<?xml version='1.0' encoding='utf-8'?>
<rss version="2.0"><channel><title>Cybersecurity Tracker: OpenSSL Watch</title><link>https://cybersecuritytracker.ai/?stack=1</link><description>Stories and vulnerabilities involving OpenSSL.</description><lastBuildDate>Sun, 26 Jul 2026 22:32:52 GMT</lastBuildDate><item><title>Siemens SIDIS Secured SmartPlug</title><link>https://cisa.gov/news-events/ics-advisories/icsa-26-202-04</link><guid isPermaLink="false">cst-2930</guid><description>Siemens SIDIS Secured SmartPlug versions before V7.26.0310 contain multiple critical and high-severity vulnerabilities in OpenSSL, OpenSSH, hostapd, wpa_supplicant, and busybox components. These flaws enable side-channel attacks, key reuse exploitation, buffer overflows, and other memory corruption issues. Siemens has released version V7.26.0310 as a remediation and recommends immediate updates.</description><pubDate>Tue, 21 Jul 2026 12:00:00 GMT</pubDate></item><item><title>OpenSSL Silently Fixes ‘HollowByte’ DoS Vulnerability</title><link>https://securityweek.com/openssl-silently-fixes-hollowbyte-dos-vulnerability</link><guid isPermaLink="false">cst-2828</guid><description>OpenSSL addressed a denial of service (DoS) vulnerability, dubbed 'HollowByte', that allowed attackers to trigger unfreed buffer allocations and exhaust server memory through malicious payloads. The fix was released without prominent disclosure or fanfare.</description><pubDate>Mon, 20 Jul 2026 12:32:40 GMT</pubDate></item><item><title>HollowByte DDoS flaw bloats OpenSSL server memory with 11-byte payload</title><link>https://bleepingcomputer.com/news/security/hollowbyte-ddos-flaw-bloats-openssl-server-memory-with-11-byte-payload</link><guid isPermaLink="false">cst-2776</guid><description>A vulnerability called HollowByte enables unauthenticated attackers to trigger denial-of-service conditions on OpenSSL servers using an 11-byte malicious payload. The flaw causes excessive memory consumption on affected servers, degrading availability without requiring authentication or complex exploitation techniques.</description><pubDate>Fri, 17 Jul 2026 17:56:21 GMT</pubDate></item><item><title>Siemens Products using OpenSSL</title><link>https://cisa.gov/news-events/ics-advisories/icsa-26-174-03</link><guid isPermaLink="false">cst-282</guid><description>OpenSSL published a stack-based buffer overflow vulnerability (CVE-2025-15467) that could allow remote denial of service or remote code execution. Siemens has released fixes for several affected products including networking devices, edge computing systems, and industrial controllers, and recommends updating to the latest versions. For products without available fixes, Siemens is preparing additional versions and recommending interim countermeasures.</description><pubDate>Tue, 23 Jun 2026 12:00:00 GMT</pubDate></item></channel></rss>