When Kaspersky Lab last week spotted code-signed Trojan malware dubbed Mediyes that had been signed with a digital certificate owned by Swiss firm Conpavi AG and issued by Symantec, it touched off a hunt to determine the source of the problem. . The answer, says Symantec's website security services (based on the VeriSign certificate and authentication services acquisition), is that somehow the private encryption key associated with Conpavi AG certificate had been stolen. The link for this article located at Network World is no longer available. . Examine the breach involving a stolen confidential encryption key associated with a vulnerable digital certificate, revealing significant vulnerabilities in the security framework.. Mediyes Malware, Certification Disclosure, Key Compromise, Cyber Threats. . LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.