OpenSSL Fixes HollowByte Memory Exhaustion Bug

2026-07-19T02:51:43Zed6d11c3157b467a4b7061872753489da3a78bff563f318d98a0cd4d43724080
AI-generated codeCISACVE-2023-4346Claude Code','DeepSeek','Chinese cyber espionageDaxinEY data breachFortinet FortiSandboxHollowByteIoT botnetKnown Exploited VulnerabilitiesMicrosoft SharePointNichireiOpenSSLScattered SpiderStarland RATStupigTuxBot v3UAT-11795WLDRdenial-of-servicememory-exhaustionrootkitsupply-chain-compromisethird-party compromisetrojanized installers

What happened

Multiple high-impact security events: Okta disclosed 'HollowByte', an 11-byte OpenSSL memory-exhaustion (DoS) attack vector; Symantec found the long-running China-linked Daxin kernel rootkit and a new Stupig backdoor on a Taiwanese manufacturer's network; and CISA added multiple known-exploited flaws (including Fortinet FortiSandbox and Microsoft SharePoint issues) to its KEV catalog. Other notable incidents include an EY data breach via a compromised third-party support-ticket system, a disruptive cyberattack at Japanese food firm Nichirei, a Russian campaign (UAT-11795) using trojanized Zoom

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
securityaffairs
Record identifier
ed6d11c3157b467a4b7061872753489da3a78bff563f318d98a0cd4d43724080
Enrichment time
2026-07-19T02:51:43Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.