Attacks using Heartbleed vulnerability

April 15, 2014

Attackers begun to utilize the Hertbleed vulnerability shortly after it’s announcement. An attack using Hertbleed was detected on 8th April at the honeypot at the University of Mitchigan. More seriously, social insurance numbers of 900 Canadian citizens were stolen from the system of the Canada Revenue Agency (CRA). The attack on the CRA system occurred in a 6 hour window between the announcement of the Heartbleed vulnerability and the moment the system was put into the offline mode to patch it.

