A severe flaw in PuTTY and several applications that reuse its code can expose private keys used with the NIST P-521 ECDSA algorithm. The weakness causes the software to generate insufficiently random nonces, allowing an attacker to recover a victim’s private key after collecting roughly 60 signatures from the vulnerable implementation. The issue affects PuTTY as well as tools including FileZilla, WinSCP, and TortoiseGit; users of TortoiseSVN were advised to replace Plink with the latest PuTTY version until an official fix becomes available. Organizations were urged to update immediately and treat any affected P-521 key pairs as potentially compromised because recovered keys could be reused for SSH authentication or other trusted public-key access.
Separately, a critical compromise in XZ Utils introduced malicious code into versions 5.6.0 and 5.6.1, creating a supply-chain backdoor that could enable unauthorized access on affected Linux systems, with SSH identified as a primary exposure path. Defenders were advised to downgrade to version 5.4.6 immediately, consider disabling SSH if rollback was not possible, and verify system integrity because patching alone may not be enough if the backdoor was already exploited. The alerts noted that some Linux distributions had shipped the tainted versions while others were not observed to be vulnerable or had already issued updates.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
4 events from the most recent confirmed update back to the earliest known activity.
Fixed versions became available for PuTTY, FileZilla, WinSCP, and TortoiseGit following disclosure of the ECDSA flaw, while TortoiseSVN users were advised to replace Plink with the latest PuTTY version until an official fix is released.
A serious vulnerability was disclosed in PuTTY's implementation of the NIST P-521 ECDSA algorithm, where weak nonce generation could allow an attacker to recover a private key after collecting about 60 signatures from the vulnerable implementation.
Guidance was issued to immediately downgrade XZ Utils to version 5.4.6 or disable SSH if rollback was not possible, with some Linux distributions already releasing updates while users were warned to verify system integrity in case exploitation had occurred.
A critical supply-chain compromise was identified in XZ Utils versions 5.6.0 and 5.6.1, where malicious code introduced a backdoor that could enable unauthorized access, particularly via SSH on affected Linux systems.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
kyberturvallisuuskeskus.fi
Open sourcekyberturvallisuuskeskus.fi
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.