DigiCert Breached via Weaponized Screensaver: Threat Actor Steals EV Code Signing Certificates to Spread Zhong Stealer
A sophisticated threat actor breached DigiCert’s internal support environment in early April 2026 by tricking analysts into executing a disguised .scr malware file, ultimately obtaining EV Code Signing certificates used to distribute the Zhong Stealer malware. 60 certificates were revoked following the discovery of a 10-day undetected compromise window on a second endpoint.
Itagora tiene in archivio titolo e sommario per la ricerca interna. Il testo completo resta sulla fonte. Il link in uscita non invia referrer.