gbhackers.com • 18h
DigiCert Code-Signing Certificate Compromise by CylindricalCanine
In April 2026, the threat actor CylindricalCanine, a subgroup of the Chinese-linked GoldenEyeDog (APT-Q-27), compromised DigiCert's code-signing certificate issuance processes. By obtaining legitimate certificates, the attackers signed malicious binaries, specifically the Zhong Stealer, allowing the malware to bypass endpoint detection and response (EDR) systems and OS-level code integrity checks. This breach represents a critical failure in the Certificate Authority (CA) trust model, transitioning the actor's operational focus from targeted gaming fraud to high-impact software supply chain subversion. Remediation requires transitioning to behavior-based detection and auditing anomalous signing patterns.
Links:gbhackers.com, serisec.com, feeds.feedburner.com, Gblock, Cybersecuritynews, Hackread, Qualysec, Twit, It-connect, Cbt •