Theos Threat RadarLIVE
The window is closing.
One radar for the post-quantum threat landscape: actively exploited vulnerabilities, the quantum hardware race, NIST standards status, and every compliance deadline that decides when your cryptography expires. Computed live — every figure cited.
NIST IR 8547 (draft) · RSA & ECC deprecated after 2030
… of the migration window already elapsed since Aug 13, 2024.
Quantum-compute & standards centers · drag to spin
◆ HARVEST NOW · DECRYPT LATER
10–25+ yrs
Secrecy lifetime of health records, financial archives, IP and state data — long enough to outlive the classical crypto protecting them today. CISA, NSA and NIST jointly warn that adversaries are collecting ciphertext now to decrypt on Q-Day.
Source · CISA/NSA/NIST Quantum-Readiness factsheet (2023)
◆ SIGNATURES · SHOR
RSA · ECDSA · EdDSA · DH
Every widely deployed public-key scheme — TLS handshakes, code signing, document signatures, PKI — is broken by Shor's algorithm on a cryptographically relevant quantum computer.
Source · NIST IR 8547 (draft)
◆ SYMMETRIC · GROVER
AES-128 → ~64-bit
Grover's algorithm halves effective symmetric security. AES-256 and SHA-384 remain safe margins — which is why CNSA 2.0 mandates them alongside ML-KEM and ML-DSA.
Source · NSA CNSA 2.0 advisory
Advisory feed
What attackers are exploiting right now.
Cryptography fails through implementation long before Q-Day. These feeds pull from the CISA Known Exploited Vulnerabilities catalog and the GitHub Advisory Database.
CISA · Known Exploited Vulnerabilities
LIVE · HOURLY- CVE-2026-505222026-07-22
Microsoft SharePoint Deserialization of Untrusted Data Vulnerability
- CVE-2026-162322026-07-22
Check Point SmartConsole Improper Authentication Vulnerability
- CVE-2021-271372026-07-21
DD-WRT Stack-Based Buffer Overflow Vulnerability
- CVE-2026-07702026-07-21
Langflow Inclusion of Functionality from Untrusted Control Sphere Vulnerability
- CVE-2026-630302026-07-21
WordPress Core Interpretation Conflict Vulnerability
- CVE-2026-601372026-07-21
WordPress Core SQL Injection Vulnerability
- CVE-2026-398082026-07-16
Fortinet FortiSandbox OS Command Injection Vulnerability
- CVE-2026-250892026-07-16
Fortinet FortiSandbox OS Command Injection Vulnerability
Cryptography-relevant advisories
LIVE · HOURLY- GHSA-6vch-q96h-7gc3high · 2026-07-24
etcd: `tlsListener.acceptLoop` spawns unbounded handshake goroutines with no deadline
- GHSA-8q49-2h5h-434xmedium · 2026-07-24
FrontMCP: Server-Side Request Forgery (SSRF) in the OpenAPI adapter spec-change poller
- GHSA-jpcw-4wr7-c3vqmedium · 2026-07-24
kin-openapi openapi3filter: unauthenticated nil-pointer panic when validating a request against a `content` parameter whose media type has no schema
- GHSA-j6g5-3hh3-pgw8high · 2026-07-24
AWS Bedrock AgentCore: Improper neutralization of argument delimiters in the Python SDK install_packages()
- GHSA-xg4h-6gfc-h4m8high · 2026-07-24
etcd: Watch API authorization bypass via open-ended range requests
- GHSA-jvxp-qmx7-gjpxhigh · 2026-07-24
Smithy-RS: Allocation of resources without limits in the default aws-smithy-http-server serve() path allows unauthenticated Slowloris denial of service
- GHSA-hmj8-5xmh-5573high · 2026-07-24
libp2p: yamux connection DoS via oversized data frame
- GHSA-3r53-75j5-3g7jmedium · 2026-07-24
Quasar: Prototype pollution in the extend() utility
NIST PQC standards · status board
ML-KEM (Kyber)
FIPS 203 · Key encapsulation
FINALAug 2024
ML-DSA (Dilithium)
FIPS 204 · Digital signatures
FINALAug 2024
SLH-DSA (SPHINCS+)
FIPS 205 · Hash-based signatures
FINALAug 2024
FN-DSA (FALCON)
FIPS 206 · Compact lattice signatures
DRAFTIn progress
HQC
Backup KEM · code-based
SELECTEDMar 2025
Quantum hardware race · physical qubits
Curated from public disclosures · reviewed 2026-07. Physical qubits track the trend — error rates and logical qubits decide the real timeline.
Atom Computing · 1,180-qubit neutral-atom array
1,180
announced Oct 2023
IBM · Condor
1,121
unveiled Dec 2023
IBM · Heron r2
156
error-focused tuning
Google · Willow
105
below-threshold error correction, Dec 2024
USTC · Zuchongzhi 3.0
105
superconducting
Quantinuum · H2
56
trapped-ion, high fidelity
IonQ · Forte
36
#AQ 36 algorithmic qubits
Compliance countdown
The deadlines are already published.
Regulators are not waiting for Q-Day. Every date below comes from a public policy document.
EU DORA
—
2025-01-17 · EU
Digital Operational Resilience Act applies — EU financial entities must manage ICT & third-party risk, including cryptographic posture.
NSA CNSA 2.0 · new acquisitions
—
2027-01-01 · US · NSS
NSA timeline: new National Security System acquisitions should support CNSA 2.0 (ML-KEM, ML-DSA, SHA-2/384+) from 2027.
NIST IR 8547 · RSA/ECC deprecated
—
2030-12-31 · US · Federal
NIST draft transition guidance: 112-bit-strength classical public-key crypto (RSA-2048, ECDSA P-256) deprecated after 2030.
NSA CNSA 2.0 · full adoption
—
2033-01-01 · US · NSS
NSA target for National Security Systems to have completed transition to CNSA 2.0 algorithms.
NIST IR 8547 · RSA/ECC disallowed
—
2035-12-31 · US · Federal
NIST draft transition guidance: classical public-key algorithms disallowed for federal use after 2035.
How we got here
Three decades from theory to deadline.
1994
Peter Shor publishes the algorithm that breaks RSA and ECC on a large quantum computer.
2016
NIST opens the global post-quantum cryptography standardization competition.
2019
Google announces quantum supremacy on a 53-qubit processor (Sycamore).
2022
NIST selects CRYSTALS-Kyber, CRYSTALS-Dilithium, SPHINCS+ and FALCON for standardization.
2023
IBM Condor passes 1,000 physical qubits; Atom Computing announces a 1,180-qubit array.
2024
NIST finalizes FIPS 203, 204 and 205 (Aug 13). Google Willow demonstrates below-threshold error correction.
2025
NIST selects HQC as backup KEM; FN-DSA (FIPS 206) drafting continues; CNSA 2.0 clock running.
2030
NIST draft guidance deprecates RSA-2048 and ECDSA P-256 for federal systems.
The Quantum Window
36% of the world's PQC migration window is already gone.
Attackers are harvesting encrypted data today to decrypt on Q-Day. The window is closing — start now.
Put this on your own site — get the free embeddable widget →
Don't watch the radar alone.
AutoPQC finds every vulnerable algorithm in your estate, maps it to the NIST standards above, and sequences the migration — before these deadlines become findings in your audit.
The Quantum Threat Brief
Standards drift, deadline changes, and what actually matters — in your inbox when something moves. No noise.