Security News

Hackers Compromise Mongolian Certificate Authority to Spread Malware
2021-07-02 15:59

An unknown threat actor has compromised the servers of Mongolian certificate authority MonPass and abused the organization's website for malware distribution, according to security researchers at Avast. A major CA in East Asia, MonPass appears to have been breached at least six months ago, with the attackers returning to a compromised public web server approximately eight times.

Mongolian Certificate Authority Hacked to Distribute Backdoored CA Software
2021-07-02 05:54

In yet another instance of software supply chain attack, unidentified hackers breached the website of MonPass, one of Mongolia's major certificate authorities, to backdoor its installer software with Cobalt Strike binaries. Avast's investigation into the incident began after it discovered the backdoored installer and the implant on one of its customers' systems.

Microsoft Teams bug is prompting users to select a certificate
2021-06-10 15:12

A recent Microsoft Teams update is causing a "Select a certificate" prompt to be displayed to Teams users before they can use the software. Microsoft has acknowledged the bug and is tracking the issue under the 'TM261228' advisory, where they state a recent update to the software is causing the problem.

Microsoft Exchange admin portal blocked by expired SSL certificate
2021-05-23 19:21

The Microsoft Exchange admin portal is currently inaccessible from some browsers after Microsoft forgot to renew the SSL certificate for the website. Starting at 8 AM EST today, Microsoft Exchange admins who attempted to access the admin portal at admin.

Dispelling four myths about automating PKI certificate lifecycle management
2021-05-06 04:30

There are four primary myths about cloud-based PKI solutions and digital certificate lifecycle automation that have kept organizations from adopting such solutions. Eliminating the pain of manual digital certificate management requires dispelling these myths and learning how to maximize the benefits of today's cloud-based solutions using PKI best practices.

Brit MPs and campaigners come together to oppose COVID status certificates as 'divisive and discriminatory'
2021-04-28 14:32

With Minister for the Cabinet Office Michael Gove expected to announce app-based "COVID status certificates," the UK's post-lockdown plan looks set to come under fierce attack. They join other campaign groups, including Liberty, in backing the statement: "We oppose the divisive and discriminatory use of COVID status certification to deny individuals access to general services, businesses or jobs."

Amex cards removed from Google Pay due to expired certificate
2021-04-16 13:49

An expired certificate has led to the repeated removal of linked American Express credit cards from user's Google Pay accounts. Starting yesterday, Google Pay users with linked American Express cards began receiving emails that Google removed their linked Amex card.

Pulse Secure VPN users can't login due to expired certificate
2021-04-12 15:05

Users worldwide cannot connect to Pulse Secure VPN devices after a code signing certificate used to digitally sign and verify software components has expired. As employees return from the weekend, network admins have been reporting [1, 2, 3, 4] that users cannot connect to Pulse Secure VPN devices and access internal company resources.

HID HydrantID ACM solves difficult digital certificate lifecycle management problems
2021-03-30 01:00

HID Global announced the HID HydrantID Account Certificate Manager solution that eliminates manual, risk-prone processes for tracking, installing and renewing privately-issued as well as trusted Secure Socket Layer/Transport Layer Security certificates. "HydrantID ACM solves today's difficult digital certificate lifecycle management problems by providing one secure and convenient cloud-based platform for organizational teams to easily access private Certificate Authority services managed by HydrantID on their behalf," said Brad Jarvis, Senior Vice President & Managing Director, Identity & Access Management Business Area, with HID Global.

Why certificate automation is no longer just “nice to have”
2021-03-29 04:30

As internet standards groups look to boost trust and security through new requirements for shorter certificate lifecycles and online privacy acts introduce increasingly punitive regulatory mandates, the business risks of certificate management are only increasing. How the four pillars of certificate automation are shaping the next normal.