Heartbleed still hurting hard. UK council fined £100,000 after data breach

Heartbleed still hurting hard. UK council fined £100,000 after data breach

A UK city council has been hit by a £100,000 fine after it suffered an embarrassing data breach as a result of not patching against the infamous Heartbleed vulnerability in a timely fashion.

Read more in my article on the Hot for Security blog.

Continue reading Heartbleed still hurting hard. UK council fined £100,000 after data breach

Torvalds Downplays SHA-1 Threat to Git

The ramifications of the recent SHA-1 collision attack have extended to Git and the Apache Subversion repository, both of which rely on the outdated and vulnerable hashing algorithm. Continue reading Torvalds Downplays SHA-1 Threat to Git

Change.org sends password reset email after CloudBleed bug

By Waqas

Change.org, a famous online petition website is sending emails to its registered petitioners encouraging them to change their account password on the website. The email came days after Google employee, Tavis Ormandy of Project Zero exposed Cloudbleed bug that seems to have leaked sensitive and personal information passing through websites using CloudFlare’s service. The email […]

This is a post from HackRead.com Read the original post: Change.org sends password reset email after CloudBleed bug

Continue reading Change.org sends password reset email after CloudBleed bug

The Internet’s Freshest Wounds: My Thoughts On Ticketbleed, Cloudbleed and HTTPS

In April 2014, the security community was shocked with the revelation that a poorly implemented TLS extension in OpenSSL could allow attackers to easily disclose private memory contents from an astonishing number of HTTPS sites. This bug, of course, is CVE-2014-0160 but it is better known by its brand name “Heartbleed.” This bug was cleverly […]… Read More

The post The Internet’s Freshest Wounds: My Thoughts On Ticketbleed, Cloudbleed and HTTPS appeared first on The State of Security.

Continue reading The Internet’s Freshest Wounds: My Thoughts On Ticketbleed, Cloudbleed and HTTPS

OpenSSL Update Fixes High-Severity DoS Vulnerability

US-CERT issues alert to server admins warning of a dangerous OpenSSL vulnerability and urges 1.1.0 users update to version 1.1.0e. Continue reading OpenSSL Update Fixes High-Severity DoS Vulnerability

OpenSSL Update Fixes High-Severity DoS Vulnerability

US-CERT issues alert to server admins warning of a dangerous OpenSSL vulnerability and urges 1.1.0 users update to version 1.1.0e. Continue reading OpenSSL Update Fixes High-Severity DoS Vulnerability