| |
# Summary In April 2023, a remote code execution vulnerability (CVE-2023-38198) in acme.sh—a tool used to automate TLS certificate renewal—was exploited to compromise the jabber.ru server, a major Russian XMPP messaging service. The attacker likely used this vulnerability to issue fraudulent TLS certificates for lawful interception purposes, an operation that was eventually exposed when the intercepted traffic was detected on hosting providers Hetzner and Linode. The article analyzes how this technical breakdown occurred and examines the mechanics of how TLS certificate-based wiretapping can be executed in practice.
Read Full Article →
← More Tech news