:

MYTHOS ATTACK ELIMINATES PQC CANDIDATE HAWK

INDUSTRY DESK1 MIN READ
WED, JUL 29, 2026

■ AI-SUMMARIZED FROM 1 SOURCE ▸ TIMELINE

A newly discovered Mythos attack has eliminated HAWK, a third-round candidate in the post-quantum cryptography (PQC) standardization process. The algorithm failed to withstand the attack despite years of prior security testing.

HAWK, which had survived extensive cryptanalysis throughout its testing period, has been removed from contention after researchers demonstrated a fatal vulnerability using the Mythos attack method. The third-round PQC candidates are being evaluated by the National Institute of Standards and Technology (NIST) as part of its effort to standardize quantum-resistant algorithms before quantum computers pose a practical threat to current encryption systems. The discovery underscores the ongoing challenge in vetting cryptographic algorithms at scale. HAWK's elimination leaves fewer candidates advancing in NIST's selection process, which is narrowing toward final standardized algorithms. Researchers continue analyzing remaining PQC candidates to identify similar weaknesses. The Mythos attack represents a significant development in post-quantum cryptography research, demonstrating that novel attack vectors can still emerge even after years of peer review.

■ SOURCES

Ars Technica

■ SUMMARY WRITTEN BY AI FROM THE LINKS ABOVE

■ MORE FROM THE SECURITY DESK

Cyberattacks against hedge funds and private equity firms have been attributed to UNC6671, an extortion group connected to the BlackFile threat actors. The campaign represents an escalating threat to the financial sector.

1H AGOSecurity Desk

A Go-based malware distributed through ClickFix attacks is targeting macOS users to steal cryptocurrency, passwords, and Apple Keychain data. The infostealer campaign combines social engineering with credential harvesting.

3H AGOIndustry Desk

A former NSA official has warned against connecting water infrastructure controllers to the internet following suspected Iranian cyberattacks on U.S. water systems.

8H AGOIndustry Desk

Security researchers scanning Polish government websites discovered critical vulnerabilities that could expose courts, hospitals, and airports to cyberattacks. The vulnerabilities stem from common software used to manage and display web content.

11H AGOAI Desk

■ SUBSCRIBE TO THE DAILY BRIEF

ONE EMAIL, 5 STORIES, 06:00 UTC. UNSUBSCRIBE ANYTIME.