A silently patched flaw nicknamed HollowByte shows how a TLS handshake can turn into a resource-drain attack when parser allocations are not reclaimed cleanly.
A reported OpenSSL flaw tied to a 11-byte trigger shows how pre-authentication bugs in shared cryptographic libraries can become operational outages, even when no data theft is involved.
A newly described OpenSSL weakness turns the earliest TLS exchange into a potential denial-of-service choke point, where unauthenticated traffic may be enough to force dangerous memory allocation.