Vulnerability Management18 July 2026
OpenSSL's HollowByte DoS Flaw Shipped With No CVE — Here's Why That Matters
An 11-byte TLS handshake header can lock up hundreds of megabytes of server memory before authentication even starts. OpenSSL fixed it in June 2026 without a CVE, an advisory, or a changelog entry.
openssldenial-of-servicevulnerability-management
4 min readRead
Cryptography & PKI30 June 2026
Short-Sleeve RSA: How Zero-Block Prime Structure Exposed 603 Private Keys in the Wild
Trail of Bits and the badkeys project have uncovered a new class of factorable RSA key — one defined by evenly spaced zero-bit blocks in its prime factors — and found hundreds already deployed in real TLS, SSH, and PGP infrastructure.
rsacryptographypki
4 min readRead