OpenSSL 3.6.2: The Moderate Severity Wave

OpenSSL 3.6.2: The Moderate Severity Wave

OpenSSL 3.6.2 landed this week carrying eight CVE fixes, with the project rating the most severe issue as Moderate. On the surface, that sounds reassuring—no critical exploits, no ransomware-grade zero-days.…
CVE-2024-12797 OpenSSL Vulnerability Patched

CVE-2024-12797 OpenSSL Vulnerability Patched

CVE-2024-12797 is a critical security vulnerability discovered in OpenSSL, a widely used cryptographic library that provides secure communication over computer networks. This vulnerability poses significant risks to the integrity and…
Outdated OpenSSL Version used by major vendors

Outdated OpenSSL Version used by major vendors

Researchers has discovered devices from Dell, HP, and Lenovo using outdated versions of the OpenSSL cryptographic library. The OpenSSL software library allows secure communications over computer networks against eavesdropping or…
OPENSSL Infinite Loop Bug Addressed

OPENSSL Infinite Loop Bug Addressed

The OpenSSL Project has fixed a vulnerability in several versions of the software that could enable an attacker to cause a DoS condition on machines that are targetted. The bug…
New Code Signing Evades Detection

New Code Signing Evades Detection

Financially motivated threat actors have started using new code signing tricks to increase the chances of their software evading detection on Windows systems. The new technique has been used by…