News und Hintergrund-Geschichten von heise Security - dem Sicherheitsportal von heise online. Offizieller Account 🤖 Die meisten Posts sind automatisiert https://www.heise.de/security/impressum.html
heise Security
@heisec@social.heise.de
social.heise.de
„HollowByte“: Denial-of-Service-Lücke in OpenSSL
Die OpenSSL-Maintainer haben stillschweigend eine Denial-of-Service-Lücke geschlossen. Okta nennt sie „HollowByte“.
https://www.heise.de/news/HollowByte-Denial-of-Service-Luecke-in-OpenSSL-11370866.html?wt_mc=sm.red.ho.mastodon.mastodon.md_beitraege.md_beitraege&utm_source=mastodon
#DoSSchwachstelle #IT #OpenSSL #Security #Sicherheitslücken #Updates #news
OpenSSL HollowByte: A DoS Hiding in 11 Bytes
https://sec.okta.com/articles/2026/06/openssl-hollowbtye-a-dos-hiding-in-11-bytes/
#Security #OpenSSL #Vulnerability
securityaffairs
@securityaffairs@infosec.exchange
Pierluigi Paganini is a member of the ENISA (European Union Agency for Network and Information Security) Ad-Hoc Working Group on Cyber Threat Landscapes and Cyber G7 Group, he is also a Security Evangelist, Security Analyst and Freelance Writer. Pierluigi is a cyber security expert with over 25 years of experience in the field.
infosec.exchange
Daily CyberSecurity
@DailyCyberSecurity@infosec.exchange
Stay ahead with Daily CyberSecurity. We deliver rapid zero-hour alerts and expert analysis on critical vulnerabilities, CVEs, and emerging cyber threats.
infosec.exchange
A widespread OpenSSL error handling flaw makes apt fail HTTPS in FIPS mode. A stale error queue entry gets misread as fatal. Audit your code.
#OpenSSL #ErrorHandling #FIPS #apt #Debian #TLS #CyberSecurity #InfoSec
https://securityonline.info/openssl-error-handling-apt-fips/?utm_source=mastodon&utm_medium=jetpack_social
The pandemic of incomplete OpenSSL error handling
https://blog.jak-linux.org/2026/07/03/openssl-pandemic/
#OpenSSL #Security #Programming
Harry Sintonen
@harrysintonen@infosec.exchange
Infosec consultant at REVƎЯSEC https://reversec.com - Coding, Research + various other interests
infosec.exchange
Significant number of vulnerabilities fixed in #OpenSSL - https://openssl-library.org/news/secadv/20260609.txt
The most serious one is CVE-2026-45447: Use-After-Free in the PKCS7_verify() Function that could lead to remote code execution in some conditions.
#CVE_2026_45447
You've seen all posts