Bug hunter exposes SSL.com flaw, triggers certificate revocations

April 21, 2025, 10:20 pm

A security researcher exploited a bug in SSL.com’s domain validation process to illicitly obtain digital certificates for an Alibaba Cloud domain. After the error led to ten additional certificates being mis-issued, all have now been revoked, underscoring glaring vulnerabilities in digital certificate safeguards.


theregister.com / Bug hunter tricked SSL.com into issuing cert for Alibaba Cloud domain in 5 steps

10 other certificates 'were mis-issued and have now been revoked' Certificate issuer SSL.com’s domain validation system had an unfortunate bug that was exploited by miscreants to obtain, without authorization, digital certs for legit websites.…


permalink / 1 stories from 1 sources in 6 hours ago #cybersecurity #infosec #cloudsec #app-security #technology



Disclaimer: The information provided on this website is intended for general informational purposes only. While we strive for accuracy, we do not guarantee the completeness or reliability of the content. Users are encouraged to verify all details independently. We accept no liability for errors, omissions, or any decisions made based on this information.