Issue 5 | August 2026
This month: Leo Grove, SSL President and CEO, breaks down why we’re giving away trust and how it helps innovators overcome barriers.
Plus: What is vishing? Also explore the impacts of cyberattacks, from large corporations to much closer to home: the kitchen faucet.
From the Desk of Leo Grove, SSL President and CEO
Over the years, I’ve seen enough security standards stall out to know why: the on-ramp is often too expensive for anyone but the biggest players.
As C2PA continues to raise the bar with updated requirements, SSL now offers free Assurance Level 1 Claim Signing Certificates, with 10,000 trusted timestamps for qualifying conformant products.
In my newest blog post, I discuss in detail why we’re doing this and what I believe it means for the standard’s future.
If you work in or around content provenance, I would love to hear what you think, especially if you’re building something C2PA-conformant.
Recent News: The Latest from the Digital Trust Landscape
U.S. Companies Face Rising Wave of Cyberattacks – A growing list of major US companies, including Nike, West Pharmaceutical Services, and Carnival, among others, have disclosed cyberattacks this year involving stolen data, exposed customer records, and disrupted operations. See who’s on the list, and whether your own data might already be part of it. Full story
Wall Street’s Biggest Funds Hit by Vishing Attacks – Hackers recently launched a wave of sophisticated attacks on major money managers including Point72, Millennium, Citadel, and Two Sigma, using AI-powered voice phishing (also referred to as “vishing”) to trick employees into handing over access. See how hedge funds managing trillions are responding, and what it says about how AI is changing the attacker’s playbook. Full story
Water supply hacks expose years of ignored warnings – Federal and state officials are racing to address a widespread assault on the nation’s water supply that they believe is likely the work of Iranian hackers, following years of blocked efforts to strengthen the sector’s cyberdefenses. See how deep the exposure goes and what it reveals about the infrastructure that protects your own tap water. Full story
Industry Spotlight: Practical Solutions for Real-World Challenges
When Your Videoconferencing Server Becomes a Malware Delivery System
A threat actor known as Head Mare has been exploiting security flaws in unpatched TrueConf servers to replace the platform’s own client installers. The threat uses poisoned versions that deliver the PhantomCore backdoor and remote access trojan into the systems of anyone who downloads them. The attack does not rely on tricking users into visiting a suspicious link or opening a malicious attachment. It weaponizes the update mechanism they already trust.
The vulnerability chain gives attackers arbitrary code execution with SYSTEM-level privileges on the server, after which they install a web shell for persistent access and substitute the legitimate TrueConf client distribution with an infected version. From that point forward, every employee who downloads what they believe is their organization’s official videoconferencing client is installing malware.
The business impact: Kaspersky detected the attacks in July 2026, targeting organizations across instrumentation, electronics, transport, energy, IT, and software development sectors. Once installed, PhantomCore gives attackers persistent remote access, credential harvesting capability, and a foothold from which to move laterally across the network. The attack is particularly difficult to detect because the delivery mechanism is a trusted internal server, not an external threat actor pushing unsolicited files. By the time the compromise is identified, the attacker may have been resident across the network for weeks.
What would have prevented it: The TrueConf installer itself carried a legitimate signature. The attack worked at a different layer, replacing the running software after installation by exploiting a vulnerability in the service itself. Catching that kind of substitution requires application control enforcement. Tools like AppLocker and Windows Defender Application Control can be configured to verify the signature of every binary before it is allowed to execute, not just at install time, but at runtime. A replaced or tampered binary that cannot present a valid, trusted signature gets blocked before it runs. For that policy to hold, legitimate software needs to be properly code signed in the first place. SSL’s code signing certificates provide the cryptographic foundation that application control policies enforce. Without signed binaries, there is no trust baseline for these tools to work from.
The broader lesson: Supply chain integrity, including the integrity of software that organizations distribute internally, is increasingly a primary attack surface. Patching server vulnerabilities remains essential, but it is not sufficient on its own. Organizations that cryptographically sign their software, and configure their endpoints to enforce those signatures, add a layer of defense that persists even when the delivery infrastructure is compromised.
Source:
https://thehackernews.com/2026/08/head-mare-exploits-trueconf-flaws-to.html
Past and Upcoming Events: Conferences, Standards Meetings, and more
Did you miss our latest webinar? No worries! You can now watch the replay on demand.
“Beyond the spec: Building real trust into C2PA” was hosted by Dominique Guinard, SSL Director of Product – Content Authenticity and IoT, and Tony Rodriguez, Digimarc Chief Technology Officer.
This webinar explores what production-grade trust requires; how to make Content Credentials more trustworthy, durable, and interoperable in practice; and the practitioner perspectives of teams shipping on C2PA today. Watch now.
EU Artificial Intelligence Act Article 50
Effective back on August 2, 2026, any organization that builds or deploys generative AI systems that reach people in the EU has a new legal duty: it must disclose that the content is AI-generated. Learn more about the regulation here.
California AI Transparency Act (SB 942 / AB 853)
California’s law also took effect on August 2, 2026. AB 853 pushed the original January 2026 effective date back specifically to align with the EU’s timeline. Large generative AI providers serving California must embed provenance data, offer a free detection tool, and make their systems’ AI-generated output machine-detectable. AB 853 points directly to standards like C2PA to satisfy the provenance requirement. Catch up on all the latest AI regulation deadlines here.
Quick Links: Guides, Articles, and Industry Resources
- Identity Validation for SSL.com Certificates: A Complete Guide — Learn how to complete SSL identity validation, including accepted ID documents by country, liveness video tips, and steps to fix a failed submission.
- DNS CNAME Validation for SSL/TLS Certificates — Learn how to verify domain ownership with DNS CNAME validation for SSL/TLS certificates using GoDaddy, Namecheap, Amazon Route 53, and Cloudflare.
- Getting Started With Your Code Signing Certificate: Installation, Configuration, and Your First Signing Operation — Learn how to install, configure, and use your SSL.com code signing certificate to securely sign software and verify your application’s authenticity.
- What is the ACME Protocol? — Learn about the ACME protocol, an automated method for managing SSL/TLS certificate lifecycles. Discover how it streamlines certificate issuance and renewal, and improves website security through standardized automation.
Have questions about any of these topics or want to discuss your digital trust solutions with our experts? Reach out to us below: