Attackers Exploit DigiCert Support to Issue Unauthorized Code Signing.
DigiCert Support Breach Leads to Unauthorized Code Signing Certificates: A Lapse in EDR Coverage DigiCert , a leading provider of digital certificates, has reported a security incident involving the unauthorized issuance of 60 code signing certificates . The breach was discovered after customers flagged suspicious certificates issued in the names of various organizations without their consent. The Attack Vector: A Social Engineering Gambit The investigation revealed that the attackers targeted DigiCert’s support staff. Using a classic social engineering tactic, the threat actors contacted support agents claiming to need help with a technical issue. They attempted to send a "screenshot" for review, which was actually a malicious .scr (Windows Screen Saver) file . While initial attempts were thwarted by security software on the first agent's machine, the attackers persisted. They eventually found a second support agent whose workstation lacked CrowdStrike EDR (Endpoint Dete...