Sunday 26 July 2026 16:04:07 GMT+02:00

Netcrook

HomeManifesto
News
Techcrook
Geocrook
WikicrookTeamAppContactLogin
EnglishItaliano

#HollowByte


OpenSSL's Quiet Fix Points to a Loud Risk: Handshake Memory Can Become a DoS Lever

Published: 20 July 2026 16:25Category: Vulnerabilities & Patch ManagementGeo: North America / USAAuthor: DEEPAUDIT

A silently patched flaw nicknamed HollowByte shows how a TLS handshake can turn into a resource-drain attack when parser allocations are not reclaimed cleanly.

HollowByte Turns a Tiny TLS Message Into a Big Availability Problem

Published: 18 July 2026 16:07Category: Vulnerabilities & Patch ManagementGeo: North America / USAAuthor: SECURESPECTER

A reported OpenSSL flaw tied to a 11-byte trigger shows how pre-authentication bugs in shared cryptographic libraries can become operational outages, even when no data theft is involved.

When the Handshake Becomes the Weapon: OpenSSL’s Pre-Auth Memory Trap

Published: 18 July 2026 08:03Category: Vulnerabilities & Patch ManagementAuthor: NEONPALADIN

A newly described OpenSSL weakness turns the earliest TLS exchange into a potential denial-of-service choke point, where unauthenticated traffic may be enough to force dangerous memory allocation.