Security News

CAs Reissue Over One Million Weak Certificates
2019-03-18 11:23

Turns out that the software a bunch of CAs used to generate public-key certificates was flawed: they created random serial numbers with only 63 bits instead of the required 64. That may not seem...

Study Finds Rampant Sale of SSL/TLS Certificates on Dark Web
2019-03-07 16:59

SSL and TLS certificates and related services can be easily acquired from dark web marketplaces, according to an academic study sponsored by Venafi, a company specializing in the protection of...

Sale of SSL/TLS certificates on the dark web is rampant
2019-03-06 09:43

There is no dearth of compromised, fake and forged SSL/TLS certificates for sale on dark web markets, researchers have found. TLS certificates are sold individually and packaged with a wide range...

How to regenerate certificates on VMware host servers
2019-02-21 16:13

Regenerating certificates may securely resolve authentication traffic, which is not being properly encrypted.

74% of organizations face outages due to expired certificates
2019-02-19 06:00

As information security budgets grow and funds are allocated to protect the defensive perimeter, many companies have overlooked the critical importance of digital certificate management. And a new...

Google also abused its Apple developer certificate to collect iOS user data
2019-01-31 11:38

It turns out that Google, like Facebook, abused its Apple Enterprise Developer Certificate to distribute a data collection app to iOS users, in direct contravention of Apple’s rules for the...

Shutdown hits government websites as certificates begin to expire
2019-01-14 14:32

The US government shutdown is affecting more than just physical sites like national parks and monuments.

TLS Certificates for Many .gov Domains Not Renewed Due to Government Shutdown
2019-01-10 17:02

Many TLS certificates for .gov domains have not been renewed due to the ongoing shutdown of the United States government, making them insecure or inaccessible. read more

Serious Security: When cryptographic certificates attack
2018-12-19 14:29

Machine learning is all the rage - but don't knock human savvy just yet! One weird character can be enough to alert a smart researcher...

Oh my chord! Sennheiser hits bum note with major HTTPS certificate cock-up
2018-11-29 01:11

Audiophiles could get played like a fiddle, have their web traffic snooped by son-of-a-pitch scammers Headphone maker Sennheiser is facing the music after being caught compromising the security of...