
Two Threats, One Data Problem: Key Findings from the Thales Quantum and AI Threat Report lee.potok@thal… Tue, 07/28/2026 - 07:50 Artificial intelligence and quantum computing are reshaping cybersecurity faster than many organizations realize. The 2026 Thales Quantum & AI Threat Report reveals how these technologies are converging on a single target enterprise data and why "harvest now, decrypt later" has become the leading quantum concern. Explore the report's key findings and learn why strengthening your data security foundation today is essential for protecting against both current AI-driven threats and tomorrow's quantum risks. Encryption Data Security Anina Steele | Senior PR Manager More About This Author > Artificial intelligence and quantum computing are often discussed as separate technology trends. But fresh findings from the Thales Quantum and AI Threat Report suggest that treating them as separate problems is a mistake we can’t really afford right now. Based on responses from 3,120 security and technology professionals across 20 countries, the report reveals a common theme running through both technologies: they are converging on the same target - enterprise data. So, how should we go about protecting data at the crossroads of two revolutions? Key takeaways The Thales 2026 Quantum & AI Threat Report surveyed 3,120 security and IT professionals across 20 countries.98% of respondents now weigh how AI and quantum computing affect each other — both are converging on one target: enterprise data.Harvest now, decrypt later (HNDL) is the top quantum concern, cited by 61% of respondents.AI risk is already here: 59% have experienced deepfake attacks, and only 3% report no harm from AI-generated threats.Organizations with stronger data security fundamentals are consistently more ready for both the AI and the quantum shift. AI and quantum computing can’t be viewed in isolation AI doesn’t take away the need to prepare for quantum — it makes that need more urgent. AI can make attacks happen faster, while we depend more and more on encryption to keep things safe.Going back to the report, the vast majority (98%) of respondents said they are considering how AI and quantum computing interact. The conversation has already moved past viewing these technologies in isolation. While AI and quantum operate on different timelines, both are creating pressure on the same security foundations, including data discovery, classification, encryption, key management, and cloud security. The organizations making progress in one area are often further ahead in the other.That concern is not only defensive. According to 451 Research's VoTE Digital Pulse Quantum Computing study, 36% of organizations expect quantum computing to deliver material business value within one to three years, and 52% cite competitive advantage as the main driver of investment. The AI data security pressure is already here Unlike quantum computing, AI security is not a concern for some future date.Organizations are already increasing spending on AI initiatives. 25% ranked AI security as the second-highest security spending category, after cloud. 30% reported significant increases in AI-specific security budgets.At the same time, security teams are finding themselves under pressure to support AI programs where speed and innovation often take precedence. Security ranked second from the bottom among reported AI project success criteria at just 35%, suggesting that many organizations still see it as a supporting function rather than a primary objective.The major hurdles to AI implementation also relate to data. The top inhibitors to AI adoption were data quality and governance (65%) and data exposure (61%).The report also highlights how quickly AI-generated risks have become part of everyday security operations. Only 3% of respondents reported experiencing no harm or damage from AI-generated threats. Human error is the leading cause of breaches, but deepfakes emerged as the leading AI-related concern. 59% of respondents reported experiencing deepfake attacks, while 48% reported reputational damage linked to AI-generated threats, reflecting the growing sophistication of AI-enabled social engineering.The growing adoption of agentic AI and autonomous systems within organizations is driving a surge in the volume and velocity of data use. As such, cybersecurity professionals are under pressure to control data access and understand where the data resides, how it is used, and whether it is adequately protected as it is used in complex AI workflows. Quantum risk is no longer future tense: harvest now, decrypt later If AI is today's pressure, quantum computing is tomorrow's deadline.The report shows that organizations are already adjusting their security priorities in response. Harvest-Now, Decrypt-Later (HNDL) attacks are now the leading quantum-related concern, cited by 61% of respondents.In a harvest now, decrypt later attack, adversaries collect encrypted data today and store it to decrypt in the future, once quantum computers can break the encryption that protects it. The concern is straightforward. Sensitive data stolen today could be retained and decrypted years later once sufficiently powerful quantum systems become available.A significant portion of organizations are already preparing. Nearly a third (32%) are either experimenting with or surveying quantum computing initiatives, while 59% plan to prototype or evaluate post-quantum cryptography (PQC) algorithms within the next 18 to 24 months.Current trends reveal that discussions about timing are becoming pressing. A recent preprint (not yet peer-reviewed) from a Caltech-led research team found that Shor’s algorithm could run at cryptographically relevant scales with as few as 10,000 reconfigurable atomic qubits — dramatically fewer than earlier estimates for attacks on schemes such as 256-bit elliptic curve cryptography.The timing of when a true "Q-Day" will arrive remains contested, but some estimates say it could be as early as 2030. Irrespective of whether that timeline is right, transitioning to quantum-resistant security controls will take years, so preparation must start as soon as possible. Leaders and Laggards: The Data Gap The report also compared technology leaders and laggards.AI security leaders were defined as organizations that have invested in AI-specific security and consider themselves ahead of peers in AI adoption. Quantum leaders were organizations actively experimenting with or surveying quantum computing opportunities.Across both groups, stronger data security fundamentals consistently appeared alongside greater readiness for emerging technologies.Among AI leaders, 36% reported complete knowledge of where their data is stored, compared with 28% of laggards. 43% reported being able to fully classify their data, compared with 35% among laggards.The relationship also works in the other direction. AI leaders are further along in their quantum journey, with 33% actively experimenting with or surveying quantum projects compared with 22% of laggards. Meanwhile, 89% of quantum leaders have invested in AI-specific security compared with 80% of quantum laggards.The implication is difficult to ignore. Organizations that build stronger foundations around data security appear better positioned to adapt to both technological shifts. Cloud Remains the Common Attack Surface The report also reinforces the central role cloud environments play in modern security risk.According to 451 Research's VoTE Digital Pulse Quantum Computing, cloud security has been the leading enterprise security pain point every year since 2021.That trend appears throughout the report's findings. The three most frequently targeted assets are all cloud-related: cloud storage (35%), cloud applications (34%), and cloud management infrastructure (32%).The average organization now uses 2.3 cloud providers, while 39% use more than three. As AI initiatives depend on cloud infrastructure for training, inference, and data storage, the attack surface continues to widen.For security teams, visibility becomes increasingly important as environments become more distributed and data moves across multiple platforms, providers, and AI services. The leader/laggard split in the report suggests that organizations investing in data fundamentals now are not just managing today's AI risk. They are also narrowing their exposure to a quantum threat that will not announce itself in advance. Frequently asked questions What is harvest now, decrypt later (HNDL)?Harvest now, decrypt later (HNDL) is an attack strategy in which adversaries steal and store encrypted data today so they can decrypt it later, once quantum computers are powerful enough to break current encryption. In the Thales 2026 Quantum & AI Threat Report, 61% of respondents named HNDL their top quantum-related concern.Is quantum computing a cybersecurity threat?Yes. Large-scale quantum computers are expected to break the public-key encryption — such as RSA and elliptic curve cryptography — that protects most data in transit and at rest. The most immediate risk is harvest now, decrypt later, where data stolen today is decrypted once that capability exists.When is Q-Day?“Q-Day” is the point at which a quantum computer can break today’s encryption. Estimates vary and remain contested, but some place it as early as 2030. Because migrating to quantum-resistant controls takes years, most experts advise starting preparation now.How can organizations prepare for AI and quantum data threats?The report points to strong data security fundamentals: knowing where data lives, classifying it, and protecting it with encryption and key management. Practical first steps include building crypto-agility and evaluating post-quantum cryptography, and using data security posture management to discover and protect sensitive data across cloud and hybrid environments.Download the full Thales Quantum and AI Threat Report to explore the complete findings and recommendations. Schema <script type="application/ld+json"> { "@context": "https://schema.org", "@graph": , "potentialAction": { "@type": "SearchAction", "target": "https://cpl.thalesgroup.com/search?search={search_term_string}", "query-input": "required name=search_term_string" } }, "keywords": , "articleSection": "Encryption", "inLanguage": "en-US" } ] } </script> studio THALES BLOG Two Threats, One Data Problem: Key Findings from the Thales Quantum and AI Threat Report July 28, 2026
Nguồn: https://securityboulevard.com/2026/07/two-threats-one-data-problem-key-findings-from-the-thales-quantum-and-ai-threat-report. 8sync News chỉ tóm tắt và dẫn link; bản quyền nội dung thuộc tác giả và nguồn gốc.
Bài viết thông báo về bản cập nhật bảo mật của Redis nhằm ứng phó với các tuyên bố về lỗ hổng Kimi K3. Redis khuyến khích sử dụng Redis Enterprise để khai thác tối đa tiềm năng của cơ sở dữ liệu Redis và phát triển ứng dụng nhanh chóng.
Lập trình viên nên đọc bài này để hiểu cách Redis đã giải quyết nguy cơ bảo mật Kimi-K3 và cập nhật các biện pháp bảo vệ mới, giúp ứng dụng của bạn an toàn hơn trong môi trường sử dụng Redis.
Arista vừa vá lỗ hổng zero-day nghiêm trọng (command injection) trong VeloCloud Orchestrator triển khai tại chỗ, lỗ hổng này đang bị khai thác tích cực trong các cuộc tấn công.
Lập trình viên nên đọc bài này để hiểu cách bảo mật hệ thống cloud và cách phát hiện lỗ hổng zero-day trong các ứng dụng phần mềm, giúp nâng cao kiến thức về bảo vệ hệ thống khỏi các cuộc tấn công mới và áp dụng các biện pháp phòng ngừa hiệu quả.
Microsoft ra mắt Project Perception, hệ thống bảo mật agentic dành cho kỷ nguyên AI, tích hợp ba nhóm agent chuyên biệt (red team, blue team, green team) thành vòng tuần hoàn phòng thủ khép kín. Hệ thống này hoạt động trên kiến trúc 'Cyber Stack' mới, kết hợp tín hiệu, ngữ cảnh bảo mật, mô hình AI đa dạng và actuator để phản ứng đe dọa liên tục ở tốc độ máy. MAI-Cyber-1-Flash, mô hình chuyên dụng cho quản lý lỗ hổng phần mềm, đạt 96% trên CyberGym benchmark với chi phí tiết kiệm ~50%. Bản xem trước công khai sẽ ra mắt vào ngày 3 tháng 8.
Lập trình viên nên đọc bài này để hiểu cách AI hiện đại hóa bảo mật phần mềm, từ việc phát hiện lỗ hổng tự động đến tối ưu hóa phản ứng với mối đe dọa với chi phí thấp hơn gấp đôi so với phương pháp truyền thống.
Các AI agent "shadow" (không được quản lý bởi IT) đang lan rộng trong doanh nghiệp mà không bị phát hiện, tiềm ẩn rủi ro bảo mật. Nudge Security đề xuất cách doanh nghiệp tìm kiếm, đánh giá và kiểm soát chúng trước khi các quyền hạn không quản lý được và hành động tự động gây ra nguy cơ.
Lập trình viên nên đọc bài này để hiểu cách bảo vệ hệ thống của doanh nghiệp trước các AI shadow agents hoạt động độc lập mà không được kiểm soát, có thể gây rủi ro về quyền riêng tư, an ninh và hiệu suất công việc.
Thị trường Relay (gray market) cung cấp giải pháp B2B giá rẻ, có cấu trúc cho người bán lại token tại Trung Quốc đại lục, giúp họ truy cập các dịch vụ AI như OpenAI, Anthropic hay Google.
Lập trình viên nên đọc bài này để hiểu cách các công ty và cá nhân trong thị trường gray-market (đen) vận hành hệ thống relay—công cụ quan trọng cho việc tiếp cận và phân phối dịch vụ AI lớn như OpenAI và Anthropic mà nhiều người vẫn chưa biết đến.
Bản cập nhật Astro 7.1 mang đến nhiều cải tiến như hỗ trợ CSP, phân trang, server phát triển và collections nội dung.
Lập trình viên phát triển web nên đọc bài này để khám phá cách Astro 7.1 nâng cao kiểm soát CSP (Content Security Policy) và cải thiện hiệu suất với pagination và bộ nhớ cache nội dung, giúp tối ưu hóa ứng dụng web của mình một cách hiệu quả hơn.
GitHub's AI agent có lỗ hổng bảo mật 'GitLost' cho phép rò rỉ dữ liệu private repository khi được yêu cầu theo cách nhất định, hiện chưa có bản vá hay tài liệu chính thức từ GitHub.
Lập trình viên nên đọc bài này để hiểu về nguy cơ bảo mật mới trong GitHub, đặc biệt khi làm việc với các dự án riêng tư, và cách phòng tránh rủi ro khi sử dụng công cụ AI tích hợp trong hệ thống.
Bài viết giới thiệu một trình xác thực (verifier) sản xuất cho giao thức ML-DSA, được viết hoàn toàn bằng Python với chỉ 350 dòng code, dễ đọc và đáng tin cậy.
Một lập trình viên cần đọc bài này để tìm hiểu cách triển khai một hệ thống xác minh ML-DSA (Machine Learning Digital Signature Algorithm) trong Python với hiệu suất cao và độ tin cậy, giúp tiết kiệm thời gian phát triển và tối ưu hóa cho ứng dụng sản xuất thực tế.
Đọc tin ở đây, luyện code, học theo lộ trình và luyện IELTS trên các sản phẩm anh em — tất cả kết nối với nhau trong hệ sinh thái 8 Sync Dev.
Cổng chính của hệ sinh thái: giới thiệu sản phẩm, blog và bảng giá trọn bộ.
Khám pháHọc theo lộ trình rõ từng chặng: video, quiz chấm tự động, certificate và mentor đang làm nghề.
Xem lộ trình1.000+ bài DSA, đề tiếng Việt, chấm tự động 7 ngôn ngữ — nhiều bài FREE, chạy ngay trên trình duyệt.
Luyện miễn phíChấm bốn kỹ năng IELTS bằng AI, phản hồi chi tiết theo rubric.
Dùng thử miễn phíAI IDE 22 MB cho dev Việt.
Tải miễn phíBộ nhớ tổ chức cho AI agent.
Khám pháAI trực Fanpage, tự sàng lọc lead.
Dùng thử