Skip to main content

Over 300,000 servers remain vulnerable to Heartbleed after initial wave of patches

Over 300,000 servers remain vulnerable to Heartbleed after initial wave of patches

Share this story

Two months ago, security experts and web users panicked when a Google engineer discovered a major bug — known as Heartbleed — that put over a million web servers at risk. The bug doesn't make the news much anymore, but that doesn't mean the problem's solved. Security researcher Robert David Graham has found that at least 309,197 servers are still vulnerable to the exploit.

Immediately after the announcement, Graham found some 600,000 servers were exposed by Heartbleed. One month after the bug was announced, that number dropped down to 318,239. In the past month, however, only 9,042 of those servers have been patched to block Heartbleed. That's cause for concern, because it means that smaller sites aren't making the effort to implement a fix.

Considering the numbers, it's likely that the lightly-trod corners of the internet will remain vulnerable for many years to come, as sites with sub-par security standards continue to leave themselves — and their users — exposed. The danger is particularly real now since the exploit has been widely publicized. The bug, which affects the OpenSSL protocol used widely online, can cause some serious damage — it can be exploited to give hackers encryption keys, passwords, and other sensitive information.