All CosmicBytez Labs articles tagged #MITM, across news, security advisories, how-to guides, and projects.
Signal launched Automatic Key Verification on August 12, 2026, using key transparency audited by Cloudflare and Trail of Bits to defeat MITM attacks.
Apache HttpComponents Client 5.4+ async mode ignores HostnameVerificationPolicy#BUILTIN, enabling MITM attacks against TLS connections in affected applications.
A critical TLS hostname verification flaw in Apache Thrift's c_glib bindings allows network-positioned attackers to conduct man-in-the-middle attacks against any service-to-service communication using the affected transport. Fixed in Apache Thrift 0.24.0.
The Apache Airflow Git provider runs git-over-SSH with StrictHostKeyChecking=no by default, allowing a network-position attacker to silently impersonate...
A critical CVSS 9.4 vulnerability disables TLS certificate validation via TrustAllCerts routines and combines this with hard-coded DES symmetric encryption…
Improper certificate validation in Amazon Athena ODBC driver versions prior to 2.1.0.0 allows man-in-the-middle attackers to intercept authentication...