CYBERSECURITYTRACKER
TRACKING
Permanent story citation

New Attack Against RSA

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 8715

As cited

Copy frozen at (site build).

research

New Attack Against RSA

Researchers have demonstrated a practical attack that forges RSA digital signatures without recovering the private key, based on algorithmic work from 2007 but with new implementation techniques. The attack works only on unpadded signatures and remains subexponential in complexity, requiring roughly 1,380 CPU core-years to forge a 1,024-bit RSA signature. This does not represent a fundamental break of RSA as commonly deployed in modern systems, which rely on padded signature schemes and larger key sizes.

Why it matters: Organizations relying on legacy unpadded RSA signatures or 1,024-bit keys should assess whether they are still in use; practitioners should verify their implementations use standard padding schemes and modern key lengths to remain unaffected by this attack.

Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary