Close Menu
    Facebook X (Twitter) Instagram
    Wifi PortalWifi Portal
    • Blogging
    • SEO & Digital Marketing
    • WiFi / Internet & Networking
    • Cybersecurity
    • Tech Tools & Mobile / Apps
    • Privacy & Online Earning
    Facebook X (Twitter) Instagram
    Wifi PortalWifi Portal
    Home»Cybersecurity»DigiCert Revokes Certificates After Support Portal Hack
    Cybersecurity

    DigiCert Revokes Certificates After Support Portal Hack

    adminBy adminMay 5, 2026No Comments2 Mins Read
    Facebook Twitter LinkedIn Telegram Pinterest Tumblr Reddit WhatsApp Email
    DigiCert
    Share
    Facebook Twitter LinkedIn Pinterest Email

    DigiCert last week announced that certificates fraudulently obtained from its internal support portal after a cyberattack were revoked.

    The attack, the company said in a detailed report, occurred on April 2, when a threat actor targeted DigiCert’s support team with a malicious payload delivered via a customer chat channel, disguised as a screenshot.

    The malware infected two endpoints, one of which was identified on April 3, and another on April 14. DigiCert blames the late discovery of the second infection on the malfunctioning security solutions running on the endpoint.

    According to the company, the hackers pivoted from the infected system to its internal support portal, using a limited access function to obtain EV Code Signing certificates.

    This was possible because DigiCert’s authenticated support analysts can proxy into customer accounts, which provides them with access to specific functions, including initialization codes for pending Code Signing certificate orders.

    “Possession of an initialization code, combined with an approved order, is sufficient to obtain the resulting certificate. Since the threat actor was able to obtain these two pieces of information for a finite set of approved orders, they were able to obtain EV Code Signing certificates across a set of customer accounts and CAs,” DigiCert says.

    Advertisement. Scroll to continue reading.

    By April 17, the company identified and revoked 60 certificates associated with the incident, including 27 explicitly linked to the threat actor. Of these, 11 were reported by the community and were used to sign the Zhong Stealer malware family, DigiCert says.

    “In our investigation, we did not find evidence that the threat actor misused other internal systems other than the Code Signing initialization codes within specific accounts,” the company says.

    DigiCert says that all certificates potentially linked to this activity were revoked by April 17, and pending orders were canceled to close the attackers’ access.

    Additionally, the company improved its security and access controls to enforce multi-factor authentication for administrative workflows, prevent access to initialization codes from proxied support users, restrict the file types that can be sent using support chat and Salesforce case attachments, and improve logging.

    Related: Edtech Firm Instructure Discloses Data Breach Amid Hacker Leak Threats

    Related: Over 40,000 Servers Compromised in Ongoing cPanel Exploitation

    Related: FBI Warns of Surge in Hacker-Enabled Cargo Theft

    Related: Two US Security Experts Sentenced to Prison for Helping Ransomware Gang 

    Certificates DigiCert Hack portal Revokes Support
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Telegram Email
    Previous ArticleIBM unveils its blueprint to help enterprises run AI at the core of their business
    Next Article Fintech AI search case study: 4 lessons from Wise.com
    admin
    • Website

    Related Posts

    Encryption Consulting launches CertSecure Manager v3.3 with zero-touch certificate renewals

    May 20, 2026

    GitHub confirms breach of 3,800 repos via malicious VSCode extension

    May 20, 2026

    Grafana GitHub Breach Exposes Source Code via TanStack npm Attack

    May 20, 2026
    Add A Comment
    Leave A Reply Cancel Reply

    Search Blog
    About
    About

    At WifiPortal.tech, we share simple, easy-to-follow guides on cybersecurity, online privacy, and digital opportunities. Our goal is to help everyday users browse safely, protect personal data, and explore smart ways to earn online. Whether you’re new to the digital world or looking to strengthen your online knowledge, our content is here to keep you informed and secure.

    Trending Blogs

    Google tests new conversational ad formats in AI Mode and Search

    May 21, 2026

    How to measure AI search visibility: KPIs & reporting

    May 21, 2026

    Mueller Explains Why Google Uses Markdown On Dev Docs

    May 21, 2026

    Google Marketing Live 2026: Everything you need to know

    May 21, 2026
    Categories
    • Blogging (82)
    • Cybersecurity (1,955)
    • Privacy & Online Earning (223)
    • SEO & Digital Marketing (1,216)
    • Tech Tools & Mobile / Apps (1,796)
    • WiFi / Internet & Networking (306)

    Subscribe to Updates

    Stay updated with the latest tips on cybersecurity, online privacy, and digital opportunities straight to your inbox.

    WifiPortal.tech is a blogging platform focused on cybersecurity, online privacy, and digital opportunities. We share easy-to-follow guides, tips, and resources to help you stay safe online and explore new ways of working in the digital world.

    Our Picks

    Google tests new conversational ad formats in AI Mode and Search

    May 21, 2026

    How to measure AI search visibility: KPIs & reporting

    May 21, 2026

    Mueller Explains Why Google Uses Markdown On Dev Docs

    May 21, 2026
    Most Popular
    • Google tests new conversational ad formats in AI Mode and Search
    • How to measure AI search visibility: KPIs & reporting
    • Mueller Explains Why Google Uses Markdown On Dev Docs
    • Google Marketing Live 2026: Everything you need to know
    • Google unveils Gemini 3.5 Flash and a redesigned ‘intelligent Search box’
    • 12 Awesome Custom Google Analytics Reports Created by the Experts
    • Selector targets the network visibility gap in multi-cloud infrastructure
    • How to Persuade Your Boss to Send You to Ahrefs Evolve in San Diego
    © 2026 WifiPortal.tech. Designed by WifiPortal.tech.
    • Home
    • About Us
    • Contact Us
    • Privacy Policy
    • Terms and Conditions
    • Disclaimer

    Type above and press Enter to search. Press Esc to cancel.