Nearly 11 million SSH servers vulnerable to new Terrapin attacks
ID: fa53c91c-4620-5458-9eec-307a31caef26
STIX ID: report--fa53c91c-4620-5458-9eec-307a31caef26
Feed Name: Bleeping Computer
Researchers disclosed the Terrapin attack against SSH, a handshake-sequence-number manipulation that can compromise channel integrity and downgrade authentication when certain encryption modes (e.g., ChaCha20-Poly1305 or CBC with Encrypt-then-MAC) are used. Shadowserver reports ~11 million internet-exposed SSH servers (about 52% of scanned hosts) appear susceptible; exploitation requires an adversary-in-the-middle but gives attackers a large pool of targets and a scanner is available to check susceptibility.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
