always set OP_NO_SSLv3 by default (closes #25530)
diff --git a/Misc/NEWS b/Misc/NEWS
index 2869f80..03aac95 100644
--- a/Misc/NEWS
+++ b/Misc/NEWS
@@ -49,6 +49,9 @@
 Library
 -------
 
+- Issue #25530: Disable the vulnerable SSLv3 protocol by default when creating
+  ssl.SSLContext.
+
 - Issue #25569: Fix memory leak in SSLSocket.getpeercert().
 
 - Issue #7759: Fixed the mhlib module on filesystems that doesn't support