⤷ Title: CVE-2024-12797 – High-Severity OpenSSL Flaw: Update Now to Prevent MITM Attacks
════════════════════════
𐀪 Author: do son
════════════════════════
ⴵ Time: Tue, 11 Feb 2025 23:24:10 +0000
════════════════════════
⌗ Tags: #Vulnerability #CVE_2024_12797 #openssl
════════════════════════
𐀪 Author: do son
════════════════════════
ⴵ Time: Tue, 11 Feb 2025 23:24:10 +0000
════════════════════════
⌗ Tags: #Vulnerability #CVE_2024_12797 #openssl
Cybersecurity News
CVE-2024-12797 - High-Severity OpenSSL Flaw: Update Now to Prevent MITM Attacks
Discover the high-severity vulnerability in OpenSSL (CVE-2024-12797) that could allow man-in-the-middle attacks. Learn about the potential consequences and ways to mitigate the risk.
⤷ Title: From Sudo OpenSSL to Root: Privilege Escalation with Dynamic Engine Abuse
════════════════════════
𐀪 Author: Evyeveline
════════════════════════
ⴵ Time: Tue, 25 Mar 2025 01:31:01 GMT
════════════════════════
⌗ Tags: #privilege_escalation #ethical_hacking #ethical_hacking_tips #openssl #penetration_testing
════════════════════════
𐀪 Author: Evyeveline
════════════════════════
ⴵ Time: Tue, 25 Mar 2025 01:31:01 GMT
════════════════════════
⌗ Tags: #privilege_escalation #ethical_hacking #ethical_hacking_tips #openssl #penetration_testing
Medium
From Sudo OpenSSL to Root: Privilege Escalation with Dynamic Engine Abuse
Today I got stuck on an exploit with openssl, I landed on a Linux target and run the usual sudo -l. I found out I could run openssl without…
⤷ Title: Configuring Static IP and Network Connectivity Between Windows and Linux VMs
════════════════════════
𐀪 Author: Adrian Gonzalez
════════════════════════
ⴵ Time: Tue, 06 May 2025 03:41:21 GMT
════════════════════════
⌗ Tags: #iptables #virtual_networking #servers #cybersecurity #openssl
════════════════════════
𐀪 Author: Adrian Gonzalez
════════════════════════
ⴵ Time: Tue, 06 May 2025 03:41:21 GMT
════════════════════════
⌗ Tags: #iptables #virtual_networking #servers #cybersecurity #openssl
Medium
🔐 Configuring Static IP and Network Connectivity Between Windows and Linux VMs
I spent most of the evening troubleshooting network connectivity issues between my Windows Server 2019 VM and an Ubuntu Linux Server for…
⤷ Title: Critical Vulnerability (CVSS 9.3): Icinga 2 Flaw Risks Certificate Impersonation
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 30 May 2025 00:16:09 +0000
════════════════════════
⌗ Tags: #Vulnerability #certificate impersonation #CVSS #Icinga 2 #monitoring system #openssl #security
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 30 May 2025 00:16:09 +0000
════════════════════════
⌗ Tags: #Vulnerability #certificate impersonation #CVSS #Icinga 2 #monitoring system #openssl #security
Daily CyberSecurity
Critical Vulnerability (CVSS 9.3): Icinga 2 Flaw Risks Certificate Impersonation
A critical Icinga 2 vulnerability (CVSS 9.3) allows malicious certificate impersonation, affecting builds with older OpenSSL. Update now!
⤷ Title: High-severity flaw (CVE-2025-8069) in AWS Client VPN for Windows Allows Privilege Escalation
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 24 Jul 2025 04:09:27 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #AWS Client VPN #CVE_2025_8069 #cybersecurity #local exploit #openssl #privilege escalation #Vulnerability #windows
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 24 Jul 2025 04:09:27 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #AWS Client VPN #CVE_2025_8069 #cybersecurity #local exploit #openssl #privilege escalation #Vulnerability #windows
Daily CyberSecurity
High-severity flaw (CVE-2025-8069) in AWS Client VPN for Windows Allows Privilege Escalation
A high-severity flaw (CVE-2025-8069) in AWS Client VPN for Windows allows local users to escalate privileges due to an OpenSSL config file path vulnerability.
⤷ Title: OpenSSL Patches Three Flaws: Timing Side-Channel RCE Risk and Memory Corruption Affect All Versions
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 01 Oct 2025 02:02:46 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #cryptography #CVE_2025_9230 #Denial of Service #openssl #rce #security advisory #Timing Attack
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 01 Oct 2025 02:02:46 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #cryptography #CVE_2025_9230 #Denial of Service #openssl #rce #security advisory #Timing Attack
Daily CyberSecurity
OpenSSL Patches Three Flaws: Timing Side-Channel RCE Risk and Memory Corruption Affect All Versions
OpenSSL patches three flaws, including CVE-2025-9230 (RCE/DoS risk) and a SM2 timing side-channel (CVE-2025-9231) that could allow private key recovery on ARM64.
⤷ Title: OpenSSL 3.6 Released: Major Cryptography Update Adds LMS Signatures and NIST PKEY Support
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 06 Oct 2025 01:47:52 +0000
════════════════════════
⌗ Tags: #Technology #cryptography #ECDSA #FIPS #LMS Signatures #openssl #OpenSSL 3.6 #security #software update
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 06 Oct 2025 01:47:52 +0000
════════════════════════
⌗ Tags: #Technology #cryptography #ECDSA #FIPS #LMS Signatures #openssl #OpenSSL 3.6 #security #software update
Penetration Testing Tools
OpenSSL 3.6 Released: Major Cryptography Update Adds LMS Signatures and NIST PKEY Support
OpenSSL 3.6 has been released, adding support for NIST security categories for PKEY objects, LMS signatures in FIPS, and deprecating ANSI-C compiler support.
⤷ Title: CVE-2025-27237: Zabbix Agent Flaw Allows Local Privilege Escalation via OpenSSL DLL Injection
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 06 Oct 2025 00:30:36 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2025_27237 #DLL injection #openssl #privilege escalation #Windows Security #Zabbix #Zabbix Agent
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 06 Oct 2025 00:30:36 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2025_27237 #DLL injection #openssl #privilege escalation #Windows Security #Zabbix #Zabbix Agent
Daily CyberSecurity
CVE-2025-27237: Zabbix Agent Flaw Allows Local Privilege Escalation via OpenSSL DLL Injection
⤷ Title: Memory Under Siege: OpenSSL Releases Urgent Patches for Critical Buffer Overflows
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Thu, 29 Jan 2026 04:12:17 +0000
════════════════════════
⌗ Tags: #Vulnerability #AES_GCM #Buffer Overflow #cryptography #CVE_2025_15467 #InfoSec 2026 #openssl #PKCS#12 #Security Patch #Sysadmin #TLS 1.3
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Thu, 29 Jan 2026 04:12:17 +0000
════════════════════════
⌗ Tags: #Vulnerability #AES_GCM #Buffer Overflow #cryptography #CVE_2025_15467 #InfoSec 2026 #openssl #PKCS#12 #Security Patch #Sysadmin #TLS 1.3
Penetration Testing Tools
Memory Under Siege: OpenSSL Releases Urgent Patches for Critical Buffer Overflows
The OpenSSL team has disseminated a comprehensive security advisory detailing a constellation of vulnerabilities afflicting the ubiquitous cryptographic
⤷ Title: Sabotaged Strings: The “Malicious” Vandalism Behind Tor Browser’s Emergency 15.0.5 Patch
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Wed, 04 Feb 2026 03:14:58 +0000
════════════════════════
⌗ Tags: #Technology #Android Security #localization attack #NoScript #OpenSSL 3.5.5 #software vandalism #Supply Chain Security #Tech News #Tor Browser 15.0.5 #Tor Project #Vietnamese translation
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Wed, 04 Feb 2026 03:14:58 +0000
════════════════════════
⌗ Tags: #Technology #Android Security #localization attack #NoScript #OpenSSL 3.5.5 #software vandalism #Supply Chain Security #Tech News #Tor Browser 15.0.5 #Tor Project #Vietnamese translation
Penetration Testing Tools
Sabotaged Strings: The "Malicious" Vandalism Behind Tor Browser’s Emergency 15.0.5 Patch
The architects of Tor Browser have inaugurated a nascent iteration, Tor Browser 15.0.5. This unscheduled refinement was catalyzed
⤷ Title: I Encrypted a File on Linux — Here’s What I Learned About Real Security
════════════════════════
𐀪 Author: Natasha Iyowe
════════════════════════
ⴵ Time: Sat, 07 Feb 2026 22:02:46 GMT
════════════════════════
⌗ Tags: #encryption #ethical_hacking #linux #cybersecurity #openssl
════════════════════════
𐀪 Author: Natasha Iyowe
════════════════════════
ⴵ Time: Sat, 07 Feb 2026 22:02:46 GMT
════════════════════════
⌗ Tags: #encryption #ethical_hacking #linux #cybersecurity #openssl
Medium
I Encrypted a File on Linux — Here’s What I Learned About Real Security
When most people hear “encryption”, they imagine something unbreakable. Something hackers can’t touch.
❤1
⤷ Title: Implementando uma PKI com HSM Simulado no Kali Linux
════════════════════════
𐀪 Author: Herique Tavares
════════════════════════
ⴵ Time: Sat, 14 Mar 2026 06:22:45 GMT
════════════════════════
⌗ Tags: #openssl #infosec #cybersecurity #kali_linux #pki
════════════════════════
𐀪 Author: Herique Tavares
════════════════════════
ⴵ Time: Sat, 14 Mar 2026 06:22:45 GMT
════════════════════════
⌗ Tags: #openssl #infosec #cybersecurity #kali_linux #pki
Medium
Implementando uma PKI com HSM Simulado no Kali Linux
Infraestrutura de Chaves Públicas (PKI) é um dos pilares da segurança em redes corporativas. Neste projeto de laboratório, implementei uma…
⤷ Title: OpenSSL Issues Major Security Advisory: RSA and Memory Vulnerabilities Fixed
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 08 Apr 2026 03:40:33 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #AES_CFB_128 #CVE_2026_31789 #CVE_2026_31790 #cybersecurity #infosec #Memory Leak #openssl #Patch Tuesday #RSA #security advisory #Vulnerability Research
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 08 Apr 2026 03:40:33 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #AES_CFB_128 #CVE_2026_31789 #CVE_2026_31790 #cybersecurity #infosec #Memory Leak #openssl #Patch Tuesday #RSA #security advisory #Vulnerability Research
Daily CyberSecurity
OpenSSL Issues Major Security Advisory: RSA and Memory Vulnerabilities Fixed
OpenSSL's April 2026 advisory reveals 7 flaws, including a moderate RSA memory leak (CVE-2026-31790). Learn if your version is affected and how to patch.
⤷ Title: Nginx 1.29.8 and FreeNginx Launch with Critical Security Shields
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Thu, 09 Apr 2026 08:33:14 +0000
════════════════════════
⌗ Tags: #Vulnerability #CVE_2026_27654 #CVE_2026_28753 #DNS PTR vulnerability #FreeNginx 1.29.7 #Mainline Branch #max_headers directive #nginx 1.29.8 #OpenSSL 4.0 #Server Security 2026 #WebDAV exploit
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Thu, 09 Apr 2026 08:33:14 +0000
════════════════════════
⌗ Tags: #Vulnerability #CVE_2026_27654 #CVE_2026_28753 #DNS PTR vulnerability #FreeNginx 1.29.7 #Mainline Branch #max_headers directive #nginx 1.29.8 #OpenSSL 4.0 #Server Security 2026 #WebDAV exploit
Penetration Testing Tools
Nginx 1.29.8 and FreeNginx Launch with Critical Security Shields
Within the nginx ecosystem, a dual release has emerged, impacting both the project’s primary development branch and its
⤷ Title: Beyond the Legacy: OpenSSL 4.0.0 Arrives with Encrypted Client Hello and Post-Quantum Prep
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Thu, 16 Apr 2026 10:19:10 +0000
════════════════════════
⌗ Tags: #Technology #API Migration #cryptography #Cyber Security #Encrypted Client Hello #Infosec #open source software #OpenSSL 4.0.0 #Post_Quantum Cryptography #SSLv3 #TLS 1.3
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Thu, 16 Apr 2026 10:19:10 +0000
════════════════════════
⌗ Tags: #Technology #API Migration #cryptography #Cyber Security #Encrypted Client Hello #Infosec #open source software #OpenSSL 4.0.0 #Post_Quantum Cryptography #SSLv3 #TLS 1.3
Penetration Testing Tools
Beyond the Legacy: OpenSSL 4.0.0 Arrives with Encrypted Client Hello and Post-Quantum Prep
The OpenSSL Project has inaugurated a seminal update that profoundly reshapes both its internal architecture and its repertoire
⤷ Title: Next-Gen Performance: NGINX 1.30.0 Stable Arrives with HTTP/2 Backend & Early Hints
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Thu, 16 Apr 2026 10:06:16 +0000
════════════════════════
⌗ Tags: #Technology #Encrypted ClientHello #HTTP Early Hints #HTTP/2 Upstream #load balancing #Multipath TCP #Networking #NGINX 1.30.0 #OpenSSL 4.0 #reverse proxy #Web Server
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Thu, 16 Apr 2026 10:06:16 +0000
════════════════════════
⌗ Tags: #Technology #Encrypted ClientHello #HTTP Early Hints #HTTP/2 Upstream #load balancing #Multipath TCP #Networking #NGINX 1.30.0 #OpenSSL 4.0 #reverse proxy #Web Server
Penetration Testing Tools
Next-Gen Performance: NGINX 1.30.0 Stable Arrives with HTTP/2 Backend & Early Hints
Nginx has inaugurated the stable 1.30.0 release, successfully concluding an extensive developmental cycle within the 1.29.x branch. This
⤷ Title: OpenSSL Security Patches Fix Remote Code Execution Risk
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Wed, 10 Jun 2026 02:21:00 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Cryptographic Library #CVE_2026_34182 #CVE_2026_45447 #openssl #QUIC Server #use after free #vulnerability management
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Wed, 10 Jun 2026 02:21:00 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Cryptographic Library #CVE_2026_34182 #CVE_2026_45447 #openssl #QUIC Server #use after free #vulnerability management
Daily CyberSecurity
OpenSSL Security Patches Fix Remote Code Execution Risk
New OpenSSL security patches address a critical use-after-free bug that introduces an immediate remote code execution risk across enterprise systems.
⤷ Title: OpenSSL Error Handling Defect Breaks apt HTTPS Access in FIPS Mode
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Mon, 06 Jul 2026 13:23:51 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #APT #Debian #ERR_clear_error #error queue #FIPS mode #openssl #OpenSSL error handling #Secure Coding #tls
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Mon, 06 Jul 2026 13:23:51 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #APT #Debian #ERR_clear_error #error queue #FIPS mode #openssl #OpenSSL error handling #Secure Coding #tls
Daily CyberSecurity
OpenSSL Error Handling Defect Breaks apt HTTPS Access in FIPS Mode
TL;DR A Debian maintainer flagged a widespread OpenSSL error handling problem across the open-source ecosystem. It surfaced when apt failed HTTPS repository access on FIPS-only systems, then trace…
⤷ Title: OpenSSL HollowByte Vulnerability Causes Memory Exhaustion
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Mon, 20 Jul 2026 00:00:38 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #dos attack #HollowByte #openssl
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Mon, 20 Jul 2026 00:00:38 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #dos attack #HollowByte #openssl
Daily CyberSecurity
OpenSSL HollowByte Vulnerability Causes Memory Exhaustion
TL;DR The Okta Red Team recently found a severe crash flaw in a core secure library. A remote attacker can freeze server memory by sending a tiny bad payload. The OpenSSL HollowByte vulnerability …
⤷ Title: OpenSSL HollowByte Memory Leak Vulnerability
════════════════════════
𐀪 Author: Nam Phong
════════════════════════
ⴵ Time: Mon, 20 Jul 2026 12:59:46 +0000
════════════════════════
⌗ Tags: #Vulnerability #Cyber Security #HollowByte #Memory Leak #openssl
════════════════════════
𐀪 Author: Nam Phong
════════════════════════
ⴵ Time: Mon, 20 Jul 2026 12:59:46 +0000
════════════════════════
⌗ Tags: #Vulnerability #Cyber Security #HollowByte #Memory Leak #openssl
Information Security News
OpenSSL HollowByte Memory Leak Vulnerability
Eleven bytes are enough to force a weak OpenSSL server to use up to 131 KB of RAM. After that, it waits for a message that never comes. Following a sudden drop, the code frees the buffer. Yet, Lin…