Now the Shodan CEO John Matherly revealed that more than two years after its disclosure, about 200,000 services remain affected by the Heartbleed flaw due to the usage of unpatched OpenSSL instances.
Most of the vulnerable installations are located in the United States (42,032), followed by Korea (15,380), China (14,116), and Germany (14,072).
According to Matherly, the list of top affected organizations includes IT giants like Amazon, Verizon Wireless, German ISP Strato, OVH, 1&1 Internet, and Comcast.
The most affected product is Apache HTTP Server (httpd), in particular versions 2.2.22 and 2.2.15. Top operating system is Linux 3.x, followed by Linux 2.6.x and Windows 7/8. According to the report published by Shodan, more than 70,000 devices run services with expired SSL certificates.
[adrotate banner=”9″]
(Security Affairs – OpenSSL, Heartbleed)
[adrotate banner=”12″]
Google addressed a critical Chrome vulnerability, tracked as CVE-2024-4058, that resides in the ANGLE graphics…
Nation-state actor UAT4356 has been exploiting two zero-days in ASA and FTD firewalls since November…
A malware campaign has been exploiting the updating mechanism of the eScan antivirus to distribute…
The Treasury Department's Office of Foreign Assets Control (OFAC) sanctioned four Iranian nationals for their…
A cyber attack on Leicester City Council resulted in certain street lights remaining illuminated all…
The National Police Agency in South Korea warns that North Korea-linked threat actors are targeting…
This website uses cookies.