Certificate Trust Breaks When DigiCert Is Breached

A certificate authority breach is not just another vendor incident. It puts trust infrastructure in the same blast radius as the systems it is meant to secure, because compromise at that layer can affect how organizations validate identities and software. DigiCert was breached through a malicious screensaver file, according to Risky Biz News. The report places the incident alongside other security developments, but the key fact is the target: DigiCert is a major certificate authority, so the compromise carries trust implications beyond a normal corporate intrusion. The immediate risk is not a CVE or a patch cycle. It is the possibility that a trusted security provider can be turned into a source of downstream uncertainty, and that uncertainty can persist even after the initial breach is contained.

Part of the PlainSec briefing for 2026-05-05

Sources