Security News

How to create locally signed SSL certificates with mkcert
2021-08-26 18:38

If you need to generate quick SSL certificates for test servers and services, mkcert might be the fastest option available. For anything in production, you'll be purchasing your SSL certificates from a certificate authority, otherwise, you're not really giving those users much assurance.

Managing digital certificates still a challenge, automation lagging
2021-08-09 04:00

Managing digital certificates, especially expirations and renewals, continues to be a challenging process for businesses of all sizes, a study of over 300 IT professionals in the U.S. and the UK conducted by Opinium reveals. Most companies rely on digital certificates and digital signatures, but the methods being utilized to manage the technology still leave plenty of room for error and improvement.

DigiCert issues Verified Mark Certificates to help organizations secure their emails from abuse
2021-07-14 02:10

Paired with the required DMARC enforcement, VMCs are a critical step in a series of security measures that help strengthen email security, build trust in the inbox and help users associate the brand logo with the company they expect to communicate with. "With BIMI and VMC from DigiCert for DMARC-verified domains, organizations can now demonstrate to their customers a higher level of email security. DigiCert VMCs not only help reduce instances of spam and spoofing customers receive, because of the DMARC requirement, but they also enable organizations to go beyond displaying default email addresses to increase engagement rates and display their brands more prominently."

Google Cloud Certificate Authority Service Becomes Generally Available
2021-07-13 12:29

Google Cloud on Monday announced that its Certificate Authority Service is now generally available. The Google Cloud Certificate Authority Service, for which a public preview was announced in October 2020, is designed to help organizations "Simplify, automate, and customize the deployment, management, and security of private certificate authorities."

Hackers Compromise Mongolian Certificate Authority to Spread Malware
2021-07-02 15:59

An unknown threat actor has compromised the servers of Mongolian certificate authority MonPass and abused the organization's website for malware distribution, according to security researchers at Avast. A major CA in East Asia, MonPass appears to have been breached at least six months ago, with the attackers returning to a compromised public web server approximately eight times.

Mongolian Certificate Authority Hacked to Distribute Backdoored CA Software
2021-07-02 05:54

In yet another instance of software supply chain attack, unidentified hackers breached the website of MonPass, one of Mongolia's major certificate authorities, to backdoor its installer software with Cobalt Strike binaries. Avast's investigation into the incident began after it discovered the backdoored installer and the implant on one of its customers' systems.

Microsoft Teams bug is prompting users to select a certificate
2021-06-10 15:12

A recent Microsoft Teams update is causing a "Select a certificate" prompt to be displayed to Teams users before they can use the software. Microsoft has acknowledged the bug and is tracking the issue under the 'TM261228' advisory, where they state a recent update to the software is causing the problem.

Microsoft Exchange admin portal blocked by expired SSL certificate
2021-05-23 19:21

The Microsoft Exchange admin portal is currently inaccessible from some browsers after Microsoft forgot to renew the SSL certificate for the website. Starting at 8 AM EST today, Microsoft Exchange admins who attempted to access the admin portal at admin.

Dispelling four myths about automating PKI certificate lifecycle management
2021-05-06 04:30

There are four primary myths about cloud-based PKI solutions and digital certificate lifecycle automation that have kept organizations from adopting such solutions. Eliminating the pain of manual digital certificate management requires dispelling these myths and learning how to maximize the benefits of today's cloud-based solutions using PKI best practices.

Brit MPs and campaigners come together to oppose COVID status certificates as 'divisive and discriminatory'
2021-04-28 14:32

With Minister for the Cabinet Office Michael Gove expected to announce app-based "COVID status certificates," the UK's post-lockdown plan looks set to come under fierce attack. They join other campaign groups, including Liberty, in backing the statement: "We oppose the divisive and discriminatory use of COVID status certification to deny individuals access to general services, businesses or jobs."