OpenSSL 4.0.0 release cuts deprecated protocols and gains post-quantum support

2026-04-14T20:51:52Z0ed50b562bd8e86fe4edb8e7bbe562a7fa2fc4b03dc88af7ec4812cac03ad833
api-breaking-changesbasic-fitbinary-defensebooking.comclarotyclaude-mythosdata-breachdatavisordavmailencrypted-client-hellofraud-amllaw-enforcement-takedownllm-securitymicrosoft-grapholigoopenssl-4.0.0phishing-kitpost-quantumregex-vulnerabilityruntime-exploit-protectionsslv3-removalveravisibility-orchestrationw3llxDome

What happened

This feed covers multiple timely security developments: OpenSSL 4.0.0 is released with post‑quantum support, Encrypted Client Hello (ECH), and removal of long‑deprecated features (SSLv3, SSLv2 ClientHello, engine API) plus breaking API changes that may require application updates; Anthropic’s Claude Mythos Preview was tested by the UK AISI and shown to improve offensive capabilities but cannot reliably execute autonomous attacks on hardened networks; the FBI and Indonesian authorities dismantled the W3LL phishing kit service used to deploy credential‑stealing pages; DavMail 6.6.0 fixes a regex

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
helpnetsecurity
Record identifier
0ed50b562bd8e86fe4edb8e7bbe562a7fa2fc4b03dc88af7ec4812cac03ad833
Enrichment time
2026-04-14T20:51:52Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.