Independent evidence

A vendor's exposed edge can become your attack path.

Organizations inherit risk through remote access, embedded software, trusted updates, identity providers, managed services, and connected infrastructure. Outside-in assessment provides independent evidence that a vendor's public-facing controls still meet the minimum security expectations attached to that trust.

Documented vendor pathways

The dependency can be large or very small.

These cases show different ways a supplier or connected service became part of the attack path. They support continuous vendor assurance, but they do not imply that a certificate assessment alone would have prevented every incident.

2013Vendor credentials

Target and a small HVAC contractor

A U.S. Senate staff analysis reported that attackers stole credentials from Fazio Mechanical Services, a small Pennsylvania HVAC contractor with remote access for billing and project work. The attackers used vendor access as a foothold into Target, where information relating to as many as 110 million customers was taken.

Control lesson: supplier access, multifactor authentication, least privilege, segmentation, and continuous review must match the risk created by the connection.

U.S. Senate staff report
2018Embedded third-party code

Ticketmaster and Inbenta

The UK Information Commissioner's Office found that an attacker inserted malicious code into a third-party chatbot hosted by Inbenta. Because Ticketmaster placed that code on payment pages, it could collect names, payment-card details, CVVs, usernames, and passwords entered by customers.

Control lesson: externally loaded scripts and services operate inside the customer experience and require inventory, integrity controls, monitoring, and removal when their risk exceeds their value.

UK ICO penalty notice
2021MSP management software

Kaseya and downstream businesses

Attackers exploited zero-day vulnerabilities in Kaseya VSA and used normal product functionality to deploy ransomware. Kaseya reported fewer than 60 directly affected customers, many of them service providers, and fewer than 1,500 downstream businesses.

Control lesson: one privileged management platform can concentrate risk across many smaller organizations that may never contract directly with the original software vendor.

Kaseya technical overview
2020Trusted software update

SolarWinds Orion

CISA documented that an advanced actor added malicious code to multiple versions of the SolarWinds Orion platform. Selected government, critical-infrastructure, and private-sector customers then experienced persistent access, identity compromise, and sensitive-data exfiltration.

Control lesson: vendor approval is not permanent. Trusted software, signing systems, update channels, and externally visible changes require continuing verification and incident coordination.

CISA incident guidance

Certificate and TLS pathways

Public trust signals have been abused in real attacks.

Certificate, DNS, network, geographic, and historical evidence becomes more valuable when it is correlated. No single anomaly proves compromise; combinations of unexpected changes can identify where investigation should begin.

2017–2019Stolen certificates

Sea Turtle

Cisco Talos documented DNS hijacking, legitimate CA-signed impersonation certificates, and stolen SSL certificates deployed on actor-controlled servers to harvest credentials. Talos identified at least 40 organizations across 13 countries.

Observable clues: certificate or public-key reuse on a new IP, ASN, provider, or country; DNS drift; issuer changes; self-signed appliance certificates; and short-lived deployments.

Cisco Talos investigation
2011Fraudulent issuance

DigiNotar

A compromised certificate authority issued fraudulent certificates for Google and other services. ENISA reported that false certificates were used to eavesdrop on users in Iran and noted roughly 300,000 Iranian OCSP requests as an estimate—not a definitive victim count.

Observable clues: an unexpected CA, unauthorized issuance, unusual geographic concentration, and infrastructure that does not match the legitimate operator.

ENISA analysis
2017Expired monitoring certificate

Equifax

A U.S. House investigation found that an internal certificate used to inspect encrypted traffic had expired 19 months before the breach was discovered, limiting visibility into data exfiltration affecting approximately 148 million people. The initial entry point was an unpatched Apache Struts vulnerability.

Boundary: the failed certificate was internal and would not necessarily be visible to Vellitas's standard public-facing assessment.

U.S. House investigation
2014TLS implementation defect

Canadian government Heartbleed breach

A Government of Canada review documented remote exploitation and data exfiltration through the OpenSSL Heartbleed flaw across 12 departments, including at least 900 taxpayer Social Insurance Numbers.

Boundary: certificate metadata alone cannot detect Heartbleed. Safe TLS implementation testing is a separately governed adjacent capability, not a current certificate-only claim.

Government of Canada review

Correlated evidence

One signal raises a question. Several signals establish priority.

Vellitas should correlate the following observations across approved customer and vendor scope. Continuous Certificate Transparency ingestion and event-driven issuance alerts remain explicit roadmap capabilities until production implementation is verified.

  • Certificate fingerprint and public-key reuse across IP addresses
  • New countries, ASNs, cloud providers, or hosting networks
  • Certificate Transparency issuance and unexpected issuers
  • DNS A, AAAA, CNAME, MX, and NS changes
  • Short-lived certificate and DNS changes
  • New or unusual subject alternative names
  • Self-signed and temporary appliance certificates
  • Revocation, OCSP, and certificate-chain status
  • TLS versions, accepted cipher suites, and downgrade exposure
  • Historical first-seen, last-seen, and infrastructure movement
Geography is context—not a verdict.

A certificate appearing in a new country or network is a risk signal rather than proof of compromise. CDNs, cloud migrations, disaster recovery, acquisitions, and authorized service providers can produce legitimate changes. Vellitas combines location with certificate, DNS, network ownership, history, and customer policy before assigning confidence or recommending action.

Reference framework

Findings should explain the standard behind the expectation.

Vellitas uses authoritative guidance where it is relevant to the observed evidence and the customer's industry. Referencing a standard does not mean Vellitas or the customer is certified against it.

TLS baseline

IETF RFC 8996

TLS 1.0 and TLS 1.1 are formally deprecated because they lack modern cryptographic protections and increase downgrade and misconfiguration risk.

Read RFC 8996
TLS configuration

NIST SP 800-52 Rev. 2

NIST requires modern TLS and approved cipher suites for federal systems and provides guidance for certificates and security-relevant TLS extensions.

Read the NIST publication
DNS tampering

CISA Certificate Transparency guidance

CISA recommends monitoring Certificate Transparency logs as part of reducing the risk created by DNS infrastructure tampering and traffic redirection.

Read the CISA guidance
Supplier governance

NIST CSF 2.0 · GV.SC

The supply-chain category calls for known and prioritized suppliers, defined requirements, due diligence, ongoing assessment, monitoring, and incident coordination.

Read the NIST quick-start guide
Supply-chain risk

NIST SP 800-161 Rev. 1

NIST provides a structured program for identifying, assessing, and mitigating cybersecurity risks in products and services across the supply chain.

Read the NIST publication
Managed services

CISA, NSA, FBI and partner guidance

Customers should place security measures in vendor contracts, protect remote access, require MFA where possible, and enable monitoring and logging.

Read the joint guidance
Payment environments

PCI DSS Requirement 12.8

Where applicable, organizations must manage and oversee third-party service-provider relationships and monitor their PCI DSS compliance status at least annually.

Read the PCI SSC guidance

Attackers have used misissued and stolen certificates, DNS hijacking, and actor-controlled infrastructure to impersonate trusted services and harvest credentials. Vellitas correlates certificate, DNS, network, geographic, and historical evidence to surface changes that warrant investigation.

Verify the public controls behind the trust you place in a vendor.

Request a briefing