Home
360 Addresses Private Key Leak Incident, Cites Release Error and Urgent Certificate Revocation

Even seasoned veterans in the cybersecurity field can sometimes stumble. Recently, 360 Company's new AI offering, "360 Security Lobster," was found to have a critical, fundamental security oversight, raising widespread industry concerns about the rigor of AI product release cycles.
Reports indicate the issue stemmed from the product's installation package, which was discovered to contain the SSL private keys and certificates for the wildcard domain *.myclaw.360.cn. This is akin to leaving a master key out in the open. If obtained by an attacker, this private key could theoretically be used to impersonate a server, execute man-in-the-middle attacks, or intercept user data traffic.
Addressing the controversy, 360 Company responded swiftly, attributing the problem to a low-level procedural error during the release phase that accidentally bundled an internal domain certificate into the public installation package.
To mitigate the impact, 360 has implemented the following emergency actions:
Immediate Revocation: The compromised certificate has been revoked and is now entirely invalid.
Risk Assessment: The company states that ordinary users are not currently at risk, and technical measures have been deployed to block potential server forgery using the private key.
For a leading domestic cybersecurity firm like 360 to encounter such a security pitfall with its own AI product serves as a stark warning for the entire AI industry. Amid the current wave of frequent large model and intelligent agent releases, ensuring automated release checks are substantive, not merely procedural, has become a critical area for improvement.
Related article
AIGCPanel 2.0.0 Major Update: Workflow Engine Opens New Era of Automated Digital Human Creation
AIGCPanel, a powerful tool for local digital human creation, has just launched version 2.0.0—billed as "the most significant update yet." This core overhaul addresses the fragmentation of AI creation tools by linking digital human synthesis, voice cl
BuzzFeed launches AI junk app subsidiary
Amid a significant business crisis, the former digital media giant BuzzFeed is launching an ambitious self-rescue experiment powered by artificial intelligence. At the recent SXSW conference, co-founder and CEO Jonah Peretti announced the creation of
ChatGPT Adult Mode Delayed Again; Ultraman: Prioritize Intelligence First
OpenAI Delays Controversial Feature Again, Focuses on Personalization and Proactive InteractionWhether “inappropriate content” should be part of a productive AI tool has long sparked debate in the tech community. Promising to make ChatGPT better unde
Related Special Topic Recommendations
Comments (0)
0/500

Even seasoned veterans in the cybersecurity field can sometimes stumble. Recently, 360 Company's new AI offering, "360 Security Lobster," was found to have a critical, fundamental security oversight, raising widespread industry concerns about the rigor of AI product release cycles.
Reports indicate the issue stemmed from the product's installation package, which was discovered to contain the SSL private keys and certificates for the wildcard domain *.myclaw.360.cn. This is akin to leaving a master key out in the open. If obtained by an attacker, this private key could theoretically be used to impersonate a server, execute man-in-the-middle attacks, or intercept user data traffic.
Addressing the controversy, 360 Company responded swiftly, attributing the problem to a low-level procedural error during the release phase that accidentally bundled an internal domain certificate into the public installation package.
To mitigate the impact, 360 has implemented the following emergency actions:
Immediate Revocation: The compromised certificate has been revoked and is now entirely invalid.
Risk Assessment: The company states that ordinary users are not currently at risk, and technical measures have been deployed to block potential server forgery using the private key.
For a leading domestic cybersecurity firm like
AIGCPanel 2.0.0 Major Update: Workflow Engine Opens New Era of Automated Digital Human Creation
AIGCPanel, a powerful tool for local digital human creation, has just launched version 2.0.0—billed as "the most significant update yet." This core overhaul addresses the fragmentation of AI creation tools by linking digital human synthesis, voice cl
BuzzFeed launches AI junk app subsidiary
Amid a significant business crisis, the former digital media giant BuzzFeed is launching an ambitious self-rescue experiment powered by artificial intelligence. At the recent SXSW conference, co-founder and CEO Jonah Peretti announced the creation of
ChatGPT Adult Mode Delayed Again; Ultraman: Prioritize Intelligence First
OpenAI Delays Controversial Feature Again, Focuses on Personalization and Proactive InteractionWhether “inappropriate content” should be part of a productive AI tool has long sparked debate in the tech community. Promising to make ChatGPT better unde











