#MITM
All CosmicBytez Labs articles tagged #MITM, across news, security advisories, how-to guides, and projects.
- News
Signal Adds Automatic Key Verification to Thwart Man-in-the-Middle Attacks
Signal launched Automatic Key Verification on August 12, 2026, using key transparency audited by Cloudflare and Trail of Bits to defeat MITM attacks.
- Security
Apache HttpComponents TLS Hostname Verification Bypass
Apache HttpComponents Client 5.4+ async mode ignores HostnameVerificationPolicy#BUILTIN, enabling MITM attacks against TLS connections in affected applications.
- Security
CVE-2026-48144: Apache Thrift c_glib TLS Certificate Host Mismatch (CVSS 9.1)
A critical TLS hostname verification flaw in Apache Thrift's c_glib bindings allows network-positioned attackers to conduct man-in-the-middle attacks...
- Security
CVE-2026-58065: Apache Airflow Git Provider Disables SSH Host Key Verification
The Apache Airflow Git provider runs git-over-SSH with StrictHostKeyChecking=no by default, allowing a network-position attacker to silently impersonate...
- Security
CVE-2026-50208: TLS Bypass and Hard-Coded DES Keys Enable MITM Attacks
A critical CVSS 9.4 vulnerability disables TLS certificate validation via TrustAllCerts routines and combines this with hard-coded DES symmetric encryption…
- Security
CVE-2026-35560: Amazon Athena ODBC Driver Fails Certificate
Improper certificate validation in Amazon Athena ODBC driver versions prior to 2.1.0.0 allows man-in-the-middle attackers to intercept authentication...