The IETF has moved draft-ietf-tls-mlkem to IETF-wide Last Call, advancing a specification that defines pure ML-KEM-512, ML-KEM-768, and ML-KEM-1024 NamedGroups for key establishment in TLS 1.3. If approved, the document would become an Informational RFC and give implementers a stable reference for standalone ML-KEM in TLS, while the IANA registry would continue to mark the pure ML-KEM groups as Recommended = N and the hybrid X25519MLKEM768 group as Recommended = Y.
The proposal remains contentious after multiple Working Group Last Calls, appeals, and objections from cryptographers who argue that pure ML-KEM lacks the resilience of hybrid key exchange if one component later proves weak. The latest draft adds clarification on the meaning of the registry recommendation flag and expands security considerations around randomness exposure in ML-KEM. Despite the debate, downstream standards bodies including O-RAN, IEEE 802.11, and 3GPP have backed publication to obtain a stable post-quantum reference for their own specifications.

Track how attackers are adapting to this technology.
9 events from the most recent confirmed update back to the earliest known activity.
The IESG issued an IETF-wide Last Call for draft-ietf-tls-mlkem, which defines pure ML-KEM-512, ML-KEM-768, and ML-KEM-1024 NamedGroups for key establishment in TLS 1.3 as an Informational RFC.
Joseph Salowey requested publication of draft-ietf-tls-mlkem, moving the document forward after the working group process.
Joseph Salowey replied that the mailing list is public, rough consensus has no fixed threshold, and the chairs would not release further detailed analysis of numbers, weights, or methods.
Draft-09 was posted with clarifications including RFC 9847's definition of the IANA 'N' registry marking and new security-considerations text about ML-KEM randomness exposure.
TLS working group co-chair Joseph Salowey declared rough consensus to advance the draft after the third Working Group Last Call, despite sustained objections from some cryptographers.
Tanja Lange wrote that none of her concerns had been addressed and that she did not support publication of the draft.
The third Working Group Last Call for draft-ietf-tls-mlkem ran in the TLS working group as part of the prolonged dispute over publishing pure ML-KEM NamedGroups for TLS 1.3.
The first Working Group Last Call on the pure ML-KEM TLS draft ended with the chairs finding no consensus to publish the document.
NIST standardized ML-KEM as FIPS 203, providing the underlying post-quantum KEM referenced in the TLS draft.
Follow how adversaries are adapting to this technology, and where it touches your stack today.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.