Updates on the Fortinet incident: badkeys now detects a more complete set of affected keys, and I have also identified 314 keys for active ACME accounts for @letsencrypt in the data. I have disabled the affected ACME accounts. Some updates in the blogpost: https://blog.hboeck.de/archives/908-Private-Keys-in-the-Fortigate-Leak.html
badkeys
@badkeys@infosec.exchange
badkeys is an open-source tool and web service to identify compromised cryptographic keys.
infosec.exchange
6
0
3
Loading comments...