Update Tuesday, April 2015 – Urgent action needed over Microsoft HTTP bug

We don’t usually focus on one vulnerability and say, “Do that first.” But this month, we’re willing to make an exception. The Microsoft HTTP stack has a bug that could let attackers straight in with a simple HTTP request…

TLS certificate blunder revisited – whither China Internet Network Information Center?

Just under three weeks ago, we wrote about a TLS certificate blunder by a Root Certificate Authority called CNNIC. We thought we’d revisit that story today to see how the Big Four browser makers responded to the lapse…