 blog.zksecurity.xyz · Sep 21
1 person saved or upvoted this
CVE-2026-6550: AWS Encryption SDK key-commitment cache bypass notcve.org · Sep 21 notcve.org · Sep 21
1 person saved or upvoted this
CVE-2026-45446 writeup: missing cryptographic step rapid7.com · Sep 21 rapid7.com · Sep 21
1 person saved or upvoted this
CVE-2026-45446: OpenSSL AES-SIV/GCM-SIV empty ciphertext forgery nvd.nist.gov · Sep 21 nvd.nist.gov · Sep 21
1 person saved or upvoted this