⤷ Title: The “Invulnerable” Leak: How Qihoo 360 Accidently Shipped a Private SSL Master Key in its AI Installer
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Thu, 19 Mar 2026 09:26:32 +0000
════════════════════════
⌗ Tags: #Data Leak #360 Security Claw #AI Assistant #China Cybersecurity #Digital Certificate #Encryption Failure #Lukasz Olejnik #OpenClaw #Private Key Exposure #Qihoo 360 #SSL Leak
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Thu, 19 Mar 2026 09:26:32 +0000
════════════════════════
⌗ Tags: #Data Leak #360 Security Claw #AI Assistant #China Cybersecurity #Digital Certificate #Encryption Failure #Lukasz Olejnik #OpenClaw #Private Key Exposure #Qihoo 360 #SSL Leak
Penetration Testing Tools
The "Invulnerable" Leak: How Qihoo 360 Accidently Shipped a Private SSL Master Key in its AI Installer
The Chinese conglomerate Qihoo 360, a preeminent leviathan within the cybersecurity dominion, has become ensnared in a controversy
⤷ Title: Client security, runtime tampering, and why SPKI and TLS do not prove trusted execution
════════════════════════
𐀪 Author: Mark Solo
════════════════════════
ⴵ Time: Thu, 19 Mar 2026 20:36:57 GMT
════════════════════════
⌗ Tags: #application_security #information_security #mobile_app_architecture #ssl_pinning #cybersecurity
════════════════════════
𐀪 Author: Mark Solo
════════════════════════
ⴵ Time: Thu, 19 Mar 2026 20:36:57 GMT
════════════════════════
⌗ Tags: #application_security #information_security #mobile_app_architecture #ssl_pinning #cybersecurity
Medium
Client security, runtime tampering, and why SPKI and TLS do not prove trusted execution
SPKI pinning and TLS can prove that a mobile app reached the correct backend over a protected channel. They cannot prove that the client…
⤷ Title: SSL Sadece Bir Şifreleme mi, Yoksa Küresel Bir Güven Sözleşmesi mi?
════════════════════════
𐀪 Author: Mevlüt Kamalı
════════════════════════
ⴵ Time: Wed, 08 Apr 2026 09:28:20 GMT
════════════════════════
⌗ Tags: #ssl #computer_networking #cybersecurity #ethical_hacking #web_güvenliği
════════════════════════
𐀪 Author: Mevlüt Kamalı
════════════════════════
ⴵ Time: Wed, 08 Apr 2026 09:28:20 GMT
════════════════════════
⌗ Tags: #ssl #computer_networking #cybersecurity #ethical_hacking #web_güvenliği
Medium
SSL Sadece Bir Şifreleme mi, Yoksa Küresel Bir Güven Sözleşmesi mi?
Modern web güvenliğinin temel taşı olan SSL (Secure Sockets Layer), sadece tarayıcıdaki o küçük “kilit” simgesinden ibaret değildir…
⤷ Title: VPN Security Alert: Synology Patches Flaws in SSL VPN Client
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 14 Apr 2026 02:00:01 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2021_47960 #CVE_2021_47961 #Data Disclosure #infosec #Patch Alert #Remote Work Security #SSL VPN Client #Synology #Traffic Interception #VPN security
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 14 Apr 2026 02:00:01 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2021_47960 #CVE_2021_47961 #Data Disclosure #infosec #Patch Alert #Remote Work Security #SSL VPN Client #Synology #Traffic Interception #VPN security
Daily CyberSecurity
VPN Security Alert: Synology Patches Flaws in SSL VPN Client
Synology urges SSL VPN Client users to update to v1.4.5-0684. Fixes critical 8.1 CVSS flaw allowing PIN theft and traffic interception. Secure your data now!
⤷ Title: Patch Now: GnuTLS Release 3.8.13 Fixes 12 Vulnerabilities
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 04 May 2026 13:07:51 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #cryptography #CVE_2026_33846 #DTLS #GnuTLS #Heap Overwrite #infosec #Linux Security #OCSP Revocation #patch management #RSA_PSK #SSL/TLS
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 04 May 2026 13:07:51 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #cryptography #CVE_2026_33846 #DTLS #GnuTLS #Heap Overwrite #infosec #Linux Security #OCSP Revocation #patch management #RSA_PSK #SSL/TLS
Daily CyberSecurity
Patch Now: GnuTLS Release 3.8.13 Fixes 12 Vulnerabilities
GnuTLS v3.8.13 fixes critical heap overwrites, identity truncation, and OCSP bypasses. Secure your Linux comms and upgrade to the latest version now.
⤷ Title: Microsoft Defender Flaw Erased DigiCert Root Certificates and Paralyzed Windows Systems
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 05 May 2026 08:32:06 +0000
════════════════════════
⌗ Tags: #Malware #Browser Error #cyber security 2026 #DigiCert #EV Code Signing #false positive #Microsoft Defender #Root Certificate #SSL/TLS #Trojan:Win32/Cerdigicert.A!dha #Windows 10 #Windows 11 Security
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 05 May 2026 08:32:06 +0000
════════════════════════
⌗ Tags: #Malware #Browser Error #cyber security 2026 #DigiCert #EV Code Signing #false positive #Microsoft Defender #Root Certificate #SSL/TLS #Trojan:Win32/Cerdigicert.A!dha #Windows 10 #Windows 11 Security
Daily CyberSecurity
Microsoft Defender Flaw Erased DigiCert Root Certificates and Paralyzed Windows Systems
Microsoft Defender erroneously flagged DigiCert root certificates as "Cerdigicert" malware. Discover the fix and how to restore your system's trusted root store.
⤷ Title: Let’s Encrypt Slashes Certificate Lifespans and Sunsets mTLS on May 13
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Sat, 09 May 2026 02:31:06 +0000
════════════════════════
⌗ Tags: #Technology #45_Day Certificates #ACME #cybersecurity #DevSecOps #Generation Y Intermediates #Let's Encrypt #mTLS #ssl #SysAdmin #tls #Web Security
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Sat, 09 May 2026 02:31:06 +0000
════════════════════════
⌗ Tags: #Technology #45_Day Certificates #ACME #cybersecurity #DevSecOps #Generation Y Intermediates #Let's Encrypt #mTLS #ssl #SysAdmin #tls #Web Security
Daily CyberSecurity
Let’s Encrypt Slashes Certificate Lifespans and Sunsets mTLS on May 13
May 13 Deadline: Let’s Encrypt launches 45-day certs, freezes mTLS, and moves to Gen Y intermediates. Is your automation ready for the triple-threat update?
⤷ Title: Regulatory Alignment: Let’s Encrypt Amends Subscriber Agreement to Enforce US Sanctions and Export Compliance
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Wed, 10 Jun 2026 08:50:55 +0000
════════════════════════
⌗ Tags: #Technology #domain certificate rules #Let's Encrypt subscriber agreement #SSL sanctions compliance #U.S. export controls tool #Version 1.7 update #Web Hosting Security
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Wed, 10 Jun 2026 08:50:55 +0000
════════════════════════
⌗ Tags: #Technology #domain certificate rules #Let's Encrypt subscriber agreement #SSL sanctions compliance #U.S. export controls tool #Version 1.7 update #Web Hosting Security
Daily CyberSecurity
Regulatory Alignment: Let’s Encrypt Amends Subscriber Agreement to Enforce US Sanctions and Export Compliance
Discover the new Let's Encrypt subscriber agreement changes. Learn how Version 1.7 integrates U.S. sanctions compliance for global SSL domains.
⤷ Title: CISA KEV Additions: Arista VeloCloud and FortiOS Flaws Now Exploited
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Mon, 27 Jul 2026 21:52:47 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Arista #CISA KEV #CVE_2025_68686 #CVE_2026_16812 #Fortinet #FortiOS #Known Exploited Vulnerabilities #os command injection #SSL VPN #VeloCloud Orchestrator
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Mon, 27 Jul 2026 21:52:47 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Arista #CISA KEV #CVE_2025_68686 #CVE_2026_16812 #Fortinet #FortiOS #Known Exploited Vulnerabilities #os command injection #SSL VPN #VeloCloud Orchestrator
Daily CyberSecurity
CISA KEV Additions: Arista VeloCloud and FortiOS Flaws Now Exploited
TL;DR: On July 27, 2026, CISA made two KEV additions. Both are known exploited vulnerabilities. One is a critical Arista VeloCloud RCE, while the other is a FortiOS persistence bypass. Why These C…
⤷ Title: CVE-2026-42533: NGINX Heap Overflow Enables RCE and ASLR Bypass, Public PoC Released
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Tue, 28 Jul 2026 13:01:47 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #ASLR Bypass #CVE_2026_42533 #heap overflow #map directive #nginx #NGINX Plus #proof_of_concept #Remote Code Execution #ssl_preread #stream module
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Tue, 28 Jul 2026 13:01:47 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #ASLR Bypass #CVE_2026_42533 #heap overflow #map directive #nginx #NGINX Plus #proof_of_concept #Remote Code Execution #ssl_preread #stream module
Daily CyberSecurity
CVE-2026-42533: NGINX Heap Overflow Enables RCE and ASLR Bypass, Public PoC Released
TL;DR: A public proof-of-concept now targets CVE-2026-42533, an NGINX heap overflow rated CVSS 9.2. The bug lets an unauthenticated attacker corrupt worker memory through crafted requests. Researc…
⤷ Title: Certificate Pinning in Production (Android)
════════════════════════
𐀪 Author: Khizar Khan
════════════════════════
ⴵ Time: Mon, 10 Aug 2026 06:07:46 GMT
════════════════════════
⌗ Tags: #ssl #mobile_security #cybersecurity #application_security #android_development
════════════════════════
𐀪 Author: Khizar Khan
════════════════════════
ⴵ Time: Mon, 10 Aug 2026 06:07:46 GMT
════════════════════════
⌗ Tags: #ssl #mobile_security #cybersecurity #application_security #android_development
Medium
Certificate Pinning in Production (Android)
Part 3 of our Android security series. Part 2 covered Network Security Config — pinning builds directly on top of it.