Tuesday, August 11, 2026
LIVEThe Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///The Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///
Subscribe
Cyber Security
Independent · Digital
Thehackingpost
CybersecurityAI-assisted

TrustAsia Revoked 143 Certificates Following LiteSSL ACME Service Vulnerability

TrustAsia has revoked 143 SSL/TLS certificates due to a vulnerability identified in its LiteSSL ACME service. The issue involved the improper reuse of domain validation data across different ACME accounts, leading to the suspension of issuance services…

TrustAsia has revoked 143 SSL/TLS certificates due to a vulnerability identified in its LiteSSL ACME service. The issue involved the improper reuse of domain validation data across different ACME accounts, leading to the suspension of issuance services and a subsequent revocation of affected certificates.

This incident, documented under Mozilla Bugzilla ticket #2011713, was initiated by a community report on January 21, 2026. The vulnerability affected certificates issued via the ACME protocol after December 29, 2025.

The primary issue arose from a logic error in the LiteSSL ACME service's handling of Authorization objects. It was discovered that authorization data was reused across different ACME accounts, circumventing the need for unique validation per account context.

Total Certificates Impacted: 143 Affected Protocol: ACME (Automated Certificate Management Environment) Vulnerable Period: Issuance dates post-2025-12-29 Status: All affected certificates have been revoked; the service is patched and operational.

The following timeline outlines TrustAsia's response actions on January 21, 2026 (Times in UTC+8).

Time Event Description

14:55 Compliance team received a report regarding domain validation reuse.

15:10 Preliminary confirmation of the issue; ACME issuance service suspended.

TrustAsia has revoked 143 SSL/TLS certificates due to a vulnerability identified in its LiteSSL ACME service.
Mark Jensen · Thehackingpost

15:30 Impact scope confirmed; investigation into specific certificates began.

15:33 Revocation initiated for the two specific certificates mentioned in the initial report.

21:00 Code fix completed and validated in the test environment.

21:21 Identification of all 143 affected certificates completed; batch revocation initiated.

21:30 Revocation completed for the 140 remaining valid certificates (3 were previously revoked).

21:41 Patched code deployed to the production environment.

Advertisement

22:35 Reset of all ACME Authorizations from VALID to REVOKED , forcing client re-validation.

23:00 External ACME issuance service fully restored.

This incident violates the CA/Browser Forum Baseline Requirements (TLS BR Version 2.2.2), specifically Section 3.2.2.4, which mandates that the Certificate Authority must validate each Fully-Qualified Domain Name (FQDN) prior to issuance.

TrustAsia has announced that a Full Incident Report will be released to the Mozilla Bugzilla thread, which will include a comprehensive root cause analysis and the definitive start date of the non-compliance.

All ACME Authorizations in the production environment were reset to REVOKED status to prevent any lingering invalid authorizations from being used for new issuance.

Based on reporting by Cyber Security News.

AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories