Click to Pray, Click to Leak: The Pope’s Official App Exposes 700,000+ User Emails
|
submitted by /u/HumbleRestaurant790 [comments] |
|
submitted by /u/HumbleRestaurant790 [comments] |
OpenSSL Fixes HollowByte Memory Exhaustion Bug Pierluigi Paganini July 18, 2026 Okta disclosed HollowByte, an 11-byte OpenSSL flaw that lets remote attackers exhaust server memory and trigger denial-of-service attacks. Okta’s Red Team disclosed a denial-of-service vulnerability in OpenSSL they named HollowByte, and the attack payload is exactly 11 bytes. A remote, unauthenticated attacker sends that…
The US government is seeking to tackle a growing vulnerability management challenge with the launch of Gold Eagle, a program intended to drive faster exploit detection and remediation. Gold Eagle was trailed in Executive Order 14409 in June, and involves the collaboration of the Cybersecurity and Infrastructure Security Agency (CISA), the Treasury, and the Department…
T-Mobile / Elyse Betters Picaro / ZDNET An advertiser paid for editorial consideration of this deal. Our editorial experts vetted the deal using their independent expertise. Because we determined that the deal will save money for the consumer, we wrote the content. In 2026, a fast home internet connection is a must-have, but the monthly…
Here’s a question that keeps CISOs up at night: if OpenAI and Anthropic both promise not to train on your company’s data, why does sensitive corporate information keep ending up in AI models anyway? The answer, it turns out, has less to do with the AI companies and more to do with Karen from accounting…
Ravie LakshmananJul 22, 2026Vulnerability / Browser Security Cybersecurity researchers have disclosed details of a now-patched vulnerability chain in the Adobe Acrobat Chrome extension that has over 314 million users, which, if exploited, could facilitate a silent hijack of a user’s WhatsApp data. The shortcoming has been codenamed HermeticReader by Guardio Labs. It’s officially tracked as…
EFF and ARTICLE 19 have submitted joint comments to the European Commission on draft guidelines for the Digital Services Act’s trusted flagger mechanism. Having long advocated for a DSA that protects freedom of expression while preserving intermediary liability protections and the prohibition on general monitoring, we welcome the Commission’s effort to provide practical guidance on…