<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>SSL - malgregator</title>
    <link>https://malgregator.com/tags/ssl/</link>
    <description>Recent content in SSL on malgregator</description>
    <generator>Hugo -- gohugo.io</generator>
    <language>en</language>
    <managingEditor>you@example.com</managingEditor>
    <webMaster>you@example.com</webMaster>
    <lastBuildDate>Thu, 30 Dec 2021 00:00:00 +0000</lastBuildDate>
    
        <atom:link href="https://malgregator.com/tags/ssl/index.xml" rel="self" type="application/rss+xml" />
    
    <item>
      <title>Automating Internal Certificate Issuance With ACME-based Certificate Authority</title>
      <link>https://malgregator.com/post/automating-internal-certificate-issuance-with-acme-based-certificate-authority/</link>
      <pubDate>Thu, 30 Dec 2021 00:00:00 +0000</pubDate>
      <author>you@example.com</author>
      <guid>https://malgregator.com/post/automating-internal-certificate-issuance-with-acme-based-certificate-authority/</guid>
      <description>Lessons learned from running Let&#39;s Encrypt Boulder certificate authority software in the company.</description>
    </item><item>
      <title>Vault Authentication with YubiKey</title>
      <link>https://malgregator.com/post/vault-authentication-with-yubikey/</link>
      <pubDate>Thu, 19 Mar 2020 00:00:00 +0000</pubDate>
      <author>you@example.com</author>
      <guid>https://malgregator.com/post/vault-authentication-with-yubikey/</guid>
      <description>Leverage PKCS#11 support in curl to authenticate with the Vault&#39;s TLS Certificates Auth Method</description>
    </item><item>
      <title>InfoSec Week 3, 2019</title>
      <link>https://malgregator.com/post/week-3-2019/</link>
      <pubDate>Fri, 18 Jan 2019 08:30:00 +0000</pubDate>
      <author>you@example.com</author>
      <guid>https://malgregator.com/post/week-3-2019/</guid>
      <description>35-year-old vulnerability has been discovered in the SCP file transfer utility. According to the advisory impact section, &#39;Malicious scp server can write arbitrary files to scp target directory, change the target directory permissions and to spoof the client output.&#39;</description>
    </item><item>
      <title>InfoSec Week 48, 2018</title>
      <link>https://malgregator.com/post/week-48-2018/</link>
      <pubDate>Fri, 30 Nov 2018 08:07:00 +0000</pubDate>
      <author>you@example.com</author>
      <guid>https://malgregator.com/post/week-48-2018/</guid>
      <description>Sennheiser&#39;s HeadSetup software is installing a root certificate into the OS Trusted CA Certificate store.   They have also put a private key on a device, the same one for all users, which allows any user to perform a man-in-the-middle SSL attacks against SSL communication.</description>
    </item><item>
      <title>InfoSec Week 32, 2018</title>
      <link>https://malgregator.com/post/week-32-2018/</link>
      <pubDate>Fri, 10 Aug 2018 07:31:00 +0000</pubDate>
      <author>you@example.com</author>
      <guid>https://malgregator.com/post/week-32-2018/</guid>
      <description>A Comcast security flaws exposed more than 26 millions of customers’ personal information. Basically, an attacker could spoof IP address using &#39;X-forwarded-for&#39; header on a Comcast login page and reveal the customer’s location.</description>
    </item><item>
      <title>InfoSec Week 27, 2018</title>
      <link>https://malgregator.com/post/week-27-2018/</link>
      <pubDate>Thu, 05 Jul 2018 11:28:00 +0000</pubDate>
      <author>you@example.com</author>
      <guid>https://malgregator.com/post/week-27-2018/</guid>
      <description>Samsung Galaxy S9 and S9+ devices, maybe others, are texting camera photos to random contacts through the Samsung Messages app without user permission.</description>
    </item><item>
      <title>InfoSec Week 24, 2018</title>
      <link>https://malgregator.com/post/week-24-2018/</link>
      <pubDate>Fri, 15 Jun 2018 11:34:00 +0000</pubDate>
      <author>you@example.com</author>
      <guid>https://malgregator.com/post/week-24-2018/</guid>
      <description>Yet another high severity attack against the Intel CPUs. Unpatched systems can leak SIMD, FP register state between privilege levels. These registers are used for private keys nowadays.   The cost of a patch is more expensive context switches because the fix has to unload and reload all SIMD, FP state.</description>
    </item><item>
      <title>InfoSec Week 9, 2018</title>
      <link>https://malgregator.com/post/week-09-2018/</link>
      <pubDate>Fri, 02 Mar 2018 18:13:00 +0000</pubDate>
      <author>you@example.com</author>
      <guid>https://malgregator.com/post/week-09-2018/</guid>
      <description>Wandera security researchers spotted a new sophisticated Android RedDrop malware hidden in at least 53 Android applications. It can intercept SMS, record audio and exfiltrate data to the remote server.</description>
    </item><item>
      <title>InfoSec Week 49, 2017</title>
      <link>https://malgregator.com/post/week-49-2017/</link>
      <pubDate>Thu, 14 Dec 2017 07:30:00 +0000</pubDate>
      <author>you@example.com</author>
      <guid>https://malgregator.com/post/week-49-2017/</guid>
      <description>The &#39;Janus&#39; Android vulnerability (CVE-2017-13156) allows attackers to modify the code in applications without affecting their signatures. The root of the problem is that a file can be a valid APK file and a valid DEX file at the same time. The vulnerability allows attackers to inject malware into legitimate application and avoiding detection.</description>
    </item>
  </channel>
</rss>