Security News

Use of Fake Code Signing Certificates in Malware Surges
2018-02-23 14:43

There has been surge in the use of counterfeit code signing certificates to evade security detection solutions, despite the high cost such certificates come with, a new Recorded Future report...

Counterfeit digital certificates for sale on underground forums
2018-02-23 13:12

Signing malicious code with valid digital certificates is a helpful trick used by attackers to maximize the odds that malware won’t be flagged by antivirus solutions and often even by network...

Facebook Releases New Certificate Transparency Tools
2017-12-15 15:32

Following the release of the read more

Security Vulnerabilities in Certificate Pinning
2017-12-08 12:15

New research found that many banks offer certificate pinning as a security feature, but fail to authenticate the hostname. This leaves the systems open to man-in-the-middle attacks. From the...

Estonia Invalidates Digital Certificates Over Crypto Crack
2017-11-08 11:03

Unpatched Infineon Chips in Peril as Researchers Speed Up Encryption Key AttackResearchers have discovered how to speed up an attack disclosed last month that recovers secret encryption keys...

Week in review: Estonia blocks certificates on ID cards, Chrome extension steals all data
2017-11-06 01:45

Here’s an overview of some of last week’s most interesting news and articles: Chris Eng: An infosec journey from offense to defense “Come to my lab, I promise you’ll learn something cool,” a...

Estonia blocks certificates on 760,000 ID cards due to identity theft risk
2017-11-03 16:38

On 3 November 2017 at midnight, Estonia will block the certificates of 760,000 ID cards. The decision is the result of the discovery of a security vulnerability in the Infineon-developed RSA...

How much do criminals pay for certificates on the dark web?
2017-11-03 13:15

The Cyber Security Research Institute (CSRI) conducted a six-month investigation into the sale of digital code signing certificates on the dark web. The research uncovered code signing...

Savitech Audio Drivers Caught Installing Root Certificate
2017-11-03 10:24

Savitech drivers used by several companies that provide specialized audio products expose computers to hacker attacks by installing a new root certificate into the Trusted Root Certification...

Mozilla to Completely Ban WoSign, StartCom Certificates in Firefox 58 (Security Week)
2017-09-01 13:35

Mozilla this week announced plans to completely remove trust in the digital certificates issued by Chinese certificate authority WoSign and its subsidiary StartCom starting with Firefox 58.  read more