Malicious Java applet sign with stolen certs 

Malicious Java applet sign with stolen certs

Researchers believe the stolen private key belonged to an unwitting Texas consulting company.
Queensland researchers seek 'real world' fix for TLS   

Queensland researchers seek 'real world' fix for TLS

Score $300k Govt research grant.
Hackers hijack Bit9 whitelist in targeted attack 

Hackers hijack Bit9 whitelist in targeted attack

Failed to install its own software.
TurkTrust denies security breach led to certificate gaffe 

TurkTrust denies security breach led to certificate gaffe

No 'malevolence, fraud or any other crime factor'.
Google, Microsoft drop fraudulent certificates 

Google, Microsoft drop fraudulent certificates

Turkish certificate authority issued two dodgy certificates.
DigiNotar hack details revealed by Dutch Govt 

DigiNotar hack details revealed by Dutch Govt

Final report released.
Researchers detail laundry list of dodgy crypto deployments 

Researchers detail laundry list of dodgy crypto deployments

Developer hits back at 'rude' research.
Adobe revokes all code signed since 10 July 

Adobe revokes all code signed since 10 July

Follows attack.
Hackers raid Adobe, compromise certificate to sign malware 

Hackers raid Adobe, compromise certificate to sign malware

Compromised cert to be revoked.
Toyota alleges ex-contractor sabotaged IT systems 

Toyota alleges ex-contractor sabotaged IT systems

Claims systems broken into, altered.
Microsoft revokes certificates with fewer than 2048 bits 

Microsoft revokes certificates with fewer than 2048 bits

Kills insecure Windows gadgets.
Cyberoam hacked private key posted online 

Cyberoam hacked private key posted online

Tor users extract and decrypt private key.
Comodo flags its certificate service as suspicious 

Comodo flags its certificate service as suspicious

Bug fixed, reputation red flags clear.
Flame signed with Microsoft certs 

Flame signed with Microsoft certs

Redmond kills cert store, issues patch.
Voluntary SSL standards backed by heavyweights 

Voluntary SSL standards backed by heavyweights

But Marlinspike says it won't do squat.
GlobalSign says certs weren't hacked 

GlobalSign says certs weren't hacked

Thanks everyone.
Dutch CA denies certs breached 

Dutch CA denies certs breached

But internal documents pilfered from vulnerable web database.
Malaysian Government signing key stolen  

Malaysian Government signing key stolen

Used to sign trojan.
Certificate phishing sucks bank customers into Blackhole 

Certificate phishing sucks bank customers into Blackhole

Bank business customers warned of invalid certificates.
Microsoft patches five holes, nukes six certificates 

Microsoft patches five holes, nukes six certificates

Light updates hard on DigiNotar.
GlobalSign pre-empts hack, shuts down certificates 

GlobalSign pre-empts hack, shuts down certificates

Certificate authority GlobalSign is investigating reports that the DigiNotar hacker has access to its system.
iPhone data interception tool released 

iPhone data interception tool released

Marlinspike provides a good reason to update iOS 4.3.5.
Businesses ‘plagued’ by missing encryption keys 

Businesses ‘plagued’ by missing encryption keys

Afflicts digital certificates, too.
PayPal suspends hacker's account after bogus SSL post 

PayPal suspends hacker's account after bogus SSL post

Black Hat demonstration was followed by exploits in the wild.
VeriSign addresses SSL certificate flaw 

VeriSign addresses SSL certificate flaw

VeriSign has moved to address a flaw in its Secure Sockets Layer (SSL) certification technology, which could have allowed hackers to create false certificates.
1
Sign up to receive SC Magazine email newsletters
   FOLLOW US...
Most Read