Google Cloud has set a 2027 deadline to mitigate store-now-decrypt-later risks as part of its post-quantum cryptography roadmap, with wider migration goals extending through 2028

Google Cloud has outlined a phased roadmap for its transition to post-quantum cryptography, setting a target of late 2027 for the completion of its first major security milestone. This initial phase focuses on mitigating "store-now-decrypt-later" (SNDL) risks, where data collected today could be decrypted by a future quantum computer. The comprehensive plan, published on August 12, organizes the migration into three distinct risk domains, based on Google's internal quantum threat model.
The subsequent phases aim to harden digital signatures against forgery and rebuild key management systems to support cryptographic agility. These efforts are scheduled for completion by the end of 2028, aligning with a broader industry timeline that Google, Cloudflare, and Microsoft previously established for 2029.
Significant progress has already been made in implementing quantum-safe measures. Google Cloud API endpoints, including `google.com` and `*.googleapis.com`, now offer quantum-safe key exchange using the NIST-standardized ML-KEM algorithm in a hybrid mode. Similarly, application and proxy load balancers support hybrid key exchange for TLS 1.3, initially as an opt-in feature to allow customers to validate without disrupting existing applications.
Cloud Key Management Service (KMS) has reached general availability for ML-KEM, ML-DSA, and SLH-DSA. Additionally, quantum-confidential ALTS, Google's internal traffic protocol, completed its transition in 2025. Upcoming integrations include Cloud VPN and Interconnect in 2026 and 2027, Private CA in 2027, and Cloud IAM along with a quantum-safe Cloud HSM in 2028.
A particular challenge lies in the realm of digital certificates, as post-quantum signatures are considerably larger, potentially impacting certificate chain validation performance. Google is addressing this through the use of Merkle Tree Certificates. This approach replaces multiple large signatures with a single, compact inclusion proof, aiming to keep overhead near current levels. It also integrates transparency logging directly into the issuance process, ensuring that any certificate not present in the tree is effectively non-existent.
Google has emphasized that customers will share responsibility in this transition, needing to update their client-side software to negotiate post-quantum handshakes and manage their own asymmetric key lifecycles. The company also noted that the timeline for some physical hardware components might extend beyond 2029, as their transition is partly dependent on natural equipment replacement cycles. Google previously warned in March that a cryptographically relevant quantum computer could emerge as early as 2029.

Attackers are exploiting two new PaperCut flaws to steal credentials and gain privileged access in education-sector attacks across the U.S. and Europe. Attackers are exploiting two recelty disclosed PaperCut flaws, CVE-2026-81578 and CVE-2026-82078, in attacks targeting schools and other education organizations in the U.S. and Europe, as reported by TheHackerNews. Arctic Wolf researchers observed

JetBrains is urging Cadence users to revoke and rotate all credentials following a security incident last month in which unidentified threat actors exploited a recently disclosed critical vulnerability in TeamCity to breach its own environment. "Cadence users should immediately revoke or rotate all credentials and secrets that may have been used to run their Cadence executions," JetBrains said.
A weakness has been identified in Tenda CP3 27.5.57.101. This issue affects some unknown processing of the file Net/NetCheckPing.cpp. This manipulation of the argument interface_name/host causes os command injection. The attack can be initiated remotely.
A security flaw has been discovered in Tenda CP3 27.5.57.101. This vulnerability affects the function SystemAsh of the file Apis/system.c of the component Kylin. The manipulation of the argument AlarmVoiceURL results in os command injection. It is possible to launch the attack remotely.

OpenAI has announced a $1 billion commitment to provide subsidized access to its Daybreak AI cybersecurity tools for under-resourced critical infrastructure defenders. The initiative, named Daybreak for Frontline Defenders, will offer AI models, training, and technical support over the next six months, prioritizing water and wastewater utilities, electric grid operators, and local government entities. This move aims to equip organizations with limited budgets and staff against increasingly sophisticated cyber threats.

Attackers are exploiting a new unpatched vulnerability in Magento Open Source and Adobe Commerce that lets them run malicious code on an online store's server without logging in, Dutch e-commerce security company Sansec said in an advisory published on September 5. Sansec, which discovered the flaw and named it StyleSmuggler, said attacks started on September 4. "Sansec is publishing early