Breaches · 59 days ago
A valid signature stopped being a reliable sign that software is safe. Once attackers steal code-signing certificates, they can make malware look like it came from a legitimate publisher and slip past allowlisting, reputation checks, and other “signed means trusted” controls.
Expel tied the April 2026 DigiCert breach to CylindricalCanine, a GoldenEyeDog subgroup, and said the stolen customer certificates were used to sign malware. DigiCert revoked about 60 certificates after the incident, confirming this was active misuse of trust material, not just a theft event.
The risk does not end when the original breach is closed. Any workflow that treats publisher signatures as an approval step has to assume the attacker can keep producing new signed binaries until the abused certificates are fully revoked and downstream trust stores catch up.
1 source covering this story
GoldenEyeDog Subgroup Linked to DigiCert Breach and Code-Signing Certificate Theft
Expel links CylindricalCanine to DigiCert's April 2026 breach, where stolen certificates were used to sign Zhong Stealer and 60 were revoked.
Part of the PlainSec briefing for 2026-07-18