An internal security breach caused 9 fraudulent certificates to be issued by Comodo CA last week. The attack was discovered almost immediately by an internal Comodo check. The only OCSP activity seen relating to these certificates has been two hits, one from the attackers IP and one from another very close by, plus hits from testing. Mozilla hard-code a blacklist of the certificate serial numbers into Firefox 4 (released as Firefox 4 final on 22nd March) with two additional code patches (1, 2) These patches disable these specific certificates, plus one additional certificate issued to us by comodo for testing.”]
Source: https://blog.mozilla.org/security/2011/03/25/comodo-certificate-issue-follow-up/

