Adobe overhauls digital signing system post-attack
Software giant rushes to fix signing system following discovery of digitally signed malware.

Software giant Adobe is to overhaul its digital signing procedures after the discovery of two malware samples carrying the firm's digital certificate of approval.
The certificate's presence means the "malicious utilities" would have been treated as safe by end users' computers.
We believe the vast majority of users are not at risk.
In a blog post, confirming the discovery, Adobe said the malware had been traced back to a single source and that a "compromised build server" had been discovered with access to the firm's code signing infrastructure.
"We immediately decommissioned the existing Adobe code signing infrastructure and initiated a forensics investigation to determine how these signatures were created," said the blog post.
"We are proceeding with plans to revoke the certificate and publish updates for existing Adobe software signed using the impacted certificate."
The firm said signed samples of malware are often used in "highly targeted attacks", but said the "vast majority" of users were not at risk.
Get the ITPro daily newsletter
Sign up today and you will receive a free copy of our Future Focus 2025 report - the leading guidance on AI, cybersecurity and other IT challenges as per 700+ senior executives
The software vendor has introduced an interim signing service, featuring an offline human verification stage, and revealed that it is working on a replacement system.
It will also be revoking all affected certificates, issued after 10 July 2012, on Thursday 4 October 2012.
-
The IT industry’s shift to circular, low-carbon solutions
Maximize your hardware investment and reach your sustainability goals with HP’s Renew Solutions
-
Lenovo ThinkPad X9 14 Aura Edition review
Reviews This thin and light ultraportable will draw you in with its vibrant screen – but it isn't as powerful as some of its competitors
-
Hackers are stepping up ‘qishing’ attacks by hiding malicious QR codes in PDF email attachments
News Malicious QR codes hidden in email attachments may be missed by traditional email security scanners, with over 500,000 qishing attacks launched in the last three months.
-
Warning issued over “incomplete” fix for Adobe ColdFusion vulnerability
News An incomplete fix for a vulnerability disclosure could be placing users at risk, researchers warned
-
Adobe forced to patch its own failed security update
News Company issues new fix for e-commerce vulnerability after researchers bypass the original update
-
Ask more from your CMS
Whitepaper How to get the most value in the shortest timespan
-
Adobe battles fake photos with editing tags
News Photoshop will include new tagging tools later this year to help fight against misinformation and deep fakes
-
Adobe Photoshop Elements 2019 review: Trapped in the photo-editing middle ground
Reviews A once peerless beginner’s photo-editing package that’s past its prime
-
How Adobe saved BT £630,000
Sponsored Adobe’s digital signature platform is saving time and money - and forging stronger connections between businesses and customers
-
Don't settle when it comes to creativity
Sponsored Getting the best out of your creative design team means equipping them with the best software