Home › Intelligence › Brief
BREACH BRIEF🟠 High ThreatIntel

Subexponential Forgery Attack Demonstrated Against Pure RSA Signatures

Researchers have demonstrated a subexponential‑time attack that can forge 1024‑bit RSA signatures without padding, requiring 1380 CPU core‑years. Organizations relying on raw RSA signatures must reassess their cryptographic controls to maintain audit‑ready evidence of approved algorithms.

LiveThreat™ Intelligence · 📅 September 29, 2026· 📰 schneier.com
🟠
Severity
High
TI
Type
ThreatIntel
🎯
Confidence
High
🏢
Affected
1 sector(s)
✅
Actions
2 recommended
📰
Source
schneier.com

New Subexponential Forgery Attack Demonstrated Against Pure RSA Signatures

What Happened — Researchers published a 2026 implementation of a 2007 cryptographic attack that can forge RSA digital signatures when the signature is generated without any padding. The method runs in sub‑exponential time and succeeded in forging 1024‑bit RSA signatures after roughly five months of compute (≈ 1 380 CPU core‑years). The attack does not recover the private key; it merely creates a valid signature for arbitrary messages.

Why It Matters for Trust & Control Assurance

  • It tests the control objective of cryptographic protection – ensuring only approved algorithms and proper implementation safeguards (e.g., padding) are used.
  • Continuous control‑assurance programs must capture evidence that legacy “pure” RSA is retired and that approved padding schemes (RSA‑PSS, PKCS#1 v1.5) are enforced.
  • Demonstrates the need for control mapping across frameworks so that audit evidence can show compliance with cryptographic policy requirements.

Who Is Affected

  • Enterprises that still rely on raw RSA signatures for code signing, authentication tokens, or financial transaction validation.
  • SaaS platforms, PKI services, and any legacy infrastructure that has not migrated to padded RSA or elliptic‑curve alternatives.

Recommended Actions

  • Audit all systems that generate RSA signatures and verify that a padding scheme is applied.
  • Update cryptographic policies to deprecate raw RSA and mandate approved padding (RSA‑PSS) or modern algorithms (ECDSA, EdDSA).
  • Collect and retain evidence of algorithm usage (configuration files, library versions) for audit readiness.

Technical Notes – The attack exploits the mathematical structure of unpadded RSA signatures; it is a subexponential‑time algorithm (not polynomial) and required 1 380 CPU core‑years to forge a 1024‑bit signature. No CVE is associated because the weakness lies in algorithmic usage, not a software defect. Source: Schneier on Security

📰 Original Source
https://www.schneier.com/blog/archives/2026/09/new-attack-against-rsa.html ↗

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Trust Operations

Every gap like this maps to a control you can evidence.

The Verisq AI Trust Operations platform maps incidents to your control framework and collects the evidence continuously — so your Trust Center shows proof, not promises, when a buyer or auditor asks.

Explore the Verisq AI Trust Operations platform →