Test Certificates in Production: KeyPlug’s WolfSSL Misconfiguration Leads to Infrastructure Exposure

Summary A critical security incident exposed KeyPlug malware infrastructure due to the improper use of wolfSSL test certificates in production. The 24-hour exposure revealed sophisticated attack tools linked to the RedGolf/APT41 threat group, demonstrating how poor certificate management can compromise even advanced threat actors’ operations. The Certificate Failure The compromised server was identified through its […]

Read MoreMore Tag

Announcing wolfMQTT v1.20.0: Now with WebSocket Support

We are excited to announce the release of wolfMQTT v1.20.0, which introduces WebSocket support as its headline feature. This release continues our commitment to providing a lightweight, secure, and feature-rich MQTT client implementation for embedded systems and IoT applications. What’s New in v1.20.0 The wolfMQTT v1.20.0 release includes several significant enhancements: WebSocket Support The most […]

Read MoreMore Tag

Chimera Certificate Standards Compliance

In the evolving landscape of cryptographic security, supporting multiple signature algorithms within a single certificate has become increasingly important. These certificates are known as Chimera certificates, a moniker coined by the X9.146 banking standards team. They provide enhanced security, flexibility, and agility, especially for the transition to post-quantum cryptography. As well, wolfSSL also understands the […]

Read MoreMore Tag

wolfProvider Integration with nginx: Secure Your Web Server with wolfSSL FIPS Cryptography

Securing web servers with robust cryptography is essential in today’s threat landscape. wolfProvider offers a seamless way to enhance nginx security by integrating wolfSSL’s high-performance cryptographic implementations through OpenSSL’s provider framework. This integration allows nginx to leverage wolfSSL’s FIPS cryptography without modifying code. What is wolfProvider? wolfProvider is an OpenSSL provider that integrates the wolfCrypt […]

Read MoreMore Tag

wolfSSL Inc. SP800-140C, SP800-140D and Post-Quantum efforts update!

This is an update to previous post wolfSSL Inc. SP800-140C and Post-Quantum efforts update! The National Institute of Standards and Technology (NIST) has recently updated its guidelines, enabling the certification of several post-quantum cryptographic algorithms through the Cryptographic Module Validation Program (CMVP). Notably, the digital signature algorithms ML-DSA (CRYSTALS-Dilithium), SLH-DSA, LMS, and XMSS are now […]

Read MoreMore Tag

Live Webinar: wolfHSM Design for Automotive Hardware Security Modules – Tailored for the Asia-Pacific Time Zone

Learn how wolfHSM enhances automotive security by providing powerful cryptographic protection and seamless hardware integration. Register today: wolfHSM Design for Automotive Hardware Security Modules – Tailored for the Asia-Pacific Time Zone. Date: April 30th | 7 PM PT / May 1st | 11 AM JST wolfHSM is a versatile hardware security module (HSM) framework that […]

Read MoreMore Tag

wolfSSL 5.8.0 Released

We are excited to announce that wolfSSL version 5.8.0 is now available. This release brings several important new features and improvements. Below are the key new additions: New Features Implemented various fixes to support building for Open Watcom, including OS/2 support and Open Watcom 1.9 compatibility (PR 8505, 8484). Added support for STM32H7S (tested on […]

Read MoreMore Tag

Posts navigation

1 2 3 14 15 16 17 18 19 20 215 216 217