Hackers Use Malicious Screensaver File to Breach DigiCert and Steal EV Code Signing Certificates
ID: ea75d152-22e4-5ec2-9bf4-a5d861080578
STIX ID: report--ea75d152-22e4-5ec2-9bf4-a5d861080578
Feed Name: Cyber Press
Threat Score
DigiCert confirmed an April 2026 breach in which attackers used social engineering (a malicious .scr screensaver delivered via Salesforce chat) and a failed endpoint sensor to access support tooling, abuse initialization codes to fraudulently issue 60 EV code-signing certificates (27 linked to active abuse), and sign Zhong Stealer malware; DigiCert revoked all compromised certificates and implemented UI/API restrictions, stronger MFA, suspended accounts, and other controls.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
