Yubico issued a security advisory saying an issue impacting YubiKey FIPS Series devices reduces the strength of generated RSA keys and ECDSA signatures after power-up. The company runs an active key replacement program for all impacted FIPS keys with the majority of affected devices having been replaced, or are in process of replacement with updated, fixed versions of the devices. The issue only affects certain use cases in certain use scenarios in certain scenarios, the Yubi key is more at risk than others since the weakened signatures could allow potential attackers to reconstruct the private key.
Source: https://www.bleepingcomputer.com/news/security/some-yubikey-fips-keys-allow-attackers-to-reconstruct-private-keys/

