89
OpenSSH vulnerabilities could pose huge threat to businesses everywhere
(www.techradar.com)
This is a most excellent place for technology news and articles.
Soo, the point is to not enable features that undermine security, like using an FQDN as a key (or source of a key) and to enable features that reduce DoS, like a connection timeout. Does not sound like bugs, just like missing default options.
It's still important to not use the affecting options.