We follow up on the recent Mythos attack against PQC candidate HAWK. We discuss the impact of this attack on both HAWK and FALCON.
Ressources
"Chaos engineering" describes the practice of injecting faults into a system to see what happens. This is a known strategy for deterministic systems, but with the advent of non-deterministic AI systems, chaos engineering has taken on greater importance.
Since frontier-model AIs have been trained on a large portion of published human knowledge, widespread publication of incorrect information can taint AI results. As more AI-generated slop finds its way onto the internet, this runs the risk of further poisoning AI results. This ultimately can result in completely unusable information.
Anthropic recently announced that Mythos has found mathematical weakness in the core algorithm for the third-round NIST PQC candidate HAWK, effectively halving its effective key strength. Mythos also developed a faster attack on a round-reduced version of AES-128. These are not implementation attacks but mathematical attacks on the core cryptography. We discuss the massive implications of these developments.
A newly revealed flaw in Active Directory Certificate Services (AD CS) allows an attacker to improperly obtain cryptographic credentials for an agent. We discuss the implications that this flaw Certighost (pronounced sert-uh-GHOST) has for agentic AI at large.
In our series on digital identity for AI agents, we discuss FAPI 2.0 as an option.
In our ongoing series on digital identity for agents, we have previous discussed use of certificates for authentication. In this episode we describe how cryptographic proof of possession can enable secure authentication using tokens.
We survey different strategies for securely authenticating agentic AI, including certificates and SPIFFE. We discuss Zero Trust and the Principle of Least Privileges as applied to agents.
Anthropic has announced its intentions to support SPIFFE/SPIRE with the SPIRE server rooted in an "upstream authority," which will require a root private CA rather than allowing self-attestation for agentic AI.
In our episode 640 we defined SPIFFE, which provides digital identity for agentic workloads. In this episode we explain SPIRE (SPIFFE Runtime Environment), the SPIFFE certificate provisioning protocol.
SPIFFE (Secure Production Identity Framework for Everyone) is a standard for digital identity for agentic workloads. In this episode we explain.
We recently attended the Gartner Risk and Security conference for 2026, where we observed a great deal of attention on not only AI but also post quantum cryptography (PQC). Join us as we share the key takeaways.
An emerging attack against AIs is to create a significantly complex and recursive prompt that will occupy the AI indefinitely or for a sufficiently long time that it acts as a Denial-of-Service (DoS) attack. We describe how this works.
Recent revelations about Mythos and its ability to expose vulnerabilities have forced us to rethink basic assumptions about cyber defense. In our "AI in 1000 Days" series, Jason Soroko and I examine the implications of these revelations three years from now. This includes upping the overall pace of attack and changes to best practices in cyber security defense.
Anthropic has delayed its widespread release of Mythos to give major software providers a chance to close off the many vulnerabilities it has discovered. We dig into the vast implications of Mythos and other AI models for the future of cybersecurity.
Jason describes a recent intrusion almost entirely operated by off-the-shelf AI tools. This is an important milestone in security. We describe its potential consequences.
In an innovative application, an AI has been used to find private keys for ECC (Elliptic Curve Cryptography) P 256. We explain how.
Continuing our examination of AI in 1000 days, we discuss the use of finely tuned small language models for highly specific use cases.
Besoin d'aide ?
Besoin d'aide pour effectuer un achat ? Contactez-nous dès aujourd'hui pour que votre certificat soit délivré immédiatement.