|
|
|
|
|
by eganist
1297 days ago
|
|
Pretty straightforward, honestly: if the signature on a piece of malware can be verified by a corporation's private key, unless that corporation is a remarkably inept bad actor, that corporation and its signing key have been compromised. Not saying it's how these were picked up, but that's the most obvious way. |
|