RSA-512 Certificates abused in the wild
ID: 175474e0-b5da-5141-9de1-5e799df0ef98
STIX ID: report--175474e0-b5da-5141-9de1-5e799df0ef98
Feed Name: Fox-IT blog
The report documents how attackers exploited weak 512-bit RSA certificates issued by multiple Certificate Authorities (notably Digicert Sdn.Bhd. and related issuers) by factoring the keys and using the resulting certificates to sign malware delivered in targeted attacks against governments, political organizations, and defense industry targets; it details the discovery process (including use of EFF SSL Observatory data), the certificates and hosts involved, and calls out the need for CA and platform-level mitigations such as revocation and deprecation of weak key sizes.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
