Supply ChainApr 21, 2026
"DigiCert: Misissued code signing certificates": https://t.co/BTpKShTGWE "A malware incident targ...
DigiCert misissued code signing certificates after malware compromised customer support staff.
Vendor Watch
Run DigiCert?
Get an email when a reviewed story names DigiCert, usually within the hour.
Free. Your list stays private and never appears in a subject line. One click stops it. How Vendor Watch works
Summary
DigiCert revealed that malware targeting a customer support team member led to the misissue of code signing certificates. The incident represents a critical supply chain risk, as compromised code signing certificates can be used to sign malicious software, lending it false legitimacy. The connection to APT-Q-27 remains unclear from available details.
Entities
DigiCert (vendor)APT-Q-27 (threat_actor)code signing certificates (technology)