Researchers working with the badkeys project found hundreds of internet-exposed RSA and DSA keys whose private values were generated with strong zero-bit bias, creating distinctive “short-sleeve” patterns that made the keys vulnerable to recovery. By applying a polynomial-based factorization method to public-key datasets, they recovered 603 unique RSA private keys and 74 DSA keys tied to one recurring pattern, along with 26 additional RSA keys matching a second unexplained pattern observed in expired certificates and some NetApp-associated devices.
The primary pattern was traced to a type-mismatch flaw in EnterpriseDT’s CompleteFTP key-generation code, where 8-bit random bytes were copied into 32-bit big-integer limbs, weakening RSA keys generated in versions 10.0.0–12.0.0 and DSA keys in versions 10.0.0–23.0.4. EnterpriseDT released CompleteFTP v26.1.0 and a standalone detection tool to identify affected keys and prompt regeneration, while badkeys added support for detecting the vulnerable short-sleeve RSA pattern in public-key scans.

See real exploitation activity before you spend the cycle.
5 events from the most recent confirmed update back to the earliest known activity.
The badkeys project added detection support for the vulnerable short-sleeve RSA pattern so affected keys could be identified more easily. This was reported alongside EnterpriseDT's remediation steps.
By exploiting the structured zero-bit patterns, the researchers developed and applied a polynomial-based factorization method to recover 603 unique RSA private keys and 74 DSA keys tied to CompleteFTP. They also recovered 26 RSA keys associated with the second unexplained pattern.
The researchers traced one major short-sleeve key pattern to a type-mismatch bug in EnterpriseDT CompleteFTP's big-integer random generation code. The flaw affected RSA key generation in versions 10.0.0–12.0.0 and DSA key generation in versions 10.0.0–23.0.4.
Researchers working with the badkeys project found hundreds of RSA and DSA keys with heavily biased zero-bit patterns that made private key recovery feasible. They identified two recurring short-sleeve RSA patterns, one linked to CompleteFTP and another that remained unexplained.
EnterpriseDT responded by releasing CompleteFTP v26.1.0 along with a standalone tool to detect vulnerable keys and prompt regeneration. Malware News specifies this release occurred on May 8, 2026.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
4 references tracked. Mallory keeps watching after this page renders.
scworld.com
Open sourceschneier.com
Open sourcemalware.news
Open sourceblog.trailofbits.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.