Friday, August 28, 2026
Follow on LinkedIn

SSL

Qihoo 360 Leaked Its Own Wildcard SSL Private Key Inside Public AI Installer

China's largest cybersecurity firm, Qihoo 360, has inadvertently exposed its own wildcard SSL private key by bundling it directly inside the public installer of its newly launched AI assistant, 360Qihoo (Security Claw). The flaw discovered on March 16, 2026, is...

Let’s Encrypt to Reduce Certificate Validity from 90 Days to 45 Days

Let’s Encrypt has officially announced plans to reduce the maximum validity period of its SSL/TLS certificates from 90 days to 45 days. The transition, which will be completed by 2028, aligns with broader industry shifts mandated by the CA/Browser Forum...

Mis-issued TLS Certificates for 1.1.1.1 DNS Service Enable Attackers to Decrypt Traffic

The discovery of three improperly issued TLS certificates for 1.1.1.1, the popular public DNS service from Cloudflare, and the Asia Pacific Network Information Centre (APNIC). The certificates, which were issued in May 2025, could allow attackers to intercept and decrypt...

Cobalt Strike 4.11.1 Released With Fix For ‘Enable SSL’ Checkbox

Fortra has released Cobalt Strike 4.11.1, an out-of-band update addressing critical issues discovered in their recent 4.11 release.  This update, released on May 12, 2025, focuses primarily on resolving module stomping complications while also addressing issues with SSL certificate functionality...

SSL/TLS Certificates Validity To Be Reduced From 398 Days to 47 Days

CA/Browser Forum has approved a proposal to reduce the maximum validity of SSL/TLS certificates from the current 398 days to just 47 days by 2029. The measure, initially proposed by Apple and endorsed by Sectigo, will be implemented in phases...

OpenVPN Easy-RSA Vulnerability Enables Bruteforce of Private CA Key

A critical vulnerability (CVE-2024-13454) has been identified in Easy-RSA versions 3.0.5 through 3.1.7 when used with OpenSSL 3.  This flaw allows private Certificate Authority (CA) keys to be encrypted using the outdated and weak cipher DES-EDE3-CBC (commonly referred to as...

DigiCert to Revoke Thousands of Certificates Following DNS Validation Error

DigiCert, a major certificate authority, to revoke thousands of SSL/TLS certificates because of a Domain Control Verification error. This could affect a lot of websites. The company discovered that an oversight in the DNS-based verification process affected approximately 0.4% of...

Understanding The Different Types Of SSL Certificates

As of January 2024, over 302 million SSL certificates had been issued online. Secure Sockets Layer (SSL) is a security protocol which authenticates and encrypts information passed between web servers and browsers. An SSL certificate provides added protection to...

SSL Certificate Management 101

Certificate management is crucial for ensuring the security, integrity, and authenticity of your organization's digital communications and transactions. As your teams use more apps and connected tools, the need for effective SSL certificate management becomes even more critical.  What is...

Maltego’s New SSL Certificate Spotter to Detect Suspicious Certificate

As the world becomes more reliant on technology, the importance of cybersecurity cannot be overstated. Being proactive in identifying and mitigating potential threats is crucial to protecting sensitive information and preventing devastating cyber attacks. In this constantly evolving field,...

Latest News

Latest News