logo

New Opossum Attack Allows Hackers to Compromise Secure TLS Channels with Malicious Messages

ID: 52467de3-54da-5da3-8c37-29cd8ec7b605

STIX ID: report--52467de3-54da-5da3-8c37-29cd8ec7b605

Feed Name: cybersecurityNews.com

Threat Score
70/100

Date Published: 2025-07-10

Date Updated: 2026-04-21

Author: Guru Baran

...
...

**Opossum** is a cross-protocol application-layer desynchronization vulnerability that leverages differences between implicit and opportunistic TLS to enable MITM attackers to inject messages, cause persistent client-server desynchronization, and perform session hijacking, content manipulation, and XSS across protocols (HTTP, FTP, SMTP, POP3, LMTP, NNTP). The report describes attack mechanics (redirecting implicit TLS to opportunistic TLS and abusing upgrade mechanisms like RFC 2817), notes internet-wide scanning identified millions of potentially vulnerable hosts, and recommends disabling opportunistic TLS and applying vendor patches as primary mitigations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.