CylindricalCanine Subgroup Exploits DigiCert Support Portal to Steal Code-Signing Certificates
The stolen certificates were used to sign Zhong Stealer malware, highlighting a critical gap in internal trust controls at certificate authorities. The incident underscores how legitimate support functions, when inadequately isolated, can be weaponized in supply chain attacks targeting software signing infrastructure. Read more