Researchers have discovered a novel classical computing attack on RSA that enables signature forgery without factoring, reducing computational requirements by orders of magnitude. The attack is now practical for 1024-bit keys and significantly weakens 2048-bit and 4096-bit RSA security, though widely used implementations remain safe for now.
Researchers implemented a 2007 algorithm that forges 1024-bit RSA signatures using a raw signing oracle in ~1,380 core-years, faster than factoring but requiring oracle access that most real-world RSA deployments don't expose. The attack doesn't pose immediate operational threats to properly padded RSA signatures, though it suggests RSA security estimates may need revision and supports transitioning to post-quantum cryptography.