Qihoo 360 Leaked Its Own Wildcard SSL Private Key Inside Public AI Installer
ID: 028f4023-f82c-55e5-95f9-c7ea4db271c9
STIX ID: report--028f4023-f82c-55e5-95f9-c7ea4db271c9
Feed Name: cybersecurityNews.com
Qihoo 360 accidentally shipped a live wildcard TLS private key (CN=*.myclaw.360.cn) inside the public installer for its Security Claw AI product; the key was valid from 2026-03-12 to 2027-04-12 and was confirmed to match the certificate. Because it is a wildcard key covering all subdomains, possession enables high-impact attacks (MitM, server impersonation, credential harvesting, session hijacking); the certificate was reportedly revoked after disclosure but revocation may not be instantaneous due to OCSP caching.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
