Researchers demonstrated eNFS, a special number field sieve attack that converts temporary access to an unpadded, raw RSA signing or decryption oracle into an enduring offline capability to forge signatures or decrypt chosen ciphertexts. In a large-scale proof of concept against a 1,024-bit RSA key, the attack used 232 oracle queries and roughly 1,380 CPU core-years over five months—less work than estimated full modulus factorization—without factoring the modulus or extracting the private key.
The attack targets textbook RSA exposed through raw PKCS#11 operations and blind-signature systems, including potentially Privacy Pass deployments. It does not apply to normally padded RSA schemes such as PKCS#1 v1.5 or RSA-PSS, and researchers assess immediate risk as low; however, organizations should eliminate unnecessary raw RSA interfaces, review HSM and signing-oracle exposure, rotate susceptible blind-signature keys more frequently, and migrate vulnerable designs to padded RSA schemes.

See real exploitation activity before you spend the cycle.
3 events from the most recent confirmed update back to the earliest known activity.
Antoine Joux, David Naccache, and Emmanuel Thomé introduced the underlying number-field-sieve-based algorithm later used in the attack.
The demonstrated 1,024-bit attack consumed 1,380 CPU core-years over five months and made 232 oracle queries, compared with an estimated 500,000 to 1 million CPU core-years to factor a 1,024-bit RSA modulus. The result applies to raw or blind-signature RSA oracle designs, not conventional RSA signatures protected by PKCS#1 v1.5 or RSA-PSS padding.
Laura Shea, Miro Haller, Adam Suhl, Nadia Heninger, and Emmanuel Thomé implemented the first large-scale eNFS demonstration against a 1,024-bit RSA key. The attack used temporary access to an unpadded RSA signing or decryption oracle to enable offline signature forgery or chosen-ciphertext decryption without factoring the modulus or recovering the private key.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
4 references tracked. Mallory keeps watching after this page renders.
scworld.com
Open sourcecybersecuritynews.com
Open sourcearstechnica.com
Open sourceeprint.iacr.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.