Help AG: Newly Discovered OpenSSL Bug Potentially Leaves Over Two Thirds of Global Web Servers Vulnerable to Attack
Last Update: Thursday, April 10, 2014 : 16:12 (+4GMT)
DUBAI, United Arab Emirates, 10 April, 2014: On the 8th of April, 2014, IT Security experts uncovered a major bug in the hugely popular OpenSSL cryptographic library. OpenSSL is widely implemented across an array of devices including web-servers, mobile phones and even smart-TV’s, and has so far been seen as essential to preventing eavesdropping of passwords, banking credentials, and other sensitive data.. Nicolai Solling Director of Technology Services at Help AG, a IT security firm dedicated to spreading awareness about cyber threats in the Middle East, says as much as 75% of the server infrastructure on the internet needs to be upgraded or patched to fix this massive flaw.
“The implications of this discovery are enormous given that the number of organizations that utilize OpenSSL is so vast. Though the vulnerability may be difficult for the common user to understand, is essentially means that their sensitive information such as login names and passwords for services such as e-banking or webmail could now be exposed to attackers as well as anyone who accesses the affected websites ,” said Nicolai.
Help AG warns that a number of enterprises in the Middle East run SSL and other crypto-services based on OpenSSL. The security expert has stressed that these organizations must validate their security stance in light of the finding and if necessary, take steps to patch their services in order to mitigate the issue and protect their users.
“The race against the clock has already begun as we are already starting to see the first set of attack frameworks emerge. With each passing day, we are sure to see more cyber criminals exploiting these vulnerabilities. The responsibility of fixing this issue lies with organizations since this is a server-side vulnerability. Unfortunately, for common users, this means that there is very little they could do to protect themselves,” warned Nicolai.
The bug, which has resulted from a coding error, is officially referenced as CVE-2014-0160. It allows potential attackers to retrieve unencrypted data from the OpenSSL process just by accessing the vulnerable server. This data could reveal anything from authentication credentials and potentially cryptographic material identifying a website's digital certificate. If hackers manage to uncover this information, they could gain access to data which would normally have been encrypted and protected.
Commenting on the roadmap to mitigating the issues arising out of this finding, Nicolai Solling said, “IT professionals now have their work cut out for them. As a first step, they must either patch or upgrade vulnerable servers. As we uncover more information about the bug replacement of certificates may also be required.
“This scenario has also brought to the limelight the need for stronger authentication solutions. If authentication were based on frameworks which ensured passwords are dynamic and only usable once, even if the data was leaked the attacker could not do anything with it,” concluded Nicolai.
- Bridal Season Is Officialy Open with Benefit Cosmetics!... [2480-Views]
- Dubai Summer Surprises 2026 Unveils an Action-Packed Calendar of Shopping, Din... [2026-Views]
- Joyalukkas Strengthens US Footprint with 8th Showroom in Iselin, New Jersey... [2010-Views]
- Mercato Takes Media on a Magical Summer Journey with The Grand Comedy Circus a... [1596-Views]
- Group-IB launches Purple Teaming service to close the gap between security inv... [1211-Views]
- First winner of 'Win Your Home in Dubai' initiative announced as citywide home... [1131-Views]
- Dubai Gears Up for a Spectacular Start to 29th Dubai Summer Surprises with Liv... [1101-Views]
- Government of Fujairah Signs Agreement to Purchase Gasoline Production from Et... [955-Views]
- Global Talent Attraction and Retention Committee Convenes Tenth Meeting to Rev... [922-Views]
- MAIR Group and Makani Real Estate Announce Mall of Al Ain Redevelopment and Ex... [899-Views]
- Schneider Electric joins the World Economic Forum Lighthouse Operating System ... [891-Views]
- EGA wins the AI Vision and Strategy Award at the 2026 Manufacturing Leadership... [885-Views]
- EGA inaugurates UAE's largest aluminium recycling plant... [832-Views]
- Kia introduces PV5 as its first Platform Beyond Vehicle (PBV) model in Middle ... [826-Views]
- G-SHOCK MTG-B4000BD-1A: A New Language of Structural Beauty... [820-Views]
- The New SHEGLAM Lashlighter Root-Up Lash Primer Gets to the Root of the Matter... [809-Views]
- Dubai Summer Surprises: Shop, Save, and Win as the Great Dubai Summer Sale Arr... [804-Views]
- Dubai Municipality and Enviroserve sign strategic agreement to enhance e-waste... [767-Views]
- Dubai Municipality tours first vertical farm inside residential tower in Al Ha... [762-Views]
- Commercial Bank of Dubai prices USD 550 million Additional Tier 1 perpetual no... [740-Views]




![Botim and BDO Unibank [SA1] Advance Financial Readiness for UAE-Bound Filipinos](/citylife/press_images/192940.jpg)
