A Stalled DTLS Handshake Could Make OpenSSL Send Heap Memory in Plaintext

OpenSSL fixed a high-severity DTLS flaw that can expose heap memory in plaintext. The condition is narrow, but every branch analysed in the advisory is affected.

OpenSSL fixed a high-severity DTLS flaw that can expose heap memory in plaintext. The condition is narrow, but every branch analysed in the advisory is affected.

Google disclosed three Application Integration flaws on 28 September. Its managed service was patched in June, and customers have no update to install. The questions now concern trust boundaries and what customer-side logs can show.

Microsoft found NeedyMantis hiding beside legitimate software in targeted intrusions. The real hunt starts before the backdoor appears.

Branch Target Reuse recovered a Linux root hash on Intel test systems, exposing a local JIT weakness that Linux updates now target.

The FCC's EAS cybersecurity rule reaches beyond alert encoders to studio transmitter links and remotely managed equipment in the programming path. Three targeted controls apply from 29 September.

An attacker-built Custom GPT used a real ChatGPT page to lead people to a fake check on Google Sites. The practical boundary is the instruction to run code outside the browser.

An intruder's automated decisions left DIVD investigators useful clues. That does not establish how much damage was done.

A fixed MCP Python SDK release is only part of the repair for unattended OAuth clients. Pin the issuer, rebind saved registrations and assess possible credential exposure.

A public summary can still carry private records. DC's Medicaid agency says two website reports contained hidden beneficiary information potentially reachable between 2023 and July 2026.

Cisco warns that specific Nexus 3000 and 9000 NX-OS upgrade and downgrade paths can corrupt switch configuration. Check the exact release pair before maintenance because a normal reload or rollback will not repair the damage.