Tag: code signing
7 articles

Mozilla Revokes Firefox Signing Key After GitHub Exposure
Mozilla sprang into action after discovering a sensitive Firefox signing key had been mistakenly uploaded to a private GitHub repository, revoking the exposed key and implementing extra safeguards to prevent future mishaps. Fortunately, the company found no evidence that the key was compromised during its brief online exposure.

Gatekeeper Flaw Lets Attackers Swap macOS Apps with Malicious Twins
A newly discovered flaw in macOS Gatekeeper could let attackers secretly swap your downloaded apps with malicious versions, putting your device and data at risk. Researchers have found a way to bypass Gatekeeper's security checks, allowing them to replace apps with tampered versions without needing special privileges.

GitHub Verified Commits Can Be Rewritten Without Breaking Signatures
A recent study revealed a surprising vulnerability in GitHub's verified commits, showing that signed commits can be rewritten without breaking their digital signatures. This means that tampered code can still be labeled as Verified, posing a significant risk to code security.

Malvertisers Exploit Code Signing in TamperedChef Malware Campaigns
Meet the sneaky malware campaign that's been flying under the radar, leveraging polished marketing tactics and code signing to spread its malicious reach - with over 4,000 samples and 100 unique variants uncovered across three distinct clusters of activity.

Microsoft Disrupts Malware Signing Service Used by Ransomware Groups
Microsoft cracked down on a sophisticated malware signing service run by a group called Fox Tempest, which helped ransomware gangs disguise their malicious programs as legitimate software. This service was like a master forgery operation, creating counterfeit digital signatures that even experts struggled to spot.

Microsoft Disrupts Fox Tempest's Ransomware-Enabling Code-Signing Service
Microsoft's Digital Crimes Unit has successfully disrupted a notorious code-signing service used by cybercriminals, including the group behind Fox Tempest, to create fake IDs and gain easy access to systems. This operation has effectively shut down a key tool used by hackers to spread ransomware and malware.

OpenAI Revokes macOS Certs Amid Supply Chain Breach Fallout
A recent supply chain breach has raised concerns about software trustworthiness, prompting OpenAI to revoke its macOS code-signing certificates after a malicious package was executed in its build pipeline. This swift action highlights the vulnerability of even the most secure systems to supply chain attacks.