Select a theme from the list.
Insights

From our experts

Latest
Fileless PHP Rootkit Hides a Web Shell Inside BIG-IP Server MemoryMicrosoft Brings Agentic Vulnerability Hunting Into Azure GovernmentMicrosoft's Record Patch Tuesday Forces Defenders to Rethink Update PrioritiesPublic Zero-Day Exploits Put Endpoint Security Tools Under Defensive ScrutinyPEEP Turns Trusted Browsers Into Persistent Command CentersBigBear Shows Why Microsoft 365 MFA Alone Cannot Stop Session HijackingMass Exploitation Hits WordPress Sites Through Two Critical Upload FlawsCitrix NetScaler Authentication Bypass Draws Real-World Attack TrafficProject Zenith Recasts the Windows PC as a Local AI Development PlatformPostGREShell Turns Trusted Replication Accounts Into Server BackdoorsStyleSmuggler Zero-Day Puts Magento Stores on Emergency FootingRogue AI Agents Turn an Abandoned Wiki Into a Secret Coordination HubFileless PHP Rootkit Hides a Web Shell Inside BIG-IP Server MemoryMicrosoft Brings Agentic Vulnerability Hunting Into Azure GovernmentMicrosoft's Record Patch Tuesday Forces Defenders to Rethink Update PrioritiesPublic Zero-Day Exploits Put Endpoint Security Tools Under Defensive ScrutinyPEEP Turns Trusted Browsers Into Persistent Command CentersBigBear Shows Why Microsoft 365 MFA Alone Cannot Stop Session HijackingMass Exploitation Hits WordPress Sites Through Two Critical Upload FlawsCitrix NetScaler Authentication Bypass Draws Real-World Attack TrafficProject Zenith Recasts the Windows PC as a Local AI Development PlatformPostGREShell Turns Trusted Replication Accounts Into Server BackdoorsStyleSmuggler Zero-Day Puts Magento Stores on Emergency FootingRogue AI Agents Turn an Abandoned Wiki Into a Secret Coordination Hub
Security Insight

DigiCert Intrusion Reveals How Stolen Code-Signing Trust Can Shield Malware

DigiCert Intrusion Reveals How Stolen Code-Signing Trust Can Shield Malware
Photo by Tima Miroshnichenko on Pexels

Researchers have linked DigiCert's April 2026 security incident to CylindricalCanine, a subgroup associated with the GoldenEyeDog cybercrime operation. The attackers allegedly compromised support workstations, intercepted certificate initialization codes, and used fraudulently obtained code-signing certificates to make malware appear more trustworthy.

New threat intelligence has connected the April 2026 DigiCert security incident to CylindricalCanine, a subgroup of the GoldenEyeDog cybercrime operation. The incident is significant because the attackers were not merely seeking documents or account credentials. They targeted code-signing certificates, which can give malicious software a misleading appearance of legitimacy.

Support Access Became the Entry Point

The intrusion reportedly began when an attacker contacted DigiCert's support team through a customer chat channel and submitted a ZIP archive disguised as a screenshot. The archive contained a malicious screen-saver executable that compromised two support analyst workstations.

The attackers then abused a support portal feature that allowed authorized analysts to view customer accounts while assisting them. This access exposed initialization codes associated with approved but undelivered extended-validation code-signing certificate orders. Possession of those codes was functionally sufficient to complete certificate retrieval across a limited group of customer accounts.

DigiCert revoked 60 certificates associated with the incident. Researchers said 27 were directly connected to the threat actor and that some were used to sign Zhong Stealer malware. The company subsequently changed its platform to conceal initialization codes from proxied support sessions through both the user interface and API.

Why Signed Malware Is Dangerous

Code signing does not prove that software is harmless. It confirms who signed the file and whether it was altered afterward. However, users, administrators, security products, and application-control systems may place greater trust in properly signed executables. A stolen certificate can therefore help malware bypass warnings or survive initial inspection.

Defensive Priorities

  • Isolate support personnel on hardened, privileged workstations.
  • Block executable attachments and archives in customer-support channels.
  • Require additional approval before certificate initialization or delivery.
  • Monitor certificate transparency and reputation systems for unexpected issuance.
  • Immediately investigate software signed with revoked or suspicious certificates.

I believe certificate authorities and other trust providers must treat support systems as part of their critical security perimeter. Support teams routinely receive files from strangers, yet they may also hold access capable of affecting customer identities and software trust. This combination makes them exceptionally attractive targets. Stronger file isolation, narrowly scoped support permissions, and independent verification of certificate delivery should become standard controls across the industry.

Talk to our team →

Latest

Fileless PHP Rootkit Hides a Web Shell Inside BIG-IP Server MemorySep 9, 2026Microsoft Brings Agentic Vulnerability Hunting Into Azure GovernmentSep 9, 2026Microsoft's Record Patch Tuesday Forces Defenders to Rethink Update PrioritiesSep 9, 2026Public Zero-Day Exploits Put Endpoint Security Tools Under Defensive ScrutinySep 8, 2026PEEP Turns Trusted Browsers Into Persistent Command CentersSep 8, 2026BigBear Shows Why Microsoft 365 MFA Alone Cannot Stop Session HijackingSep 8, 2026

Most read

1Sophos Turns Its Own Network Into a Proving Ground for Safer Enterprise AI2Sophos Fusion Recasts the Security Platform as an AI-Driven Defense System3Global CMS Exploitation Wave Plants Webshells on Business Websites4Microsoft Makes Passkeys the Entra ID Default and Sets a Deadline for Native SMS Authentication5Laser Attack Exposes an Unpatchable Weakness in Tangem Crypto Wallet Cards6Critical NGINX Overflow Puts Internet-Facing Servers on an Urgent Upgrade Path