SSL

Bar Mitzvah attack exploits the Invariance Weakness in RC4Bar Mitzvah attack exploits the Invariance Weakness in RC4

Bar Mitzvah attack exploits the Invariance Weakness in RC4

Bar Mitzvah is the name of a new attack on RC4-Based SSL/TLS encryption that allows disclosure of sensitive data by…

10 years ago
Qualys provides SSL Labs APIs and a tool to automate SSL/TLS testsQualys provides SSL Labs APIs and a tool to automate SSL/TLS tests

Qualys provides SSL Labs APIs and a tool to automate SSL/TLS tests

Qualys announced the availability of free assessment SSL Labs APIs and a tool that could be used by users to…

10 years ago
OpenSSL announced fix for mystery high critical vulnerabilityOpenSSL announced fix for mystery high critical vulnerability

OpenSSL announced fix for mystery high critical vulnerability

New versions of OpenSSL will be released on Thursday to patch critical security vulnerabilities, one of which is considered very…

10 years ago
Mozilla continues the phasing out of 1024-bit SSL CA certificatesMozilla continues the phasing out of 1024-bit SSL CA certificates

Mozilla continues the phasing out of 1024-bit SSL CA certificates

Mozilla products including the Firefox browser will stop trusting SSL certificates that were issued using old root CA certificates with…

10 years ago
GE Multilink Switches affected by critical vulnerabilitiesGE Multilink Switches affected by critical vulnerabilities

GE Multilink Switches affected by critical vulnerabilities

GE MultiLink managed switches are affected by two vulnerabilities which could be exploited to gain unauthorized access and run DoS…

10 years ago
Phishing campaign via Dropbox exploits SSL of the popular cloud servicePhishing campaign via Dropbox exploits SSL of the popular cloud service

Phishing campaign via Dropbox exploits SSL of the popular cloud service

Experts at Symantec have detected a scam based on Dropbox accounts to serve phishing pages over secure communication channels. Recently…

11 years ago
Millions Android Cyanogenmod users exposed to MitM attacks due to Code re-useMillions Android Cyanogenmod users exposed to MitM attacks due to Code re-use

Millions Android Cyanogenmod users exposed to MitM attacks due to Code re-use

Researcher explains that vulnerable code re-use of zero-day in Android's CyanogenMod exposes million users to Man-In-The-Middle attacks. Security experts always…

11 years ago
LinkedIn vulnerable to MITM attack that leverages an SSL stripping could expose users data at riskLinkedIn vulnerable to MITM attack that leverages an SSL stripping could expose users data at risk

LinkedIn vulnerable to MITM attack that leverages an SSL stripping could expose users data at risk

Security experts at Zimperium firm revealed that LinkedIn users could be potentially vulnerable to Man-in-the-Middle attacks leveraging an SSL stripping.…

11 years ago
Dyreza banking Trojan uses browser hooking to defeat SSLDyreza banking Trojan uses browser hooking to defeat SSL

Dyreza banking Trojan uses browser hooking to defeat SSL

Security experts at CSIS in Denmark have discovered a new piece of banking malware, dubbed Dyreza, which implements browser hooking…

11 years ago
New critical flaws discovered in OpenSSL, patch nowNew critical flaws discovered in OpenSSL, patch now

New critical flaws discovered in OpenSSL, patch now

The OpenSSL Foundation has fixed a series of new vulnerabilities, two of them considered critical. Organizations are invited to apply…

11 years ago