Of course this is just the latest example of a code vulnerability and the harsh conclusion for modern security is that you have to assume you have been compromised. Applications and code always contain vulnerabilities and heatbleed is just the latest example that has been made public

  • ‘Zero Day Problem’
  • Implementation Specific Vulnerabilities (Heartbeat)
  • Practice and Policy Vulnerabilities
  • Trust Anchor Vulnerabilities
  • Exposure of Secrets (Key Compromise)
  • Malicious Insiders
  • Misconfiguration Issues
  • Increased Abstraction via Virtualization and SDN

