Topic: certificate authority

  • DigiCert Breached After Malicious Screensaver File Used

    DigiCert Breached After Malicious Screensaver File Used

    A social engineering attack on DigiCert's customer support channel, using a malicious ZIP file disguised as a screenshot, allowed an attacker to access initialization codes and fraudulently issue EV Code Signing certificates. DigiCert revoked 60 certificates,27 directly linked to the attacker and...

    Read More »
  • Securing the inbox at the intersection of identity, brand, and security

    Securing the inbox at the intersection of identity, brand, and security

    Traditional email brand verification required separate coordination with a DMARC provider and a Certificate Authority, causing friction and delays. The convergence of identity, brand, and security now allows organizations to authenticate domains and display trusted logos in a single, streamlined ...

    Read More »
  • Rising Threat: More 1.1.1.1 Certificates Mis-Issued

    Rising Threat: More 1.1.1.1 Certificates Mis-Issued

    Mis-issued TLS certificates for Cloudflare's 1.1.1.1 service raised security concerns, potentially allowing interception and manipulation of encrypted DNS traffic. Cloudflare confirmed twelve certificates were improperly issued by Fina CA, all now revoked with no evidence of malicious use. The er...

    Read More »
  • Google Squeezes 2.5kB into 64 Bytes to Quantum-Proof HTTPS

    Google Squeezes 2.5kB into 64 Bytes to Quantum-Proof HTTPS

    Google is implementing quantum-resistant HTTPS certificates in Chrome to secure web browsing against future quantum computing threats, but the new certificates are about 40 times larger than current ones, posing a performance risk. The increased certificate size threatens to slow down website con...

    Read More »