Security researchers have discovered a new variant of an old encryption attack that can be used to intercept data from the HTTPS protocol. This attack has been named ROBOT (Return Of Bleichenbacher's Oracle Threat) as it is based on the old “Bleichenbacher” attack on the RSA algorithm. Let's take a look at its history…
In 1998, Daniel Bleichenbacher of Bell Laboratories discovered a bug in the operation of TLS servers, specifically in the encryption of the security key between server and client. When a client (browser) and a server start communicating with each other via HTTPS, the client chooses a random key to encrypt the server's public key. Because the RSA algorithm is not very secure, another layer with random bits on the key is used for greater protection. The problem is found in the case of someone using the PKCS(PUBLIC Kia Cryptography Standards) #1 1.5 system, as the attacker can learn what the key is for decrypting messages between the server and client through a simple brute-force attack.
Returning to 2017, the three researchers report that the problem lies mainly in the server equipment offered by various manufacturers (Cisco, Citrix, F5, Radware) which do not comply with the TLS RFC 5246 standard (Section 7.4.7.1), therefore using the specific encryption system with this vulnerability.
In a test conducted by researchers on Alexa's Top 100 sites, they discovered that 27 have this security flaw, including the well-known Facebook and PayPal.
Until a patch is released, the solution is to disable RSA encryption on HTTPS(TLS) connections and use ECDH. For those interested, there is also a Python script that was created for server admins to check if this vulnerability exists on their network. (https://github.com/robotattackorg/robot-detect)

