Every story tagged Cryptography Vulnerability, curated for CIOs and IT leaders — ranked by source credibility, engagement, and freshness.
2 stories · open in the command center
In Bouncy Castle for Java before 1.85, CMS AuthEnvelopedData fails to enforce tag-length on decryption. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bcpkix-fips 1.0.12 (1.0.X series), 2.0.12 (2.0.X series) and 2.1.12 (2.1.X series).
A critical cryptographic vulnerability was discovered in Dusk Network's PLONK zero-knowledge proof implementation that protects approximately $60M in assets, allowing attackers to forge proofs and mint arbitrary tokens by exploiting unvalidated polynomial commitments in the verification step. This represents a complete breakdown of the network's security model, enabling attackers to bypass all transaction constraints and move fraudulent funds through the system undetected. For IT organizations managing blockchain infrastructure or custody of digital assets, this incident underscores the necessity of rigorous cryptographic code audits, formal verification of consensus-critical components, and immediate incident response protocols for identified vulnerabilities in production systems.