Not sure what is more shocking:

A CA having 23k private keys of their customer's certs and the CEO emailing them: blog.koehntopp.info/index.php/

A CA having a website which allows RCE as root, from a website input: arstechnica.com/information-te

I'm just speechless.

#security #infosec #netsec