Update Tuesday, April 2015 – Urgent action needed over Microsoft HTTP bug

We don’t usually focus on one vulnerability and say, “Do that first.” But this month, we’re willing to make an exception. The Microsoft HTTP stack has a bug that could let attackers straight in with a simple HTTP request…

TLS certificate blunder revisited – whither China Internet Network Information Center?

Just under three weeks ago, we wrote about a TLS certificate blunder by a Root Certificate Authority called CNNIC. We thought we’d revisit that story today to see how the Big Four browser makers responded to the lapse…

We TOLD you not to use WPS on your Wi-Fi router! We TOLD you not to knit your own crypto!

Belkin is the latest router vendor to be found relying on “non-secret secrets.” Paul Ducklin looks at the router equivalent of locking the key to the company safe in the top drawer of your desk…