#digicert — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #digicert, aggregated by home.social.
-
Just about the entire internet uses certificate authorities to establish trust. Here, a simple old-school social engineering trick broke this trust and allowed hackers to get signed certificates from DigiCert for their malware.
There is a better way to establish certificate trust that doesn't rely on a 3rd party, and it's free too. It's called DANE, which binds the trust directly to the Domain Name System by using DNSSEC. DANE is ideal for code signing certificates (and other uses), but is overlooked.
This attack is virtually impossible under DANE. A vulnerable support person is of no use. Hackers would need to directly compromise the target's DNS infrastructure, the registrar, and the top-level domain authority. All three. Nearly impossible compared to just finding some dupe at the CA in a public chat room.
https://hackread.com/hackers-digicert-issue-certificates-sign-malware/
-
📢⚠️ Hackers tricked #DigiCert support staff into executing a malicious file, allowing attackers to obtain code-signing certificates later used to sign malware. DigiCert revoked 60 certificates after the breach was reported.
Read: https://hackread.com/hackers-digicert-issue-certificates-sign-malware/
-
#LetsEncrypt has suspended issuing certificates after it identified security issues in one of its roots (!)[^1]
We temporarily disabled certificate issuance, deployed a configuration change to prevent future issuance from the cross-signed Gen Y hierarchy, and then re-enabled issuance. Certificate revocation and CRL generation remains functional for Gen Y certificates.
A few days ago #DigiCert was hacked with a Windows (!) screensaver (!)[^2]
I cannot but remind that both organisations are part of the #WebTrust cartel who had last year unrolled a massive “grassroots” smear campaign against EU #QWAC certificates, presenting them as “security and privacy threat”, whereas from both legal and technical point of view QWAC is much more secure:
https://krvtz.net/en/posts/the-real-story-behind-eu-qwac.html
[^2]: https://cybersecuritynews.com/digicert-hacked-screensaver/
-
Defender Misflags DigiCert Root Certificates, Breaking Windows SSL Trust
#MicrosoftDefender #Microsoft #DigiCert #Cybersecurity #Malware #AntivirusSoftware #WindowsSecurity #ThreatIntelligence #Windows11 #MicrosoftWindows
-
Genau bei der Zertifizierung von solcher Software hat nun aber die Zertifizierungsstelle #DigiCert sich übertölpeln lassen. Und zwar in der teuersten und damit angeblich sichersten Kategorie «Extended Validation» (EV). So wurden mindestens 27 Code-Signing-Zertifikate im Namen von reputablen Firmen ausgestellt, aber für Cyberkriminelle. Digicert ist dem erst nachgegangen, als über 8 Tage hinweg 7 missbräuchliche Zertifikate durch Dritte gemeldet wurden.
https://mastodon.social/@hrbrmstr/116516180487899285 -
DigiCert breached via malicious screensaver file
#DigiCert #MicrosoftDefender #ZhongStealer
https://www.helpnetsecurity.com/2026/05/04/digicert-breach-code-signing-certificates-malware/ -
Vorfall bei #DigiCert: #Malware-Autoren klauten Zertifikate | Security https://www.heise.de/news/Nach-Malware-Angriff-Kriminelle-nutzten-Codesigning-Zertifikate-von-DigiCert-11280757.html
-
@squiblydoo : perhaps this is related to the DigiCert hack described in https://bugzilla.mozilla.org/show_bug.cgi?id=2033170?
-
Ich bin mir nicht sicher, ob „Zuerst infizierten Kriminelle Kundendienstmitarbeiter mit Schadsoftware“ der korrekte Ausdruck ist, aber schon wieder #DigiCert?
-
Microsoft Defender wrongly flags DigiCert certs as Trojan:Win32/Cerdigent.A!dha
#MicrosoftDefender #DigiCert #GoldenEyeDog #ZhongStealer
https://www.bleepingcomputer.com/news/security/microsoft-defender-wrongly-flags-digicert-certs-as-trojan-win32-cerdigentadha/ -
#DigiCert customer support compromised with
.scrZIP attachment 🤷During our investigation between 2026-04-14 and 2026-04-17, as DigiCert identified certificates potentially affected by the threat actor’s actions, we revoked them. DigiCert revoked 60 certificates issued from the following CAs:
- DigiCert Trusted G4 Code Signing RSA4096 SHA256 2021 CA1
- DigiCert Trusted G4 Code Signing RSA4096 SHA384 2021 CA1
- GoGetSSL G4 CS RSA4096 SHA256 2022 CA-1
- Verokey High Assurance Secure Code EV
-
[UPDATE 20260503-2020 UTC: Clarified type of certificate involved since it appears there may be two unrelated certificate revocations that were conflated as one event. ^AG]
This is an evolving situation, but it appears that a legitimate 𝗿𝗼𝗼𝘁 c̶o̶d̶e̶-̶s̶i̶g̶n̶i̶n̶g̶ certificate issued by #DigiCert was stolen by a threat actor for misuse.
#Microsoft is now detecting the stolen code-signing certificate as "Trojan:Win32/Cerdigent.A!dha" via Microsoft Windows Defender, with a not-yet-very-detailed entry about it at:
https://www.microsoft.com/en-us/wdsi/threats/malware-encyclopedia-description?Name=Trojan:Win32/Cerdigent.A!dha&ThreatID=2147968144Computer security researcher @cyb3rops has a discussion about it on Twitter at:
https://x.com/cyb3rops/status/2050916842730869197as well as the following update:
https://x.com/cyb3rops/status/2050924042173943820This discussion may or may not be related to the 𝗿𝗼𝗼𝘁 certificate issue. It discusses stolen code-signing certificates:
T̶h̶e̶r̶e̶'̶s̶ ̶a̶ ̶s̶o̶m̶e̶w̶h̶a̶t̶ ̶t̶e̶c̶h̶n̶i̶c̶a̶l̶ ̶d̶i̶s̶c̶u̶s̶s̶i̶o̶n̶ ̶o̶f̶ ̶t̶h̶e̶ ̶t̶h̶e̶f̶t̶ ̶i̶n̶ ̶M̶o̶z̶i̶l̶l̶a̶'̶s̶ ̶b̶u̶g̶ ̶d̶a̶t̶a̶b̶a̶s̶e̶ ̶a̶s̶ ̶w̶e̶l̶l̶:̶
https://bugzilla.mozilla.org/show_bug.cgi?id=2033170There's also an ongoing discussion on Reddit about it as well at:
https://old.reddit.com/r/antivirus/comments/1t2l6tk/windows_defender_picked_up_a_trojan_what_do_i_do/At this point, there's not really a lot for most Windows users to do here. This is, or at least was, a legitimate 𝗿𝗼𝗼𝘁 c̶o̶d̶e̶-̶s̶i̶g̶n̶i̶n̶g̶ certificate, so its presence on a system is not unexpected. And just because it was found on a system does not mean the system has malware on it or was targeted by a threat actor.
I recommend monitoring the situation and wait for additional clarification from Microsoft.
-
RE: https://old.mermaid.town/@futzle/116400393579103110
Watching this thread closely, because I’ve been with DNS Made Easy for years 👀
I got an email from #digicert today which states:
> Your account [redacted] is currently exceeding its monthly DNS query threshold
My monthly threshold is 5m queries/month. On a good month, I don’t exceed 15k.
So they’re outright lying to me in order to scare me to upgrade. That’s not cool.
-
The Internet Last Week
* DigiCert CA bundle expiry
https://help.duo.com/s/article/9451
* Various US DoD route updates
https://www.cidr-report.org/cgi-bin/as-report?as=AS306
https://stat.ripe.net/widget/routing-history#resource=306&starttime=2026-03-29
https://www.cidr-report.org/cgi-bin/as-report?as=AS721
https://stat.ripe.net/widget/routing-history#resource=721&starttime=2026-03-29
https://www.cidr-report.org/cgi-bin/as-report?as=AS27064
https://stat.ripe.net/widget/routing-history#resource=27064&starttime=2026-03-29
https://www.cidr-report.org/cgi-bin/as-report?as=AS27065
https://stat.ripe.net/widget/routing-history#resource=27065&starttime=2026-03-29
* Quad9 enables DoH3 and DoQ
https://quad9.net/news/blog/quad9-enables-dns-over-http-3-and-dns-over-quic/ -
Ich wollte ein älteres Tablet mit Android 7 bzw. #LineageOS wieder in Betrieb nehmen mit neuem #Firefox. Leider wurden keine https-Webseiten geladen. Nach einer Stunde Suche habe ich festgestellt, dass die Root-#Zertifikate aufgrund eines veränderten Hashes nicht gefunden wurden.
openssl x509 -in DigiCert_Global_Root_CA.crt -subject_hash_old -noout
openssl x509 -in DigiCert_Global_Root_CA.crt -subject_hash -noout
1/2
-
That’s an interesting error page from #DigiCert. What’s up with that CD-ROM emoji?
-
TLS certificate lifetimes will be reduced to 47 days worldwide, for enhanced security. System administrators will be forced to implement renewal automation and developers will be forced to update their caching strategies.
https://www.digicert.com/blog/tls-certificate-lifetimes-will-officially-reduce-to-47-days
#news #tech #security #cybersecurity #infosec #encryption #networking #sysadmin #coding #programming #web #browser #digicert
-
- knowing how to restore a blocked #Digicert code signing token instead of plain panicking came in handy
- took a bit of overtime to go grocery shopping during the lunch break and got pizza on the way back
- the #Mastodon bots, that I set up in the last days started posting news, I would have never noticed otherwise. Thank you, @mastofeed
#3GoodThings #ThreeGoodThings -
Tiens, chez #DigiCert, ils vont réduire la durée de validité des certificats #TLS à 47 jours à compter du 15 mars 2029 (si on arrive jusque-là…) ; avec deux étapes de réductions successives intermédiaires, les 15 mars 2026 et 2027 :
“TLS Certificate Lifetimes Will Officially Reduce to 47 Days” :
https://www.digicert.com/blog/tls-certificate-lifetimes-will-officially-reduce-to-47-days -
TLS Certificate Lifetimes Will Officially Reduce to 47 Days
https://www.digicert.com/blog/tls-certificate-lifetimes-will-officially-reduce-to-47-days
#ycombinator #2025 #april #digicert #blog #certificate_management -
🔒😂 Apparently, #DigiCert thinks we're all speed demons with their new 47-day #TLS certificate sprint. Meanwhile, the rest of us are still wrestling with cookie #consent like it's a foreign language. 🍪🤦♂️
https://www.digicert.com/blog/tls-certificate-lifetimes-will-officially-reduce-to-47-days #cookies #speeddemons #techhumor #cybersecurity #HackerNews #ngated -
- #Digicert has a well documented way of resetting passwords on certificate tokens
- our wood oven has been removed (we're not allowed to operate starting April) and the pipe hole is closed
- did some coding for the #WikiTree Browser Extension
- Bonus: cuddled with Gelbi
#3GoodThings #ThreeGoodThings -
Soo, remove #Digicert from the trust root?
-
DigiCert: Threat of legal action to stifle Bugzilla discourse — https://bugzilla.mozilla.org/show_bug.cgi?id=1950144
#HackerNews #DigiCert #Bugzilla #LegalAction #Discourse #Cybersecurity #Mozilla -
What?!? Digicert is removing support for #ipv6 ?
Upon further reading, they state that they are moving to a CDN and must remove support for IPv6 addresses.
What CDN does not support IPv6 these days?
Not that I use DigiCert anyway, but I don't like seeing things go in the wrong direction.