I wonder whether a quickly updated AV database is required in case a (zero-day or not) malicious app runs with a valid trusted cert. or not?
I can imagine that only in this case only a quickly updated AV database offers protection but maybe I'm mistaken.
I can imagine that only in this case only a quickly updated AV database offers protection but maybe I'm mistaken.

