#digicert — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #digicert, aggregated by home.social.
-
Golden Gh0st RAT let GoldenEyeDog subgroup CylindricalCanine steal DigiCert code-signing certificates and slip past Windows SmartScreen.
#GoldenGh0stRAT #CylindricalCanine #DigiCert #CodeSigning #Malware
https://meterpreter.org/golden-gh0st-rat/?utm_source=mastodon&utm_medium=jetpack_social
-
Golden Gh0st RAT let GoldenEyeDog subgroup CylindricalCanine steal DigiCert code-signing certificates and slip past Windows SmartScreen.
#GoldenGh0stRAT #CylindricalCanine #DigiCert #CodeSigning #Malware
https://meterpreter.org/golden-gh0st-rat/?utm_source=mastodon&utm_medium=jetpack_social
-
Just about the entire internet uses certificate authorities to establish trust. Here, a simple old-school social engineering trick broke this trust and allowed hackers to get signed certificates from DigiCert for their malware.
There is a better way to establish certificate trust that doesn't rely on a 3rd party, and it's free too. It's called DANE, which binds the trust directly to the Domain Name System by using DNSSEC. DANE is ideal for code signing certificates (and other uses), but is overlooked.
This attack is virtually impossible under DANE. A vulnerable support person is of no use. Hackers would need to directly compromise the target's DNS infrastructure, the registrar, and the top-level domain authority. All three. Nearly impossible compared to just finding some dupe at the CA in a public chat room.
https://hackread.com/hackers-digicert-issue-certificates-sign-malware/
-
Just about the entire internet uses certificate authorities to establish trust. Here, a simple old-school social engineering trick broke this trust and allowed hackers to get signed certificates from DigiCert for their malware.
There is a better way to establish certificate trust that doesn't rely on a 3rd party, and it's free too. It's called DANE, which binds the trust directly to the Domain Name System by using DNSSEC. DANE is ideal for code signing certificates (and other uses), but is overlooked.
This attack is virtually impossible under DANE. A vulnerable support person is of no use. Hackers would need to directly compromise the target's DNS infrastructure, the registrar, and the top-level domain authority. All three. Nearly impossible compared to just finding some dupe at the CA in a public chat room.
https://hackread.com/hackers-digicert-issue-certificates-sign-malware/
-
Just about the entire internet uses certificate authorities to establish trust. Here, a simple old-school social engineering trick broke this trust and allowed hackers to get signed certificates from DigiCert for their malware.
There is a better way to establish certificate trust that doesn't rely on a 3rd party, and it's free too. It's called DANE, which binds the trust directly to the Domain Name System by using DNSSEC. DANE is ideal for code signing certificates (and other uses), but is overlooked.
This attack is virtually impossible under DANE. A vulnerable support person is of no use. Hackers would need to directly compromise the target's DNS infrastructure, the registrar, and the top-level domain authority. All three. Nearly impossible compared to just finding some dupe at the CA in a public chat room.
https://hackread.com/hackers-digicert-issue-certificates-sign-malware/
-
Just about the entire internet uses certificate authorities to establish trust. Here, a simple old-school social engineering trick broke this trust and allowed hackers to get signed certificates from DigiCert for their malware.
There is a better way to establish certificate trust that doesn't rely on a 3rd party, and it's free too. It's called DANE, which binds the trust directly to the Domain Name System by using DNSSEC. DANE is ideal for code signing certificates (and other uses), but is overlooked.
This attack is virtually impossible under DANE. A vulnerable support person is of no use. Hackers would need to directly compromise the target's DNS infrastructure, the registrar, and the top-level domain authority. All three. Nearly impossible compared to just finding some dupe at the CA in a public chat room.
https://hackread.com/hackers-digicert-issue-certificates-sign-malware/
-
Just about the entire internet uses certificate authorities to establish trust. Here, a simple old-school social engineering trick broke this trust and allowed hackers to get signed certificates from DigiCert for their malware.
There is a better way to establish certificate trust that doesn't rely on a 3rd party, and it's free too. It's called DANE, which binds the trust directly to the Domain Name System by using DNSSEC. DANE is ideal for code signing certificates (and other uses), but is overlooked.
This attack is virtually impossible under DANE. A vulnerable support person is of no use. Hackers would need to directly compromise the target's DNS infrastructure, the registrar, and the top-level domain authority. All three. Nearly impossible compared to just finding some dupe at the CA in a public chat room.
https://hackread.com/hackers-digicert-issue-certificates-sign-malware/
-
#DigiCert und die Sicherheit. 🙁
Kriminelle sind kreativ wie man sehen kann:
"On 2 April 2026, DigiCert’s support team became the target of a carefully planned attack, which allowed hackers to steal EV Code Signing certificates by simply pretending to be a customer in a help chat."
Und wie ging es weiter:
"While the company thought the situation was under control by 3 April, a second machine, ENDPOINT2, was also compromised on 4 April. This machine had a malfunctioning CrowdStrike sensor, which created a gap in their Endpoint Detection and Response (EDR), due to which no telemetry data reached the security team to warn them of the breach."
Und was bedeutet das nun:
"DigiCert revokes 60 code signing certificates after hackers used a malicious support chat attachment to sign the Zhong Stealer malware."
Da ist also nicht ganz so sicher wie man es gerne hätte. Wünsche den Admins viel Erfolg bei den Updates. 🙂
https://hackread.com/hackers-digicert-issue-certificates-sign-malware/
-
📢⚠️ Hackers tricked #DigiCert support staff into executing a malicious file, allowing attackers to obtain code-signing certificates later used to sign malware. DigiCert revoked 60 certificates after the breach was reported.
Read: https://hackread.com/hackers-digicert-issue-certificates-sign-malware/
-
📢⚠️ Hackers tricked #DigiCert support staff into executing a malicious file, allowing attackers to obtain code-signing certificates later used to sign malware. DigiCert revoked 60 certificates after the breach was reported.
Read: https://hackread.com/hackers-digicert-issue-certificates-sign-malware/
-
📢⚠️ Hackers tricked #DigiCert support staff into executing a malicious file, allowing attackers to obtain code-signing certificates later used to sign malware. DigiCert revoked 60 certificates after the breach was reported.
Read: https://hackread.com/hackers-digicert-issue-certificates-sign-malware/
-
📢⚠️ Hackers tricked #DigiCert support staff into executing a malicious file, allowing attackers to obtain code-signing certificates later used to sign malware. DigiCert revoked 60 certificates after the breach was reported.
Read: https://hackread.com/hackers-digicert-issue-certificates-sign-malware/
-
📢⚠️ Hackers tricked #DigiCert support staff into executing a malicious file, allowing attackers to obtain code-signing certificates later used to sign malware. DigiCert revoked 60 certificates after the breach was reported.
Read: https://hackread.com/hackers-digicert-issue-certificates-sign-malware/
-
#LetsEncrypt has suspended issuing certificates after it identified security issues in one of its roots (!)[^1]
We temporarily disabled certificate issuance, deployed a configuration change to prevent future issuance from the cross-signed Gen Y hierarchy, and then re-enabled issuance. Certificate revocation and CRL generation remains functional for Gen Y certificates.
A few days ago #DigiCert was hacked with a Windows (!) screensaver (!)[^2]
I cannot but remind that both organisations are part of the #WebTrust cartel who had last year unrolled a massive “grassroots” smear campaign against EU #QWAC certificates, presenting them as “security and privacy threat”, whereas from both legal and technical point of view QWAC is much more secure:
https://krvtz.net/en/posts/the-real-story-behind-eu-qwac.html
[^2]: https://cybersecuritynews.com/digicert-hacked-screensaver/
-
#LetsEncrypt has suspended issuing certificates after it identified security issues in one of its roots (!)[^1]
We temporarily disabled certificate issuance, deployed a configuration change to prevent future issuance from the cross-signed Gen Y hierarchy, and then re-enabled issuance. Certificate revocation and CRL generation remains functional for Gen Y certificates.
A few days ago #DigiCert was hacked with a Windows (!) screensaver (!)[^2]
I cannot but remind that both organisations are part of the #WebTrust cartel who had last year unrolled a massive “grassroots” smear campaign against EU #QWAC certificates, presenting them as “security and privacy threat”, whereas from both legal and technical point of view QWAC is much more secure:
https://krvtz.net/en/posts/the-real-story-behind-eu-qwac.html
[^2]: https://cybersecuritynews.com/digicert-hacked-screensaver/
-
#LetsEncrypt has suspended issuing certificates after it identified security issues in one of its roots (!)[^1]
We temporarily disabled certificate issuance, deployed a configuration change to prevent future issuance from the cross-signed Gen Y hierarchy, and then re-enabled issuance. Certificate revocation and CRL generation remains functional for Gen Y certificates.
A few days ago #DigiCert was hacked with a Windows (!) screensaver (!)[^2]
I cannot but remind that both organisations are part of the #WebTrust cartel who had last year unrolled a massive “grassroots” smear campaign against EU #QWAC certificates, presenting them as “security and privacy threat”, whereas from both legal and technical point of view QWAC is much more secure:
https://krvtz.net/en/posts/the-real-story-behind-eu-qwac.html
[^2]: https://cybersecuritynews.com/digicert-hacked-screensaver/
-
#LetsEncrypt has suspended issuing certificates after it identified security issues in one of its roots (!)[^1]
We temporarily disabled certificate issuance, deployed a configuration change to prevent future issuance from the cross-signed Gen Y hierarchy, and then re-enabled issuance. Certificate revocation and CRL generation remains functional for Gen Y certificates.
A few days ago #DigiCert was hacked with a Windows (!) screensaver (!)[^2]
I cannot but remind that both organisations are part of the #WebTrust cartel who had last year unrolled a massive “grassroots” smear campaign against EU #QWAC certificates, presenting them as “security and privacy threat”, whereas from both legal and technical point of view QWAC is much more secure:
https://krvtz.net/en/posts/the-real-story-behind-eu-qwac.html
[^2]: https://cybersecuritynews.com/digicert-hacked-screensaver/
-
#LetsEncrypt has suspended issuing certificates after it identified security issues in one of its roots (!)[^1]
We temporarily disabled certificate issuance, deployed a configuration change to prevent future issuance from the cross-signed Gen Y hierarchy, and then re-enabled issuance. Certificate revocation and CRL generation remains functional for Gen Y certificates.
A few days ago #DigiCert was hacked with a Windows (!) screensaver (!)[^2]
I cannot but remind that both organisations are part of the #WebTrust cartel who had last year unrolled a massive “grassroots” smear campaign against EU #QWAC certificates, presenting them as “security and privacy threat”, whereas from both legal and technical point of view QWAC is much more secure:
https://krvtz.net/en/posts/the-real-story-behind-eu-qwac.html
[^2]: https://cybersecuritynews.com/digicert-hacked-screensaver/
-
📢 DigiCert compromis via ingénierie sociale : émission non autorisée de certificats EV Code Signing
📝 ## 🔍 ContexteSource : Help Net Security, publié le 4 mai 2026.
📖 cyberveille : https://cyberveille.ch/posts/2026-05-08-digicert-compromis-via-ingenierie-sociale-emission-non-autorisee-de-certificats-ev-code-signing/
🌐 source : https://www.helpnetsecurity.com/2026/05/04/digicert-breach-code-signing-certificates-malware/
#Code_Signing #DigiCert #Cyberveille -
📢 Faux positifs Microsoft Defender sur certificats DigiCert liés à une brèche réelle de l'AC
📝 ## 🗓️ ContextePublié le 3 mai 2026 sur BleepingComputer par La...
📖 cyberveille : https://cyberveille.ch/posts/2026-05-06-faux-positifs-microsoft-defender-sur-certificats-digicert-lies-a-une-breche-reelle-de-l-ac/
🌐 source : https://www.bleepingcomputer.com/news/security/microsoft-defender-wrongly-flags-digicert-certs-as-trojan-win32-cerdigentadha/
#APT_Q_27 #DigiCert #Cyberveille -
Defender Misflags DigiCert Root Certificates, Breaking Windows SSL Trust
#MicrosoftDefender #Microsoft #DigiCert #Cybersecurity #Malware #AntivirusSoftware #WindowsSecurity #ThreatIntelligence #Windows11 #MicrosoftWindows
-
Defender Misflags DigiCert Root Certificates, Breaking Windows SSL Trust
#MicrosoftDefender #Microsoft #DigiCert #Cybersecurity #Malware #AntivirusSoftware #WindowsSecurity #ThreatIntelligence #Windows11 #MicrosoftWindows
-
Defender Misflags DigiCert Root Certificates, Breaking Windows SSL Trust
#MicrosoftDefender #Microsoft #DigiCert #Cybersecurity #Malware #AntivirusSoftware #WindowsSecurity #ThreatIntelligence #Windows11 #MicrosoftWindows
-
Defender Misflags DigiCert Root Certificates, Breaking Windows SSL Trust
#MicrosoftDefender #Microsoft #DigiCert #Cybersecurity #Malware #AntivirusSoftware #WindowsSecurity #ThreatIntelligence #Windows11 #MicrosoftWindows
-
Defender Misflags DigiCert Root Certificates, Breaking Windows SSL Trust
#MicrosoftDefender #Microsoft #DigiCert #Cybersecurity #Malware #AntivirusSoftware #WindowsSecurity #ThreatIntelligence #Windows11 #MicrosoftWindows
-
Genau bei der Zertifizierung von solcher Software hat nun aber die Zertifizierungsstelle #DigiCert sich übertölpeln lassen. Und zwar in der teuersten und damit angeblich sichersten Kategorie «Extended Validation» (EV). So wurden mindestens 27 Code-Signing-Zertifikate im Namen von reputablen Firmen ausgestellt, aber für Cyberkriminelle. Digicert ist dem erst nachgegangen, als über 8 Tage hinweg 7 missbräuchliche Zertifikate durch Dritte gemeldet wurden.
https://mastodon.social/@hrbrmstr/116516180487899285 -
Genau bei der Zertifizierung von solcher Software hat nun aber die Zertifizierungsstelle #DigiCert sich übertölpeln lassen. Und zwar in der teuersten und damit angeblich sichersten Kategorie «Extended Validation» (EV). So wurden mindestens 27 Code-Signing-Zertifikate im Namen von reputablen Firmen ausgestellt, aber für Cyberkriminelle. Digicert ist dem erst nachgegangen, als über 8 Tage hinweg 7 missbräuchliche Zertifikate durch Dritte gemeldet wurden.
https://mastodon.social/@hrbrmstr/116516180487899285 -
Genau bei der Zertifizierung von solcher Software hat nun aber die Zertifizierungsstelle #DigiCert sich übertölpeln lassen. Und zwar in der teuersten und damit angeblich sichersten Kategorie «Extended Validation» (EV). So wurden mindestens 27 Code-Signing-Zertifikate im Namen von reputablen Firmen ausgestellt, aber für Cyberkriminelle. Digicert ist dem erst nachgegangen, als über 8 Tage hinweg 7 missbräuchliche Zertifikate durch Dritte gemeldet wurden.
https://mastodon.social/@hrbrmstr/116516180487899285 -
Genau bei der Zertifizierung von solcher Software hat nun aber die Zertifizierungsstelle #DigiCert sich übertölpeln lassen. Und zwar in der teuersten und damit angeblich sichersten Kategorie «Extended Validation» (EV). So wurden mindestens 27 Code-Signing-Zertifikate im Namen von reputablen Firmen ausgestellt, aber für Cyberkriminelle. Digicert ist dem erst nachgegangen, als über 8 Tage hinweg 7 missbräuchliche Zertifikate durch Dritte gemeldet wurden.
https://mastodon.social/@hrbrmstr/116516180487899285 -
Genau bei der Zertifizierung von solcher Software hat nun aber die Zertifizierungsstelle #DigiCert sich übertölpeln lassen. Und zwar in der teuersten und damit angeblich sichersten Kategorie «Extended Validation» (EV). So wurden mindestens 27 Code-Signing-Zertifikate im Namen von reputablen Firmen ausgestellt, aber für Cyberkriminelle. Digicert ist dem erst nachgegangen, als über 8 Tage hinweg 7 missbräuchliche Zertifikate durch Dritte gemeldet wurden.
https://mastodon.social/@hrbrmstr/116516180487899285 -
DigiCert breached via malicious screensaver file
#DigiCert #MicrosoftDefender #ZhongStealer
https://www.helpnetsecurity.com/2026/05/04/digicert-breach-code-signing-certificates-malware/ -
DigiCert breached via malicious screensaver file
#DigiCert #MicrosoftDefender #ZhongStealer
https://www.helpnetsecurity.com/2026/05/04/digicert-breach-code-signing-certificates-malware/ -
DigiCert breached via malicious screensaver file
#DigiCert #MicrosoftDefender #ZhongStealer
https://www.helpnetsecurity.com/2026/05/04/digicert-breach-code-signing-certificates-malware/ -
DigiCert breached via malicious screensaver file
#DigiCert #MicrosoftDefender #ZhongStealer
https://www.helpnetsecurity.com/2026/05/04/digicert-breach-code-signing-certificates-malware/ -
DigiCert breached via malicious screensaver file
#DigiCert #MicrosoftDefender #ZhongStealer
https://www.helpnetsecurity.com/2026/05/04/digicert-breach-code-signing-certificates-malware/ -
📢 DigiCert : émission frauduleuse de certificats EV Code Signing via compromission d'endpoints support
📝 ## 🔍 ContexteRapport d'incident publié sur Bugzilla Mozilla (bug #2033170) par DigiCert, daté du 2026-04-02 au 2026-04-17.
📖 cyberveille : https://cyberveille.ch/posts/2026-05-04-digicert-emission-frauduleuse-de-certificats-ev-code-signing-via-compromission-d-endpoints-support/
🌐 source : https://bugzilla.mozilla.org/show_bug.cgi?id=2033170
#DigiCert #IOC #Cyberveille -
Vorfall bei #DigiCert: #Malware-Autoren klauten Zertifikate | Security https://www.heise.de/news/Nach-Malware-Angriff-Kriminelle-nutzten-Codesigning-Zertifikate-von-DigiCert-11280757.html
-
Vorfall bei #DigiCert: #Malware-Autoren klauten Zertifikate | Security https://www.heise.de/news/Nach-Malware-Angriff-Kriminelle-nutzten-Codesigning-Zertifikate-von-DigiCert-11280757.html
-
Vorfall bei #DigiCert: #Malware-Autoren klauten Zertifikate | Security https://www.heise.de/news/Nach-Malware-Angriff-Kriminelle-nutzten-Codesigning-Zertifikate-von-DigiCert-11280757.html
-
Vorfall bei #DigiCert: #Malware-Autoren klauten Zertifikate | Security https://www.heise.de/news/Nach-Malware-Angriff-Kriminelle-nutzten-Codesigning-Zertifikate-von-DigiCert-11280757.html
-
@squiblydoo : perhaps this is related to the DigiCert hack described in https://bugzilla.mozilla.org/show_bug.cgi?id=2033170?
-
@squiblydoo : perhaps this is related to the DigiCert hack described in https://bugzilla.mozilla.org/show_bug.cgi?id=2033170?
-
@squiblydoo : perhaps this is related to the DigiCert hack described in https://bugzilla.mozilla.org/show_bug.cgi?id=2033170?
-
@squiblydoo : perhaps this is related to the DigiCert hack described in https://bugzilla.mozilla.org/show_bug.cgi?id=2033170?
-
https://www.europesays.com/at/139707/ Vorfall bei DigiCert: Malware-Autoren klauten Zertifikate #AT #Austria #Digicert #IT #Malware #Österreich #PKI #Science #Science&Technology #Security #Technik #Technology #WebPKI #Wissenschaft #Wissenschaft&Technik
-
Ich bin mir nicht sicher, ob „Zuerst infizierten Kriminelle Kundendienstmitarbeiter mit Schadsoftware“ der korrekte Ausdruck ist, aber schon wieder #DigiCert?
-
Ich bin mir nicht sicher, ob „Zuerst infizierten Kriminelle Kundendienstmitarbeiter mit Schadsoftware“ der korrekte Ausdruck ist, aber schon wieder #DigiCert?
-
Ich bin mir nicht sicher, ob „Zuerst infizierten Kriminelle Kundendienstmitarbeiter mit Schadsoftware“ der korrekte Ausdruck ist, aber schon wieder #DigiCert?
-
Microsoft Defender's recent false positive, flagging legitimate DigiCert root certificates as 'Trojan:Win32/Cerdigent.A!dha', sent IT teams globally into a frenzy on May 3. This widespread incident consumed valuable operational time, undermined faith in automated defenses, and highlights the urgent need for more stringent testing of security intelligence updates for foundational system…
#cybersecurity #microsoftdefender #digicert
🤖 This post was AI-generated.
-
Microsoft Defender wrongly flags DigiCert certs as Trojan:Win32/Cerdigent.A!dha
#MicrosoftDefender #DigiCert #GoldenEyeDog #ZhongStealer
https://www.bleepingcomputer.com/news/security/microsoft-defender-wrongly-flags-digicert-certs-as-trojan-win32-cerdigentadha/ -
Microsoft Defender wrongly flags DigiCert certs as Trojan:Win32/Cerdigent.A!dha
#MicrosoftDefender #DigiCert #GoldenEyeDog #ZhongStealer
https://www.bleepingcomputer.com/news/security/microsoft-defender-wrongly-flags-digicert-certs-as-trojan-win32-cerdigentadha/ -
Microsoft Defender wrongly flags DigiCert certs as Trojan:Win32/Cerdigent.A!dha
#MicrosoftDefender #DigiCert #GoldenEyeDog #ZhongStealer
https://www.bleepingcomputer.com/news/security/microsoft-defender-wrongly-flags-digicert-certs-as-trojan-win32-cerdigentadha/ -
Microsoft Defender wrongly flags DigiCert certs as Trojan:Win32/Cerdigent.A!dha
#MicrosoftDefender #DigiCert #GoldenEyeDog #ZhongStealer
https://www.bleepingcomputer.com/news/security/microsoft-defender-wrongly-flags-digicert-certs-as-trojan-win32-cerdigentadha/ -
Microsoft Defender wrongly flags DigiCert certs as Trojan:Win32/Cerdigent.A!dha
#MicrosoftDefender #DigiCert #GoldenEyeDog #ZhongStealer
https://www.bleepingcomputer.com/news/security/microsoft-defender-wrongly-flags-digicert-certs-as-trojan-win32-cerdigentadha/ -
#DigiCert customer support compromised with
.scrZIP attachment 🤷During our investigation between 2026-04-14 and 2026-04-17, as DigiCert identified certificates potentially affected by the threat actor’s actions, we revoked them. DigiCert revoked 60 certificates issued from the following CAs:
- DigiCert Trusted G4 Code Signing RSA4096 SHA256 2021 CA1
- DigiCert Trusted G4 Code Signing RSA4096 SHA384 2021 CA1
- GoGetSSL G4 CS RSA4096 SHA256 2022 CA-1
- Verokey High Assurance Secure Code EV
-
#DigiCert customer support compromised with
.scrZIP attachment 🤷During our investigation between 2026-04-14 and 2026-04-17, as DigiCert identified certificates potentially affected by the threat actor’s actions, we revoked them. DigiCert revoked 60 certificates issued from the following CAs:
- DigiCert Trusted G4 Code Signing RSA4096 SHA256 2021 CA1
- DigiCert Trusted G4 Code Signing RSA4096 SHA384 2021 CA1
- GoGetSSL G4 CS RSA4096 SHA256 2022 CA-1
- Verokey High Assurance Secure Code EV
-
#DigiCert customer support compromised with
.scrZIP attachment 🤷During our investigation between 2026-04-14 and 2026-04-17, as DigiCert identified certificates potentially affected by the threat actor’s actions, we revoked them. DigiCert revoked 60 certificates issued from the following CAs:
- DigiCert Trusted G4 Code Signing RSA4096 SHA256 2021 CA1
- DigiCert Trusted G4 Code Signing RSA4096 SHA384 2021 CA1
- GoGetSSL G4 CS RSA4096 SHA256 2022 CA-1
- Verokey High Assurance Secure Code EV
-
#DigiCert customer support compromised with
.scrZIP attachment 🤷During our investigation between 2026-04-14 and 2026-04-17, as DigiCert identified certificates potentially affected by the threat actor’s actions, we revoked them. DigiCert revoked 60 certificates issued from the following CAs:
- DigiCert Trusted G4 Code Signing RSA4096 SHA256 2021 CA1
- DigiCert Trusted G4 Code Signing RSA4096 SHA384 2021 CA1
- GoGetSSL G4 CS RSA4096 SHA256 2022 CA-1
- Verokey High Assurance Secure Code EV