SANS warned to end users against Heartbleed

  In the fourth briefing on the bug from the SANS Institute’s Internet Storm Centre (ISC), the risk of Heartbleed client-side attacks and recommendations for end users is focused. “A lot of the effort initially has been on servers, and servers are certainly at the most risk — not just…

read more

NSA used Heartbleed for years

Bloomberg news reports that NSA had been using Heartbleed from many years, OpenSSL encryption software used by a majority of websites and a multitude of other pieces of Internet infrastructure. Atleast 2 sources told Bloomberg that NSA had been using HeartBleed 0day for almost 2 years. One source told Bloomberg:-…

read more

Heartbleed: Serious OpenSSL 0day Vulnerability Revealed

Everyday new security bugs are being discovered. And one of these newly identified bugs is the the so-called Heartbleed Bug in the OpenSSL cryptographic library. While Heartbleed only effects OpenSSL’s 1.0.1 and the 1.0.2-beta release, 1.01 is already broadly deployed. Since Secure-Socket Layer (SSL) and Transport Layer Security (TLS) are…

read more