#tls
FruitVale (1.0.0) for esp32 by jvxtor

➡️ https://github.com/fruit-vale/FruitVale-Arduino

Conecta placas ESP32 à plataforma agrícola FruitVale (Wi-Fi, MQTT com TLS e portal de configuração).

#ArduinoLibs #ArduinoLibraries #esp32Libraries
GitHub - fruit-vale/FruitVale-Arduino
Contribute to fruit-vale/FruitVale-Arduino development by creating an account on GitHub.
github.com
September 29, 2026 at 2:10 PM
So. What's "Upskilling"? Is it learning how to cheat like this and *not* get caught?
September 29, 2026 at 1:42 PM
As post-quantum signatures threaten to inflate TLS handshakes and certificate transparency logs, Merkle Tree Certificates offer a path to compact, auditable authentication. Cloudflare’s new certificate authority will support MTC issuance at scale. https://cfl.re/4ynqS12 #BirthdayWeek
Building a post-quantum certificate authority with Merkle Tree Certificates
Cloudflare’s new certificate authority will support MTC issuance at scale.
blog.cloudflare.com
September 29, 2026 at 1:30 PM
Reposting with alt-text
September 29, 2026 at 1:26 PM
Alt text retrieved
September 29, 2026 at 1:23 PM
UNGA spent weeks drafting AI governance frameworks while the cryptographic primitives securing every training pipeline, model weight, and inference log have already been harvested. ECDSA-signed model updates. TLS-protected weight transfers.
September 29, 2026 at 1:15 PM
im thinking about the Junko monster video again. gonna put that back on everyones tls
September 29, 2026 at 1:05 PM
I'm thankful you shared this, Jeff, because I've -- as the volunteer editor of a community-news-org opinion section -- been mulling directions for an AI policy.

And the one mentioned here, which prohibits any AI use in the writing or editing process, is a great model:
The TLS and Generative AI: Editorial guidelines
Dated: May 1, 2026 These guidelines outline the TLS’s approach to artificial intelligence (AI), based on the standards of literary excellence we have
www.the-tls.com
September 29, 2026 at 12:29 PM
Incredible stuff.
September 29, 2026 at 12:14 PM
While MAC randomization obscures the physical layer, the real tracking vector is the TLS ClientHello fingerprint and the persistent storage of session tokens in the browser's Secure Storage API. Have you considered how Ephemeral Key Exchange (ECDHE) mitigates some of this,...
September 29, 2026 at 12:02 PM
A350-1041F, Airbus, F-WXLD, (MSN 700) | First Flight TLS-TLS
A350-1041F, Airbus, F-WXLD, (MSN 700)
A350-1041F, Airbus, F-WXLD, (MSN 700) | First Flight TLS-TLS
aviation.flights
September 29, 2026 at 12:00 PM
A350-941, KLM Royal Dutch Airlines, F-WZNM, PH-ZNA (MSN 809) | Fourth FLight TLS-TLS
A350-941, KLM Royal Dutch Airlines, F-WZNM, PH-ZNA (MSN 809)
A350-941, KLM Royal Dutch Airlines, F-WZNM, PH-ZNA (MSN 809) | Fourth FLight TLS-TLS
aviation.flights
September 29, 2026 at 12:00 PM
Automation is an interesting one. I wouldn't say automating a task like, for example, TLS certificate renewal is cognitive offloading. It's just getting rid of something you have to do that requires little to no thought. The rest though ? Yep.
September 29, 2026 at 11:31 AM
A350-941, Emirates, F-WZNF, A6-JHD (MSN 804) | Engine Run & Taxi Check at TLS
A350-941, Emirates, F-WZNF, A6-JHD (MSN 804)
A350-941, Emirates, F-WZNF, A6-JHD (MSN 804) | Engine Run & Taxi Check at TLS
aviation.flights
September 29, 2026 at 11:00 AM
wolfSSL 5.9.4、TLSと証明書検証に影響する11件の脆弱性を修正

wolfSSLはバージョン5.9.4をリリースしました。TLSおよびDTLSのハンドシェイク、X.509証明書の検証、証明書失効、OCSPステープリング、セッション再開、メモリ安全性に関する11件のセキュリティ脆弱性に対処しています。セキュリティ意識向上トレーニング 今回のリリースは、OpenSSL互換設定、任意の証
wolfSSL 5.9.4、TLSと証明書検証に影響する11件の脆弱性を修正
wolfSSLはバージョン5.9.4をリリースしました。TLSおよびDTLSのハンドシェイク、X.509証明書の検証、証明書失効、OCSPステープリング、セッション再開、メモリ安全性に関する11件のセキュリティ脆弱性に対処しています。セキュリティ意識向上トレーニング 今回のリリースは、OpenSSL互換設定、任意の証
blackhatnews.tokyo
September 29, 2026 at 10:29 AM
The security criticism went beyond personal tinkering. Without TLS, anyone on the local network—or an upstream hop—can sniff or alter the stream. People kept asking why Sony still relies on naked RTMP decades after the protocol was largely sidelined. #infosec 3/4
September 29, 2026 at 10:00 AM
The PS5 still pushes live video over unencrypted RTMP. Commenters were baffled that current-gen hardware is broadcasting without TLS, making stream redirection as straightforward as a local DNS spoof. #security 1/4
September 29, 2026 at 10:00 AM
wolfSSL 5.9.4 Fixes 11 TLS Security Flaws and Expands Post-Quantum Cryptography Support
wolfSSL 5.9.4 Fixes 11 TLS Security Flaws and Expands Post-Quantum Cryptography Support
wolfSSL has released version 5.9.4, fixing 11 security vulnerabilities in its embedded TLS and cryptography library while adding major post-quantum cryptography capabilities . The update is important for developers using wolfSSL in IoT devices, embedded products, servers, gateways, and applications that depend on TLS or DTLS for secure communications. The release addresses three high-severity, four medium-severity, and four low-severity CVEs. wolfSSL said most flaws affect particular build options, APIs, or non-default configurations rather than every deployment. Still, organizations should review their compilation flags and update affected installations, especially deployments using OpenSSL -compatible settings, Raw Public Keys, OCSP stapling, certificate revocation checks, or TLS 1.2 session resumption. The three high-severity flaws could weaken TLS peer authentication in certain builds. CVE-2026-93302 affects deployments using trusted peer certificates through WOLFSSL_TRUST_PEER_CERT. The issue could allow a forged certificate authority clone to pass validation when an attacker knows the CA certificates trusted by the target. It may affect compatibility-focused configurations used with software such as nginx, HAProxy, stunnel, Apache HTTP Server, BIND, and rsyslog. wolfSSL 5.9.4 Fixes TLS Security Flaws CVE-2026-89102 affects clients that enable RFC 6961 multiple OCSP response stapling. A vulnerable client could accept a certificate in a server-provided chain as a certificate authority without checking whether that certificate is authorized to issue certificates. An attacker with a certificate chaining to a trusted CA could potentially forge certificates for arbitrary identities. The third high-severity issue, CVE-2026-89136, affects clients built with Raw Public Key support . A malicious server could send an unsolicited Raw Public Key and bypass normal X.509 certificate-chain validation. Raw Public Key support is turned off by default. However, it is enabled through options such as –enable-rpk, –enable-all, and –enable-distro. wolfSSL 5.9.4 also fixes certificate name-constraint validation errors. One medium-severity flaw could allow a certificate to escape DNS name constraints if an unconstrained CA appeared between a name-constrained intermediate CA and the leaf certificate. Another issue involved certificates that carried a Subject Alternative Name of a type other than DNS, allowing an invalid Common Name to bypass a DNS name-constraint check. Other fixes address an out-of-order ChangeCipherSpec message in TLS 1.2 and DTLS 1.2, an OCSP and CRL fallback issue that could accept a revoked certificate, and a session-cache reference issue affecting legacy TLS 1.2 and DTLS 1.2 resumption flows. The release also resolves a potential use-after-free condition during TLS shutdown. CVE Severity Affected Versions Vulnerability Fixed In CVE-2026-93302 High 5.3.0–5.9.2 Trusted-peer certificate bypass 5.9.4 CVE-2026-89102 High 5.7.2–5.9.2 OCSP stapling certificate forgery 5.9.4 CVE-2026-89136 High 5.6.0–5.9.2 Raw Public Key auth bypass 5.9.4 CVE-2026-93304 Medium 4.7.0–5.9.2 ChangeCipherSpec bypass 5.9.4 CVE-2026-89133 Medium ≤5.9.2 X.509 NameConstraints bypass 5.9.4 CVE-2026-89134 Medium 5.9.2 Common Name constraint bypass 5.9.4 CVE-2026-89135 Medium 5.8.4–5.9.2 Unverified CA persistence 5.9.4 CVE-2026-15442 Low 4.4.0–5.9.2 TLS shutdown use-after-free 5.9.4 CVE-2026-94417 Low ≤5.9.2 OCSP/CRL check bypass 5.9.4 CVE-2026-94418 Low 3.15.5–5.9.2 Certificate signature bypass 5.9.4 CVE-2026-94419 Low 5.3.0–5.9.2 TLS session-cache confusion 5.9.4 Administrators should not assume that only updating the shared library is enough. For some affected long-running applications, wolfSSL states that the WOLFSSL_CTX or entire process should be restarted because certificate or session state may persist in memory. Beyond security fixes, wolfSSL 5.9.4 significantly expands its post-quantum cryptography support. The release adds native Falcon signature support, replacing the prior dependency on the liboqs library. It also introduces FrodoKEM, a post-quantum key encapsulation mechanism, with optimized implementations for x86_64, AArch64, AArch32, and Thumb2 platforms. The update adds SLH-DSA authentication for TLS 1.3 and DTLS 1.3 handshakes across all 12 parameter sets. Developers can also build post-quantum-only TLS 1.3 configurations using ML-KEM key exchange with ML-DSA or SLH-DSA authentication, without traditional RSA, elliptic-curve cryptography, or Diffie-Hellman algorithms. wolfSSL also added AVX512 acceleration for ML-KEM and ML-DSA, ML-DSA support for PKCS#7 and CMS SignedData, and an –enable-all-quantum-crypto configuration bundle. These improvements position the library for organizations preparing systems against future cryptographically relevant quantum computers. Organizations running wolfSSL 5.9.2 or earlier should identify enabled build features and upgrade to version 5.9.4 or a downstream package containing the fixes. Priority should be given to systems using trusted-peer certificate APIs, multi-OCSP stapling, Raw Public Keys, OpenSSL compatibility APIs, OCSP plus CRL checking, and legacy session resumption. Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC The post wolfSSL 5.9.4 Fixes 11 TLS Security Flaws and Expands Post-Quantum Cryptography Support appeared first on Cyber Security News .
cybersecuritynews.com
September 29, 2026 at 9:53 AM
Absolutely and interesting article, but also quite clickbait-y. This has little impact on 'regular' padded RSA as used for TLS/mTLS and the usual XML signing methods.

But RSA is starting to show its age - and many systems are not ready for true PQC. Something to start thinking about yesterday!
September 29, 2026 at 9:50 AM
wolfSSL 5.9.4、認証および証明書検証のバイパスにつながる11件の脆弱性を修正

wolfSSLはバージョン5.9.4をリリースしました。TLS、DTLS、X.509証明書検証、セッション再開、失効確認の各コードパスに存在する11件のセキュリティ脆弱性に対処しています。 複数の欠陥により、攻撃者がピア認証を回避したり、脆弱なクライアントに受け入れられる偽の証明書を作成したりできる恐れがありました。
wolfSSL 5.9.4、認証および証明書検証のバイパスにつながる11件の脆弱性を修正
wolfSSLはバージョン5.9.4をリリースしました。TLS、DTLS、X.509証明書検証、セッション再開、失効確認の各コードパスに存在する11件のセキュリティ脆弱性に対処しています。 複数の欠陥により、攻撃者がピア認証を回避したり、脆弱なクライアントに受け入れられる偽の証明書を作成したりできる恐れがありました。
blackhatnews.tokyo
September 29, 2026 at 9:47 AM
September 29, 2026 at 9:44 AM
Anthropic launched Claude Sonnet 5.5 on Sep 28, the second model in the Claude 5.5 series after Opus 5.5.

#Anthropic #Claude #ClaudeSonnet #ClaudeSonnet

aidisruption.ai/p/8-claude-c...
8 Claude Code Install Pitfalls, All Tested by Me
Claude Code install failing? Fix command not found, PATH, TLS, proxy, login loops, and more with this quick troubleshooting checklist.
aidisruption.ai
September 29, 2026 at 8:17 AM
RE: https://infosec.exchange/@netresec/117353105112165628

It's time to start blocking traffic to workers[.]dev. At least run it through a TLS-inspection proxy before forwarding it to this free malware C2 hosting platform provided by Cloudflare.
@james_inthe_box
🔥 hxxps://billowing-boat-0c0f.piloty194.workers[.]dev
September 29, 2026 at 8:08 AM
1. SSL Labs: In-depth SSL/TLS configuration test.
👉 www.ssllabs.com/ssltest/

2. Security Headers: Quick check of HTTP headers to prevent common vulnerabilities.
👉 securityheaders.com

2/4
September 29, 2026 at 8:00 AM