(1 votes, average: 5.00 out of 5)

Attackers Hijack 3 Country-code Registries, Obtain Google Certificates

Google revealed on October 6, 2026 that attackers have hijacked the administrators of three country-code domain registries to get illegitimate HTTPS certificates for a number of Google sites and other domain names. Google said it blocked the certificates in Chrome and that its own systems were not breached. What was…
(1 votes, average: 5.00 out of 5)

6 Months to 100 Day TLS: The Certificate Automation Wake-Up Call

March 15, 2027, cuts public TLS to 100 days. Manually renewing will not be the way to go through the chop. Six months left. On March 15, 2027, new public TLS drops to 100 days. TLS 200-day is now available. The renewal process will not change from twice a year…
(4 votes, average: 5.00 out of 5)

What Is Quantum Readiness? How to Assess Your Organization’s Quantum Readiness

Most of today’s data is encrypted using public-key algorithms that quantum computers can break. Security experts already harvest data from these machines that is encrypted and can be decrypted later. There is a need to act now at the organisational level. This guide provides assessment steps, a roadmap, a framework,…
(5 votes, average: 5.00 out of 5)

What is a Cross Certificate in PKI? How it Helps Maintain Continuous PKI Trust?

Key Takeaways Introduction Different entities use separate PKIs, and each has a different root of trust. This makes it impossible for users to validate certificates and their identities between trust domains. To solve this problem, cross-certificates come into play, as they make connections between separate trust domains while maintaining certification…
(5 votes, average: 5.00 out of 5)

What Is a Merkle Tree Certificate (MTC)? [Detailed Guide]

As businesses and organizations ramp up their utilization of digital certificate systems, there arises a need to be able to verify certificate-related data in an efficient manner, without subjecting large datasets to a cumbersome verification process again and again. Merkle Tree Certificates (MTCs) use cryptographic hash trees to create compact…
(4 votes, average: 5.00 out of 5)

Complete Guide to ACME External Account Binding (EAB)

Hand-releasing SSL/TLS certificates no longer scales because it starts with a request. They did so by allowing servers to communicate directly with Certificate Authorities, but Let’s Encrypt’s registration is open, whereas enterprise CAs & commercial providers require verification of who they are issuing a certificate to. This is where External…
(4 votes, average: 5.00 out of 5)

Google, Microsoft, Cloudflare & DigiCert Prepare for 2029 PQC Migration

Quantum computers will not only become faster. They’ll get dangerous. After passing that threshold, they could break RSA and ECC encryption protecting your banking transfers, medical details, and “HTTPS” connections. Attackers aren’t waiting. They are currently collecting encrypted data, hoping to eventually be able to decrypt the information as quantum…
(4 votes, average: 5.00 out of 5)

Verified & Common Mark Certificate (VMC and CMC) Validation Process for BIMI Compliance

With the development of email security, Verified Mark Certificates (VMCs) and Common Mark Certificates (CMCs) have become critical for organisations that want to showcase their brand logos in email clients using the BIMI (Brand Indicators For Message Identification) standard. Before an organisation’s logo appears in a recipient’s inbox, however, it…
(4 votes, average: 5.00 out of 5)

What are the ACME Challenges for Domain Validation? Which One Should You Use?

Your SSL pipeline breaks at 2 am… Does this sound like you? Nothing was going wrong at all. Certificates were issued. Renewals were automated. You felt confident. And your page gives a certificate warning. Now you’re scrambling and checking logs. Restarting services and asking yourself why some automatic thing just…
(3 votes, average: 5.00 out of 5)

What are ACME Clients? What are the Most widely used ACME Clients?

When your certificate expires, your site does not even slow down. It breaks trust instantly. There is a large red warning for visitors. Browsers block access. And within seconds, your credibility gets a blow. No matter how good your product is, you cannot be sure that people can access your…
(4 votes, average: 5.00 out of 5)

NIST’s Latest PQC Milestone: 9 Signature Algorithms Advance to Round 3

The National Institute of Standards and Technology (NIST) announced a significant step toward further development of post-quantum cryptography (PQC), as nine digital signature algorithms (DSAs) continue to proceed through the third round of its PQC Standardisation Process (PQCSP). The move follows 18 months of testing and evaluation and marks NIST’s…
(3 votes, average: 5.00 out of 5)

Classical vs. Quantum vs. Post-Quantum Cryptography Difference Explained

Quantum computers are not something you see in movies anymore. They are real. They are a major problem in how we keep things safe online. This includes our bank accounts, the way we talk to each other, and our identities. Most of the ways we keep things secret today are…
(4 votes, average: 5.00 out of 5)

Chrome Policy Update 2026: Mandatory CT Logging for DigiCert TLS Certificates

Key Changes June 2026 If your organisation uses DigiCert, GeoTrust, Thawte, RapidSSL, or Encryption Everywhere to issue public TLS certificates and currently opts out of Certificate Transparency (CT) logging, your certificates will be force-logged starting June 1, 2026. Every domain name on those certificates becomes publicly visible. If you do…
(4 votes, average: 5.00 out of 5)

What Is Hybrid Cryptography? [The Practical Path to PQC]

Every time you log into your bank, send an email, or connect to a VPN, encryption quietly does the heavy lifting. The internet feels simple. The security underneath it? Anything but simplicity. That’s a problem most newbs miss: No encryption fits all cases. Symmetric encryption is quick but makes key…
(3 votes, average: 5.00 out of 5)

What Is Vishing Attacks? Examples, Types & Prevention Tips

Introduction Owing to the advancement in technology, hackers are never idle as they continue to look for new ways that they can use to penetrate and gain unauthorized access to people’s information. Among these up-and-coming threats is vishing, or voice phishing, a form of social engineering wherein the attacker uses…