Widely-Used PuTTY SSH Client Found Vulnerable to Key Recovery Attack (thehackernews.com)
from kid@sh.itjust.works to cybersecurity@sh.itjust.works on 17 Apr 2024 11:36
https://sh.itjust.works/post/17959385

#cybersecurity

threaded - newest

HubertManne@kbin.social on 17 Apr 2024 12:12 collapse

and remediated if using the latest version or latest version of things using it.

mp3@lemmy.ca on 17 Apr 2024 12:28 collapse

I’d consider the ecdsa-sha2-nistp521 private keys used with those versions as compromised, and suggest generating new private keys asap.

leds@feddit.dk on 17 Apr 2024 15:45 collapse

Does anyone know if the new versions of putty (or applications using putty likeTortoiseGIT) will warn users about this?