The Trust Briefing September 2026

Related Content

Want to keep learning?

Subscribe to SSL.com’s newsletter, stay informed and secure.

Issue 6 | September 2026

This month: A hacker convention takes over the skies, and AI cybersecurity concerns move from IT closets to boardrooms worldwide. 

Plus: It can happen to anyone! Read on to learn about a major technology company’s recent outage incident, the likely surprising cause, and whether your team was impacted.

Recent News: The Latest from the Digital Trust Landscape

AI is changing the economics of cyber risk, and CEOs are taking notice — Cyber risk has moved from an IT line item to a boardroom concern, as executives increasingly recognize that a single breach can halt operations, damage customer trust, and erode reputation well beyond the cost of the technology itself. Explore how AI is accelerating both the threats companies face and the pressure on leadership to respond. Full story

Crypto4A achieves world-first quantum-safe HSM validation — Canadian cybersecurity company Crypto4A announced that its QASM cryptographic module became the first hardware security module to earn FIPS 140-3 Level 3 validation while supporting the full suite of NIST-approved post-quantum algorithms. As governments and enterprises race to prepare for a post-quantum future, independently validated hardware like this is becoming the foundation everything else gets built on. Full story

Rogue Wi-Fi network turns a Delta flight into a real-time phishing lesson — On a flight home from DEF CON, one of the world’s largest hacking conferences, someone jammed the plane’s in-flight Wi-Fi and broadcast a lookalike network called “Delta WiFi Fast” that led to a phishing page. The crew shut down the Wi-Fi mid-flight and federal authorities are now investigating, in what experts say is a simple, cheap attack anyone could pull off on their next flight. Full story 

McKesson confirms massive healthcare data breach — Pharmaceutical distribution giant McKesson confirmed hackers stole customer data after the ShinyHunters extortion group claimed to have taken 284 million records and demanded a $55 million ransom. The breach adds McKesson to a growing list of healthcare and health-tech companies hit by the same group this year, including Abbott Laboratories and Medtronic. Full story 

Industry Spotlight: Practical Solutions for Real-World Challenges

Did a Missed Certificate Renewal Cause Microsoft 365 to Go Down for Four Days?

On August 31, 2026, Microsoft 365 began failing for users worldwide. Exchange Online went down first, followed by Teams, SharePoint, OneDrive, Purview, Defender XDR, and the Microsoft 365 admin center itself. Microsoft tracked the incident as EX1464935 and described the root cause in deliberately broad terms: “an issue within a core authentication configuration used by multiple Microsoft 365 services.” While Microsoft did not publicly confirm a certificate expiry as the cause, multiple non-Microsoft outlets covering the incident attributed the failure to a lapsed internal certificate renewal. Full recovery wasn’t declared until September 3, four days after the outage began.

OpenAI, whose services run on Microsoft infrastructure, was also affected. For any organization running Microsoft 365, email, calendar, file storage, communications, and security tooling all went down together.

The business impact: This was not a security breach. No data was exfiltrated. No attacker was involved. An expired internal certificate likely caused the disruption, and an automated process should have renewed it but didn’t. For four days, millions of users across thousands of organizations could not reliably send or receive email, access files, or use the productivity tools their businesses run on. 

The lesson for enterprise customers is uncomfortable: if a large organization like Microsoft, with its scale and engineering resources, could possibly let a core authentication certificate lapse and take down its entire cloud platform with it, the question every organization should be asking is what certificates in their own infrastructure are in the same position. An expired certificate in a critical service/endpoint certainly has the potential for a “big blast radius.”

What would have prevented it: Automated certificate renewal eliminates the category of failure this incident represents. SSL’s ACME support enables fully automated certificate issuance and renewal via the ACME protocol (RFC 8555), with no human action required after initial setup. Once configured, certificates renew before they expire, without anyone needing to remember, calendar, or manually trigger the process. 

For organizations already running a CLM platform, SSL integrates directly as a CA into Venafi TPP and Keyfactor Command, so automated renewal workflows operate through the same inventory and lifecycle management infrastructure the team already uses. The certificate that brought down Microsoft 365 had a known expiration date. That date was always on a calendar somewhere. Automation means it never has to be on anyone’s calendar again.

Sources:
https://www.bleepingcomputer.com/news/microsoft/microsoft-exchange-online-outage-causes-email-failures-auth-issues/

https://startupfortune.com/microsoft-365-went-down-worldwide-because-someone-forgot-to-renew-a-certificate/  

Past and Upcoming Events: Conferences, Standards Meetings, and more

Did you miss our latest webinar? No worries! You can now watch the replay on demand. 

“Beyond the spec: Building real trust into C2PA” was hosted by Dominique Guinard, SSL Director of Product – Content Authenticity and IoT, and Tony Rodriguez, Digimarc Chief Technology Officer. 

This webinar explores what production-grade trust requires; how to make Content Credentials more trustworthy, durable, and interoperable in practice; and the practitioner perspectives of teams shipping on C2PA today. Watch now.

Keep an eye out for our next webinar in October, which will focus on why you need a Backup Certificate Authority, hosted by SSL’s Director of Product Management, Tim Reidel.

SSL representatives will also be attending the ICANN87 Annual General Meeting (AGM)  in Bali.  This six-day AGM will be focused on showcasing ICANN’s work to a broader global audience, with more time dedicated to capacity building and leadership training sessions.

SSL will also be attending Cloudfest Americas in Miami. The even is part of the CloudFest global event series and serves as the convergence point for the Cloud and internet infrastructure ecosystem across the Americas.

Contact us now to schedule upcoming meetings with our team.

Quick Links: Guides, Articles, and Industry Resources

Have questions about any of these topics or want to discuss your digital trust solutions with our experts? Reach out to us below:

Stay Informed and Secure

SSL.com is a global leader in cybersecurity, PKI and digital certificates. Sign up to receive the latest industry news, tips, and product announcements from SSL.com.

SSL.com

We’d love your feedback

Take our survey and let us know your thoughts on your recent purchase.

Privacy Overview
SSL.com

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognizing you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.

For more information read our Cookie and privacy statement.

3rd Party Cookies

This website uses Google Analytics & Statcounter to collect anonymous information such as the number of visitors to the site, and the most popular pages.

Keeping these cookies enabled helps us to improve our website.

Show details