Arthur Fleck retuiteado
Arthur Fleck
32.7K posts

Arthur Fleck retuiteado
Arthur Fleck retuiteado
Arthur Fleck retuiteado
Arthur Fleck retuiteado

‼️🚨 One of the world's largest Certificate Authorities, DigiCert, was compromised by a malicious screensaver file sent through a customer support chat. Their antivirus blocked the malware four times. The agent kept clicking. The fifth try got through.
27 code signing certificates were stolen and used to sign malware.
DigiCert ultimately revoked 60 certificates.
Per DigiCert's incident report, filed in Mozilla's CA compliance tracker as Bug 2033170, here is how it unfolded:
April 2: an attacker contacted a DigiCert helpdesk agent through the company's customer support chat channel, posing as a customer. The lure was a zip file pitched as a screenshot. Inside the zip was a .scr file. On Windows, .scr files are executables, and this one carried a malicious payload.
Opening a file a customer sent through the official support channel is what an agent is supposed to do. Support staff are the one role designed to accept files from strangers.
DigiCert's endpoint security blocked four infection attempts. On the fifth, the support analyst's machine was infected.
DigiCert detected the infection, ran an investigation, and concluded the incident was contained.
Eleven days later, an external researcher tipped DigiCert off about misuse of DigiCert-issued code signing certificates in the wild. That tip led to the discovery of a second compromised machine, belonging to a different support analyst, infected through the same vector. The EDR on that machine had not been functioning correctly, so the original investigation missed it.
The second machine gave the attacker access to DigiCert's internal support portal. That portal lets support staff reach limited views of customer accounts, including initialization codes for ordered but not-yet-issued code signing certificates. Combining a stolen initialization code with an approved order let the attacker pull a real, validly issued code signing certificate. They did this 27 times.
DigiCert's own list of what went wrong:
- File-type filtering on the customer support chat channel did not catch the .scr
- EDR coverage was inconsistent and incomplete, creating a blind spot
- Initialization codes for code signing certificates were not adequately protected
DigiCert says it got lucky. An outside researcher found the malware abuse before DigiCert did. Without that tip, the second machine and the active certificate theft might still be running today.


English
Arthur Fleck retuiteado
Arthur Fleck retuiteado
Arthur Fleck retuiteado
Arthur Fleck retuiteado

टीएमसी ने चुनाव परिणाम को अब सुप्रीम कोर्ट में चुनौती देने की तैयारी कर ली है...क्योंकि सुप्रीम कोर्ट ने कहा था-हम तब दखल देंगे जब हटाए गए वोट इतने अधिक थे कि वे जीत-हार के अंतर को बदल सके....
बंगाल में बीजेपी को 2 करोड़ 92 लाख 24 हजार 804 वोट मिले
टीएमसी को 2 करोड़ 60 लाख 13 हजार 377 वोट मिले
बीजेपी को टीएमसी से 32 लाख 11 हजार 427 वोट ज्यादा मिले
SIR में 91 लाख वोट कटे थे...यानी हर सीट पर औसतन 30 हजार वोटर के नाम काटे गए...176 सीटों पर जीत का अंतर 30 हजार से कम और 117 सीटों पर जीत का अंतर 30 हजार वोटों से ज्यादा रहा....इस आधार पर टीएमसी रिजल्ट को कोर्ट में चुनौती दे सकती है...
हिन्दी
Arthur Fleck retuiteado
Arthur Fleck retuiteado
Arthur Fleck retuiteado

Arthur Fleck retuiteado
Arthur Fleck retuiteado
Arthur Fleck retuiteado
Arthur Fleck retuiteado
Arthur Fleck retuiteado
Arthur Fleck retuiteado
Arthur Fleck retuiteado

In 49 seats in Bengal, under-adjudication voters exceeded win margins.
This assume significance in view of Justice Joymalya Bagchi's observation that if no. of deleted voters was higher than margins, the court would have to apply its mind. @OishaniB_
altnews.in/bengal-results…
English
Arthur Fleck retuiteado

वोट चोरी से कभी सीटें चुराई जाती हैं, कभी पूरी सरकार।
लोकसभा के 240 BJP सांसदों में से, मोटे तौर पर हर छठा सांसद वोट चोरी से जीता है। पहचानना मुश्किल नहीं - क्या उन्हें BJP की भाषा में “घुसपैठिए” कहें?
और हरियाणा? वहाँ तो पूरी सरकार ही “घुसपैठिया” है।
जो संस्थाएँ अपनी जेब में रखते हैं, जो मतदाता सूचियों और चुनावी प्रक्रिया को तोड़-मरोड़ देते हैं - वो ख़ुद “remote controlled” हैं।
उन्हें असली डर सच्चाई का है। क्योंकि निष्पक्ष चुनाव हो जाएँ, तो आज ये 140 के पास भी नहीं जीत सकते।
हिन्दी





























