Cloudflare, Mozilla, and Opera moved to disable or sharply reduce support for SSLv3 after the disclosure of POODLE, a flaw that lets a man-in-the-middle force encrypted web sessions to downgrade from TLS to SSLv3 and then exploit a CBC padding oracle to recover sensitive data such as HTTP cookies. Mozilla said the issue affected any browser or site that still supported SSLv3, even if newer TLS versions were available, because insecure fallback behavior made downgrade attacks practical; its telemetry showed SSLv3 still accounted for roughly 0.3% of Firefox HTTPS connections, while external measurements found about 0.42% of the Alexa top million domains still relied on it in some way.
In response, Cloudflare disabled SSLv3 by default, Mozilla said Firefox 34 would turn off SSLv3 by default and Firefox 35 would add TLS_FALLBACK_SCSV downgrade protection, and Opera announced multiple mitigations across desktop and Android, including anti-POODLE record splitting, support for TLS_FALLBACK_SCSV, removal of security indicators for SSLv3-only sites, and disabling SSLv3 in Opera 12 desktop. Vendors also urged website operators to retire SSLv3 and migrate to modern TLS, while Opera noted its main servers had already been patched and that Opera Mini clients were not affected.

See real exploitation activity before you spend the cycle.
5 events from the most recent confirmed update back to the earliest known activity.
Opera announced anti-POODLE record splitting in Opera 25 for desktop and Android, support for TLS_FALLBACK_SCSV, removal of security indicators for SSLv3-only sites, and disabling SSLv3 in Opera 12 desktop. Opera also said its main servers had been patched, while noting iOS fixes depended on Apple's SSL stack.
Microsoft published Security Advisory 3009008 for CVE-2014-3566, stating that all supported Windows versions implementing SSL 3.0 were affected by the protocol flaw and recommending customers disable SSL 3.0 and migrate to TLS. Microsoft said it was not aware of active attacks at the time and noted its online services would phase out SSL 3.0 support.
Mozilla said Firefox 34 would disable SSLv3 by default on November 25, 2014, and that Firefox 35 would add TLS_FALLBACK_SCSV downgrade protection. It also urged website operators to disable SSLv3 and migrate to modern TLS.
Cloudflare announced that it had disabled SSLv3 support by default across its service in response to the POODLE vulnerability, aiming to reduce customer exposure to downgrade attacks against the obsolete protocol.
Google researchers identified the POODLE vulnerability in SSLv3, showing that a man-in-the-middle attacker could force protocol downgrades and exploit CBC padding weaknesses to recover sensitive data such as cookies from encrypted sessions.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
7 references tracked. Mallory keeps watching after this page renders.
technet.microsoft.com
Open sourceblogs.opera.com
Open sourceblog.mozilla.org
Open sourceimperialviolet.org
Open sourceblog.cloudflare.com
Open sourcepraetorian.com
Open sourceopenssl.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.