{"type":"rich","version":"1.0","provider_name":"Transistor","provider_url":"https://transistor.fm","author_name":"Cybersecurity Tech Brief By HackerNoon","title":"Attested TLS Was Supposed to Be the Last Trust Boundary. It Isn't. Formal Methods Show How. ","html":"<iframe width=\"100%\" height=\"180\" frameborder=\"no\" scrolling=\"no\" seamless src=\"https://share.transistor.fm/e/420e4cee\"></iframe>","width":"100%","height":180,"duration":1512,"description":"\n        This story was originally published on HackerNoon at: https://hackernoon.com/attested-tls-was-supposed-to-be-the-last-trust-boundary-it-isnt-formal-methods-show-how.\nFormal methods researchers at TU Dresden found a relay attack in attested TLS. It hits Meta, Cocos AI, Edgeless Systems, and three IETF drafts.\nCheck more stories related to cybersecurity at: https://hackernoon.com/c/cybersecurity.\n            You can also check exclusive content about #cybersecurity, #cyber-threats, #confidential-computing, #cve, #open-source, #ietf, #ai-cyber-security, #hackernoon-top-story,  and more.\nThis story was written by: @salkimmich. Learn more about this writer by checking @salkimmich's about page,\n            and for more stories, please visit hackernoon.com.\nA relay attack breaks attested TLS, the mechanism confidential computing uses to prove a secure cloud enclave is genuine. Formal verification found it in Meta's WhatsApp privacy system, Edgeless Systems' Contrast, Cocos AI, and three IETF draft standards, none of which a prior manual security audit caught. It's tracked as CVE-2026-33697 (CVSS 7.5), with three more related CVEs near 9.1 still in disclosure.\n        \n        ","thumbnail_url":"https://img.transistorcdn.com/SySK4I0jwuU6AzeawZdYiDqTq8yzBjxJ5qfTpUuAxEo/rs:fill:0:0:1/w:400/h:400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS9zaG93/LzQxMjY2LzE2ODM1/ODIzNTYtYXJ0d29y/ay5qcGc.webp","thumbnail_width":300,"thumbnail_height":300}