INTEL_REPORT
Trail of Bits — Security engineering · published 1/29/2026, 12:00:00 PM · TLP amber
Summary
Ingested excerpt (first ~500 chars of normalized text).
Building cryptographic agility into Sigstore Software signatures carry an invisible expiration date. The container image or firmware you sign today might be deployed for 20 years, but the cryptographic signature protecting it may become untrustworthy within 10 years. SHA-1 certificates become worthless, weak RSA keys are banned, and quantum computers may crack today’s elliptic curve cryptography. The question isn’t whether our current signatures will fail, but wh…
https://blog.trailofbits.com/2026/01/29/building-cryptographic-agility-into-sigstore
sha256:81c3a22826b86a0cf7e240fe36336cb02ada2c1fab58a6f543bd951e6fbf7fbe
What we pulled out
Deterministic extractor (IOC + allowlisted tokens + ATT&CK IDs present in DB).
Indicators
Linked with report → mentions → indicator. Values open the indicator workspace.
Malware families
Allowlist token matches only.
Threat actors mentioned
Allowlist mentions — not a formal attribution verdict.
ATT&CK techniques
MITRE IDs referenced in text and present in local technique table.
CONTINUE INVESTIGATION
High-signal pivots without leaving the thread you started in search.
Browse the report corpus.
Neighborhood from the first linked indicator.
| cosign.bundle |
| Open → |
| domain | verificationmaterial.certificate.rawbytes | Open → |