logo

In a first, cryptographic keys protecting SSH connections stolen in new attack

ID: 86b68407-33b8-5ff3-ab77-1ce744adba18

STIX ID: report--86b68407-33b8-5ff3-ab77-1ce744adba18

Feed Name: Ars Technica Security

Threat Score
70/100

Date Published: 2023-11-13

Date Updated: 2026-04-19

Author: Dan Goodin

...
...

Research analyzing active SSH scan data found multiple vendor SSH implementations producing faulty RSA signatures that leak private keys. These faults—observed across thousands of signatures for vendors such as Zyxel and others—allow passive observers to recover keys and perform man-in-the-middle impersonation to steal credentials; the root causes are unclear (possible crypto accelerator bugs, memory/storage corruption, or transient bit-flips), and some devices show transient faults while others remain consistently vulnerable.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.