The 2020 Pwnie Winner For Most Epic Fail

Microsoft

Microsoft’s implementation of elliptic curve signatures allowed attackers to generate private pairs for the public keys of any legitimate signer. This enabled spoofing of any HTTPS website or signed binary on affected versions of Windows. We wish Microsoft was as lenient when choosing the time of updates, as it was for choosing generator points!

CVE-2020-0601