SSH protects the world’s most sensitive networks. It just got a lot weakerArs Technica · Security·Dec 19, 17:35 UTC · Dec 19, 2023VulnerabilityCVE-2023-48795CVE-2023-46445CVE-2023-4644647
In a first, cryptographic keys protecting SSH connections stolen in new attackArs Technica · Security·Nov 15, 00:00 UTC · Nov 15, 2023Vulnerability30
Cybercriminals Weaponizing Open-Source SSHThe Hacker News·Feb 23, 03:18 UTC · Feb 23, 2024Vulnerability in the wild57
Quickly audit and adjust SSH server configurations with SSH-auditHelp Net Security·Jul 31, 22:19 UTC · Jul 31, 2018Vulnerability30
Cloud Atlas group acquires PowerCloud, ReverseSocks, SSHKaspersky Securelist·May 22, 09:12 UTC · May 22, 2026VulnerabilityCVE-2018-080247
OpenSSH 10.3 patches five security bugs and drops legacy rekeying supportHelp Net Security·Jun 19, 12:13 UTC · Jun 19, 2026Vulnerability30
Critical Erlang/OTP SSH Vulnerability (CVSS 10.0) Allows Unauthenticated Code ExecutionThe Hacker News·Apr 24, 12:41 UTC · Apr 24, 2025VulnerabilityCVE-2025-3243360
SSH vulnerability exploitable in Terrapin attacks (CVE-2023-48795)Help Net Security·Dec 19, 00:00 UTC · Dec 19, 2023VulnerabilityCVE-2023-48795CVE-2023-46445CVE-2023-4644635
UAT-6382 exploits Cityworks zeroCisco Talos·May 22, 10:00 UTC · May 22, 2025Vulnerability in the wildCVE-2025-0994CVE-2025-094460
SSHamble: Open-source security testing of SSH servicesHelp Net Security·Aug 8, 00:00 UTC · Aug 8, 2024Vulnerability55
Nexpose appliances were shipped with a weak default SSH configurationSecurity Affairs·Jun 4, 09:12 UTC · Jun 4, 2017VulnerabilityCVE-2017-524335
GitKraken flaw lead to the generation of weak SSH keysSecurity Affairs·Oct 12, 14:23 UTC · Oct 12, 2021Vulnerability30
Bitwarden centralizes cryptographic key managementHelp Net Security·Jan 29, 00:00 UTC · Jan 29, 2025Vulnerability55
Cisco warns of hard-coded credentials and default SSH key issues in some productsSecurity Affairs·Nov 4, 20:19 UTC · Nov 4, 2021VulnerabilityCVE-2021-34795CVE-2021-4011960
Expert found a hardcoded SSH Key in Fortinet SIEM appliancesSecurity Affairs·Jan 21, 06:14 UTC · Jan 21, 2020VulnerabilityCVE-2019-1765935
Cisco Security Appliances contain a default SSH KeySecurity Affairs·Jun 26, 06:16 UTC · Jun 26, 2015Vulnerability55
New Terrapin Flaw Could Let Attackers Downgrade SSH Protocol SecurityThe Hacker News·Jan 4, 08:25 UTC · Jan 4, 2024VulnerabilityCVE-2023-4879560
OAS Engine Deep Dive: Abusing low-impact vulnerabilities to escalate privilegesCisco Talos·Jan 31, 17:00 UTC · Jan 31, 2024VulnerabilityCVE-2023-31242CVE-2023-34998CVE-2023-32615+2 CVEs35
Terrapin attack allows to downgrade SSH protocol securitySecurity Affairs·Jan 2, 10:18 UTC · Jan 2, 2024VulnerabilityCVE-2023-4879560
CVE-2018-15919 username enumeration flaw affects OpenSSH Versions Since 2011Security Affairs·Aug 29, 20:35 UTC · Aug 29, 2018VulnerabilityCVE-2018-15919CVE-2018-1547360
Millions still haven’t patched Terrapin SSH protocol vulnerabilityArs Technica · Security·Jan 3, 21:49 UTC · Jan 3, 2024VulnerabilityCVE-2023-4879535
Static SSH host key in Cisco Umbrella allows stealing admin credentialsSecurity Affairs·Apr 21, 12:11 UTC · Apr 21, 2022VulnerabilityCVE-2022-2077347
Microsoft Says Chinese Hackers Were Behind SolarWinds Serv-U SSH 0The Hacker News·Sep 6, 10:12 UTC · Sep 6, 2021Vulnerability in the wildCVE-2021-3521160
Keys, tokens and too much trust found in container imagesHelp Net Security·Jun 19, 22:20 UTC · Jun 19, 2017Vulnerability30
Attackers Use LLM Agent for Post-Exploitation After Marimo CVE-2026The Hacker News·May 31, 12:13 UTC · May 31, 2026Vulnerability in the wildCVE-2026-3998760
PuTTY SSH Client flaw allows of private keys recoverySecurity Affairs·Apr 16, 19:04 UTC · Apr 16, 2024VulnerabilityCVE-2024-3149760
Hardcoded SSH Key in Cisco Policy Suite Lets Remote Hackers Gain Root AccessThe Hacker News·Nov 5, 06:15 UTC · Nov 5, 2021VulnerabilityCVE-2021-40119CVE-2021-34795CVE-2021-40113+3 CVEs60
SSH bug exposes more than 2M IoT Devices to SSHowDowN Proxy attacksSecurity Affairs·Oct 14, 09:51 UTC · Oct 14, 2016VulnerabilityCVE-2004-165347
Erlang/OTP SSH Vulnerability Sees Spike in Exploitation AttemptsInfosecurity Magazine·Aug 13, 16:45 UTC · Aug 13, 2025Vulnerability in the wildCVE-2025-3243360
Researchers Spot Surge in Erlang/OTP SSH RCE Exploits, 70% Target OT FirewallsThe Hacker News·Aug 11, 15:08 UTC · Aug 11, 2025Vulnerability in the wildCVE-2025-3243360
Widely-Used PuTTY SSH Client Found Vulnerable to Key Recovery AttackThe Hacker News·Apr 17, 07:58 UTC · Apr 17, 2024VulnerabilityCVE-2024-3149760
New OpenSSH Vulnerability Exposes Linux Systems to Remote Command InjectionThe Hacker News·Jul 24, 10:05 UTC · Jul 24, 2023VulnerabilityCVE-2023-38408CVE-2023-2513635
Expert found RCE in Visual Studio Code Remote Development ExtensionSecurity Affairs·Sep 27, 18:39 UTC · Sep 27, 2021VulnerabilityCVE-2020-1714847
Watchbog and the Importance of PatchingCisco Talos·Sep 11, 16:10 UTC · Sep 11, 2019VulnerabilityCVE-2018-100086135
WAGO Industrial Switches affected by multiple flawsSecurity Affairs·Jun 13, 21:42 UTC · Jun 13, 2019VulnerabilityCVE-2017-16544CVE-2015-0235CVE-2019-1255060
12-Year-Old SSH Bug Exposes More than 2 Million IoT DevicesThe Hacker News·Oct 15, 00:00 UTC · Oct 15, 2016VulnerabilityCVE-2004-165360
Weathering the storm: In the midst of a TyphoonCisco Talos·Feb 20, 13:00 UTC · Feb 20, 2025VulnerabilityCVE-2018-0171CVE-2023-20198CVE-2023-20273+1 CVEs47