OpenSSL walked back the severity of a pair of vulnerabilities that were revealed Tuesday around OpenSSL 3.0 and that garnered significant hype in cybersecurity circles. One researcher told SC Media that there are currently 16,000 publicly accessible servers worldwide that running potentially vulnerable versions of OpenSSL, while around 238,000 servers are still vulnerable to Heartbleed, which was disclosed eight years ago.
An authentication bypass flaw in security firm Fortinet's products, which was patched on 6 October, is being exploited in the wild, the company ha.