Remove certifications what-the-hack
article thumbnail

Q&A: SolarWinds, Mimecast hacks portend intensified third-party, supply-chain compromises

The Last Watchdog

Related: Digital certificates destined to play key role in securing DX. Thanks to a couple of milestone hacks disclosed at the close of 2020 and start of 2021, they will forever be associated with putting supply-chain vulnerabilities on the map. Certificate compromises. Supplier trojans. The infected entities included the U.S.

Hacking 228
article thumbnail

Ask Fitis, the Bear: Real Crooks Sign Their Malware

Krebs on Security

Code-signing certificates are supposed to help authenticate the identity of software publishers, and provide cryptographic assurance that a signed piece of software has not been altered or tampered with. “Why do I need a certificate?” One of Megatraffer’s ads on an English-language cybercrime forum.

Malware 242
Insiders

Sign Up for our Newsletter

This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

article thumbnail

SHARED INTEL: Automating PKI certificate management alleviates outages caused by boom

The Last Watchdog

Our Public Key Infrastructure is booming but also under a strain that manual certificate management workflows are not keeping up with. PKI and digital certificates were pivotal in the formation of the commercial Internet, maturing in parallel with ecommerce. Certificate confusion.

article thumbnail

STEPS FORWARD: Regulators are on the move to set much needed IoT security rules of the road

The Last Watchdog

Without them the integrity of our food supplies, the efficacy of our transportation systems and reliability of our utilities would not be what they are. Without them the integrity of our food supplies, the efficacy of our transportation systems and reliability of our utilities would not be what they are.

IoT 220
article thumbnail

Microsoft fixed two zero-day bugs exploited in malware attacks

Security Affairs

CVE-2024-26234 – Proxy Driver Spoofing Vulnerability – The flaw reported by Sophos ties a malicious driver signed with a valid Microsoft Hardware Publisher Certificate. In December 2023, Sophos X-Ops received a report of a false positive detection on an executable that was signed using a valid Microsoft Hardware Publisher Certificate.

Malware 114
article thumbnail

Thinking of a Cybersecurity Career? Read This

Krebs on Security

In most cases, the aspirants ask which certifications they should seek, or what specialization in computer security might hold the brightest future. In most cases, the aspirants ask which certifications they should seek, or what specialization in computer security might hold the brightest future.

article thumbnail

SHARED INTEL Q&A: My thoughts and opinions about cyber threats — as discussed with OneRep

The Last Watchdog

What drew you to this field? I held this position from 2000 through 2014, during which time Windows emerged as a prime target for both precocious script kiddies and emerging criminal hacking rings. Erin: What cybersecurity technologies are you most excited about right now? Erin: So, let’s get started.