Around 300,000 OpenSSL servers still vulnerable to Heartbleed vulnerability. Only 9,000 servers have been patched in the past month. Many of those servers are likely not likely to get patched anytime soon. The flaw allows attackers to extract information from memory of servers that run OpenSSL 1.0.1 through 1.1.1f, if they support an SSL feature called “heartbeat” The flaw was publicly disclosed in early April and can be used to extract user passwords and private keys.”]

