logo

Nearly 11 million SSH servers vulnerable to new Terrapin attacks

ID: fa53c91c-4620-5458-9eec-307a31caef26

STIX ID: report--fa53c91c-4620-5458-9eec-307a31caef26

Feed Name: Bleeping Computer

Threat Score
70/100

Date Published: 2024-01-03

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

Researchers disclosed the Terrapin attack against SSH, a handshake-sequence-number manipulation that can compromise channel integrity and downgrade authentication when certain encryption modes (e.g., ChaCha20-Poly1305 or CBC with Encrypt-then-MAC) are used. Shadowserver reports ~11 million internet-exposed SSH servers (about 52% of scanned hosts) appear susceptible; exploitation requires an adversary-in-the-middle but gives attackers a large pool of targets and a scanner is available to check susceptibility.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.