Security 7
- OpenSSL's ARM64 SM2 Path Leaks a Private-Key Timing Fingerprint
- ML-DSA Forgery, Part 2: Off-Process Key Recovery in wolfSSL
- A 992-Byte PDF That Crashes Poppler (and an lcms2 Bug That Also Hits OpenJDK and Friends)
- "Shall Destroy, Did Not": Recovering ML-DSA Private Keys from wolfSSL's Heap
- Coming Soon: OpenSSL Vulnerability Disclosure
- RingWraith: Summary
- RingWraith: Use-After-Free in libfuse's io_uring Transport