Let's Encrypt is developing support for post-quantum cryptography to protect HTTPS certificates against future quantum computing threats. The certificate authority plans to issue post-quantum certificates starting in 2026.
Let's Encrypt announced plans to issue certificates using post-quantum cryptographic algorithms, addressing security risks posed by quantum computers capable of breaking current encryption methods.
The initiative involves implementing hybrid certificates that combine classical and post-quantum algorithms during a transition period. This approach ensures compatibility with existing systems while introducing quantum-resistant security.
Post-quantum cryptography relies on mathematical problems believed to resist quantum computing attacks, such as lattice-based and hash-based algorithms. Standards for these methods are being finalized by NIST, with adoption expected across the industry.
The 2026 timeline aligns with the broader industry push toward quantum-safe infrastructure. Let's Encrypt's role as a major certificate provider makes this transition significant for web security.
The move follows growing recognition that encrypted data collected today could be decrypted by quantum computers in the future, creating urgency for cryptographic modernization across critical infrastructure.
A hacker collective breached a Flock camera and released internal data revealing the extent of the device's surveillance capabilities. The leaked files show the system captured 1.6 million images of 50,000 vehicles within just 21 days.
Google released September 2026 security updates addressing 110 vulnerabilities in Pixel devices, including a zero-day flaw currently being exploited in targeted attacks.
Apple has introduced Reference Image, a new approach to verified photography that authenticates images at the point of capture. The technology aims to combat image manipulation and provide proof of content authenticity.
Attackers are actively exploiting a critical vulnerability in the WooCommerce Wholesale Lead Capture premium plugin to deploy PHP backdoors on WordPress sites. The flaw allows unauthorized code execution on affected installations.