← DigiCert cases
Bugzilla #2033170 · Certificate Misissuance
DigiCert: Misissued code signing certificates
DigiCert · ASSIGNED
AI Summary
DigiCert reported a security incident involving the misissuance of code signing certificates due to a malware attack on their support team. A threat actor gained access to initialization codes for several certificates, which were subsequently used to sign malware. DigiCert acted swiftly, revoking the affected certificates within 24 hours of discovery and implementing additional security measures to prevent future incidents.
Chronology
- Threat actor compromised support endpoint.
- First endpoint detected and contained.
- Second endpoint identified as compromised.
- 60 certificates revoked.
Participants
DigiCert
External References
Similar Local Cases
DigiCert: CAA processing during network disruption
DigiCert: Misissuance detected by PKIMetal
DigiCert: Domain validation skipped
DigiCert: "Some-State" in stateOrProvinceName
DigiCert: Org-JOI type mismatch
DigiCert: in-addr.arpa Misissuance
DigiCert: Unclear Disclosure of CAA Issuer Domain Names
DigiCert: Mis-issuance of certificate with https in CN/SAN