Critical zero-day bug, first since Heartbleed, identified in OpenSSL

John Leonard
clock • 2 min read
Critical zero-day bug, first since Heartbleed, identified in OpenSSL
Image:

Critical zero-day bug, first since Heartbleed, identified in OpenSSL

New version to be released 1st November. Organisations should act now to track down OpenSSL 3.0.x in their infrastructure, warns Sonatype

The team maintaining OpenSSL, the cryptographic library that secures almost all traffic on the Internet, have revealed the presence of a critical zero-day vulnerability in later versions of the sof...

To continue reading this article...

Join Computing

  • Unlimited access to real-time news, analysis and opinion from the technology industry
  • Receive important and breaking news in our daily newsletter
  • Be the first to hear about our events and awards programmes
  • Join live member only interviews with IT leaders at the ‘IT Lounge’; your chance to ask your burning tech questions and have them answered
  • Access to the Computing Delta hub providing market intelligence and research
  • Receive our members-only newsletter with exclusive opinion pieces from senior IT Leaders

Join now

 

Already a Computing member?

Login

You may also like
Apple addresses two new zero-day flaws in iOS

Threats and Risks

Emergency security update available for newest versions

clock 06 March 2024 • 1 min read
Microsoft announces critical zero-day Exchange bug

Security

Enables remote control of Exchange Server

clock 16 February 2024 • 1 min read
Oracle's controversial stewardship of Java: The good and the bad

Open Source

Oracle is doing a good job in keeping Java relevant. But that's pretty much where it ends, says Azul CTO

clock 15 February 2024 • 5 min read

More on Threats and Risks

Hackers launch brute-force attacks on business VPNs and more

Hackers launch brute-force attacks on business VPNs and more

The attacks rely on trial-and-error attempts to crack login credentials

clock 18 April 2024 • 2 min read
Palo Alto Networks patches 'critical' vulnerability under active exploitation

Palo Alto Networks patches 'critical' vulnerability under active exploitation

Volexity says a ‘spike in exploitation’ is likely

Kyle Alspach
clock 16 April 2024 • 2 min read
CISA issues emergency order on Microsoft breach by Russian hackers

CISA issues emergency order on Microsoft breach by Russian hackers

Affected bodies must take immediate action, agency says

Kyle Alspach
clock 12 April 2024 • 2 min read