OpenSSL Fixes HollowByte Memory Exhaustion Bug

2026-07-18T20:51:48Z0dab65cb4bcc041ed8366e64275561e12ab41d4a043d960920f8221675502293
cisacve-2023-4346daxindenial-of-serviceeyfortinetfortisandboxhollowbyteincident-responsekevknown-exploited-vulnerabilitiesmalwarememory-exhaustionmicrosoftnichireiopensslphishingrootkitsharepointstarland-ratstupigsupply-chainthird-party-breachtrojanized-installers','russian-actor','uat-11795'wldr

What happened

Multiple high-impact security developments: Okta disclosed ‘HollowByte,’ an 11-byte OpenSSL memory-exhaustion/DoS condition that can be triggered remotely; Symantec found the long-running China-linked Daxin kernel rootkit (plus a new Stupig backdoor) active on a Taiwanese manufacturer’s network since ~2013; CISA expanded its Known Exploited Vulnerabilities (KEV) catalog to include Fortinet FortiSandbox, Microsoft SharePoint issues and other flaws (including CVE-2023-4346); Ernst & Young reported a data breach stemming from a compromised third-party support-ticket system; a cyberattack impacted

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
securityaffairs
Record identifier
0dab65cb4bcc041ed8366e64275561e12ab41d4a043d960920f8221675502293
Enrichment time
2026-07-18T20:51:48Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · OpenSSL Fixes HollowByte Memory Exhaustion Bug · Baitaphish