The hack that released (among other things) Nvidia's code-signing certificates is obviously bad but the most frustrating thing I find about it is all the information I find on it makes it very unclear as to what, if anything, I should be doing about it, but certainly makes the problem sound scary and only ever describes potential solutions as "well it's really complicated to do something about this and it might cause other problems if you try"
Like, okay, but, like, that's not very reassuring, is there any kind of simpler thing an average user like me should be doing to avoid downloading malware with a fake Nvidia certificate, how concerned should I actually be about this?