In response to reports of a private key leak concerning its product "360 Security Lobster," the company has stated it promptly revoked the involved SSL certificate. The certificate is now completely invalid, which technically prevents attackers from using the private key to spoof servers or hijack traffic. The company assured that ordinary users are not affected by this incident. According to the company's explanation, the private key leak resulted from an operational error during the product release process, causing an internal domain's website certificate to be accidentally included in the public installation package. The company has initiated an internal review process and will further enhance its security management mechanisms to prevent similar oversights from recurring.
Comments