Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

What is SLH-DSA? Hash-Based Post-Quantum Digital Signature Guide

SLH-DSA is NIST’s standardised post-quantum digital signature algorithm (hash-based). It generates quantum-resistant signatures, ensuring signatures are not changeable and that they will not be forged, even when later superseded by schemes like RSA and ECDSA, which are susceptible to attacks by quantum computers. Organisations are studying it today because large-scale quantum computers could, in the future, crack the algorithms that currently underpin most digital trust.

What Is ML-KEM? Guide to NIST's Post-Quantum Key Encapsulation Mechanism

Quantum computers are likely to render the current public-key cryptography used for protecting modern internet traffic, digital signatures, and encryption useless. In response, NIST has developed ML-KEM as the main post-quantum key encapsulation method. The guide below will introduce the concept of ML-KEM, how it functions, in which projects it is used, and how organisations can implement it.

OWASP Top 10 for Large Language Model Applications: Complete Guide to LLM Security Risks

Companies rush to utilise the potential of large language models; however, every new use case of generative AI introduces attack vectors previously unknown in traditional web security. The present guide provides an overview of the official OWASP GenAI LLM Top 10 2026 list and explains the appearance of each vulnerability in practice along with mitigation recommendations.

Windows Code Signing Moves Toward Post Quantum Security in 2027

Microsoft is in the process of shaping major changes to Windows code signing that will have the effect of altering the certificate infrastructure, the cryptographic algorithms, and, in the end, how Windows applications will be protected against future quantum computing threats. The changes are of particular importance to developers, IT administrators, security teams, and organizations that are using their custom software or security tools that can do their own code signature validation.

Google Cloud KMS Adds Generally Available Quantum-Safe Digital Signatures

As quantum computing develops, cybersecurity professionals are getting ready for a breakthrough in the protection of digital information. The conventional public-key cryptographic algorithms that ensure the security of digital signatures may, in the long run, be compromised by the revolutionary power of quantum computers. To minimize that risk, Google Cloud has announced general availability of the quantum-safe digital signature feature in its Google Cloud Key Management Service (Cloud KMS).

What are Software Artifacts? Types, Tools, Benefits, Best Practices

The foundation of modern-day software development relies heavily on translating requirements into products through traceability, collaboration, and reproducibility. Software artifacts are instrumental in this process, facilitating development across all areas, including application development, CI/CD pipelines, and compliance.

What is ML-DSA (CRYSTALS-Dilithium)? The Future of Digital Signatures Beyond RSA and ECC

With quantum computing soon changing the way things work in general, one of the areas that cybersecurity experts are most worried about is how digital signatures will survive. The same kinds of algorithms that have supported virtually all secure communications (both computer and otherwise) for decades are going away. Not only are RSA and Elliptic Curve Cryptography (ECC) algorithms no longer safe from being cracked by quantum computers, but they have also become obsolete.

What Is Trust Now, Forge Later (TNFL)? TNFL vs HNDL Attacks Explained

Suppose that the hospital allows a vital software update of its infusion pumps to go through, and all security tests pass. The signature looks valid. The certificate is scrapless. Everything appears legitimate. The update was forged by an attacker who cracked a key that was considered unbreakable just five years ago. The general perception of most individuals is that after encryption or after data is digitally signed, it stays secure indefinitely. That assumption is now perilously outdated.

DigiCert Software Trust Manager & DigiCert KeyLocker: Difference Explained

As the volume of software supply chain attacks continues to grow, organizations must increase controls over how they sign, store, and release code. DigiCert has launched two cloud-based solutions that help organizations both protect their private keys and improve the efficiency of their code signing operations: DigiCert KeyLocker and DigiCert Software Trust Manager.