Heartbleed bug exposes a flaw in OpenSSL, a cryptographic tool that provides communication security and privacy over the Internet for applications such as e-mail, instant messaging and some VPNs. Many organizations have made progress in remediating the risks, but some gaps still need to be addressed. Internal systems that are using the vulnerable OpenSSL libraries to secure communication are still vulnerable, experts say. Some sites have made the mistake of reusing the potentially compromised private key in the new certificate.”]
Source: https://www.databreachtoday.com/heartbleed-bug-what-risks-remain-a-6872

