ALL >> Computers >> View Article
Certification Authority Alerts Users On Fraudulent Ssl Certificates

Recently, Comodo Group, Inc., one of the leading certification authorities warned against nine fraudulent Secure Sockets Layer (SSL) certificates issued by a Registration Authority. The registration authority reportedly suffered a security breach incident, which led to the disclosure of a user account. The compromised user account was used by the attacker to create new authentication credentials, placing and receiving order for certifications. The fraudulent certificates affect login.live.com, mail.google.com, google.com, login.yahoo.com (3 fraudulent certificates), login.skype.com, addons.mozilla.org and global trustee.
Cybercriminals could use sophisticated techniques to lure users to visit websites using fraudulent certificates. As the sites appear legitimate to the users, they may enter the authentication details on the website, which could be extracted by the attackers. The fraudulent certificates could also be used to trick users to download files containing malware on their computer systems. The malware could be designed to extract confidential personal or business information. Attackers could use the fake certificates ...
... to spoof content or launch phishing attacks. Cyber education is crucial to combat growing security threats. Training sessions, seminars, online degree and e-learning programs could help in enlightening employees on Internet security issues and improve the IT security practices in organizations.
Computer forensics experts are investigating the case and the registration authority has been suspended pending investigation. The fraudulent certificates have been revoked. The certification authority has reported to the respective government authorities, browser vendors and domain owners regarding the issue of fraudulent SSL certificates.
Security breaches could be prevented by evaluating the IT infrastructure at frequent intervals through IT professionals qualified in penetration testing, security audit, masters of security science to identify and mitigate security flaws.
United States Computer Emergency Readiness Team (US-CERT) has also cautioned users against the fraudulent certificates Major browser vendors have updated their browsers to identify and block the fraudulent certificates. Mozilla has updated Firefox 3.5, 3.6 and 4.0 to block these certificates. Microsoft has released updates for Windows to address the issue. Internet users must install and regularly update anti-virus software in their computer systems. Regular adherence to security advisories and updates from developers would also help in preventing malicious attacks. Distance learning and online university degree programs could enable IT professionals to update their skill sets to combat the growing IT security threats. IT administrators must keep track of the software updates and patch releases to secure the organizational networks and computer systems from intrusions and unauthorized access.
Add Comment
Computers Articles
1. Upgrade Your Skills With The Best Business Analytics Courses In BhopalAuthor: Rohan Rajput
2. Virtual Security Guard
Author: james
3. Virtual Guard Fencing
Author: james
4. Exploring The Growth Of Mobile App Development Companies In Calgary: A 2025 Insight
Author: Josh Mark
5. Enhance Decision-making With Opentable Reviews Data Scraping
Author: DataZivot
6. How To Choose The Right Computer Repair Shop In Denver
Author: Timothy
7. Why Your 3pl Business Needs A Smarter Wms: Discover Fulfillor’s Edge
Author: Visvendra Singh
8. Top Antivirus Coupon Codes & Promo Deals
Author: Dhruv
9. Virtual Guard Video Tour & Ai Analytics System
Author: james
10. Security Incident Management
Author: james
11. Small Business Accounting Software: A Game Changer For Entrepreneurs
Author: Cecilia Robert
12. Security Guard Human Resource
Author: james
13. Guard Time And Attendance
Author: james
14. Cheap Web Design Singapore
Author: cheap
15. Video Editing Course In Hyderabad
Author: venky