A security flaw called Heartbleed was discovered in the OpenSSL encryption software that is widely used on the internet. The flaw allowed hackers to access passwords, credit card numbers, and other sensitive data without leaving a trace for over 2 years. Users are advised to change passwords on websites that may have been affected and to check if websites have patched the vulnerability.