The UK's National Cyber Security Centre (NCSC) and Vodafone recently co-hosted a workshop on post-quantum cryptography (PQC) migration, bringing together government, industry, and academic leaders. The event highlighted the critical need for collaboration in transitioning to quantum-resistant algorithms, emphasizing that no single organization can manage this shift alone. Key themes included securing executive sponsorship by framing PQC as a business risk, ensuring supply chain readiness, and fostering transparency and cross-sector collaboration to build national resilience against future quantum computing threats.

The National Cyber Security Centre (NCSC) and Vodafone, in collaboration with the National Cyber Advisory Board, recently hosted the inaugural UK government and industry workshop on post-quantum cryptography (PQC) migration. The December 2023 event brought together security leaders and PQC specialists from various sectors, including industry, academia, and government, to address the complex challenges of transitioning to quantum-resistant cryptographic algorithms. A central conclusion from the workshop was that no single organization can effectively manage this migration in isolation, underscoring the necessity of collaborative efforts.
The urgency for PQC migration stems from the anticipated threat posed by sufficiently powerful quantum computers, which are expected to be capable of breaking current public-key cryptography. This foundational cryptography secures modern networks and systems. The NCSC has established key milestones for PQC migration, with targets in 2028 and 2031, emphasizing the need for immediate action to avoid significant future costs and complexity. The transition is not merely a technical undertaking but a global strategic resilience imperative across all industries and governmental bodies.
While extensive guidance on PQC migration exists, the workshop highlighted that guidance alone is insufficient. Successful and secure migration requires deep collaboration among experts in cryptography, cybersecurity, and network operations, alongside individuals who understand the technical and business realities of their organizations. The workshop aimed to foster these connections, facilitate the sharing of real-world approaches and challenges, and build momentum for collective action.
Several key themes emerged from the discussions. One prominent theme was the critical importance of executive sponsorship and building a compelling business case for PQC. Participants stressed the need to frame PQC as a business risk and resilience priority, clearly articulating "why now?" and the potential consequences of delayed action. Approaches identified to engage boards included emphasizing the cost savings associated with early action, linking PQC efforts to broader organizational goals like addressing legacy systems and enhancing overall cyber resilience, and tailoring the business case to specific organizational priorities such as system availability, legal compliance, or financial impact.
Identifying a senior sponsor, such as a CTO, CIO, or CISO, who can advocate for the initiative at the board level was also deemed crucial. Leveraging peer and industry benchmarks to demonstrate what other organizations are doing can also influence board members. Furthermore, preparatory work, including engaging with the supply chain, conducting initial discovery exercises, and identifying critical assets, can strengthen the business case by making the risks and resource requests more concrete. Prioritizing the migration of systems that process the most valuable data or involve long-lived hardware dependencies was also recommended.
Developing a phased roadmap with clear timelines, targets, required investments, and necessary skills for each phase was seen as essential for setting expectations and building confidence in the actionable plan. The NCSC's guidance on PQC migration timelines offers suggestions for this planning process.
Another critical theme was supply-chain readiness. An organization's ability to achieve quantum readiness is directly dependent on its supply chain and the preparedness of its suppliers. Workshop participants underscored the importance of integrating PQC considerations into supplier security assessments and sourcing processes. Early engagement with suppliers to discuss PQC migration is vital for understanding and influencing their PQC roadmaps and for communicating specific requirements. Without supplier alignment, even well-planned migration strategies risk delays. Efficient and economical PQC migration often involves leveraging natural technology refresh cycles, which necessitates products with PQC functionality or upgrade capabilities.
A weakness has been identified in Tenda CP3 27.5.57.101. This issue affects some unknown processing of the file Net/NetCheckPing.cpp. This manipulation of the argument interface_name/host causes os command injection. The attack can be initiated remotely.
A security flaw has been discovered in Tenda CP3 27.5.57.101. This vulnerability affects the function SystemAsh of the file Apis/system.c of the component Kylin. The manipulation of the argument AlarmVoiceURL results in os command injection. It is possible to launch the attack remotely.

OpenAI has announced a $1 billion commitment to provide subsidized access to its Daybreak AI cybersecurity tools for under-resourced critical infrastructure defenders. The initiative, named Daybreak for Frontline Defenders, will offer AI models, training, and technical support over the next six months, prioritizing water and wastewater utilities, electric grid operators, and local government entities. This move aims to equip organizations with limited budgets and staff against increasingly sophisticated cyber threats.

Attackers are exploiting a new unpatched vulnerability in Magento Open Source and Adobe Commerce that lets them run malicious code on an online store's server without logging in, Dutch e-commerce security company Sansec said in an advisory published on September 5. Sansec, which discovered the flaw and named it StyleSmuggler, said attacks started on September 4. "Sansec is publishing early
In BPF instructions that load/store a value from/to a scratch memory register the register index is an unsigned 32-bit integer and must not exceed 15, but libpcap BPF interpreter does not validate the value. In particular uncommon use cases a crafted filter program can cause the interpreter to try reading and writing the OS process memory in the 16GiB starting at the current stack frame on 64-bit architectures and in the entire address space on 32-bit architectures.

Attackers are exploiting two new PaperCut flaws to steal credentials and gain privileged access in education-sector attacks across the U.S. and Europe. Attackers are exploiting two recelty disclosed PaperCut flaws, CVE-2026-81578 and CVE-2026-82078, in attacks targeting schools and other education organizations in the U.S. and Europe, as reported by TheHackerNews. Arctic Wolf researchers observed