security1 distinct publisher
Any valid atSign identity could write itself into a NoPorts host's authorized_keys
UltraViolet Cyber's Zonifer chained a missing manager check with an inverted strncmp in Atsign's C sshnpd daemon. Atsign patched in four days, and the CVE that inventory tools would match on is still pending.
Publishers:uvcyber.com
Reality
- Evidence52
- Adoption20
- Hype gap+18
- Incentives75