Plus more blasts from the past: NetWare, FTP, and HTTP Sometimes it takes a while to detect a vuln. A 29 year old, Heartbleed style vulnerability in Squid, a popular open source caching proxy server, silently leaked users plaintext HTTP requests and potentially revealed sensitive data, including credentials and session tokens, for decades until AI and a few humans saved the day. A security researcher and Mythos Preview found the flaw and reported it to project maintainers, who fixed the code...

Read the full article at The Register