A Stalled DTLS Handshake Could Make OpenSSL Send Heap Memory in Plaintext

OpenSSL fixed a high-severity DTLS flaw that can expose heap memory in plaintext. The condition is narrow, but every branch analysed in the advisory is affected.
Vulnerabilities, defensive security, architecture and operational security.

OpenSSL fixed a high-severity DTLS flaw that can expose heap memory in plaintext. The condition is narrow, but every branch analysed in the advisory is affected.

Microsoft found NeedyMantis hiding beside legitimate software in targeted intrusions. The real hunt starts before the backdoor appears.

Branch Target Reuse recovered a Linux root hash on Intel test systems, exposing a local JIT weakness that Linux updates now target.

An attacker-built Custom GPT used a real ChatGPT page to lead people to a fake check on Google Sites. The practical boundary is the instruction to run code outside the browser.

An intruder's automated decisions left DIVD investigators useful clues. That does not establish how much damage was done.

A public summary can still carry private records. DC's Medicaid agency says two website reports contained hidden beneficiary information potentially reachable between 2023 and July 2026.

Times Car says an intruder acquired data linked to about 6.6 million accounts. Identity-document information, including driving licence images, is in the variable field list. The number of images and any later misuse remain unconfirmed.

Adobe's August bulletin said it knew of no exploitation. CISA has now placed the unauthenticated privilege-escalation flaw in KEV and called for forensic triage.

Apple says a maliciously crafted file could trigger arbitrary code execution and may have been used against specific targeted individuals. The fixes reach iPhone, iPad and two supported macOS branches.

Half of the hunters in a new SANS survey say data is their biggest obstacle. A clean search result means little until the team has proved the evidence path works.