DigiCert disclosed that April 2026 support-channel social engineering let attackers harvest certificate initialization codes and issue legitimate EV code-signing certificates before revocation and endpoint containment.
Canonical record: DigiCert 2026 support incident on BreachHistory.
Sources: Help Net Security, Mozilla bug 2033170