360 responds to the security lobster private key leak incident

robot
Abstract generation in progress

Recently, it was reported that 360 Company’s AI product, 360 Security Lobster, had serious security vulnerabilities upon its release: the product installation package contained the SSL private key and certificate for the *.myclaw.360.cn wildcard domain directly packaged within, raising significant concerns about information security among the industry and users.

360 Company stated to Yicai Global that it has promptly revoked the involved certificate, and the certificate is now invalid, so ordinary users will not be affected. 360 Company revealed that this issue originated from a mistake during the release process, which led to the internal domain’s website certificate being accidentally packaged into the installation package. After the problem was discovered, the company immediately took emergency measures to complete the revocation of the involved certificate, technically preventing attackers from using the private key to forge servers and hijack traffic. (Yicai Global)

View Original
This page may contain third-party content, which is provided for information purposes only (not representations/warranties) and should not be considered as an endorsement of its views by Gate, nor as financial or professional advice. See Disclaimer for details.
  • Reward
  • Comment
  • Repost
  • Share
Comment
Add a comment
Add a comment
No comments
  • Pin