Certificate failures can cost firms over $250,000

Help Net Security

Overview

A recent report from DigiCert warns that the shift to 47-day public TLS certificates by 2029 will significantly increase the burden of certificate management for businesses. Organizations will face the need to renew certificates over eight times more frequently than before and will have to perform domain validations 40 times more often. This change could lead to costly outages, with failures potentially costing companies upwards of $250,000. The report emphasizes that companies should prepare for these challenges to avoid disruptions that can impact business operations. Proper certificate management is essential to prevent unexpected downtime and financial losses.

Key Takeaways

  • Affected Systems: TLS certificates, DigiCert services
  • Action Required: Organizations should enhance their certificate management practices and prepare for more frequent renewals and validations.
  • Timeline: Disclosed on October 2023

Original Article Summary

The move toward 47-day public TLS certificates by 2029 will increase the certificate management workload for enterprises, according to DigiCert’s Certificate Management Outlook. Organizations will need to renew certificates more than eight times as often as under the previous certificate lifecycle and conduct 40 times as many domain validations. What certificate management challenges were listed as a combination of very or extremely concerned? (Source: DigiCert) Certificate failures cause costly outages Certificate failures can disrupt business … More → The post Certificate failures can cost firms over $250,000 appeared first on Help Net Security.

Impact

TLS certificates, DigiCert services

Exploitation Status

No active exploitation has been reported at this time. However, organizations should still apply patches promptly as proof-of-concept code may exist.

Timeline

Disclosed on October 2023

Remediation

Organizations should enhance their certificate management practices and prepare for more frequent renewals and validations.

Additional Information

This threat intelligence is aggregated from trusted cybersecurity sources. For the most up-to-date information, technical details, and official vendor guidance, please refer to the original article linked below.

Related Coverage

New Warnings About the Risks of AI to Humanity Revive a Long-Running Debate

SecurityWeek

Recent discussions have intensified around the risks associated with advanced artificial intelligence technologies. As AI models grow more powerful, experts are raising alarms about their potential misuse by individuals with malicious intentions. This includes fears that AI could be leveraged for cyberattacks, misinformation campaigns, and other criminal activities. The debate is not new, but the increasing capabilities of AI systems have made these concerns more pressing. Researchers and industry leaders are urging for a more cautious approach to AI development and implementation to mitigate these risks.

Sep 14, 2026

Personal, Financial Info Exposed in Revolut Data Breach

SecurityWeek

Revolut has suffered a data breach that exposed personal and financial information of its users. The company inadvertently shared this sensitive data with a third party that was posing as a government agency. This incident raises significant concerns about the security of customer information and the potential for identity theft or fraud. Affected users may now face risks associated with their exposed data, which could include unauthorized transactions or other forms of financial exploitation. Revolut has not disclosed how many users were impacted or what specific information was leaked, but the incident underscores the need for strict verification processes when handling sensitive data.

Sep 14, 2026

AI Changed the Exposure Problem. Validation Needs to Change With It.

The Hacker News

The article discusses how the rapid discovery of vulnerabilities, particularly in the context of artificial intelligence, has outpaced the ability of cybersecurity defenders to assess which ones require urgent attention. In the first half of 2026 alone, over 35,000 Common Vulnerabilities and Exposures (CVEs) were published, marking a significant increase from previous years. This surge creates a dilemma for security teams who must prioritize their responses amid an overwhelming volume of findings. The focus is on the need for improved validation processes to help defenders identify which vulnerabilities pose the greatest risk. As the landscape evolves, organizations need to adapt their strategies to effectively manage these vulnerabilities and protect their systems.

Sep 14, 2026

Revolut discloses data breach exposing financial info, passports

BleepingComputer

Revolut, a fintech company, has reported a data breach involving the exposure of sensitive customer information. Attackers managed to impersonate a government agency and trick Revolut into sharing data from an unspecified number of customers. The breach has resulted in the potential compromise of financial information and passport details. This incident raises significant concerns about the security of customer data and the effectiveness of identity verification processes used by financial institutions. Customers of Revolut should be vigilant and monitor their accounts for any unusual activity as the company investigates the breach and works to enhance its security measures.

Sep 14, 2026

CISA: Hackers now exploit max severity GitLab flaw in attacks

BleepingComputer

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued a warning that hackers are actively exploiting a high-severity vulnerability in GitLab. This flaw could allow attackers to take control of affected systems, which poses significant risks for organizations using the platform. GitLab users must be vigilant, as the vulnerability is being targeted in the wild. It’s crucial for companies to apply any available patches or updates to secure their systems. Failure to address this issue could lead to unauthorized access and data breaches, impacting the integrity of their operations.

Sep 14, 2026

Turn it off and on again, but for critical infrastructure

Help Net Security

Researchers at KTH Royal Institute of Technology created a model of an industrial network to test its defenses against cyber attacks. Over 14 days, they simulated multiple attacks and analyzed the network traffic to train a defense agent. This agent monitors packet counts across different segments of the network, allowing it to detect intruders' movements and decide when to intervene. This study is significant because it explores proactive defense mechanisms in critical infrastructure, which is increasingly vulnerable to cyber threats. As industries rely more on interconnected systems, enhancing security measures like this could help protect essential services from potential disruptions.

Sep 14, 2026