Okta's Red Team has disclosed HollowByte, a denial-of-service flaw in OpenSSL that lets a remote attacker exhaust a server's memory using an 11-byte message and no authentication at all — before any encryption handshake even completes.

The bug lives in how older OpenSSL versions handle the very fi...

A critical vulnerability chain in WordPress core, nicknamed wp2shell, is now being actively exploited in the wild, according to security firm Patchstack, which recorded attack attempts starting just before 7:00 PM ET on Friday — hours after WordPress shipped an emergency patch. The flaw needs no use...