From Heartbleed to Now: Evolving Threats in OpenSSL and How to Guard Against Them

In 2014, the cybersecurity community witnessed a critical OpenSSL vulnerability, “Heartbleed,” which changed how the world perceived digital security. It is considered to be among the most serious flaws in internet history ...

Multiple OpenSSL Vulnerabilities Fixed

In 2023, a total of 17 vulnerabilities have been addressed in OpenSSL, a popular cryptography library. They pose a significant risk due to their potential to cause substantial availability disruptions. It consists ...

Guarding Against a glibc Vulnerability: A Security Guide

The GNU C Library, also called glibc, is a fundamental component of the Linux-based operating systems. It offers essential functions that programs need to work properly on your system. The glibc library ...
The story of the OpenSSL patch 3.0.7 and the lessons you can learn from it

The story of the OpenSSL patch 3.0.7 and the lessons you can learn from it

| | Cybersecurity, openssl, SBOM
OpenSSL is a widely-used open-source software library for implementing secure communications over computer networks. How widely used? Well, chances are that if you’ve ever accessed an HTTPS web page you did so ...
An OpenSSL example screenshot that shows the version of the command line utility tool

OpenSSL Issues Update to Fix Formerly ‘Critical’ Vulnerability Nov. 1

This high-severity vulnerability affects the OpenSSL version 3.0 series. If you’re using an earlier version of OpenSSL (i.e., anything 3.X.X) on your server or platform, then this CVE doesn’t affect... The post ...

CVE ALERT! OpenSSL CVE-2022-3786 and CVE-2022-3602: X.509 Email Address Buffer Overflows

After a week of speculation about OpenSSL vulnerabilities, the OpenSSL project disclosed two new CVEs to address buffer overrun vulnerabilities in its cryptographic library that could trigger crashes or lead to remote ...
Clearing the Fog Over the New OpenSSL Vulnerabilities

Clearing the Fog Over the New OpenSSL Vulnerabilities

By Yotam Perkal and Ofri Ouzan, Rezilion Security Research There has been a lot of tension building up since the announcement made by the OpenSSL project team last week (October 25th) regarding ...
ransomware landscape, defenders, cybersecurity ransomware

OpenSSL Deems Vulnerability ‘Critical’, Will Publish Patch Tuesday

Does an OpenSSL vulnerability with a ‘critical’ CVE rating rival Heartbleed? That’s what some security experts are saying as they await a fix expected on Tuesday. The OpenSSL project team confirmed that ...
Security Boulevard
Detecting GnuTLS CVE-2020-13777 using Zeek

Detecting GnuTLS CVE-2020-13777 using Zeek

By Johanna Amann, Software Engineer, Corelight CVE-2020-13777 is a high severity issue in GnuTLS. In a nutshell, GnuTLS versions between 3.6.4 (released 2018-09-24) and 3.6.14 (2020-06-03) have a serious bug in their ...