In this interview with Help Net Security, Dr. Yaakov Stein, VP CTO of Allot, discusses what post-quantum readiness looks like inside a mobile network. The discussion covers which operator traffic stays sensitive for years, including subscriber identity mappings, billing records and call metadata, and which becomes worthless within hours. It walks through the order of work, starting with a crypto i

Mobile network operators face a complex and urgent challenge in preparing for post-quantum cryptography (PQC), according to Dr. Yaakov Stein, VP CTO of Allot. While some traffic, like subscriber voice calls or web browsing, quickly loses sensitivity, critical data such as subscriber identity mappings, billing records, and call metadata can remain sensitive for years, necessitating PQC protection. Financial transactions, including credit card information, also require long-term protection, though this is often handled by subscriber-side applications.
The initial step for any operator is to conduct a thorough inventory of all public-key cryptography usage. This includes identifying 5G Service-Based Architecture (SBA) interfaces, Internet Key Exchange (IKE) for IPsec-protected links, DNSSEC, and encrypted APIs. A comprehensive inventory is crucial to avoid later oversights.
Following the inventory, the next priority is to migrate all TLS-dependent systems, including SBA interfaces, Security Edge Protection Proxy (SEPP), web portals, and Operations Support System/Business Support System (OSS/BSS) APIs, to hybrid key exchange. This technology is currently the most readily available for PQC migration. Subsequently, IPsec links, encompassing backhaul, inter-data center connections, and LTE roaming interfaces, should undergo a similar migration. Other public-key reliant protocols, including proprietary ones, should then be addressed.
Once key exchanges are secured, operators can focus on authenticating long-lived connections, which can accommodate the larger public keys associated with current PQC digital signatures. Software authentication for short-lived connections can be deferred, as can hardware authentication and attestation mechanisms, which depend on vendor readiness. While 5G subscriber authentication largely relies on symmetric keys, the underlying Public Key Infrastructure (PKI) still requires PQC consideration.
For operators limited to a single PQC deployment in a given year, the most impactful measure is to deploy hybrid ML-KEM (specifically, X25519 ECC with ML-KEM, ideally with crypto-agile backup to HQC) on all TLS-protected SBA and management-plane interfaces. This represents the most accessible and effective initial step.
Operators should be wary of vendor responses that indicate a lack of understanding or a delay tactic regarding PQC. Statements such as "we are waiting for the standards to stabilize" are concerning, as PQC standardization is progressing rapidly, and crypto-agility is key to future-proofing. Similarly, claims that "cryptographically relevant quantum computers are still not here" or that "our encryption is based on symmetric encryption and so quantum safe" are red flags, suggesting either a misunderstanding of the threat or intentional misdirection.
The most common failure in an operator's PQC migration is not a cryptographic breach but an operational oversight. This typically stems from an incomplete crypto inventory, leading to the neglect of an interface such as an SSH-accessible machine, an old RADIUS interface, a load balancer, a NAT device, or an unmaintained orchestration tool. Such omissions create a false sense of security, as PQC readiness is only as strong as its weakest link. Additionally, new PQC mechanisms can sometimes disrupt legacy equipment, as seen with early implementations of Kyber, which caused issues with middleboxes due to multi-packet TLS client hellos and required rollback.
A weakness has been identified in Tenda CP3 27.5.57.101. This issue affects some unknown processing of the file Net/NetCheckPing.cpp. This manipulation of the argument interface_name/host causes os command injection. The attack can be initiated remotely.
A security flaw has been discovered in Tenda CP3 27.5.57.101. This vulnerability affects the function SystemAsh of the file Apis/system.c of the component Kylin. The manipulation of the argument AlarmVoiceURL results in os command injection. It is possible to launch the attack remotely.

OpenAI has announced a $1 billion commitment to provide subsidized access to its Daybreak AI cybersecurity tools for under-resourced critical infrastructure defenders. The initiative, named Daybreak for Frontline Defenders, will offer AI models, training, and technical support over the next six months, prioritizing water and wastewater utilities, electric grid operators, and local government entities. This move aims to equip organizations with limited budgets and staff against increasingly sophisticated cyber threats.

Attackers are exploiting a new unpatched vulnerability in Magento Open Source and Adobe Commerce that lets them run malicious code on an online store's server without logging in, Dutch e-commerce security company Sansec said in an advisory published on September 5. Sansec, which discovered the flaw and named it StyleSmuggler, said attacks started on September 4. "Sansec is publishing early
In BPF instructions that load/store a value from/to a scratch memory register the register index is an unsigned 32-bit integer and must not exceed 15, but libpcap BPF interpreter does not validate the value. In particular uncommon use cases a crafted filter program can cause the interpreter to try reading and writing the OS process memory in the 16GiB starting at the current stack frame on 64-bit architectures and in the entire address space on 32-bit architectures.

Attackers are exploiting two new PaperCut flaws to steal credentials and gain privileged access in education-sector attacks across the U.S. and Europe. Attackers are exploiting two recelty disclosed PaperCut flaws, CVE-2026-81578 and CVE-2026-82078, in attacks targeting schools and other education organizations in the U.S. and Europe, as reported by TheHackerNews. Arctic Wolf researchers observed