OpenSSH 10.3 patches five security bugs and drops legacy rekeying support
2026-04-02T14:51:49Z•66075335e90003fafc8e1495612f3b5e7f9760f0fc7c3f41aacb6675f1752b69
5GAppleAxiosCVE-2026-3502Check PointDarkSwordExchange OnlineHasbroHigh Volume EmailNorth KoreaOpenSSHRed Hat Enterprise LinuxTrueConfUNC1069compatibilitydata breachdrone detectionextended life cycleiOS 18npmrekeyingsupply-chainzero-day
What happened
This feed aggregates multiple security news items: OpenSSH 10.3 is released with five security fixes and drops legacy rekeying compatibility (may break older SSH implementations); a TrueConf client zero-day (CVE-2026-3502) is being exploited to deliver malware into government networks as reported by Check Point; Apple extended iOS 18 security updates after active exploitation tied to the DarkSword exploit kit; an npm supply-chain compromise of Axios packages is attributed to North Korean actors (links to UNC1069); Hasbro confirmed a disruptive cyberattack; Microsoft launched High Volume Email(
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- helpnetsecurity
- Record identifier
- 66075335e90003fafc8e1495612f3b5e7f9760f0fc7c3f41aacb6675f1752b69
- Enrichment time
- 2026-04-02T14:51:49Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.