Security News

Amex cards removed from Google Pay due to expired certificate
2021-04-16 13:49

An expired certificate has led to the repeated removal of linked American Express credit cards from user's Google Pay accounts. Starting yesterday, Google Pay users with linked American Express cards began receiving emails that Google removed their linked Amex card.

Pulse Secure VPN users can't login due to expired certificate
2021-04-12 15:05

Users worldwide cannot connect to Pulse Secure VPN devices after a code signing certificate used to digitally sign and verify software components has expired. As employees return from the weekend, network admins have been reporting [1, 2, 3, 4] that users cannot connect to Pulse Secure VPN devices and access internal company resources.

HID HydrantID ACM solves difficult digital certificate lifecycle management problems
2021-03-30 01:00

HID Global announced the HID HydrantID Account Certificate Manager solution that eliminates manual, risk-prone processes for tracking, installing and renewing privately-issued as well as trusted Secure Socket Layer/Transport Layer Security certificates. "HydrantID ACM solves today's difficult digital certificate lifecycle management problems by providing one secure and convenient cloud-based platform for organizational teams to easily access private Certificate Authority services managed by HydrantID on their behalf," said Brad Jarvis, Senior Vice President & Managing Director, Identity & Access Management Business Area, with HID Global.

Why certificate automation is no longer just “nice to have”
2021-03-29 04:30

As internet standards groups look to boost trust and security through new requirements for shorter certificate lifecycles and online privacy acts introduce increasingly punitive regulatory mandates, the business risks of certificate management are only increasing. How the four pillars of certificate automation are shaping the next normal.

How to get affordable DV certificates for onion sites
2021-03-26 03:55

The Tor Project, the nonprofit developers of the Tor network and Tor Browser, have announced two exciting developments for onion services: affordable DV certificates for v3 onion sites from HARICA, and new, easy onion site setup guides. Onion sites are websites that are only accessible over the Tor network: you can spot them because they end in the TLD.onion.

OpenSSL fixes severe DoS, certificate validation vulnerabilities
2021-03-25 16:44

Today, the OpenSSL project has issued an advisory for two high-severity vulnerabilities CVE-2021-3449 and CVE-2021-3450 lurking in OpenSSL products. CVE-2021-3450: An improper Certificate Authority certificate validation vulnerability which impacts both the server and client instances.

Phony COVID-19 vaccine certificates are now selling on the Dark Web
2021-03-23 13:59

A report released Tuesday by threat intelligence firm Check Point Research explains how phony COVID-19 vaccine documents are selling on the Dark Web and how to avoid these fake documents. For individuals who don't have such a certificate or can't wait for a vaccine, the Dark Web is becoming home to fake documents, according to Check Point's analysis.

GLEIF CA Stakeholder Group accelerates integration of LEIs in digital certificates
2021-03-15 01:30

GLEIF has launched a CA Stakeholder Group to facilitate communication between GLEIF, CAs and TSPs from across the world, as they collectively aim to coordinate and encourage a global approach to LEI usage across digital identity products. The collaboration announcement follows news last year that ISO has standardized the process of embedding LEIs in digital certificates.

Recent Google Voice outage caused by expired certificates
2021-02-28 14:25

In an incident report published on Friday, Google said that a Google Voice outage affecting a majority of the telephone service's users earlier this month was caused by expired TLS certificates. During regular operation, voice calls made through Google Voice are controlled using the Session Initiation Protocol, with client devices immediately retrying their connection to the service once it breaks.

Google Voice silenced by expired TLS certificate in February outage
2021-02-28 14:25

In an incident report published on Friday, Google said that a Google Voice outage affecting a majority of the telephone service's users earlier this month was caused by expired TLS certificates. During regular operation, voice calls made through Google Voice are controlled using the Session Initiation Protocol, with client devices immediately retrying their connection to the service once it breaks.