Google Cloud outlines its roadmap to full post-quantum cryptography readiness, with key milestones targeted for 2027 and 2028. The post Google Cloud Sets Out Post-Quantum Roadmap With 2029 Readiness Goal appeared first on SecurityWeek.

Google Cloud has reportedly outlined its comprehensive roadmap for achieving full post-quantum cryptography (PQC) readiness, targeting a complete transition by 2029. This initiative includes specific milestones planned for 2027 and 2028, indicating a phased approach to integrating quantum-resistant cryptographic algorithms across its cloud infrastructure. The move reflects a proactive stance by Google Cloud in preparing for the potential threat that future quantum computers pose to current cryptographic standards.
The core of this roadmap involves the implementation of PQC algorithms designed to withstand attacks from cryptographically relevant quantum computers. Traditional public-key cryptography, such as RSA and elliptic curve cryptography (ECC), relies on mathematical problems that are computationally intractable for classical computers but could be efficiently solved by sufficiently powerful quantum machines using algorithms like Shor's algorithm. The transition to PQC aims to replace or augment these vulnerable algorithms with new ones that are believed to be secure against both classical and quantum attacks.
Google Cloud's strategy likely encompasses several key technical areas. This would include the development and deployment of PQC-enabled TLS/SSL certificates for secure communication, the migration of data encryption keys to PQC standards, and the updating of authentication mechanisms. Furthermore, the roadmap would need to address the secure storage of data at rest and in transit, ensuring that all cryptographic primitives used throughout the Google Cloud ecosystem are quantum-resistant. The complexity arises from the need to manage a hybrid environment during the transition, where both classical and PQC algorithms may coexist.
The challenge in deploying PQC algorithms lies not only in their mathematical soundness but also in their practical performance characteristics, such as key sizes, computational overhead, and bandwidth requirements. These factors can impact the efficiency and scalability of cloud services. Products in this category commonly undergo extensive testing and standardization processes, such as those led by the National Institute of Standards and Technology (NIST), to ensure their robustness and interoperability. Google Cloud's roadmap would likely align with these emerging standards.
Typical mitigation guidance for organizations preparing for the quantum threat often involves inventorying cryptographic assets, identifying dependencies on classical algorithms, and developing a migration strategy. This includes staying informed about PQC standardization efforts, evaluating the performance implications of new algorithms, and planning for cryptographic agility to allow for future algorithm updates. For cloud users, this often means relying on their cloud provider to implement the underlying PQC infrastructure, while also understanding how their own applications and data interact with these new cryptographic layers.
The announcement by Google Cloud underscores the growing industry recognition of the "Y2Q" or "quantum apocalypse" concern, where the advent of large-scale quantum computers could render much of today's internet security infrastructure obsolete. By setting out a clear roadmap with specific targets, Google Cloud is positioning itself at the forefront of this cryptographic transition, aiming to provide its users with a secure and future-proof cloud environment against the evolving threat landscape posed by quantum computing. This proactive approach is critical for maintaining long-term data confidentiality and integrity in an increasingly quantum-aware world.

Attackers are exploiting two new PaperCut flaws to steal credentials and gain privileged access in education-sector attacks across the U.S. and Europe. Attackers are exploiting two recelty disclosed PaperCut flaws, CVE-2026-81578 and CVE-2026-82078, in attacks targeting schools and other education organizations in the U.S. and Europe, as reported by TheHackerNews. Arctic Wolf researchers observed

JetBrains is urging Cadence users to revoke and rotate all credentials following a security incident last month in which unidentified threat actors exploited a recently disclosed critical vulnerability in TeamCity to breach its own environment. "Cadence users should immediately revoke or rotate all credentials and secrets that may have been used to run their Cadence executions," JetBrains said.
A weakness has been identified in Tenda CP3 27.5.57.101. This issue affects some unknown processing of the file Net/NetCheckPing.cpp. This manipulation of the argument interface_name/host causes os command injection. The attack can be initiated remotely.
A security flaw has been discovered in Tenda CP3 27.5.57.101. This vulnerability affects the function SystemAsh of the file Apis/system.c of the component Kylin. The manipulation of the argument AlarmVoiceURL results in os command injection. It is possible to launch the attack remotely.

OpenAI has announced a $1 billion commitment to provide subsidized access to its Daybreak AI cybersecurity tools for under-resourced critical infrastructure defenders. The initiative, named Daybreak for Frontline Defenders, will offer AI models, training, and technical support over the next six months, prioritizing water and wastewater utilities, electric grid operators, and local government entities. This move aims to equip organizations with limited budgets and staff against increasingly sophisticated cyber threats.

Attackers are exploiting a new unpatched vulnerability in Magento Open Source and Adobe Commerce that lets them run malicious code on an online store's server without logging in, Dutch e-commerce security company Sansec said in an advisory published on September 5. Sansec, which discovered the flaw and named it StyleSmuggler, said attacks started on September 4. "Sansec is publishing early