This was sent to me from a guy I work with around 12 today:
There appears to be a major OpenSSH vulnerability that is quietly being exploited at some high-profile targets. OpenSSH 3.7p1 was released earlier this am. Linux appears to be particularly vulnerable; no clear information on others such as OpenBSD, nor other versions/implementations of SSH.
Note that there are many implementations of SSH that run on many devices, including network appliance-class devices.
Until more information is available, system operators should patch your systems to OpenSSH >= 3.7p1 and check your firewalls allowing SSH only from trusted sources.