logo

KyberSlash attacks put quantum encryption projects at risk

ID: a8bb0939-71c9-5e72-88b4-053790c2f56a

STIX ID: report--a8bb0939-71c9-5e72-88b4-053790c2f56a

Feed Name: Bleeping Computer

Threat Score
70/100

Date Published: 2024-01-07

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

Multiple implementations of the CRYSTALS-Kyber post-quantum key encapsulation mechanism are affected by timing-based flaws collectively called KyberSlash that can leak secret keys during decapsulation. Researchers demonstrated key recovery in lab conditions, vendors released patches for some libraries while several popular implementations (including components used by Signal) were initially unpatched, and impact depends on deployment details and key usage patterns.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.