LINKED LIST [txt mode] ▸ @pubkey ▸ Blog
home explore | log in

Blog

by @pubkey · last added 2026-10-06 · 17 items

─── 2026-10-06 (1) ─────────────────────────────────────

* OpenSSH 10.6: LZ77 compression disabled over cross-channel plaintext recovery, GSSAPI and sftp path fixes
openssh.com · node›

─── 2026-10-05 (1) ─────────────────────────────────────

* Smashing the token limit: CSS-injection exfil of long tokens via overlapping fragments
portswigger.net · node›

─── 2026-10-04 (1) ─────────────────────────────────────

* Too Small to Hide: single-trace key recovery from ML-KEM keygen
eprint.iacr.org · node›

─── 2026-10-03 (1) ─────────────────────────────────────

* Recovering SNOVA secret keys from biased vinegar sampling
eprint.iacr.org · node›

─── 2026-10-02 (1) ─────────────────────────────────────

* Incomplete FO ciphertext compare in ML-KEM: IND-CCA2 break to key recovery
eprint.iacr.org · node›

─── 2026-10-01 (1) ─────────────────────────────────────

* OpenSSL Security Advisory (29 Sep 2026): DTLS heap disclosure, EC/SM2 timing leaks
openssl-library.org · node›

─── 2026-09-29 (1) ─────────────────────────────────────

* MAMBA-Frost: lattice KEM from Learning With Quantization
eprint.iacr.org · node›

─── 2026-09-28 (1) ─────────────────────────────────────

* Breaking the Gómez-Torrecillas–Lobillo–Navarro cryptosystem with LLL
eprint.iacr.org · node›

─── 2026-09-27 (1) ─────────────────────────────────────

* Forging 1024-bit RSA signatures in nearly SNFS time
eprint.iacr.org · node›

─── 2026-09-26 (2) ─────────────────────────────────────

* Factoring "short-sleeve" RSA keys with polynomials
blog.trailofbits.com · node›
* Automatic Key Exchange: post-quantum origin TLS without the HelloRetryRequest tax
blog.cloudflare.com · node›

─── 2026-09-23 (2) ─────────────────────────────────────

* pyca/cryptography: duplicate self-signed certs cause exponential path-building DoS
github.com · node›
* TLS 1.3 client skips server auth on unsolicited PSK (Erlang/OTP)
github.com · node›

─── 2026-09-21 (4) ─────────────────────────────────────

* Fiat-Shamir bugs: how one missing line breaks a proof system
blog.zksecurity.xyz · node›
* CVE-2026-6550: AWS Encryption SDK key-commitment cache bypass
notcve.org · node›
* CVE-2026-45446 writeup: missing cryptographic step
rapid7.com · node›
* CVE-2026-45446: OpenSSL AES-SIV/GCM-SIV empty ciphertext forgery
nvd.nist.gov · node›