Attacker abused a bug in ssl.com to authorize fake certificates

Rebecca Kelly, Technical Program Manager at SSL.com, used the SSL/TLS certificate in all the error reports of SSL/TLS certificates we investigated. ” Rebecca Kelly, SSL.com’s technical project manager, used domain name 3.2.2.4.14 when we investigated.
In the preliminary incident report that came with the comments section of the demo, it was revealed that SSL.com misunderstood a total of 10 certificates using the wrong method and was therefore revoked. Kelly added that these improperly issued certificates (except one) were found to be found to be non-forged errors during the investigation.
While the CSO waits for SSL.com’s reply about the status of a wrongly issued certificate, it is recommended that major websites, including email and cloud providers, double-check the entire list of wrongly issued certificates to stay alert.