A valid signature stopped being a reliable sign that software is safe. Once attackers steal code-signing certificates, they can make malware look like it came from a legitimate publisher and slip past allowlisting, reputation checks, and other “signed means trusted” controls.
Expel tied the April 2026 DigiCert breach to CylindricalCanine, a GoldenEyeDog subgroup, and said the stolen customer certificates were used to sign malware. DigiCert revoked about 60 certificates after the incident, confirming this was active misuse of trust material, not just a theft event.
The risk does not end when the original breach is closed. Any workflow that treats publisher signatures as an approval step has to assume the attacker can keep producing new signed binaries until the abused certificates are fully revoked and downstream trust stores catch up.