/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

← → days · ↑ ↓ browse · Enter similar · o open

300k servers vulnerable to Heartbleed one month later

It's been a month since the Heartbleed bug was announced, so I thought I'd rescan the Internet (port 443) to see how many systems remain vulnerable.  Whereas my previous scan a month ago found 600,000 vulnerable systems …

Errata Security Robert Graham

Context & Ripple Effects

A month after OpenSSL's Heartbleed flaw was disclosed on April 7, Errata Security has rerun its Internet-wide scan of port 443: 300,000 servers remain vulnerable, down from 600,000 in its first sweep. The halving is real progress, but it also quantifies how slow patching is even for a bug that lets anyone on the Internet read server memory, as the disclosure coverage explained.

The scan lands alongside two other measures of cleanup lag: an April 18 status check found 0.52% of the top 10K sites and 2% of the top 1M still exposed ten days after disclosure, and Heartbleed-driven certificate revocation had already swollen certificate revocation lists enough to strain bandwidth for authorities and site operators. Eight outlets picked up the rescan within a day, from Ars Technica to PC World — unusual breadth for a single researcher's measurement, and a sign the industry is tracking remediation numbers as closely as the bug itself.

First-order effects

  • The roughly 300,000 operators still running unpatched OpenSSL on port 443 face continued exposure of private keys and session memory to any attacker who scans for the flaw.
  • Certificate authorities and large site operators keep paying the revocation bill: every newly patched host that rotates keys adds to CRL sizes and the bandwidth costs documented since mid-April.

Second-order effects

  • Hosting providers and enterprises with large TLS footprints face mounting pressure to automate patch deployment, since a month-long tail of 300,000 hosts shows manual remediation cannot keep pace with Internet-scale vulnerabilities.
  • Security vendors gain a recurring product line in continuous exposure scanning — Errata Security's serial rescans establish the format competitors will be pushed to match as long as the vulnerable population stays measurable.

Third-order effects

  • If disclosure-driven rescans become the standard yardstick, vulnerability severity will increasingly be judged by remediation curves rather than CVSS scores alone, shifting accountability toward whoever operates — or funds maintenance of — critical open-source infrastructure like OpenSSL.

The trend: Internet-wide vulnerability disclosure is entering a measurement era where researchers track patch-remediation decay curves publicly, exposing how long-tail and structurally underfunded open-source security maintenance is.