WhisperX tag archive

#SSL/TLS

This page collects WhisperX intelligence signals tagged #SSL/TLS. It is designed for humans, search engines, and AI agents: each item links to a canonical source-backed record with sector, source, timestamp, credibility, and exportable structured data.

Latest Signals (1)

The Lab · 2026-03-27 11:27:32 · GitHub Issues

1. Security Flaw: Default Nginx Template Enables Vulnerable SSLv3 and Deprecated TLSv1.1

A critical security misconfiguration has been identified in a widely used Nginx configuration template. The file `template.nginx-conf` explicitly enables the obsolete and vulnerable SSLv3 protocol alongside the deprecated TLSv1.1, creating a direct attack vector for man-in-the-middle (MITM) downgrade attacks. This conf...