logo

DigiCert Hacked via Weaponized Screensaver File to Obtain EV Code Signing Certificates

ID: fae717da-17ac-5614-8235-978c9ee7b501

STIX ID: report--fae717da-17ac-5614-8235-978c9ee7b501

Feed Name: cybersecurityNews.com

Threat Score
88/100

Date Published: 2026-05-04

Date Updated: 2026-05-05

Author: Guru Baran

...
...

**Executive summary:** A threat actor compromised DigiCert support analysts via a malicious .scr inside a ZIP delivered through a Salesforce chat, enabling theft and activation of 60 EV Code Signing certificates that were used to sign and distribute the Zhong Stealer malware; DigiCert revoked all affected certificates, identified seven attacker IPs, linked 27 certs to the attacker, and implemented UI/API fixes, stricter MFA controls, suspended analyst accounts, and canceled pending code-signing orders.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.