Risky Bulletin Newsletter
April 17, 2024
Risky Biz News: PuTTY crypto bug exposes private keys, may lead to supply chain attacks
Presented by
News Editor
A team of German academics has discovered a crypto vulnerability in PuTTY, an extremely popular SSH and Telnet client for Windows users.
The vulnerability allows attackers who run malicious SSH servers to observe cryptographic signatures and recover a user's private key. This allows attackers to connect to systems where the private keys are being used for authentication.
But the vulnerability main impact is on source code repositories if they've been managed via a client that embeds PuTTY.