Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
DigiCert Enhances Security After Support Portal Hack

DigiCert Enhances Security After Support Portal Hack

Posted on May 4, 2026 By CWS

DigiCert recently took action to address a security breach in its internal support portal by revoking certificates that were fraudulently obtained. The breach was identified following a cyberattack that exploited their support system.

Details of the Cyberattack

The attack, as detailed by DigiCert, occurred on April 2 when an attacker targeted their support team using a deceptive payload. This malware was disguised as a screenshot and delivered through a customer chat channel.

The infection spread to two endpoints, with one being detected swiftly on April 3, while the second was not identified until April 14. DigiCert attributed the delay in detecting the second infection to malfunctioning security solutions on the affected endpoint.

Impact on Certificates

From the compromised system, the attackers managed to access DigiCert’s internal support portal. They exploited a limited access function to obtain EV Code Signing certificates by leveraging the ability of authenticated support analysts to proxy into customer accounts, gaining access to crucial initialization codes.

This breach enabled the attackers to acquire EV Code Signing certificates for a specific set of customer accounts. DigiCert reported that by April 17, they had revoked 60 certificates related to the breach, including 27 directly linked to the attackers. Eleven of these were reportedly used to sign malware.

Security Enhancements and Future Precautions

DigiCert assured that all certificates potentially impacted by this incident were revoked, and pending orders were canceled to thwart any further unauthorized access. To bolster security, they have implemented several measures, including enforcing multi-factor authentication on administrative actions and restricting access to initialization codes by proxied support users.

Further preventive steps include limiting the file types that can be transmitted through support chat and Salesforce case attachments, along with enhancing logging capabilities for better monitoring.

These upgrades are part of DigiCert’s commitment to strengthening its defenses against future threats and ensuring the integrity of its systems and customer data.

Security Week News Tags:certificate revocation, Cybersecurity, data breach, DigiCert, EV Code Signing, Hack, Malware, multi-factor authentication, security update, tech news

Post navigation

Previous Post: AI-Driven Cyber Attacks Surge in 2025
Next Post: Silver Fox Targets India and Russia with ABCDoor Malware

Related Posts

AI Tools Vulnerable to Comment-Based Prompt Injection AI Tools Vulnerable to Comment-Based Prompt Injection Security Week News
Norwegian Police Say Pro-Russian Hackers Were Likely Behind Suspected Sabotage at a Dam Norwegian Police Say Pro-Russian Hackers Were Likely Behind Suspected Sabotage at a Dam Security Week News
SAP Patches Critical Flaws That Could Allow Remote Code Execution, Full System Takeover SAP Patches Critical Flaws That Could Allow Remote Code Execution, Full System Takeover Security Week News
Android Fixes Critical StrongBox and DoS Vulnerabilities Android Fixes Critical StrongBox and DoS Vulnerabilities Security Week News
Hacker Conversations: Rachel Tobac and the Art of Social Engineering Hacker Conversations: Rachel Tobac and the Art of Social Engineering Security Week News
Critical Linux Flaw ‘Pack2TheRoot’ Grants Root Access Critical Linux Flaw ‘Pack2TheRoot’ Grants Root Access Security Week News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Apple SoCs Vulnerable to New BootROM Exploit
  • Outdated REDCap Servers Pose Cybersecurity Risks
  • INC Ransomware Dominates 2026 with Over 830 Attacks
  • Hackers Exploit SQL Server 2025 AI for Data Theft
  • Critical NGINX Vulnerabilities Patched by F5

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Apple SoCs Vulnerable to New BootROM Exploit
  • Outdated REDCap Servers Pose Cybersecurity Risks
  • INC Ransomware Dominates 2026 with Over 830 Attacks
  • Hackers Exploit SQL Server 2025 AI for Data Theft
  • Critical NGINX Vulnerabilities Patched by F5

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark