Jenkins recently announced that their docker images ssh-agent (CVE-2025-32754) and ssh-slave (CVE-2025-32755) had pregenerated, static SSH host keys. They're now detected by badkeys. https://www.jenkins.io/security/advisory/2025-04-10/
badkeys
@badkeys@infosec.exchange
badkeys is an open-source tool and web service to identify compromised cryptographic keys.
infosec.exchange
10
0
4
Loading comments...