Home
360 Addresses Private Key Leak Incident, Cites Release Error and Urgent Certificate Revocation

Even seasoned veterans in the cybersecurity field can sometimes stumble. Recently, 360 Company's new AI offering, "360 Security Lobster," was found to have a critical, fundamental security oversight, raising widespread industry concerns about the rigor of AI product release cycles.
Reports indicate the issue stemmed from the product's installation package, which was discovered to contain the SSL private keys and certificates for the wildcard domain *.myclaw.360.cn. This is akin to leaving a master key out in the open. If obtained by an attacker, this private key could theoretically be used to impersonate a server, execute man-in-the-middle attacks, or intercept user data traffic.
Addressing the controversy, 360 Company responded swiftly, attributing the problem to a low-level procedural error during the release phase that accidentally bundled an internal domain certificate into the public installation package.
To mitigate the impact, 360 has implemented the following emergency actions:
Immediate Revocation: The compromised certificate has been revoked and is now entirely invalid.
Risk Assessment: The company states that ordinary users are not currently at risk, and technical measures have been deployed to block potential server forgery using the private key.
For a leading domestic cybersecurity firm like 360 to encounter such a security pitfall with its own AI product serves as a stark warning for the entire AI industry. Amid the current wave of frequent large model and intelligent agent releases, ensuring automated release checks are substantive, not merely procedural, has become a critical area for improvement.
Related article
iFLYTEK Unveils Spark X2.5 General Large Model
On September 1, iFlytek will open-source two edge-focused large language models, Xinghuo X2.5-4B and Xinghuo X2.5-1.7B, according to the latest official announcement. Both models natively support a context window of up to 1 million tokens. They deliv
Meta Removes AI Photo Editing Feature Following User Backlash
Meta, the social media giant, is once again embroiled in a public debate regarding the delicate balance between artificial intelligence and user privacy. According to TechCrunch, Meta’s Superintelligence Labs introduced a new AI image generator, Muse
DeepMind CEO Hassabis: I sleep six hours a day, usually feel energetic around 1 a.m.
Fortune recently featured an interview with Demis Hassabis, CEO of Google DeepMind, revealing his unconventional approach to rest and productivity. Hassabis disclosed that he sleeps very little, structuring his waking hours into two distinct work blo
Related Special Topic Recommendations
Comments (0)
0/500

Even seasoned veterans in the cybersecurity field can sometimes stumble. Recently, 360 Company's new AI offering, "360 Security Lobster," was found to have a critical, fundamental security oversight, raising widespread industry concerns about the rigor of AI product release cycles.
Reports indicate the issue stemmed from the product's installation package, which was discovered to contain the SSL private keys and certificates for the wildcard domain *.myclaw.360.cn. This is akin to leaving a master key out in the open. If obtained by an attacker, this private key could theoretically be used to impersonate a server, execute man-in-the-middle attacks, or intercept user data traffic.
Addressing the controversy, 360 Company responded swiftly, attributing the problem to a low-level procedural error during the release phase that accidentally bundled an internal domain certificate into the public installation package.
To mitigate the impact, 360 has implemented the following emergency actions:
Immediate Revocation: The compromised certificate has been revoked and is now entirely invalid.
Risk Assessment: The company states that ordinary users are not currently at risk, and technical measures have been deployed to block potential server forgery using the private key.
For a leading domestic cybersecurity firm like
iFLYTEK Unveils Spark X2.5 General Large Model
On September 1, iFlytek will open-source two edge-focused large language models, Xinghuo X2.5-4B and Xinghuo X2.5-1.7B, according to the latest official announcement. Both models natively support a context window of up to 1 million tokens. They deliv
Meta Removes AI Photo Editing Feature Following User Backlash
Meta, the social media giant, is once again embroiled in a public debate regarding the delicate balance between artificial intelligence and user privacy. According to TechCrunch, Meta’s Superintelligence Labs introduced a new AI image generator, Muse
DeepMind CEO Hassabis: I sleep six hours a day, usually feel energetic around 1 a.m.
Fortune recently featured an interview with Demis Hassabis, CEO of Google DeepMind, revealing his unconventional approach to rest and productivity. Hassabis disclosed that he sleeps very little, structuring his waking hours into two distinct work blo











