:

LET'S ENCRYPT RESTRICTS CERTS IN US SANCTIONED ZONES

INDUSTRY DESK1 MIN READ
TUE, JUN 9, 2026

■ AI-SUMMARIZED FROM 1 SOURCE ▸ TIMELINE

Let's Encrypt has updated its subscriber agreement to prohibit certificate issuance and usage in US-sanctioned territories, effective immediately. The change aligns the free certificate authority with American export control regulations.

The updated policy, detailed in version 1.7 of Let's Encrypt's Subscriber Agreement, bars the use of its certificates in any region subject to US sanctions. This includes territories under OFAC (Office of Foreign Assets Control) restrictions. Let's Encrypt, operated by the Internet Security Research Group, must comply with US law to maintain its operations. The restriction applies to both new certificate issuance and continued use of existing certificates in sanctioned areas. The move affects websites and services operating in designated sanctioned territories. Organizations in these regions will need to source certificates through alternative providers. The policy update generated significant discussion in the developer community, with 86 comments on Hacker News reflecting concerns about internet accessibility in restricted regions and the practical implications for affected services. Let's Encrypt previously faced similar compliance requirements and has adjusted policies accordingly. The organization continues to provide free SSL/TLS certificates globally outside sanctioned zones.

■ SOURCES

Hacker News

■ SUMMARY WRITTEN BY AI FROM THE LINKS ABOVE

■ MORE FROM THE SECURITY DESK

Modern phishing techniques can circumvent multi-factor authentication without stealing passwords, according to a new webinar. Behavioral AI tools can help security teams detect compromised accounts faster and automate response measures.

1H AGOIndustry Desk

AI agents now access data, trigger workflows, and deploy code across critical business systems with minimal governance controls. Security researchers warn that organizations are failing to manage these digital entities as formal identities.

1H AGOAI Desk

Ofcom has contacted Telegram seeking clarification on how the messaging app detects illegal incitement, after a Ukrainian man was convicted of arson attacks on property linked to UK Prime Minister Keir Starmer. The attacker was directed via the platform by a handler.

4H AGOIndustry Desk

A New York man faces cyberstalking charges after allegedly creating and distributing AI-generated nude images of a Georgia college student. He also fabricated racist messages using fake social media profiles.

4H AGOAI Desk

■ SUBSCRIBE TO THE DAILY BRIEF

ONE EMAIL, 5 STORIES, 06:00 UTC. UNSUBSCRIBE ANYTIME.