CuraSec

tag: Code-Signing · 1 items

2026-07-18 · The Hacker News · source ↗ #threat-actor#supply-chain#code-signing
  • Engineer — Plan: Code-signing certificate theft from a major CA is a trust-chain risk: audit any DigiCert-issued code-signing certificates in your CI/CD pipeline or software distribution path, and confirm with DigiCert whether your certificates were in scope for revocation.
  • SOC/IR — Learn: Attribution of CylindricalCanine as a GoldenEyeDog subgroup adds context to actor tracking, but the summary is too thin to yield IOCs or mappable TTPs for detection work — monitor for a fuller technical disclosure before building hunts.
  • Leader — Act: A confirmed breach at DigiCert involving stolen code-signing certificates is a vendor risk event: confirm whether your organization uses DigiCert for code signing or certificate services, and request DigiCert’s formal incident attestation and revocation scope this week.