risk

Compromised or counterfeit certificates / certificate authority

Adversary counterfeits or compromises a certificate authority so that malware or connections appear legitimate, defeating trust in TLS and code-signing and enabling man-in-the-middle or malicious-code delivery.

In catalog since 2026-09-17T22:28:00Z · Last changed 2026-09-17T22:28:00Z (f368a6cce277)

Record JSON · Open in map · Data retrieval guide

Catalog revision: 791ff2dd3a45707290badee660f185e514d15f1cf518908628f425c2f2c56ee4. A connection does not establish full coverage.

Attributes

category
cyber_security
domain
  • Cryptography & Key Management
  • Network & Communications Security
taxonomy
  • nist-800-30-threat-event
inherent_rating
high

Details

risk_id
crypto-counterfeit-certificates
category
cyber_security
likelihood
low
impact
high
inherent_rating
high
treatment
mitigate
taxonomies
  • nist-800-30-threat-event

Source

No record-specific source URL is provided.

Connections