A Vulnerable U episode previewed content filmed at Palo Alto Networks focused on how quantum computing is expected to impact security planning over the next decade, arguing that while the underlying physics is complex, many preparedness actions resemble familiar infosec transitions (e.g., inventorying cryptography dependencies and planning migrations). It also highlighted how public debate around encryption can be distorted by headlines—citing renewed discussion tied to a WhatsApp-related lawsuit and pointing to cryptographer Matthew Green’s technical breakdown as a corrective to overbroad claims that “end-to-end encryption is broken.”
Separately, Gopher Security warned that adopting post-quantum cryptography (PQC) does not address implementation-layer leakage, emphasizing that side-channel attacks (including remotely observable timing/power effects such as Hertzbleed) can undermine “quantum-safe” designs. The post described how electromagnetic (EM) emissions from AI hardware can leak sensitive information during inference, citing research such as BarraCUDA (weight extraction from NVIDIA Jetson devices via EM measurements) and academic work indicating side-channels can break embedded AI “black-box” assumptions by enabling extraction of logits/weights or gradient estimation—creating model theft and evasion risks even when cryptographic algorithms are strong.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
10 events from the most recent confirmed update back to the earliest known activity.
A court filing indicated that Apple iPhone Lockdown Mode prevented the FBI from accessing a reporter’s iPhone, illustrating the feature’s real-world defensive impact.
Palo Alto Networks Unit 42 described a broad, geopolitically aligned campaign using the ShadowGuard eBPF kernel rootkit together with a custom loader called Diaoyu.
Reporting described China-linked espionage activity leveraging a WinRAR vulnerability as part of ongoing operations.
Russia-linked APT28 was reported to have quickly begun exploiting a newly patched Microsoft Office vulnerability after a fix became available.
A reported supply-chain compromise affected Notepad++ update infrastructure, with the activity attributed to China-linked attackers.
Reports indicated active exploitation of a React Native Metro vulnerability that allows remote command execution against exposed development servers.
CISA warned that an older GitLab server-side request forgery vulnerability was being actively exploited in the wild, elevating the urgency for organizations to patch exposed systems.
A reported side-channel attack demonstrated secret extraction from a Cortex-M4 implementation of Kyber (mkm4) using a single trace, highlighting implementation risks in post-quantum cryptography.
Researchers reported that electromagnetic emissions from NVIDIA Jetson devices during inference could be used to recover neural network weights, undermining the assumption that deployed models are only accessible as black boxes.
The Hertzbleed research showed that power-related side-channel leakage can be observed remotely through runtime effects, challenging the assumption that side-channel attacks require physical access.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.