ZeroHour

Search: “G7 Cyber Security Working Group”

2,539 stories

Preparing for the Post-Quantum Era: A Call to Action

CISA and the G7 Cyber Security Working Group urge organizations to begin post-quantum cryptography migration, outlining five transition priorities.

CISA and the G7 Cyber Security Working Group jointly released "Preparing for the Post-Quantum Era: A Call to Action". The document urges governments and organizations to begin migrating sensitive data, authentication systems, and critical assets to post-quantum cryptography against emerging quantum computing threats. It defines five priorities: raising quantum-risk awareness, national PQC strategies, quantum-safe R&D, public-private partnerships, and integrating PQC into cybersecurity requirements and procurement.

CISA Advisories · 12d agoPolicy & legal

G7 urges organizations to prepare for quantum cyber threats

G7 Cyber Security Working Group and CISA jointly urge organizations to begin migrating to post-quantum cryptography now, citing harvest-now-decrypt-later risk.

In a joint advisory, the G7 Cyber Security Working Group and CISA recommend starting post-quantum cryptography migration immediately rather than waiting for quantum computers to break current encryption. They warn attackers can already harvest encrypted data for later decryption, threatening long-lived secrets such as government records and trade secrets. Organizations are told to inventory sensitive systems, prioritize them, and fold quantum-resistant upgrades into routine refresh cycles. The advisory follows a UK 2035 PQC roadmap and recent US executive orders on quantum preparedness.

The Record · 11d agoAdvisory

Risky Bulletin: Russia tells data centers to deploy drone defenses

Russia ordered data center operators to deploy drone strike defenses under a Putin decree allowing temporary state takeover of unprotected critical infrastructure.

The Russian government instructed data center operators to deploy protections against drone strikes under a presidential decree signed by Putin that allows temporary state administration of critical infrastructure operators failing to defend against Ukrainian hacks and drone strikes. Although data centers are not formally critical infrastructure in Russia, the decree applies to them because other sectors depend heavily on cloud services; Russia has more than 180 data centers, over 80% in the European region within range of Ukrainian strikes. The digest also reports a Dropbox breach affecting nearly 5,000 accounts via the Lenovo ID integration, spyware attacks on at least 14 Serbians using NoviSpy or Pegasus, and a password recovery attack targeting hundreds of thousands of X accounts tied to the new X Money service. Other items include a 14-hour compromise of Coder's Cloudflare infrastructure delivering malicious Terraform modules, donor data breaches at Davayte and You Are Not Alone via the Stripe/WooCommerce integration, a $2.5M Aquifer crypto heist, and a TVING breach exposing data of almost 40 million accounts.

Risky Business News · 11d agoPolicy & legal