360 Responds to Security Lobster Private Key Leak Incident

robot
Abstract generation in progress

Recently, 360 Security Lobster, an AI product under 360 Company, was exposed for a serious security oversight during its release: the installation package directly included a bundled SSL private key and certificate for the *.myclaw.360.cn wildcard domain, raising high concerns about information security among industry professionals and users.

360 Company told Yicai that they have revoked the affected certificate immediately. The certificate is now invalid, and ordinary users will not be affected. The company revealed that the issue stemmed from a release error, which caused the internal domain website certificate to be accidentally included in the installation package. After discovering the problem, the company took emergency measures to revoke the affected certificate, technically blocking attackers from using the private key to forge servers or hijack traffic. (Yicai)

View Original
This page may contain third-party content, which is provided for information purposes only (not representations/warranties) and should not be considered as an endorsement of its views by Gate, nor as financial or professional advice. See Disclaimer for details.
  • Reward
  • Comment
  • Repost
  • Share
Comment
Add a comment
Add a comment
No comments
  • Pin