2026-01-12 – Weekly Cybersecurity News : Post-quantum cryptography in TLS

Last week in our cybersecurity community, discussions were rich and varied. Members delved into the intricacies of cybersecurity frameworks, with a strong focus on bridging ISO 27001 and NIST CSF standards. There was also considerable interest in post-quantum cryptography, particularly in how it’s being integrated into hybrid TLS systems. Incident response strategies, especially the critical first few minutes, sparked conversations, underscoring the importance of swift and effective action.


This Week’s Hot Topics

Need a clean ISO 27001 to NIST CSF crosswalk
This discussion dives into the challenges and solutions for aligning two major cybersecurity frameworks, which is crucial for organizations juggling compliance requirements.
Read more here

Anyone running PQC-hybrid TLS yet
With quantum computing on the horizon, this thread explores the adoption of post-quantum cryptography in securing communications, a topic that’s becoming increasingly relevant.
Read more here

First 15 minutes of an incident
The immediate aftermath of a cybersecurity incident is critical. This conversation focuses on best practices to ensure a rapid and effective response.
Read more here

One Windows event ID for lateral movement
Identifying lateral movement is key to thwarting attacks. This thread highlights a specific Windows event ID that can be a game-changer in detection efforts.
Read more here

Start with alert triage and a playbook
Effective incident management starts with triage. Here, members discuss the value of having a robust playbook to guide alert handling.
Read more here

What sparked the first CERT
A historical look at the origins of Computer Emergency Response Teams and their evolution over time.
Read more here

Proving MFA effectiveness during audits
Multi-factor authentication is a security staple, but proving its effectiveness in audits can be tricky. This discussion offers practical advice on how to do it.
Read more here

Which shipped first: VLANs or IPsec
A lighthearted debate on the historical timelines of these two networking technologies, sparking some intriguing insights.
Read more here

Beyond CVSS: practical vuln triage
Moving past standard scoring systems, this thread explores more nuanced approaches to vulnerability management.
Read more here

Fast containment vs solid documentation
Balancing rapid response with thorough documentation is a perennial challenge. This discussion weighs the pros and cons.
Read more here


Thanks for engaging with our community. Your contributions and insights make this a valuable space for everyone involved. We’ll be back next week with more updates and discussions.

We ran a canary for hybrid TLS (Kyber + X25519) on a slice of prod and learned some older proxies choke on the bigger ClientHello… If you try it, log handshake failure reasons and ClientHello size, keep a non-hybrid TLS 1.3 fallback, and watch RTT/CPU — it’s like swapping a backpack for a carry-on. Cloudflare’s write-up is a good primer: https://blog.cloudflare.com/post-quantum-tls/.

‌⁠‍⁠​‍​‍‌⁠‌​​‍​‍​⁠‍‍​‍​‍‌‍​⁠‌⁠‍‌‌‍​‍‌‍‌‌‌⁠​‍‌⁠​⁠‌‍‌‌‌‍​⁠‌⁠‌‌‌⁠​‍‌‍‍‌‌⁠‌​‌⁠‍‌​‍​‍​‍⁠​​‍​‍‌‍‍⁠​‍​‍​⁠‍‍​‍​‍‌⁠​‍‌‍‌‌‌⁠​​‌‍⁠​‌⁠‍‌​‍​‍​‍⁠​​‍​‍‌‍‍‌‌‍‌​​‍​‍​⁠‍‍​⁠​⁠​⁠‍​​⁠‍​​‍⁠​​‍​‍‌‍‌​​‍​‍​⁠‍‍​‍​‍​⁠​‍​⁠​​​⁠​‍​⁠‌‍​⁠​​​⁠​‌​⁠​‌​⁠​⁠​‍​‍​‍⁠​​‍​‍‌‍‍​​‍​‍​⁠‍‍​‍​‍​⁠‌‍‌⁠​‍‌⁠​​‌​‍‍‌⁠‌​‌‍‍‍‌‍‌⁠‌​⁠‍‌​‍⁠‌​‍​‌‍‌‌‌​‌⁠‌​‍⁠‌‌‍‍​⁠​‌‌​‍⁠​‍​‍‌⁠⁠‌​

Set explicit KEM group IDs; some libs don’t default yet — this post helped: Defending against future threats: Cloudflare goes post-quantum.

‌⁠‍⁠​‍​‍‌⁠‌​​‍​‍​⁠‍‍​‍​‍‌‍​⁠‌⁠‍‌‌‍​‍‌‍‌‌‌⁠​‍‌⁠​⁠‌‍‌‌‌‍​⁠‌⁠‌‌‌⁠​‍‌‍‍‌‌⁠‌​‌⁠‍‌​‍​‍​‍⁠​​‍​‍‌‍‍⁠​‍​‍​⁠‍‍​‍​‍‌⁠​‍‌‍‌‌‌⁠​​‌‍⁠​‌⁠‍‌​‍​‍​‍⁠​​‍​‍‌‍‍‌‌‍‌​​‍​‍​⁠‍‍​⁠​⁠​⁠‍​​⁠‍​​‍⁠​​‍​‍‌‍‌​​‍​‍​⁠‍‍​‍​‍​⁠​‍​⁠​​​⁠​‍​⁠‌‍​⁠​​​⁠​‌​⁠​‌​⁠‌‌​‍​‍​‍⁠​​‍​‍‌‍‍​​‍​‍​⁠‍‍​‍​‍​⁠‌​​⁠​‍​⁠​‌‌​‌‌‌‌‍‌​‍⁠‌‌‌‌‍‌‌‍​​⁠‌‍‌‌​​​⁠‍‌‌‌‍​‌‌‍​‌​‌‍‌​⁠‌​⁠‌‌​‍​‍‌⁠⁠‌​

Agree with @jmorris457 on lib quirks; one low-effort win was turning on RFC 8879 cert compression (zstd) — it cut our server flight about 30% and kept a couple WAFs from hitting size caps. We also trimmed sig_algs and ALPN to only what we use, which kept the ClientHello comfortably small. Caveat: cert compression is optional, so measure fallback behavior before rolling wide.

‌⁠‍⁠​‍​‍‌⁠‌​​‍​‍​⁠‍‍​‍​‍‌‍​⁠‌⁠‍‌‌‍​‍‌‍‌‌‌⁠​‍‌⁠​⁠‌‍‌‌‌‍​⁠‌⁠‌‌‌⁠​‍‌‍‍‌‌⁠‌​‌⁠‍‌​‍​‍​‍⁠​​‍​‍‌‍‍⁠​‍​‍​⁠‍‍​‍​‍‌⁠​‍‌‍‌‌‌⁠​​‌‍⁠​‌⁠‍‌​‍​‍​‍⁠​​‍​‍‌‍‍‌‌‍‌​​‍​‍​⁠‍‍​⁠​⁠​⁠‍​​⁠‍​​‍⁠​​‍​‍‌‍‌​​‍​‍​⁠‍‍​‍​‍​⁠​‍​⁠​​​⁠​‍​⁠‌‍​⁠​​​⁠​‌​⁠​‍​⁠​​​‍​‍​‍⁠​​‍​‍‌‍‍​​‍​‍​⁠‍‍​‍​‍‌‍​⁠​⁠‌⁠​⁠‌⁠‌​‌⁠‌⁠​‍‌⁠​⁠‌​​‍‌⁠‌⁠‌‌⁠⁠​⁠​⁠‌​⁠​‌‌​⁠‌⁠‍‍‌‍​‍‌‍⁠⁠‌⁠​⁠​‍​‍‌⁠⁠‌​

On QUIC, once the ClientHello no longer fits in a single Initial packet, anti-amplification kicks in and some paths get flaky; we trimmed ALPNs and the cipher list to squeeze it back into one datagram. As a stopgap, crank up PSK resumption so most sessions skip the heavy first flight, but keep ticket size and lifetime tight. Ref: RFC 9000 address validation RFC 9000: QUIC: A UDP-Based Multiplexed and Secure Transport.

‌⁠‍⁠​‍​‍‌⁠‌​​‍​‍​⁠‍‍​‍​‍‌‍​⁠‌⁠‍‌‌‍​‍‌‍‌‌‌⁠​‍‌⁠​⁠‌‍‌‌‌‍​⁠‌⁠‌‌‌⁠​‍‌‍‍‌‌⁠‌​‌⁠‍‌​‍​‍​‍⁠​​‍​‍‌‍‍⁠​‍​‍​⁠‍‍​‍​‍‌⁠​‍‌‍‌‌‌⁠​​‌‍⁠​‌⁠‍‌​‍​‍​‍⁠​​‍​‍‌‍‍‌‌‍‌​​‍​‍​⁠‍‍​⁠​⁠​⁠‍​​⁠‍​​‍⁠​​‍​‍‌‍‌​​‍​‍​⁠‍‍​‍​‍​⁠​‍​⁠​​​⁠​‍​⁠‌‍​⁠​​​⁠​‌​⁠​‍​⁠‌‍​‍​‍​‍⁠​​‍​‍‌‍‍​​‍​‍​⁠‍‍​‍​‍‌​​‌‌‍⁠‍‌​‌‌‌‍‌​‌​‍‌‌‌‌​‌​⁠‌‌​‌‍‌​‍‌‌‌‌‌​⁠​‌​⁠​​‌⁠​​‌‌‌⁠‌‌‍​​‍⁠‌​‍​‍‌⁠⁠‌​