7 verified briefings on Encryption. Each story includes a plain-English summary, why it matters, and the concrete action engineering teams should take.
The UK government has ordered tech companies to scan children's phones for explicit content by September. Privacy advocates warn this mandate threatens end-to-end encryption and could lead to widespread surveillance, creating significant compliance challenges for developers.
A critical vulnerability in Ruby's Net::IMAP library allows attackers to bypass TLS encryption. This could expose sensitive data in applications that use the library to communicate with email servers, requiring an immediate update to prevent attacks.
A critical vulnerability has been discovered in 'age', a popular file encryption tool. The flaw allows for arbitrary code execution if an attacker provides a specially crafted recipient or identity string. This is due to improper validation of plugin names, posing a significant security risk.
AMD has removed a memory encryption feature from its consumer CPUs without an announcement. This feature, TSME, protected devices from physical attacks, potentially leaving sensitive data on laptops and PCs more vulnerable to theft.
Following widespread criticism from the tech industry and privacy advocates, the Canadian government is amending its lawful access proposal, Bill C-22. The changes aim to protect encryption standards and provide clearer rules on how companies must handle and retain user metadata for law enforcement.
A new vulnerability called YellowKey allows attackers with access to a Windows device to bypass Bitlocker encryption and access files. Microsoft is working on a permanent patch for the flaw (CVE-2026-45585) and has released temporary mitigation steps for companies to implement immediately.
A new exploit called YellowKey can bypass Windows 11's BitLocker full-disk encryption. Published by a security researcher, the attack works on default deployments but requires direct physical access to the target computer. The vulnerability affects systems that use a TPM to store decryption keys.