DigiCert support portal compromise and misissued EV code signing certificates
An attacker posing as a customer infected DigiCert support workstations via chat and harvested EV code signing initialization codes; 60 certificates were revoked, some used to sign Zhong Stealer.
- Victim
- DigiCert, Inc.