2018.08.22 19:20:50 (1032316679672360960) from Daniel J. Bernstein:
Has anyone verified the details of https://eprint.iacr.org/2018/699? This is the latest attack against NSA's Simon cipher. The central claim is that the smallest version of Simon is broken for 27 rounds, i.e., almost 85% of the full 32 rounds. Best previous result was 23, already scary.