AutoAddPolicy in Paramiko Disables Host Key Verification and Risks Credential Leakage After IP Reassignment
A developer maintained fourteen separate scripts that performed deployment, service restarts, DNS changes, and mail diagnostics against a production VPS. Each script contained its own copy of the target IP address, a classic copy-paste pattern that survived until the provider migrated the instance.
After the move the old address was promptly reassigned to another customer. Instead of fourteen connection timeouts, every script established an SSH session to the new owner’s server and transmitted the root password stored in the environment variable VPS_PASS.
What AutoAddPolicy Actually Does
When an SSH client connects, the server presents its host key. The client compares this key against entries in known_hosts. A mismatch normally produces the warning “REMOTE HOST IDENTIFICATION HAS CHANGED!” and aborts the session. AutoAddPolicy replaces this check with an unconditional acceptance of any key, eliminating both the warning and the protection.
The policy is often described only as defense against man-in-the-middle attacks. In cloud environments the more immediate risk is simple IP reassignment: the provider reclaims the address and hands it to the next tenant without malice or interception.
Three Required Fixes
- Load system and user host keys explicitly and enforce RejectPolicy so that an unknown or changed key raises an exception before any credentials are sent.
- Store the target address in a single shared module (vps.py) imported by all scripts, eliminating the possibility of fourteen stale copies.
- Prefer key-based authentication; fall back to password only when no key file exists. The private key never leaves the client, so even an unintended connection yields nothing usable to the recipient.
The same trust problem appears when a web service fetches user-supplied URLs. The author’s checker therefore restricts requests to http and https, resolves names before connecting, rejects private, loopback, and link-local ranges, and re-validates after every redirect.
Smoke tests confirm that attempts to reach 127.0.0.1, 169.254.169.254, and file:///etc/passwd are blocked. The incident shows that disabling host-key verification is not a harmless convenience; it is the removal of a control that becomes critical the moment an IP address changes ownership.
Related articles
CISA Adds Five Actively Exploited Vulnerabilities in Apache Struts, BIND, ProFTPD, Strapi and ONLYOFFICE Docs to KEV Catalog
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added five vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog on October 8, 2026, confirming active exploitation in the wild. The affected products include Apache Struts, BIND, ProFTPD, Strapi, and ONLYOFFICE Docs, with CVEs issued between 2015 and 2023. Federal agencies have until October 11, 2026, to apply mitigations or remove affected systems. One highlighted issue, Strapi CVE-2023-22894, stems from plaintext storage of sensitive information, allowing authenticated attackers to extract user data via query filters. When combined with CVE-2023-22621, the flaws enable remote code execution. CISA also warned that some impacted products may no longer receive vendor support.
FBI Issues Alert on Active FortiBleed Campaign Harvesting Credentials from Exposed FortiGate Firewalls
The FBI and United States Secret Service have issued a joint alert regarding the FortiBleed campaign, an ongoing operation that targets internet-exposed FortiGate firewalls and SSL VPN gateways. Attackers have already collected 86,644 valid credentials from devices across 194 countries as of June 19, demonstrating the global scale of the indiscriminate scanning effort. The campaign relies on reused or previously leaked credentials combined with legacy SHA-256 password storage that enables offline cracking. Operators employ automated credential stuffing, the Go-based FortigateSniffer tool capable of intercepting 24 authentication protocols, and GPU-accelerated password cracking. Once inside, attackers create unauthorized administrator accounts and often delete legitimate ones, forcing victims to perform full device recovery rather than simple password resets. The activity was first documented in June, with the official alert released on October 7, confirming that scanning continues.
Cisco Patches 14 Vulnerabilities in NX-OS Software, Four Rated Critical
Cisco Systems has released security updates addressing 14 vulnerabilities in its Cisco NX-OS Software used in network devices. Four of the seven security advisories published on October 7, 2026, are rated Critical, while three are rated Medium. Several critical issues affect the Cisco Nexus 3000 Series and Nexus 9000 Series switches, impacting features such as NGOAM, MPLS OAM, and the NX-API management interface. Seven vulnerabilities received CVSSv3.1 base scores of 9.0 or higher, with multiple flaws enabling remote code execution as root or denial-of-service conditions. Specific CVEs including CVE-2026-76485, CVE-2026-76486, and CVE-2026-76501 stem from input validation failures in the NGOAM feature and may require SRv6 or NV Overlay configurations to be exploitable. The advisories also cover control plane denial-of-service issues, Python sandbox escapes, and endpoint group contract bypasses in ACI mode.
HPE Networking ClearPass Policy Manager Hit by 28 Vulnerabilities Including 10 Rated Critical
Hewlett Packard Enterprise has disclosed 28 vulnerabilities in its HPE Networking ClearPass Policy Manager product and released security updates to address them. The issues span the web management interface, APIs, endpoint agents, and client software components. Ten of the flaws received a Critical severity rating. Notable issues include SQL injection, multiple authentication bypasses, unsafe deserialization leading to remote code execution, and path traversal. No public exploit code or active discussions were observed at the time the advisory was published on October 6, 2026. The company urges customers to apply the available patches promptly.