logo

Hackers Use Malicious Screensaver File to Breach DigiCert and Steal EV Code Signing Certificates

ID: ea75d152-22e4-5ec2-9bf4-a5d861080578

STIX ID: report--ea75d152-22e4-5ec2-9bf4-a5d861080578

Feed Name: Cyber Press

Threat Score
78/100

Date Published: 2026-05-05

Date Updated: 2026-05-05

Author: AnuPriya

...
...

DigiCert confirmed an April 2026 breach in which attackers used social engineering (a malicious .scr screensaver delivered via Salesforce chat) and a failed endpoint sensor to access support tooling, abuse initialization codes to fraudulently issue 60 EV code-signing certificates (27 linked to active abuse), and sign Zhong Stealer malware; DigiCert revoked all compromised certificates and implemented UI/API restrictions, stronger MFA, suspended accounts, and other controls.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.