Auto-updated

Latest Cryptography & Security News

Headlines pulled automatically from NIST, IACR, and trusted security news outlets, refreshed every few hours. Titles and excerpts only — click through to read the full story at the original source.

Industry Dark Reading · Oct 9, 2026
What We Missed: FBI Strikes Back at ShinyHunters

In this video conversation, Dark Reading editors discuss some of the news they didn't get a chance to cover, from the arrest of a suspected ShinyHunters operative to the compromise of a Pentagon-run data center.

Vulnerabilities The Hacker News · Oct 8, 2026
16 Malicious Firefox Extensions Pose as Rabby and OKX Wallets to Steal Recovery Phrases

Cybersecurity researchers have discovered a cluster of 16 malicious Mozilla Firefox extensions that are capable of stealing cryptocurrency wallet recovery phrases and private keys. "The extensions masquerade as wallet portals, desktop utilities, and browser tools, but their code intercepts recovery phrases and private keys during wallet import flows and attempts to send those secrets to

Vulnerabilities The Hacker News · Oct 8, 2026
MonsterCloud Owner Accused of Billing Over $19M While Secretly Paying Ransoms to Decrypt Data

The U.S. Department of Justice (DoJ) on Wednesday announced charges against a 50-year-old U.S. and Israeli national for allegedly defrauding ransomware victims by secretly paying the attackers to obtain decryptors while claiming to use proprietary tools to recover their data. Zohar Pinhasi (aka Zack Silver and Zack Green) has been charged with two counts of wire fraud and one count of wire

Research IACR ePrint Archive · Oct 7, 2026
Time-Space Tradeoffs For Probabilistic Proofs

Many recent constructions of probabilistic proofs achieve fast proving times but have high space complexity (much higher than that of the computation being proved). Empirically this arises due to the fact that error-correcting codes, a key ingredient of such constructions, suffer from limiting time-space tradeoffs. It remained open, however, whether such time-space tradeoffs exist for proofs them…

Vulnerabilities BleepingComputer · Oct 7, 2026
Ransomware recovery CEO charged over secret ransom payments

The owner of ransomware remediation company MonsterCloud has been charged with allegedly defrauding ransomware victims by secretly paying their attackers for decryptors while claiming to use proprietary technology to recover encrypted data. [...]

Research IACR ePrint Archive · Oct 7, 2026
Game-Theoretically Fair Coin Toss from Random Walk Against $n-1$ Corruptions

Coin-tossing protocols allow mutually distrustful parties to generate trusted randomness. While strong fairness is impossible against a corrupted majority, Chung et al. (2018) introduced cooperative-strategy-proof (CSP) fairness for multi-party coin tossing, under the assumption that each party gets utility only when the outcome matches its public preference. CSP-fairness ensures that no PPT adve…

Vulnerabilities BleepingComputer · Oct 7, 2026
FBI: Ongoing FortiBleed attacks lock out FortiGate VPN admins

The FBI is warning that FortiBleed attacks are still ongoing, targeting exposed Fortinet FortiGate firewalls and SSL VPN gateways and locking out legitimate administrators. [...]

Research IACR ePrint Archive · Oct 7, 2026
The Geometry of Collusion Leakage in Inner-Product Functional Encryption

Inner-product functional encryption (IPFE) allows the holder of a functional key for a vector $y$ to learn $\langle x,y\rangle$ from an encryption of $x$, and nothing more. Keys, however, accumulate: a coalition holding sufficiently many independent keys recovers the plaintext. We model each institution by the span $W_i\leq\F_q^n$ of its authorized key vectors and show that a coalition $I$ determ…

Research IACR ePrint Archive · Oct 7, 2026
Practical and Efficient MPC from FHE, without ZKPoKs

Fully Homomorphic Encryption (FHE) enables one to implement low-round and low-communication complexity Multi-Party Computation (MPC) which is secure in the static malicious corruption model. By expanding on an idea presented in the full version of the FHE-based MPC protocol of Smart (IMA, 2023), we show how to completely remove the need for Zero-Knowledge Proofs-of-Knowledge in that protocol. Thi…

Vulnerabilities The Hacker News · Oct 7, 2026
Attackers Hijack .gh, .sl, and .as Registries to Obtain Certificates for Google Domains

Attackers compromised three country-code top-level domains (ccTLDs) and obtained unauthorized HTTPS certificates for several Google domains, Google said on October 6. Google's own systems were not breached, but any domain ending in .gh (Ghana), .sl (Sierra Leone) or .as (American Samoa) was put at risk. With such a certificate, an attacker could pose as the real site over an encrypted

Research IACR ePrint Archive · Oct 7, 2026
Revisiting Lattice-based Blind Signatures Again

We show an attack on a lattice-based blind signature proposed in Crypto'20. Formally it is a linear hash function based framework with a lattice-based instantiation. We first notice a bug in their security proof of blindness, which is overlooked these years. Then, we develop an attack under the honest key and the honest-but-curious signer setting against the blindness notion of the schemes by exp…

Research IACR ePrint Archive · Oct 7, 2026
New infinite families of APN functions from the switching construction in even dimension

We present the first new infinite family of APN functions obtained by applying the switching construction to a known family since the introduction of the Budaghyan-Carlet-Leander family in 2009. Our construction is also the first example of an infinite APN family obtained via the switching construction from an infinite family of non-power functions. More generally, we study families of APN functi…

Research IACR ePrint Archive · Oct 7, 2026
Simple Byzantine Lattice Agreement in $O(\frac{\log f}{\log \log f})$ Rounds

Lattice agreement is a relaxed version of the standard consensus problem: correct processes need not decide the same value, but their decisions must be ``comparable''. Namely, every process proposes a value from a join semi-lattice, and correct processes decide values that (1) lie on a single chain, (2) include their own proposals, and (3) include nothing beyond what was proposed. Lattice agreeme…

Research IACR ePrint Archive · Oct 7, 2026
A Note on Extractable Witness Encryption in Generic Groups

Hair and Sahai have recently proposed a construction of witness encryption for NP satisfying semantic security. In this short note we observe that this recent witness-encryption construction is unconditionally extractable in the generic group model. This yields a construction of extractable witness encryption without assuming subexponential soundness of SNARGs, in contrast to the recent work of J…

Research IACR ePrint Archive · Oct 7, 2026
Note on Extractability of PST Polynomial Commitment Scheme

A recent work by Belohorec et al. (Crypto, 2025) shows that the well-known PST multivariate polynomial commitment scheme is black-box extractable under falsifiable assumptions. They show that a minimally modified (extended) PST is extractable under an assumption ARSDH($n$), and that the canonical PST is extractable under an assumption GARSDH($n$). Both of these assumptions are new and more specia…

Research IACR ePrint Archive · Oct 7, 2026
Hashing Beats Trees: Practical Oblivious Dictionaries in SGX

Oblivious RAM (ORAM) is a powerful cryptographic primitive that hides both the contents of outsourced data and the access pattern to the data. However, it offers only a restrictive array-based interface. A principal obstacle to its deployment is building an efficient oblivious dictionary upon it. To build such a dictionary, the state-of-the-art layers an oblivious AVL tree over ORAM, avoids an ex…

Research IACR ePrint Archive · Oct 7, 2026
Hide Now, Trace Later: Retrospective Attribution in Issuer-Hiding Credentials

Attribute-based credentials (ABCs) enable privacy-preserving authentication by allowing users to prove statements about certified attributes without revealing unnecessary information. However, while ABCs hide undisclosed attributes, the credential verification process inherently reveals the issuer's identity, which can leak contextual information such as a user's nationality or residency. Issuer-…

Vulnerabilities The Hacker News · Oct 7, 2026
FBI Warns FortiBleed Remains Active After Amassing 86,644 Fortinet Device Credentials

The U.S. Federal Bureau of Investigation (FBI) and Secret Service (USSS) on Tuesday warned that the FortiBleed credential harvesting campaign remains an active threat aimed at internet-facing Fortinet FortiGate firewalls and secure socket layer (SSL) virtual private network (VPN) gateways. "The campaign exploits reused or leaked credentials and legacy SHA-256 password storage, enabling threat

Research IACR ePrint Archive · Oct 7, 2026
The Price of Privacy: Randomness Complexity of Graph-Based Multi-Secret Sharing

We study the randomness required to share possibly correlated secret bits among parties connected by a graph. A dealer places shares on the edges so that each party can recover its own secret from its incident shares and learn nothing about the others beyond what its own secret reveals. Anilkumar et al. completely determined the minimum randomness required for three binary secrets. We extend this…

Research IACR ePrint Archive · Oct 7, 2026
Post-Quantum Dropout-Resilient Verifiable Secure Aggregation for Federated Learning

Secure weighted aggregation is essential for privacy preserving federated learning, yet existing schemes do not simultaneously provide post-quantum security, resilience to client dropouts, verifiability against malicious servers, and resistance to bounded collusion between the server and clients. This paper presents PQ-DVSA, a verifiable secure aggregation scheme that provides post-quantum securi…

Research IACR ePrint Archive · Oct 7, 2026
Round Optimal MPC With Provable Cheater Identification

Secure multiparty computation with provable identifiable selective abort (PISA), introduced by Kondi and Ravi (CCS 2025), guarantees that every honest party either obtains the computation output or a certificate that convinces any external auditor that a specific party cheated. Crucially, honest parties need not agree: some may get output while others receive evidence of cheating. In contrast, se…

Research IACR ePrint Archive · Oct 7, 2026
Fair and Efficient Helper-Aided MPC with Cheater Identification

Secure multi-party computation (MPC) enables privacy-preserving tasks such as auctions and voting. In practice, more than half of the parties may collude, making security against a dishonest majority desirable. Unfortunately, dishonest-majority MPC suffers from high communication and can achieve only abort security. For instance, in an auction, an adversary may abort after learning the outcome an…

Research IACR ePrint Archive · Oct 7, 2026
Retention Choices for Quantum CHAM Key Search under a Global Qubit Budget

Retaining intermediate values can shorten a quantum cipher oracle but increase the logical qubits required by each parallel search worker. We propose a joint selection procedure for 80-round and revised 112-round CHAM-128/128 under a fixed global logical-qubit budget. It selects retained round addends, feasible integer allocations of search workers, and execution plans to minimize maximum schedul…

Research IACR ePrint Archive · Oct 7, 2026
A Universal Forgery Attack on the Origami Signature Scheme from the Public Key Alone

Origami is a multivariate signature scheme submitted to the NGCC round-1 public-key call. We show that the submitted bilinear construction is a Rainbow-type scheme whose central map is exposed. The verification map is the layered signing map in a public coordinate order. The public key therefore gives an equivalent secret key, allowing signature forgery at about the cost of one verification (abou…

Research IACR ePrint Archive · Oct 7, 2026
Lifting Bounded-Collusion Security to Full Security in Pairing-Based Encryption Schemes

Notions like identity-based encryption (IBE) and attribute-based encryption (ABE) augment public-key encryption to provide fine-grained access control to encrypted data. In these settings, there is a single master public key that anyone can encrypt to. Users in turn possess different secret keys that determine which ciphertexts they can decrypt. The standard, or full, security notion for these sc…

Research IACR ePrint Archive · Oct 7, 2026
Faster Provable Lattice Sieving with Spherical Codes

We study the computational problem $\mu$-SVP, in which the goal is to find a $\mu$-approximate shortest non-zero vector in a lattice $\mathcal{L}$, for constant approximation factors $\mu > 1$. Prior to this work, there was a large gap between the fastest algorithms for this problem whose correctness had been proven and the fastest heuristic algorithms, whose correctness has not been proven (but …

Industry Dark Reading · Oct 6, 2026
Critical Healthcare Systems Aren't Quantum-Ready

A study of 2.5 million devices across 50 healthcare organization suggests the sector has a long way to go in getting ready for the post-quantum cryptography era.

Research IACR ePrint Archive · Oct 6, 2026
Quantum Time-Lock Puzzles in the Quantum Random Oracle Model

A time-lock puzzle allows a sender to hide a message in a puzzle such that recovering the message requires substantially more sequential computation than the time required to generate the puzzle, even when parallel computation is allowed. Applications of time-lock puzzles include timed-release encryption, sealed-bid auctions, electronic voting, fair contract signing, coin flipping, and Byzantine …

Research IACR ePrint Archive · Oct 6, 2026
Provable Subexponential Algorithms for NIST Third-Round Lattice Families

We give provable classical subexponential algorithms for secret recovery in growing parameter families associated with NIST third-round lattice candidates. For the Kyber/ML-KEM, FrodoKEM, SABER, NTRU LPRime, and Dilithium/ML-DSA families studied here, polynomial moduli and polylogarithmic coefficient scales yield recovery of the short secret component in expected time and space $2^{(1/2+o(1))n/\l…

Research IACR ePrint Archive · Oct 6, 2026
SkrrtPIR: Doubly-Stateless Batch PIR from Single-Key RLWE Unpacking

Batch Private Information Retrieval (Batch PIR) allows a client to privately retrieve multiple entries from a public database while amortizing query costs. However, concretely efficient schemes typically rely on per-client server state, such as client-specific evaluation keys, which makes queries linkable across sessions and complicates deployment. In this work, we initiate the study of doubly-st…

Research IACR ePrint Archive · Oct 6, 2026
A Security-Aware PQC Benchmarking Framework on Dual-Core Xtensa Silicon

Deploying memory-heavy post-quantum cryptography (PQC) at the smart grid edge threatens real-time substation determinism, directly conflicting with the strict $\le 3 ms$ GOOSE tripping window of the IEC 61850 standard. To resolve this architectural tension, we propose a security-aware, hardware-in-the-loop benchmarking framework on the dual-core Xtensa LX7 (ESP32-S3) SoC running FreeRTOS. To prev…

Research IACR ePrint Archive · Oct 6, 2026
The Post-Quantum Cost of Garbled-Circuit Bitcoin Bridges

Recent Bitcoin bridge designs rely on verification of succinct proofs to process withdrawals. This requires off-chain garbled circuit evaluation of a succinct proof, the input labels for which must be encoded on chain in a manner compatible with malicious security. We assess the post-quantum vulnerability of these cryptographic components, and examine the costs of secure alternatives. Circuit siz…

Research IACR ePrint Archive · Oct 6, 2026
Differential-Neural Cryptanalysis of ChaCha and Related ARX Stream Ciphers

The paper presents the first-ever differential neural cryptanalysis of the Latin Dances family of Salsa, ChaCha, and Forró. First, we provide a systematic differential-neural study of the ARX stream cipher ChaCha. We train and compare six neural architectures, viz.: Gohr's residual network, DBitNet, an Inception network, an MLP-ResNet, an SE-ResNet, and a self-attention network on a 3-round reduc…

Research IACR ePrint Archive · Oct 6, 2026
The Lattice Isomorphism Problem with Hints

The Lattice Isomorphism Problem (LIP) is a relatively new problem that has gained increasing attention in the field of lattice-based cryptography. It is the underlying hard problem of the Hawk signature scheme, which has been submitted to the second NIST call for post-quantum signatures. In this paper, we propose to study the security of LIP in the presence of partial information on the secret so…

Research IACR ePrint Archive · Oct 6, 2026
The Graded Monoidal Action for Cryptography

We give a new framework for constructing post-quantum protocols based on graded monoidal actions. An essential difference between the graded monoidal action framework and the cryptographic group action framework is that our higher-rank problems give rise to infinite structures, where elements do not admit inverses, while cryptographic group actions are finite by definition. Nevertheless, we show …

Research IACR ePrint Archive · Oct 6, 2026
Settling Conjectures on Linear Structures of Inverse ChiChi Generalizations Four Proofs and a Counterexample

Belkheyar et al. introduced ChiChi as the even-dimensional, low-latency nonlinear core of ChiLow (Eurocrypt 2025), and Andreoli et al. generalized it into the SWAP and 4-cycle families (ToSC 2025/3), conjecturing five bounds on the linear height and component linear nullity of their inverses, supported by experiments in small dimensions. We settle all five conjectures: Conjectures 1–4 hold for ev…

Research IACR ePrint Archive · Oct 6, 2026
AsyncLS: an iUC Framework for Wallet-Based Asynchronous Ledger Services

We define an asynchronous ledger service ($\mathsf{AsyncLS}$) in the IITM-based universal composability (iUC) framework. The wallet-based service exposes a general state machine for a decentralized ledger-based application through registration, reads of committed application state, authenticated submission, and status queries with immutable final results. Each logical request binds the user's aut…

Research IACR ePrint Archive · Oct 6, 2026
MIKE: a fast and compact post-quantum NIKE

We introduce MIKE (Module Isogeny Key Exchange), a post-quantum NIKE (Non Interactive Key Exchange) whose security relies on the CDH problem for the rank-$2$ Hermitian module action on supersingular elliptic curves. For NIST level~$1$, MIKE has very compact public keys of 80B, and using our constant time C implementation, the key generation takes 0.65ms and the shared secret takes 4.9ms (includin…

Research IACR ePrint Archive · Oct 6, 2026
Truffle: Maliciously Secure Three-Party Shuffles with Applications to Parsing

Deploying Secure Multiparty Computation (MPC) to operate on data from real world sources requires many connective elements that have not received much attention in the literature. One prominent example is that MPC protocols typically assume conveniently structured data, whereas data in the real world comes in formats that are meant to be handled by string parsing engines. In this work, we give a …

Research IACR ePrint Archive · Oct 6, 2026
PoP! Goes the VOLE: Shorter Proofs of Possession for KEM Certificates

The shift to Post-Quantum Cryptography (PQC, a.k.a. quantum-resistant cryptography) is considered the immediate solution to the threat posed to public key cryptography/PKI by quantum computers. Due to the variety of PQC algorithms (and their characteristics), researchers have proposed different PQC migration strategies. For example, KEMTLS (Schwabe, Stebila, and Wiggers, CCS '20) replaces TLS han…