Endpoint security firm Emsisoft is urging its users to update their anti-malware and other security products and reboot their systems after using an improperly issued digital certificate to sign them.
The problem, the company says, affects its Extended Validation (EV) code signing certificate that was renewed on August 23 and used to sign all program files compiled after that date, including the latest software version, released on September 4.
GlobalSign, the certificate authority (CA) that issued the certificate, informed Emsisoft on September 4 that it introduced the wrong business number at issuance, meaning that the certificate would need to be revoked and reissued.
The CA has issued a new certificate and is revoking the improperly issued one today, September 8. Emsisoft has re-signed all files using the correct certificate and has made updates available for its products.
“The new files are available through the online update of our products and we expect that the vast majority of our customers will automatically receive the new version before the old certificate gets revoked,” Emsisoft notes.
The main issue with this mishap, however, is the fact that the security firm also used the improperly issued certificate to sign a new driver component, and updating it requires a system reboot.
“When a certificate authority revokes a certificate, all software files that have been signed with it will produce a security warning, and drivers may not load at all. This essentially breaks the protection, including the ability to run online updates,” the security firm explains.
According to Emsisoft, should it come to this, users would need to reinstall the affected software to restore the protection. As such, the company is urging all users to reboot systems after updating their security products.
“We urge all our customers to make sure automatic updates are enabled in Emsisoft Anti-Malware, Emsisoft Business Security and Emsisoft Enterprise Security and reboot their computers before September 22nd, 2023,” the company underlines.
Related: GitHub Revokes Code Signing Certificates Following Cyberattack
Related: Antivirus Firm Emsisoft Discloses Data Breach

More from Ionut Arghire
- Air Canada Says Employee Information Accessed in Cyberattack
- BIND Updates Patch Two High-Severity DoS Vulnerabilities
- Faster Patching Pace Validates CISA’s KEV Catalog Initiative
- TransUnion Denies Breach After Hacker Publishes Allegedly Stolen Data
- Legit Security Raises $40 Million in Series B Financing
- Atlassian Security Updates Patch High-Severity Vulnerabilities
- Critical Infrastructure Organizations Warned of Snatch Ransomware Attacks
- Tor-Based Drug Marketplace Piilopuoti Shut Down by Law Enforcement
Latest News
- Researchers Discover Attempt to Infect Leading Egyptian Opposition Politician With Predator Spyware
- In Other News: New Analysis of Snowden Files, Yubico Goes Public, Election Hacking
- China’s Offensive Cyber Operations in Africa Support Soft Power Efforts
- Air Canada Says Employee Information Accessed in Cyberattack
- BIND Updates Patch Two High-Severity DoS Vulnerabilities
- Faster Patching Pace Validates CISA’s KEV Catalog Initiative
- SANS Survey Shows Drop in 2023 ICS/OT Security Budgets
- Apple Patches 3 Zero-Days Likely Exploited by Spyware Vendor to Hack iPhones
