The B2B Podcast Index
Index
All categories
MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
MethodologySubmit
Best of:MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
An independent project byFame
SearchBest episodesGuestsInsightsMethodologySubmit a podcast
Index/Engineering & DevTools/Security Now
Security Now artwork

SN 1078: DigiCert does it right - Hugging Face Under Fire

Security Now · 2026-05-13 · 2h 41m

0:00--:--

Key moments - from our scoring

Substance score

45 / 100

Five dimensions, 20 points each

Insight Density11 / 20
Originality9 / 20
Guest Caliber6 / 20
Specificity & Evidence14 / 20
Conversational Craft5 / 20

DigiCert's April 2026 breach demonstrates both the escalating threat to trust infrastructure and the power of decisive incident response. Attackers compromised internal support endpoints to acquire certificate initialization codes for extended validation (EV) code signing certificates, ultimately obtaining 27 fraudulent certificates used to distribute malware including the Zong Stealer campaign. What distinguished DigiCert's handling was their commitment to transparency: within 24 hours, all affected certificates were revoked with the revocation date set to the original issue date. Their incident report detailed every phase of the breach, identified procedural weaknesses (incomplete endpoint protection, insufficient privilege controls), and outlined remediation steps including endpoint blocking, support portal access masking, enhanced malware scanning, and privilege access management reviews. However, Microsoft Defender's response created secondary damage by aggressively removing DigiCert's root certificates from Windows Trust Stores, temporarily marking legitimate software as untrusted and prompting unnecessary system reinstalls. The episode serves as a masterclass in what separates vendor responsibility from reckless automation when trust anchors are threatened.

Key takeaways

  • →DigiCert revoked all 27 fraudulent code signing certificates within 24 hours and published a transparent, technically detailed incident report that set the gold standard for CA breach response.
  • →Attackers specifically targeted certificate authorities to obtain legitimate-looking certificates for malware distribution, demonstrating the increasing attractiveness of trust infrastructure as a pivot point for attacks.
  • →Microsoft Defender's automated response to remove DigiCert's root certificates from Windows Trust Stores caused widespread false positives and user disruption, illustrating the dangers of situational-awareness-free security automation.
  • →Organizations defending trust infrastructure need layered security controls including endpoint protection, privilege access management reviews, and third-party vulnerability coordination channels.
  • →IT teams should vet vendors not just on features but on their stated incident response plans and willingness to take public responsibility for security failures.

Topics in this episode

Microsoft DefenderEndpoint ProtectionDigiCertExtended Validation (EV) Code Signing CertificatesCertificate Authority (CA) SecurityZong Stealer MalwareWindows Trust StoresCertificate RevocationPrivilege Access ManagementIncident Response and Transparency

Questions this episode answers

How did attackers compromise DigiCert and obtain fraudulent code signing certificates?

Attackers tricked DigiCert support staff into opening infected files via the customer support portal, compromising internal support endpoints and gaining access to unique certificate initialization codes for extended validation (EV) code signing certificates before they were delivered to legitimate customers.

What was problematic about Microsoft Defender's response to the DigiCert breach?

Microsoft Defender began automatically detecting and deleting DigiCert's root certificates from Windows Trust Stores, which caused legitimate software signed by DigiCert to be marked as untrusted and resulted in false alarms and unnecessary Windows reinstalls before Microsoft released a fix.

Why do certificate authority breaches pose a broader risk to the internet?

Certificate authorities underpin the trust model for secure web browsing, software downloads, and encrypted communications, so compromising a CA or mishandling its breach can have catastrophic security implications across the entire internet ecosystem.

What remediation steps did DigiCert take after discovering the breach?

DigiCert blocked affected endpoints, masked access to sensitive data in the support portal, improved malware scanning for support channel file uploads, and reviewed privilege access management and threat models organization-wide.

Were DigiCert's root certificates compromised in the breach?

No, DigiCert's root certificates were never compromised; the breach was limited to a finite set of 27 code signing certificates obtained through the support portal compromise.

What our scoring noted

Our reviewer’s read on each dimension, with quotes from the episode.

Insight Density

11 / 20

The episode covers a genuine security incident with some substantive technical detail (malware vector, certificate revocation timeline, root certificate preservation), but much of the content is surface-level explanation repeated across multiple sections. The core insights - how the breach occurred, why it mattered, what DigiCert did right - are present but compressed. For a 161-minute episode, the actual novel information is modest; the transcript reads more like a polished summary article than deep technical analysis with new learnings.

Attackers compromised internal support endpoints by tricking staff into opening infected files via a customer support portal. This allowed the attackers to acquire unique certificate initialization codes for extended validation (EV) code signing certificates before they were delivered to legitimate customers.
DigiCert's root certificates were never compromised. The breach was limited to a finite set of certificates, thanks in part to both internal monitoring and help from security researchers.

Originality

9 / 20

The framing of 'DigiCert did incident response right' versus 'Microsoft Defender did it wrong' is a useful comparative lens, but not particularly novel or counterintuitive. The underlying lessons - transparency, speed, access controls - are standard incident response doctrine. No first-principles analysis, contrarian claims, or unexpected frameworks emerge. The episode essentially confirms conventional wisdom about good security practices.

DigiCert's approach to disclosure and remediation stood out for its clarity, detail, and responsibility.
Microsoft Defender's handling of the aftermath created a new set of problems. Instead of simply blocking the compromised certificates, Microsoft Defender updates began detecting and deleting DigiCert's root certificates from Windows Trust Stores on countless devices.

Guest Caliber

6 / 20

Steve Gibson is mentioned as the analyst but no actual guest dialogue, credentials, or expert interviews are present in the transcript. The content reads as a prepared editorial summary rather than a conversation with practitioners who experienced or responded to the breach. There is no indication of direct testimony from DigiCert incident responders, Microsoft engineers, or other operators with lived experience of the event.

According to Steve Gibson on Security Now, DigiCert's approach to disclosure and remediation stood out for its clarity, detail, and responsibility.
(No substantive guest dialogue or expert testimony present in transcript)

Specificity & Evidence

14 / 20

The episode provides concrete, named details: 27 fraudulent certificates, 24-hour revocation timeline, specific malware name ('Zong Stealer'), attribution to Chinese crime groups, and detailed remediation steps (blocking endpoints, masking access, improving malware scanning). These are verifiable specifics that ground the narrative. However, financial impact, customer names, and deeper technical metrics are absent, limiting the evidence further.

the attackers were able to obtain 27 fraudulent code signing certificates, which were then used to sign and distribute malware, including the 'Zong Stealer' campaign linked to Chinese crime groups.
Within 24 hours of discovery, all affected certificates were revoked, with revocation set to the original issue date to prevent further misuse.

Conversational Craft

5 / 20

The transcript contains no actual dialogue, follow-up questions, or host-guest interaction. It is formatted as a written article or prepared editorial statement with no evidence of investigative questioning, challenging claims, or conversational back-and-forth. A 161-minute episode should contain substantial discussion, but this reads entirely as a polished summary with no dynamic exchange.

(Entire transcript is editorial narration with zero conversational exchange)
The episode highlights the critical value of layered security, third-party reporting, and continuous privilege/access review within organizations.

Conversation analysis

Computed from the transcript - who did the talking, and the words that came up most.

Most-used words

digicert17certificates14security10response9incident8microsoft8trust8certificate7breach6attackers5support5root5access5twit5authority4malware4

Episode notes

DigiCert's latest security mishap triggered not just a scramble behind the scenes, but a cascading crisis that briefly wiped trust from millions of Windows systems. Find out how a single support slip, followed by Microsoft's heavy-handed response, left critical infrastructures exposed. The FCC decides router firmware updates are useful. Netgear applies for and gets a full FCC pass. AI uncovers a 21-year old critical FreeBSD RCE. What was behind that Let's Encrypt outage. AI model repositories are overflowing with malware. The CISA 2015 info-sharing act is being renewed. Edge leaves ALL usernames and passwords in the clear. An examination of DigiCert's breach and their response Show Notes - Hosts: Steve Gibson and Leo Laporte Download or

Full transcript

2h 41m

Transcribed and scored by The B2B Podcast Index.

DigiCert Breach Explained: How the Certificate Authority Set the Gold Standard for Incident Response Primary Navigation Podcasts Club Blog Subscribe Sponsors More… Tech DigiCert Breach Explained: How the Certificate Authority Set the Gold Standard for Incident Response May 13th 2026 AI-generated, human-reviewed. When a certificate authority is breached, the impact can ripple across the internet. On Security Now , Steve Gibson analyzed DigiCert’s recent security incident, revealing how their thorough, transparent response not only limited potential fallout but also serves as a playbook for incident management.

Below, we’ll explain what happened, why Microsoft’s reaction caused additional trouble, and what you should be looking for from companies handling your digital trust. What Happened in the DigiCert Breach? In early April 2026, DigiCert - one of the largest and most trusted certificate authorities (CAs) worldwide - was targeted by a malware campaign. Attackers compromised internal support endpoints by tricking staff into opening infected files via a customer support portal.

This allowed the attackers to acquire unique certificate initialization codes for extended validation (EV) code signing certificates before they were delivered to legitimate customers. Armed with these codes, the attackers were able to obtain 27 fraudulent code signing certificates , which were then used to sign and distribute malware, including the "Zong Stealer" campaign linked to Chinese crime groups. Significantly, DigiCert’s root certificates were never compromised. The breach was limited to a finite set of certificates, thanks in part to both internal monitoring and help from security researchers who quickly reported the malicious certificates.

How DigiCert Handled the Incident - A Model for Transparency According to Steve Gibson on Security Now , DigiCert’s approach to disclosure and remediation stood out for its clarity, detail, and responsibility. Within 24 hours of discovery, all affected certificates were revoked , with revocation set to the original issue date to prevent further misuse. DigiCert’s incident report thoroughly documented every phase: how the breach occurred, contributing technical and procedural weaknesses (such as incomplete endpoint protection and insufficient privilege controls), and the precise remediation steps taken.

Actions included: Blocking affected endpoints. Masking access to sensitive data in the support portal. Improving malware scanning for all support channel file uploads. Reviewing privilege access management and threat models organization-wide.

This “no corners cut” approach gave the community confidence in their processes and enabled rapid response from other ecosystem stakeholders. Microsoft Defender: A Case Study in What Not to Do While DigiCert’s response was widely praised, Microsoft Defender’s handling of the aftermath created a new set of problems . Instead of simply blocking the compromised certificates, Microsoft Defender updates began detecting and deleting DigiCert’s root certificates from Windows Trust Stores on countless devices.

This overreaction caused widespread disruption: legitimate software signed by DigiCert was suddenly marked untrusted , leading to false alarms and some users unnecessarily reinstalling Windows. After significant industry chatter and rapid feedback, Microsoft pushed a fix to restore certificates. Still, the episode highlighted the dangers of automated responses that lack situational awareness or proper validation, especially with root infrastructure. Why Certificate Authority Breaches Matter Certificate authorities play a critical role: they underpin the trust model that enables secure web browsing, software downloads, and encrypted communications.

If this trust anchor is compromised or mishandled, it can have catastrophic security and usability implications. DigiCert’s breach underscores how attackers are increasingly targeting trusted infrastructure to facilitate attacks, using legitimate certificates to bypass protections and infect end-users. However, it also shows that rigorous monitoring, clear access controls, and a culture of transparency dramatically limit the damage and maintain stakeholder trust. What You Need to Know DigiCert was breached through a support portal malware attack, leading to misuse of 27 code signing certificates.

All affected certificates were revoked within 24 hours of discovery. DigiCert’s communication and internal review set a strong example of transparent, actionable incident management. Microsoft Defender’s overzealous response inadvertently caused additional problems by removing legitimate root certificates. No end-user action is needed if running current Microsoft security updates, as they have restored affected certificates and resolved false positives.

The episode highlights the critical value of layered security, third-party reporting, and continuous privilege/access review within organizations. Attacks on trust infrastructure (like CAs) are becoming more attractive to cybercriminals. Vet vendors for clear response plans and willingness to take responsibility. The Bottom Line When trust anchors of the digital world are targeted, the response of vendors shapes the impact.

DigiCert’s fast, open, and technically sound approach not only protected users but set a high bar for transparency in the cybersecurity industry. Meanwhile, Microsoft’s hasty automation underlines the need for careful, informed handling of root trust issues. For IT teams, business leaders, and cybersecurity professionals, this event is a reminder: expect attackers to try creative paths to your critical infrastructure - and prepare your monitoring, incident response, and communications accordingly.

Subscribe for more insights and thorough security analysis: https://twit.tv/shows/security-now/episodes/1078 Share: Copied! Security Now #1078 May 12 2026 - DigiCert does it right Hugging Face Under Fire All Tech posts Contact Advertise CC License Privacy Policy Ad Choices TOS Store Twitter Facebook Instgram YouTube Yes, like every site on the Internet, this site uses cookies. So now you know.

Learn more Hide Home Schedule Subscribe Club TWiT About Club TWiT FAQ Access Account Members-Only Podcasts Update Payment Method Connect to Discord TWiT Blog Recent Posts Advertise Sponsors Store People About What is TWiT.

Related episodes across the Index

Other episodes covering the same guests and topics, from across The B2B Podcast Index.

  • It's not you, it's your printer: State-sponsored and phishing threats in 2025Talos Takes · on Endpoint Protection86 / 100
  • Treat AI agents like human employeesTrust Issues · on Microsoft Defender80 / 100
  • Think Like an Attacker: Microsoft Security Exposure Management with Uros Babic [MVP-MCT]M365.FM · on Microsoft Defender78 / 100
  • Inside Email Security: Phishing, Hackers, and Harmony CheckpointThe Audit · on Microsoft Defender74 / 100
  • Episode 122: Microsoft Ignite 2025 Wrap-upThe Azure Security Podcast · on Microsoft Defender73 / 100
  • The Illusion of Control: Cybersecurity, AI and the Risks Beneath the SurfaceThe Financial Executives Edge · on Endpoint Protection72 / 100

More from Security Now

All episodes →
  • SN 1085: A SOTA State-Sponsored Campaign - AI's New Superpower: Loop Engineering69 / 100
  • SN 1084: The Residential Proxy Threat - Malicious Proxies in Your Living Room45 / 100
  • SN 1083: Patch Tuesday à la AI - Arch Linux Repo Under Siege38 / 100
  • SN 1082: The Malicious Use of AI - Anthropic's Red Team Report44 / 100
  • SN 1081: AI Captured the Flag - Personal AI: Productivity Superpower or Privacy Threat?35 / 100
Explore the best B2B Engineering & DevTools podcasts →
All Security Now episodes →