Microsoft issues unauthorized certificate warning, patch
Microsoft has issued a rather serious security advisory via TechNet, affecting virtually every currently supported Windows product, and issued a patch to correct the problem. The threat stems from unauthorized Microsoft Certificates being used to spoof content and carry out phishing attacks.
The report doesn't go into details on the attacks themselves, simply stating that Microsoft is aware of the problem and that the unauthorized certificates could be used to “spoof content, perform phishing attacks, or perform man-in-the-middle attacks.” Simply put, that's some pretty serious stuff, and the it could lead to a lot of personal information falling into the wrong hands if left unchecked.