🐧 Linux TippsDebian 11 Long Term Support reaches end-of-life(31.08.2026 um 02:00 Uhr)
🐧 Linux TippsUpdated Debian 13: 13.7 released(12.09.2026 um 02:00 Uhr)
🕵️ SicherheitslückenUSN-8741-1: Flatpak vulnerabilities(10.09.2026 um 10:44 Uhr)
🕵️ SicherheitslückenUSN-8742-1: Netty vulnerability(10.09.2026 um 11:01 Uhr)
🕵️ SicherheitslückenUSN-8737-2: GNU C Library vulnerabilities(10.09.2026 um 13:25 Uhr)
🕵️ SicherheitslückenUSN-8743-1: PHP vulnerabilities(10.09.2026 um 13:48 Uhr)
🕵️ SicherheitslückenUSN-8744-1: Python vulnerabilities(10.09.2026 um 15:53 Uhr)
🐧 Linux TippsUSN-8748-1: Linux kernel (NVIDIA) vulnerabilities(10.09.2026 um 17:32 Uhr)
🕵️ SicherheitslückenUSN-8745-1: KissFFT vulnerabilities(10.09.2026 um 17:36 Uhr)
🕵️ SicherheitslückenUSN-8746-1: libEBML vulnerability(10.09.2026 um 17:48 Uhr)
🐧 Linux TippsDebian 11 Long Term Support reaches end-of-life(31.08.2026 um 02:00 Uhr)
🐧 Linux TippsUpdated Debian 13: 13.7 released(12.09.2026 um 02:00 Uhr)
🕵️ SicherheitslückenUSN-8741-1: Flatpak vulnerabilities(10.09.2026 um 10:44 Uhr)
🕵️ SicherheitslückenUSN-8742-1: Netty vulnerability(10.09.2026 um 11:01 Uhr)
🕵️ SicherheitslückenUSN-8737-2: GNU C Library vulnerabilities(10.09.2026 um 13:25 Uhr)
🕵️ SicherheitslückenUSN-8743-1: PHP vulnerabilities(10.09.2026 um 13:48 Uhr)
🕵️ SicherheitslückenUSN-8744-1: Python vulnerabilities(10.09.2026 um 15:53 Uhr)
🐧 Linux TippsUSN-8748-1: Linux kernel (NVIDIA) vulnerabilities(10.09.2026 um 17:32 Uhr)
🕵️ SicherheitslückenUSN-8745-1: KissFFT vulnerabilities(10.09.2026 um 17:36 Uhr)
🕵️ SicherheitslückenUSN-8746-1: libEBML vulnerability(10.09.2026 um 17:48 Uhr)

📰 IT Security Nachrichten 🕛 vor 1 Monat 4 Min Lesezeit SECURITY-FEED
0

Mythos takes its first shot at post-quantum cryptography

↗ Quelle (csoonline.com)
🗣️ Stimme:
📑 Inhaltsübersicht








Anthropic’s Claude ).





Neither finding compromises production deployments nor weakens the security of real-world systems. Instead, Anthropic said, the findings improve the understanding of the security margins of modern cryptographic designs.





Security margin reduced





Hawk is among the post-quantum cryptographic ( designed to withstand attacks from quantum computers, and like some previously evaluated submissions relies on lattice-based cryptography.





“Despite Hawk having survived two rounds of expert human review over a period of two years, Mythos was able to improve the best-known attack on it in just 60 hours of work,” Anthropic said in a makes Hawk less practical to use because it effectively halves Hawk’s security level, meaning substantially larger key sizes will be required to restore its intended security. Such an increase would diminish many of the efficiency benefits that made Hawk an attractive post-quantum signature candidate, Anthropic wrote.





Anthropic’s new finding “is specific to Hawk and does not impact other NIST post-quantum signature candidates or lattice-based cryptography in general,” the company wrote.





The second attack is based on a new cryptanalytic technique, dubbed “Mobius Bridge,” which improves attacks against a weakened version of AES-128 using only seven “rounds” instead of the full-strength version’s 10. Rounds are the repeated series of mathematical transformations that AES and other encryption algorithms apply to protect data. Security researchers commonly study reduced-round variants to evaluate the security margins of block ciphers like AES.





Anthropic said the new technique improving the speed of the previous best attacks by 200-800 times previous attacks on the reduced-round construction while remaining well short of threatening the full versions of AES used in production.





No practical application





Anthropic explicitly stated that the research has no practical impact on the security of deployed AES implementations — and for good reason.





“The attack operates under a chosen plaintext threat model, which is the most common assumption used for studying ciphers like AES,” it explained in the blog post. This assumes that an attacker is able to request that the defender encrypt arbitrary inputs with a fixed, unknown key, and then gets to see the corresponding output. In this case, it assumes the attacker can request the encryption of 2^105 (about 4 billion billion billion) chosen plaintexts. “This attack is therefore completely impractical but quantifies the attack cost against AES under these assumptions,” it said.





Claude Mythos Preview discovered the attack almost entirely autonomously, Anthropic said, adding, “A researcher at Anthropic built a scaffold that enabled Claude to pose hypotheses, run experiments to experimentally validate or refute these hypotheses, and then asked Claude to design an attack that improves on the best cryptanalysis of AES.”





Even with AI accelerating some parts of the research, more time is spent verifying the correctness of results. The improved attack on AES was discovered in about a week, but took two researchers nearly a month to validate, Anthropic said.


Vollständiger Original-Bericht
Ausführliche Details, Code-Beispiele & Hersteller-Stellungnahme auf csoonline.com.
↗ Original-Artikel auf csoonline.com lesen
Wie bewertest du diesen Beitrag?
1 Klick Feedback
Teilen mit Netzwerk & Team:
Community Threat-Level Barometer
Live Votum

Wie stufst du das Risiko dieser Schwachstelle / Bedrohung für dein Unternehmen ein?

Noch keine Stimmen — schätze das Risiko als Erster ein.

Community-Analysen & Experten-Meinungen 0

Verfasse deine eigene Analyse, teile Workarounds oder diskutiere diesen Vorfall im Blog.
Noch keine Community-Analyse verfasst. Markiere einen Textabschnitt oder klicke oben auf Eigene Analyse verfassen“!
Community Pulse: Relevanz-Einschätzung
1 Klick Experten-Votum
🔴 Akute Relevanz 0%
🟡 In Evaluierung 0%
🟢 Keine Auswirkung 0%
Spannende Innovation 0%
Verwandte Story-Cluster & Quellen (Vektor-KI)
Port 8095 Engine
1 Quelle
Debian 11 Long Term Support reaches end-of-life
1 Quelle
Updated Debian 13: 13.7 released
1 Quelle
USN-8741-1: Flatpak vulnerabilities