DROWN Attack
DROWN is a serious vulnerability that affects HTTPS and other services that rely on SSL and TLS, some of the essential cryptographic protocols for Internet security. These protocols allow everyone on the Internet to browse the web, use email, shop online, and send instant messages without third-parties being able to read the communication.
Continue Reading https://www.drownattack.comIs your server vulnerable?
Your server is affected if it's still allowing SSLv2 -- but since October 2014, you shouldn't even support SSLv3 anymore. In case your server is vulnerable, this allows an attacker who can sniff (legit) traffic to decrypt it.
Join the Discussion