Risky Bulletin Newsletter
May 04, 2026
Risky Bulletin: DigiCert hacked with a malicious screensaver file
Presented by
News Editor
A threat actor gained access to DigiCert's backend and stole 27 code signing certificates they later used to sign malware.
The incident took place last month and was traced back to a social engineering attack that successfully compromised two employees of DigiCert's tech support team.
According to DigiCert's post-mortem, the attacker posed as a customer and tricked the tech support staff into running an SCR file, a format used to install and configure Windows screensavers.