2026-03-16 13:59:26
360 Security Lobster Exposed to Bundle HTTPS Wildcard Certificate Private Key into Local Directory
Gate News reported that on March 16, 360's recently released security product "Security Lobster" was discovered to have directly packaged the wildcard domain certificate of .myclaw.360.cn and its corresponding private key in the local installation directory. The Security Lobster interface is based on a customized 360 browser, accessed through https://myclaw.360.cn:19798/local address. In order to achieve this local HTTPS connection, engineers placed both the wildcard certificate and private key in the client. The wildcard certificate covers all subdomains under myclaw.360.cn. Once the private key is leaked, third parties can forge HTTPS encrypted connections under this domain. The certificate has not been revoked so far.