Back to Feed
Supply ChainApr 21, 2026

"DigiCert: Misissued code signing certificates": https://t.co/BTpKShTGWE "A malware incident targ...

DigiCert misissued code signing certificates after malware compromised customer support staff.

Vendor Watch

Run DigiCert?

Get an email when a reviewed story names DigiCert, usually within the hour.

Free. Your list stays private and never appears in a subject line. One click stops it. How Vendor Watch works

Summary

DigiCert revealed that malware targeting a customer support team member led to the misissue of code signing certificates. The incident represents a critical supply chain risk, as compromised code signing certificates can be used to sign malicious software, lending it false legitimacy. The connection to APT-Q-27 remains unclear from available details.

Entities

DigiCert (vendor)APT-Q-27 (threat_actor)code signing certificates (technology)