As cited
Copy frozen at (site build).
threat intel
GoldenEyeDog Subgroup Linked to DigiCert Breach and Code-Signing Certificate Theft
Cybersecurity researchers have attributed the April 2026 DigiCert security incident to a threat activity cluster called CylindricalCanine, identified as a subgroup of GoldenEyeDog, a Chinese cybercrime group known for targeting gambling and gaming sectors. The breach resulted in the theft of code-signing certificates from the certificate authority. Expel published technical details of the incident and the threat actor's methods.
Why it matters: Organizations relying on DigiCert-issued code-signing certificates face elevated risk of supply chain attacks, as stolen certificates can be used to sign malicious software; practitioners should audit certificate usage and implement additional code-signing verification controls.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
threat intel
GoldenEyeDog Subgroup Linked to DigiCert Breach and Code-Signing Certificate Theft
Researchers attribute the April 2026 DigiCert security incident to CylindricalCanine, a subgroup of GoldenEyeDog, a Chinese cybercrime group. The threat actor is known for targeting gambling and gaming sectors and was linked to code-signing certificate theft during the breach.
Why it matters: Organizations using DigiCert certificates and those in gaming or gambling industries face exposure to compromised code-signing certificates that could enable supply chain attacks; practitioners should review certificate logs and implement stricter validation controls.
- Source published
- First seen by Cybersecurity Tracker