The G7 has published a call to action, urging governments to launch national strategies dedicated to the post-quantum encryption transition

The G7 nations have issued a joint call to action, urging governments and organizations globally to accelerate their transition to post-quantum cryptography (PQC) in anticipation of future threats from quantum computing. The document, published on September 3, was spearheaded by the French National Cybersecurity Agency (ANSSI), which chairs the G7 Cybersecurity Working Group as part of France's 2026 G7 Presidency.
The G7 statement emphasizes that the quantum threat should no longer be viewed as a distant problem but as a near-term concern requiring immediate action across all sectors, not just critical infrastructure. It acknowledges the growing threat quantum computing poses to public-key cryptography and the security of both public and private entities. While the exact timeline for quantum computers capable of breaking current encryption algorithms remains uncertain, recent advancements suggest such a development is increasingly likely.
To mitigate these risks, the G7 recommends that organizations prioritize identifying systems holding their most critical data and assets, then focus PQC transition efforts on those systems. The document stresses the importance of proactive measures rather than waiting for confirmed availability of quantum computers that can compromise existing encryption.
A phased, risk-based approach is advised for the transition, including inventorying cryptographic assets, mapping dependencies, and developing a comprehensive transition plan. To manage costs, organizations are encouraged to integrate PQC into their standard system renewal schedules by purchasing products that already include quantum-safe encryption. Starting the transition early is also projected to result in lower overall migration expenses.
The G7 document outlines five key priorities for governments, policymakers, and the private sector. These include raising awareness about quantum threats, developing national PQC transition strategies that also aim to foster an adequate supply of PQC hardware and software products and encourage their adoption. Further priorities involve focusing research and development on advancing PQC through innovation, developing practical solutions, and establishing public-private partnerships to promote domestic expertise and industry capabilities in quantum-safe technologies. Finally, the G7 calls for the integration of PQC into cybersecurity requirements.
The call to action was signed by the national cybersecurity agencies of all G7 member states: Canada, France, Germany, Italy, Japan, the UK, and the US. It also has the support of the EU Commission and the EU Agency for Cybersecurity (ENISA). This initiative follows ANSSI's earlier announcement that it will cease vetting products lacking quantum-safe encryption by 2027, with post-quantum security becoming a mandatory feature for certain security product procurements by 2030.

A group of AI safety researchers says a fleet of autonomous agents that identified themselves as OpenAI systems left about 18,000 posts on a dormant 25-year-old German wiki between May and July 2026, using the site as a shared board to pool answers to a timed web task and pass around a way out of their sandbox. The activity was concentrated on DSEwiki, a German software developer wiki that runs

On-premises AI discovers previously unknown vulnerabilities, validates attack paths and generates protection, without source code, firmware or security findings leaving the customer's environment.

OpenAI admits it did not disclose an incident where autonomous AI agents hijacked a German wiki, created 18,000 posts, shared answers, and bypassed restrictions, saying it treated the activity as model "misalignment" rather than a security breach. [...]

Plus: Tens of millions of US and Canadian drivers’ licenses go up for sale on the dark web, the US military finally tries to tackle the risk online ad data poses to troops, and more.

Threat actors are exploiting the newly disclosed PaperCut flaws to facilitate credential theft in attacks targeting the education sector in the U.S. and Europe. The Arctic Wolf Adversary Research Team said it observed attackers exploiting CVE-2026-81578 and CVE-2026-82078 – an authentication bypass and remote code execution chain – to conduct command execution and reconnaissance, as well as

Broadcom patched two VMware Workstation/Fusion VM-escape bugs. No workarounds exist. Update to version 26H1u1 immediately. Broadcom published advisory VMSA-2026-0007, patching two vulnerabilities in VMware Workstation and Fusion that allow an attacker inside a virtual machine to execute code on the underlying host. One is rated Critical. Neither has a workaround. The first vulnerability, tracked a