Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

Windows Code Signing Moves Toward Post Quantum Security in 2027

Microsoft is in the process of shaping major changes to Windows code signing that will have the effect of altering the certificate infrastructure, the cryptographic algorithms, and, in the end, how Windows applications will be protected against future quantum computing threats. The changes are of particular importance to developers, IT administrators, security teams, and organizations that are using their custom software or security tools that can do their own code signature validation.

Google Cloud KMS Adds Generally Available Quantum-Safe Digital Signatures

As quantum computing develops, cybersecurity professionals are getting ready for a breakthrough in the protection of digital information. The conventional public-key cryptographic algorithms that ensure the security of digital signatures may, in the long run, be compromised by the revolutionary power of quantum computers. To minimize that risk, Google Cloud has announced general availability of the quantum-safe digital signature feature in its Google Cloud Key Management Service (Cloud KMS).

What are Software Artifacts? Types, Tools, Benefits, Best Practices

The foundation of modern-day software development relies heavily on translating requirements into products through traceability, collaboration, and reproducibility. Software artifacts are instrumental in this process, facilitating development across all areas, including application development, CI/CD pipelines, and compliance.

What is ML-DSA (CRYSTALS-Dilithium)? The Future of Digital Signatures Beyond RSA and ECC

With quantum computing soon changing the way things work in general, one of the areas that cybersecurity experts are most worried about is how digital signatures will survive. The same kinds of algorithms that have supported virtually all secure communications (both computer and otherwise) for decades are going away. Not only are RSA and Elliptic Curve Cryptography (ECC) algorithms no longer safe from being cracked by quantum computers, but they have also become obsolete.

What Is Trust Now, Forge Later (TNFL)? TNFL vs HNDL Attacks Explained

Suppose that the hospital allows a vital software update of its infusion pumps to go through, and all security tests pass. The signature looks valid. The certificate is scrapless. Everything appears legitimate. The update was forged by an attacker who cracked a key that was considered unbreakable just five years ago. The general perception of most individuals is that after encryption or after data is digitally signed, it stays secure indefinitely. That assumption is now perilously outdated.

DigiCert Software Trust Manager & DigiCert KeyLocker: Difference Explained

As the volume of software supply chain attacks continues to grow, organizations must increase controls over how they sign, store, and release code. DigiCert has launched two cloud-based solutions that help organizations both protect their private keys and improve the efficiency of their code signing operations: DigiCert KeyLocker and DigiCert Software Trust Manager.

OpenAI Revokes macOS Code Signing Cert After Axios Supply Chain Hit [Actions Required]

Something big just happened in the cybersecurity world. And if you’re using OpenAI’s macOS apps… this affects you directly. OpenAI has rotated its macOS code-signing certificates after a supply chain attack quietly slipped into its workflow. No, your data wasn’t stolen. But yes, this is serious enough that every macOS user must update before May 8, 2026.

Microsoft Advancing Windows Driver Security: Ending Cross-Signed Kernel Driver Trust

Microsoft is preparing a major change to Windows that could quietly reshape how security and compatibility are balanced across the entire ecosystem. Starting April 2026, Windows will begin blocking kernel drivers signed through the legacy cross-signed root program by default, replacing a decades-old trust model with a stricter, policy-driven approach centred on the Windows Hardware Compatibility Program (WHCP). This is more than a routine update.