{
  "id": 12387154,
  "title": "OpenSSH 10.6 released",
  "url": "https://urgent.news/2026/10/06/openssh-10-6-released",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-10-06T13:42:48.000Z",
  "source": {
    "name": "LWN",
    "slug": "lwn",
    "url": "https://lwn.net/Articles/1098980/"
  },
  "original_language": "en",
  "account": "OpenSSH version 10.6 has been released, according to the latest announcement. The OpenSSH team has been inundated with AI-assisted security bug reports, to which they extend their appreciation, particularly when accompanied by human triage, analysis, test-cases and proposed fixes. Consequently, the project anticipates more frequent releases to deploy updates to users more swiftly, rather than consolidating bug fixes for the subsequent planned release.\n\nKey updates in this release include the activation of the hybrid post-quantum ssh-mldsa44-ed25519 signature algorithm, the introduction of a -p option for sftp s lmkdir / mkdir commands, and the disabling of the LZ77 dictionary coder in ssh and sshd to counteract side-channel leaks, resulting in diminished Compression option effectiveness. Furthermore, the scp -R option, facilitating file transfers between two remote hosts, is slated for deprecation due to identified security risks; it will be ignored moving forward. Interested parties can refer to the announcement for the comprehensive rundown of all modifications and bug fixes.",
  "summary": "Version 10.6 of OpenSSH has been released. The announcement notes that the OpenSSH team has been receiving a large number of AI-assisted security bug reports. \" We very much welcome these reports, especially when combined with human triage, analysis, test-cases and particularly when accompanied by proposed fixes \". As a result, the project expects to be making more frequent releases to get…",
  "key_points": [
    "OpenSSH 10.6 released with hybrid post-quantum signature algorithm",
    "-p option added for sftp s lmkdir / mkdir commands",
    "scp -R option deprecated due to security risks"
  ],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 1,
    "also_reported_by": []
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}