Topic: certificate revocation

  • Microsoft Nukes 200+ Fake Certificates in Teams Malware Attack

    Microsoft Nukes 200+ Fake Certificates in Teams Malware Attack

    Microsoft revoked over 200 fraudulent certificates used by cybercriminals to distribute malware via fake Microsoft Teams installation files, a campaign linked to the Vanilla Tempest group. The attackers employed SEO poisoning and malvertising to trick users into downloading malicious files, which...

    Read More »
  • Microsoft Thwarts Ransomware Attack on Teams Users

    Microsoft Thwarts Ransomware Attack on Teams Users

    Microsoft invalidated over 200 fraudulent digital certificates to disrupt a ransomware campaign that used fake Teams installers, blocking the Rhysida ransomware's distribution network in early October. The attack, orchestrated by the Vanilla Tempest group, involved malvertising and spoofed websit...

    Read More »
  • Decade-Old EnCase Driver Still Defeats Modern EDR

    Decade-Old EnCase Driver Still Defeats Modern EDR

    A new malware strain can disable modern EDR solutions by exploiting an outdated, revoked-but-still-loadable kernel driver from old EnCase forensics software. The attack uses a BYOVD technique, where the legitimate driver, once loaded, allows user-mode processes to kill critical security processes...

    Read More »
  • DigiCert Breached After Malicious Screensaver File Used

    DigiCert Breached After Malicious Screensaver File Used

    A social engineering attack on DigiCert's customer support channel, using a malicious ZIP file disguised as a screenshot, allowed an attacker to access initialization codes and fraudulently issue EV Code Signing certificates. DigiCert revoked 60 certificates,27 directly linked to the attacker and...

    Read More »
  • Rising Threat: More 1.1.1.1 Certificates Mis-Issued

    Rising Threat: More 1.1.1.1 Certificates Mis-Issued

    Mis-issued TLS certificates for Cloudflare's 1.1.1.1 service raised security concerns, potentially allowing interception and manipulation of encrypted DNS traffic. Cloudflare confirmed twelve certificates were improperly issued by Fina CA, all now revoked with no evidence of malicious use. The er...

    Read More »
  • TamperedChef Infostealer Spreads via Fake PDF Editor

    TamperedChef Infostealer Spreads via Fake PDF Editor

    A malware campaign is distributing the TamperedChef infostealer through fake PDF editing software promoted via Google Ads, using over 50 domains and counterfeit certificates to appear legitimate. The malware, disguised as AppSuite PDF Editor, activated data-stealing capabilities on August 21st, h...

    Read More »