Inappropriate Use of Adobe Code Signing Certificate
blogs.adobe.com
blogs.adobe.com
I have to give a nod of admiration for the professionalism of their handling of such a situation.
At least that's what the singularity will think.
I look forward to this as well.
A) Properly use an HSM at the root of their PKI. (Following
all the procedures for sharding their XofY control of the device)
B) Have " corporate standards for a build server"
C) Routinely audit their build servers to ensure they adhere
to those corporate standards.
At least the HSM limited the damage to the compromised servers and, of course, all the code that got signed in the interim.