Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Endpoint Security

Emsisoft Tells Users to Update Products, Reboot Systems Due to Certificate Mishap

Emsisoft urges its users to update anti-malware and other security products after signing them with an improperly issued digital certificate.

Endpoint security firm Emsisoft is urging its users to update their anti-malware and other security products and reboot their systems after using an improperly issued digital certificate to sign them.

The problem, the company says, affects its Extended Validation (EV) code signing certificate that was renewed on August 23 and used to sign all program files compiled after that date, including the latest software version, released on September 4.

GlobalSign, the certificate authority (CA) that issued the certificate, informed Emsisoft on September 4 that it introduced the wrong business number at issuance, meaning that the certificate would need to be revoked and reissued.

The CA has issued a new certificate and is revoking the improperly issued one today, September 8. Emsisoft has re-signed all files using the correct certificate and has made updates available for its products.

“The new files are available through the online update of our products and we expect that the vast majority of our customers will automatically receive the new version before the old certificate gets revoked,” Emsisoft notes.

The main issue with this mishap, however, is the fact that the security firm also used the improperly issued certificate to sign a new driver component, and updating it requires a system reboot.

“When a certificate authority revokes a certificate, all software files that have been signed with it will produce a security warning, and drivers may not load at all. This essentially breaks the protection, including the ability to run online updates,” the security firm explains.

According to Emsisoft, should it come to this, users would need to reinstall the affected software to restore the protection. As such, the company is urging all users to reboot systems after updating their security products.

Advertisement. Scroll to continue reading.

“We urge all our customers to make sure automatic updates are enabled in Emsisoft Anti-Malware, Emsisoft Business Security and Emsisoft Enterprise Security and reboot their computers before September 22nd, 2023,” the company underlines.

Related: GitHub Revokes Code Signing Certificates Following Cyberattack

Related: Antivirus Firm Emsisoft Discloses Data Breach

Written By

Ionut Arghire is an international correspondent for SecurityWeek.

Click to comment

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Join the session as we discuss the challenges and best practices for cybersecurity leaders managing cloud identities.

Register

SecurityWeek’s Ransomware Resilience and Recovery Summit helps businesses to plan, prepare, and recover from a ransomware incident.

Register

People on the Move

Mike Dube has joined cloud security company Aqua Security as CRO.

Cody Barrow has been appointed as CEO of threat intelligence company EclecticIQ.

Shay Mowlem has been named CMO of runtime and application security company Contrast Security.

More People On The Move

Expert Insights

Related Content

Endpoint Security

Today, on January 10, 2023, Windows 7 Extended Security Updates (ESU) and Windows 8.1 have reached their end of support dates.

Application Security

Virtualization technology giant VMware on Tuesday shipped urgent updates to fix a trio of security problems in multiple software products, including a virtual machine...

Endpoint Security

Gigabyte has announced BIOS updates that remove a recently identified backdoor feature in hundreds of its motherboards.

Endpoint Security

Several major companies have published advisories in response to the Downfall vulnerability affecting Intel CPUs.

Data Protection

By implementing strong security practices,, organizations can significantly reduce the risks associated with lost and stolen computers and safeguard their sensitive information.

Application Security

Microsoft on Tuesday pushed a major Windows update to address a security feature bypass already exploited in global ransomware attacks.The operating system update, released...

Endpoint Security

Apple has launched a new security research blog and website, which will also be the new home of the company’s bug bounty program.

Endpoint Security

When establishing visibility and security controls across endpoints, security professionals need to understand that each endpoint bears some or all responsibility for its own...