We found a new vulnerability in TLS. It's a variant of the ALPACA attack that bypasses current countermeasures. Relativly low impact - but great insight! Check it out: opossum-attack.com
Fabian Bäumer
@skrillor.bsky.social
PhD Student @ruhr-uni-bochum.de | 🐢 Terrapin Attack | Interested in anything related to SSH and protocol security in general | Mastodon: @Skrillor@infosec.exchange
We (@lambdafu.bsky.social & me) found a critical security vulnerability in the #Erlang/OTP SSH daemon that allow attackers to execute arbitrary code via network access on devices running Erlang/OTP SSH servers. This vulnerability is #CVE-2025-32433, patches out now. Estimated CVSSv3 10.