Google revealed on October 6, 2026 that attackers have hijacked the administrators of three country-code domain registries to get illegitimate HTTPS certificates for a number of Google sites and other domain names. Google said it blocked the certificates in Chrome and that its own systems were not breached. What was…
March 15, 2027, cuts public TLS to 100 days. Manually renewing will not be the way to go through the chop. Six months left. On March 15, 2027, new public TLS drops to 100 days. TLS 200-day is now available. The renewal process will not change from twice a year…
Most of today’s data is encrypted using public-key algorithms that quantum computers can break. Security experts already harvest data from these machines that is encrypted and can be decrypted later. There is a need to act now at the organisational level. This guide provides assessment steps, a roadmap, a framework,…
Key Takeaways Introduction Different entities use separate PKIs, and each has a different root of trust. This makes it impossible for users to validate certificates and their identities between trust domains. To solve this problem, cross-certificates come into play, as they make connections between separate trust domains while maintaining certification…
As businesses and organizations ramp up their utilization of digital certificate systems, there arises a need to be able to verify certificate-related data in an efficient manner, without subjecting large datasets to a cumbersome verification process again and again. Merkle Tree Certificates (MTCs) use cryptographic hash trees to create compact…
Hand-releasing SSL/TLS certificates no longer scales because it starts with a request. They did so by allowing servers to communicate directly with Certificate Authorities, but Let’s Encrypt’s registration is open, whereas enterprise CAs & commercial providers require verification of who they are issuing a certificate to. This is where External…
Quantum computers will not only become faster. They’ll get dangerous. After passing that threshold, they could break RSA and ECC encryption protecting your banking transfers, medical details, and “HTTPS” connections. Attackers aren’t waiting. They are currently collecting encrypted data, hoping to eventually be able to decrypt the information as quantum…
With the development of email security, Verified Mark Certificates (VMCs) and Common Mark Certificates (CMCs) have become critical for organisations that want to showcase their brand logos in email clients using the BIMI (Brand Indicators For Message Identification) standard. Before an organisation’s logo appears in a recipient’s inbox, however, it…
Your SSL pipeline breaks at 2 am… Does this sound like you? Nothing was going wrong at all. Certificates were issued. Renewals were automated. You felt confident. And your page gives a certificate warning. Now you’re scrambling and checking logs. Restarting services and asking yourself why some automatic thing just…
When your certificate expires, your site does not even slow down. It breaks trust instantly. There is a large red warning for visitors. Browsers block access. And within seconds, your credibility gets a blow. No matter how good your product is, you cannot be sure that people can access your…
The National Institute of Standards and Technology (NIST) announced a significant step toward further development of post-quantum cryptography (PQC), as nine digital signature algorithms (DSAs) continue to proceed through the third round of its PQC Standardisation Process (PQCSP). The move follows 18 months of testing and evaluation and marks NIST’s…
Quantum computers are not something you see in movies anymore. They are real. They are a major problem in how we keep things safe online. This includes our bank accounts, the way we talk to each other, and our identities. Most of the ways we keep things secret today are…
Key Changes June 2026 If your organisation uses DigiCert, GeoTrust, Thawte, RapidSSL, or Encryption Everywhere to issue public TLS certificates and currently opts out of Certificate Transparency (CT) logging, your certificates will be force-logged starting June 1, 2026. Every domain name on those certificates becomes publicly visible. If you do…
Every time you log into your bank, send an email, or connect to a VPN, encryption quietly does the heavy lifting. The internet feels simple. The security underneath it? Anything but simplicity. That’s a problem most newbs miss: No encryption fits all cases. Symmetric encryption is quick but makes key…
Introduction Owing to the advancement in technology, hackers are never idle as they continue to look for new ways that they can use to penetrate and gain unauthorized access to people’s information. Among these up-and-coming threats is vishing, or voice phishing, a form of social engineering wherein the attacker uses…