logo

EFF: SSL Records Show Superfish Attacks in the Wild

ID: 7a081f8a-942f-5279-8f3f-fb0d38e33da7

STIX ID: report--7a081f8a-942f-5279-8f3f-fb0d38e33da7

Feed Name: Security Ledger

Threat Score
72/100

Date Published: 2015-02-26

Date Updated: 2026-04-26

Author: Paul Roberts

...
...

EFF researchers report evidence of active man-in-the-middle attacks abusing the Komodia SSL-interception library (used by Superfish/Lenovo), identifying ~1,600 mismatched SSL certificates tied to high-profile domains (Google, Yahoo, major banks, e-commerce). The weakness could allow attackers to intercept encrypted traffic, access accounts, and install malware; EFF warns vendors against intercepting customers' encrypted traffic.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.