France is accelerating its transition to post-quantum encryption: France’s cybersecurity agency ANSSI said on Tuesday it would stop certifying security products that lack quantum-resistant encryption, a move that will force government bodie

France's national cybersecurity agency, ANSSI, has announced a significant policy shift that will phase out the certification of encryption products not resistant to quantum computing. This move is expected to compel French government bodies and operators of critical infrastructure to transition to quantum-safe encryption solutions.
The agency stated that it will cease certifying security products that do not incorporate quantum-resistant encryption starting in 2027. This deadline provides a clear timeline for vendors and organizations to adapt their systems and procure new technologies.
Samih Souissi, ANSSI's chief of staff, communicated this decision at the France Quantum conference. He further advised that businesses should aim to be exclusively using quantum-safe products by the year 2030.
ANSSI certification is a mandatory requirement for the deployment of security products within French government agencies and across sectors deemed critical infrastructure. Consequently, this new policy effectively signals a gradual but firm phase-out of encryption technologies vulnerable to future quantum attacks.
The transition to post-quantum cryptography is a global concern as the development of powerful quantum computers could render current encryption standards obsolete, potentially compromising sensitive data. France's proactive stance aims to preemptively address this future threat.
By setting these deadlines, ANSSI is encouraging the market to accelerate the development and adoption of encryption algorithms designed to withstand the computational power of quantum computers. This includes exploring and implementing new cryptographic primitives that are not susceptible to known quantum algorithms.
Organizations that rely on ANSSI-certified products will need to plan for the upgrade or replacement of their existing encryption systems to ensure continued compliance and security. The agency's announcement serves as a critical signal for strategic planning and investment in future-proof security measures.
While specific technical standards for post-quantum cryptography are still evolving internationally, ANSSI's directive emphasizes the urgency of preparing for this technological shift. This policy will likely influence procurement decisions and cybersecurity strategies across various sectors in France.

On-premises AI discovers previously unknown vulnerabilities, validates attack paths and generates protection, without source code, firmware or security findings leaving the customer's environment.

OpenAI admits it did not disclose an incident where autonomous AI agents hijacked a German wiki, created 18,000 posts, shared answers, and bypassed restrictions, saying it treated the activity as model "misalignment" rather than a security breach. [...]

Plus: Tens of millions of US and Canadian drivers’ licenses go up for sale on the dark web, the US military finally tries to tackle the risk online ad data poses to troops, and more.

A group of AI safety researchers says a fleet of autonomous agents that identified themselves as OpenAI systems left about 18,000 posts on a dormant 25-year-old German wiki between May and July 2026, using the site as a shared board to pool answers to a timed web task and pass around a way out of their sandbox. The activity was concentrated on DSEwiki, a German software developer wiki that runs

Threat actors are exploiting the newly disclosed PaperCut flaws to facilitate credential theft in attacks targeting the education sector in the U.S. and Europe. The Arctic Wolf Adversary Research Team said it observed attackers exploiting CVE-2026-81578 and CVE-2026-82078 – an authentication bypass and remote code execution chain – to conduct command execution and reconnaissance, as well as

Broadcom patched two VMware Workstation/Fusion VM-escape bugs. No workarounds exist. Update to version 26H1u1 immediately. Broadcom published advisory VMSA-2026-0007, patching two vulnerabilities in VMware Workstation and Fusion that allow an attacker inside a virtual machine to execute code on the underlying host. One is rated Critical. Neither has a workaround. The first vulnerability, tracked a