Comodohacker

GlobalSign breach stemmed from unpatched server

GlobalSign was left red-faced last year after one of its Web servers was hacked. It turns out the incident was due to a piece of open-source software not being updated, a senior GlobalSign executive told sister site ZDNet UK.

The company ceased issuing certificates, and shut down its operations. GlobalSign said it keeps SSL-certificate issuing infrastructure "separate" from its Web site -- a common practice -- and reiterated that its operations was secure.

GlobalSign's own Web site, the site's certificate, and some other public-facing documents were compromised during the hack, but no other servers were breached.… Read more

DigiNotar files for bankruptcy

Dutch certificate authority DigiNotar is closing up shop following a recent hacking attack that caused it to issue a series of phony online security certifcates.

Parent company Vasco announced the bankruptcy filing yesterday, explaining that a trustee will work with the court as DigiNotar goes through the bankruptcy process.

Vasco is also currently analyzing the extent of the damage caused by the cyberattack.

"We are working to quantify the damages caused by the hacker's intrusion into DigiNotar's system and will provide an estimate of the range of losses as soon as possible, "Cliff Bown, Vasco's … Read more

Comodohacker: I can issue fake Windows updates

Following his recent attack against Dutch security company DigiNotar, the hacker known as Comodohacker is now threatening to exploit Microsoft's Windows Update service.

In another message posted on Pastebin last week touting his cyberattacks, the infamous hacker claims that he's able to issue phony Windows updates despite Microsoft's assertion to the contrary.

"I'm able to issue Windows update--Microsoft's statement about Windows Update and that I can't issue such update is totally false," proclaimed Comodohacker. "I already reversed ENTIRE Windows update protocol, how it reads XMLs via SSL which includes URL, KB … Read more

Comodohacker returns in DigiNotar incident

A hacker known as Comodohacker has taken responsibility for the recent attack against Dutch certificate authority DigiNotar and is now threatening to release fake security certificates for other companies that he has hacked.

Beyond issuing a phony certificate for Google.com, DigiNotar has admitted that the attack actually caused the company to issue more than 500 fake Secure Sockets Layer (SSL) certificates for a variety of major organizations, including the CIA, MI6, Facebook, Microsoft, Skype, and Twitter.

SSL certificates are used to authenticate secure Web sites to ensure that users are connecting to the intended site. Faked certificates are especially … Read more