Home Blog Page 182

Can Bots Manipulate Data and Change Facts to Fiction?

Data manipulation is a real threat to data-driven approaches at enterprises. We tested one of our own assets to see the possibilities. - Read more

A Year-End Letter from the Executive Director of Let’s Encrypt and ISRG

This letter was originally published in our 2020 annual report. ISRG’s first project, Let’s Encrypt, has been wildly successful. We’re now helping to secure more than 225 million websites and the Web is making great progress towards 100% HTTPS. We’ve put in a lot of hard work and dealt with some challenges along the way, but at a high level...

Extending Android Device Compatibility for Let’s Encrypt Certificates

Update, May 13, 2021 Please visit this post on our community forum for the latest information about chain changes as some information about the changes and dates in this blog post are outdated. We’re happy to announce that we have developed a way for older Android devices to retain their ability to visit sites that use Let’s Encrypt certificates after our...

What Is Phishing? How to Recognize and Avoid It

"What is phishing" is still a relevant question we're answering as the attack type and techniques evolve, victimizing even the most tech-savvy users. - Read more

Standing on Our Own Two Feet [Updated]

Update, July 10, 2023 See our new blog post for details on the September 2024 expiration of the newer ISRG Root X1 cross-sign from IdenTrust. Update, December 21, 2020 Thanks to community feedback and our wonderful partners at IdenTrust, we will be able to continue to offer service without interruption to people using older Android devices. We flagged the content of this...

Let’s Encrypt’s New Root and Intermediate Certificates

On Thursday, September 3rd, 2020, Let’s Encrypt issued six new certificates: one root, four intermediates, and one cross-sign. These new certificates are part of our larger plan to improve privacy on the web, by making ECDSA end-entity certificates widely available, and by making certificates smaller. Given that we issue 1.5 million certificates every day, what makes these ones special? Why did we issue them?...

How Credential Stuffing Bots Bypass Defenses

Website logins are under constant assault, with attackers quickly modifying their bots to evade simplistic defenses. - Read more

Introducing the Cryptonice HTTPS Scanner

F5 Labs has released a new open-source tool to check for HTTPS misconfigurations of public and internally hosted HTTPS websites. - Read more

Four Risks to Consider with Expanded VPN Deployments

The rush to deploy remote access solutions can bring unexpected risks to light. - Read more

Let’s Encrypt Has Issued a Billion Certificates

We issued our billionth certificate on February 27, 2020. We’re going to use this big round number as an opportunity to reflect on what has changed for us, and for the Internet, leading up to this event. In particular, we want to talk about what has happened since the last time we talked about a big round number of...

Latest article

Yarbo Android/iOS Mobile Application and Cloud Infrastructure

View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to obtain hard-coded credentials, gain access to telemetry data, and potentially send operational commands...

Check Point VPN Authentication Bypass Vulnerability

What is the Vulnerability? A critical authentication bypass vulnerability, CVE-2026-50751 (CVSS...

CISA tells agencies to patch smarter, not harder — foreshadowing broader industry practice

Security teams’ patching practices have come under intense pressure over the past year, as active exploitation is up, time-to-exploit windows...