LIVE · cybersecurity feed
Live wire
US sanctions Iranian cyber actors as UK discloses power plant attackHackers target WordPress sites in miniOrange auth bypass attacksFake GTA 6 Extended Look and demo sites deliver an infostealerCVE-2026-63520 · Rapid7 Analysis: Microsoft SharePoint Remote Code Execution (CVE-2026-63520)CISA’s logging guidance works beyond governmentCISA orders urgent patching of actively exploited Zimbra flawZero-Click Grok Chat History Theft: Adversa AI Demonstrates Cryptographic Context InjectionMalware Hijacks Android Car Head UnitsCritical Flaw in NASA/JPL Open-Source Spacecraft Command Software Allowed Unauthenticated Command ExecutionCVE-2026-73570 · U.S. CISA adds Zimbra Collaboration Suite (ZCS) flaw to its Known Exploited Vulnerabilities catalog
quantum computing

New Guidance Helps Businesses Verify Quantum-Safe Hardware Claims

The Trusted Computing Group (TCG) has released new guidance to help organizations verify if their hardware, specifically Trusted Platform Modules (TPMs), is genuinely quantum-safe. This new benchmark addresses concerns that some TPMs claiming quantum-safe compliance may not offer full security capabilities. The guidance introduces designations for 'TCG PQC-ready TPM' and 'TCG PQC-upgradable TPM' to clarify readiness for post-quantum cryptography.

zeroday.news ·

The Trusted Computing Group (TCG) has released new guidance to help organizations verify whether their hardware, specifically Trusted Platform Modules (TPMs), genuinely meet post-quantum cryptography (PQC) requirements. This move comes as businesses seek to future-proof their systems against potential quantum-enabled cyberattacks.

TCG, a non-profit organization focused on vendor-neutral standards for hardware-based security, published the guidance on August 24, 2026. TPMs are specialized security chips, often integrated into motherboards or processors, that securely store sensitive data such as passwords, digital certificates, and encryption keys. TPM 2.0, the second generation of these modules, is a requirement for Windows 11.

The organization emphasizes that TPMs will likely be crucial in PQC roadmaps due to their ability to maintain trusted identities, platform integrity, attestation, and hardware-anchored security over extended periods, potentially decades, as PQC algorithms evolve.

Not all TPMs currently available offer quantum-safe encryption, and some products advertised as "compliant" may not provide full, end-to-end security capabilities. To address this, TCG convened nearly 90 contributors in March 2026, including representatives from government, academia, and major technology companies like Intel, Google, Hewlett Packard Enterprise, Microsoft, NVIDIA, Lenovo, and STMicroelectronics. This collaboration led to the development of the TCG PC Client Platform TPM Profile (PTP) 1.07, which outlines the minimum requirements for PQC-ready TPMs.

The newly released accompanying document assists businesses in verifying if their TPMs comply with the PTP 1.07 standard. It also introduces two categories to describe a TPM's readiness for the PQC transition: 'TCG PQC-ready TPM,' for modules that already support the PQC capabilities defined in PTP 1.07, and 'TCG PQC-upgradable TPM,' for those designed to be upgraded to support the standard. These designations aim to simplify understanding a platform's PQC transition status.

TCG also announced plans to enhance its existing certification programs to specifically certify 'TCG PQC-ready TPMs,' further solidifying the verification process for quantum-safe hardware.

quantum computingcryptographyhardware securitystandardstpm
ShareXLinkedInWhatsAppFacebook

More News

view all →
nation-statecritical

US sanctions Iranian cyber actors as UK discloses power plant attack

The U.S. sanctioned several Iranian nationals for cyberattacks on critical infrastructure just days after reports emerged of a cyber intrusion on a small power plant in the United Kingdom.

cloud

SCOTUS tosses one of two injunctions against Trump USPS mail-in ballot rules

The 6-3 decision dismisses one lawsuit brought by states, saying they have no standing to sue because the disputed sections “neither requires nor forbids anything of anyone outside the executive branch.” The post SCOTUS tosses one of two injunctions against Trump USPS mail-in ballot rules appeared first on CyberScoop.

CVE-2026-73570

Exploited Zimbra Flaw Highlights Shrinking Window to Patch

CISA has issued a three-day deadline for agencies to patch a Zimbra security vulnerability, CVE-2026-73570, which allows full takeover of a user's communications.

security

You don't want this Sleepwalker backdoor on your Windows machine

Its own command language, 23 instructions - signs point to 'well-resourced operation rather than an opportunistic one'

vulnerability

Unpatched Calix flaw lets hackers bypass NAT to expose internal devices

An unpatched vulnerability in Calix GS7 XGS (GS5239XG) residential routers used by multiple U.S. broadband providers allows remote, unauthenticated attackers to create port-forwarding rules that can expose local network devices to the public internet. [...]

security

Browser fingerprint tool shows how easy you are to track using the latest sneaky tricks

Glassbox dev admits he had some help from Claude to build locally running tool