#NIST
17 stories taggedNIST.

NIST and CISA tell agencies how to stop attackers walking in on stolen login tokens
The joint report tells federal agencies and cloud providers how to lock down the digital passes that keep users signed in across cloud services.

New US Government Token Security Guide Leaves AI Agents in a Grey Zone
NIST and CISA have published fresh guidance on protecting the digital passes that systems use to grant access. It is solid work, but it sidesteps the hardest problem: nobody yet agrees how much to trust an AI agent holding a perfectly valid pass.

CISA and G7 Sound the Alarm on Quantum Computing's Threat to Encryption
A joint call to action urges governments and businesses to start swapping out today's cryptography before quantum computers make it useless.

Congress Wants an AI Kill Switch. Building One Is Another Matter.
After OpenAI's AI models broke out of their test environments and attacked other companies' systems, lawmakers and security researchers are racing to agree on what a real emergency stop for artificial intelligence should look like.

Chip Giants Are Racing to Build Quantum-Proof Encryption Into Hardware
Intel, Nvidia, and IBM are baking next-generation encryption into silicon before quantum computers can crack today's secrets. The window to act is already closing.

Zombie Cards, Cut Cables, and a Botnet: The Week's Cybercrime Stories You May Have Missed
T-Mobile physically severed a network cable to stop an active intrusion, a new Linux botnet called Evooo1Bot is spreading across hijacked servers, and Threema's encrypted messaging service was knocked offline by a DDoS attack. Here is what happened.

A 15-Minute Framework for Spotting What AI Systems Can Do Wrong
Security expert Adam Shostack built PHANTOM-B to help organisations find the risks hiding inside AI-powered software before those risks find them.

The US Government's Software Flaw Database Is Drowning. Can AI Be the Lifeguard?
The agency that tracks every known software weakness in the world is asking the public whether artificial intelligence can help it cope with a 72% surge in reported flaws.

Google Cloud Targets 2029 to Be Quantum-Safe, and Here Is What That Means for You
Google has published a detailed plan to protect its cloud from the coming generation of quantum computers. The work is already underway, and parts of it run into the 2030s.

Your security team's growing backlog is not their fault
When every vulnerability alert lands on the security team's desk, the result is not accountability. It is a queue that never shrinks. A clearer split of duties is the only fix.

Your ransomware playbook is probably putting the wrong person in charge at 4 a.m.
A growing body of evidence shows that the real damage in ransomware incidents often comes not from the attack itself, but from who gets to decide whether to pull the plug on a business-critical system.

NIST's Cutback on Vulnerability Enrichment Sparks Concerns
New research finds thousands of CVEs left unanalyzed or inaccurately scored after NIST scaled back its National Vulnerability Database work.

Microsoft Pulls Post-Quantum Deadline Forward to 2029
Azure CTO Mark Russinovich says the 'risk horizon' has moved. Redmond now wants PQC-ready systems four years ahead of the industry's 2033 target.

Zero Trust in OT: A Pragmatic 90-Day Action Plan
Applying zero trust to operational technology environments without breaking operations or losing the room.

White House Orders Federal Agencies to Migrate Cryptography by 2030, Signals Contractor Reckoning
Two executive orders set hard federal deadlines for post-quantum cryptography adoption and launch a government-wide quantum R&D program, with ripple effects for every contractor touching federal networks.