In April 2026, the Chinese threat group Cylindrical Canine breached DigiCert to steal code-signing certificates, allowing them to sign malware that looks like legitimate, trusted software. This attack severely impacts businesses by bypassing standard security filters, leading to undetected data theft, financial loss, and widespread network compromise across the Asia-Pacific region. To counter this, organizations must enforce strict zero-trust access for certificate portals and implement behavioral monitoring to spot certificate misuse immediately. Additionally, companies should rapidly revoke any potentially compromised credentials and update endpoint defenses to detect the specific file-loading techniques used by these attackers.