Digital Certificates With Shorter Lifespans Reduce Security Vulnerabilities

December 4, 2024 at 09:07AM Shortening TLS certificate life cycles to as low as 30 days improves website security by reducing exposure to vulnerabilities. Organizations should automate certificate updates to minimize errors and operational disruptions, particularly benefiting SMBs. Continuous monitoring via Certificate Lifecycle Management (CLM) can also uncover unnoticed digital certificates, enhancing overall risk management. … Read more

Russian Ransomware Gangs on the Hunt for Pen Testers

November 19, 2024 at 01:57PM Ransomware gangs like Apos, Lynx, and Rabbit Hole are recruiting pen testers to enhance their operations, reflecting the professionalization of Russian cybercrime. A Cato Networks report highlights the growing threat of ransomware, unauthorized AI, and underutilization of Transport Layer Security (TLS) in cybersecurity practices. ### Meeting Takeaways 1. **Ransomware Gangs … Read more

DigiCert Revoking Many Certificates Due to Verification Issue

July 31, 2024 at 06:36AM DigiCert is revoking TLS certificates due to a domain validation issue, affecting websites, applications, and services. The company needs to revoke certificates within 24 hours due to strict CA/Browser Forum rules. The issue was related to validating domain ownership using a DNS CNAME record. Roughly 0.4% of domain validations were … Read more

Critical SOCKS5 Vulnerability in cURL Puts Enterprise Systems at Risk

October 11, 2023 at 12:06PM Patches have been released for a critical memory corruption vulnerability in the cURL data transfer project. The flaw, tracked as CVE-2023-38545, affects the SOCKS5 proxy handshake process in cURL, allowing remote exploitation in certain configurations. The bug can lead to heap buffer overflow, and affected versions are 7.69.0 to 8.3.0. … Read more