search
TLS certificate authorities
Trends
- 1Hackers obtain counterfeit TLS certificates for Google and other services●Hackers obtain counterfeit TLS certificates for Google and other large services https://arstechnica.com/security/2026/10
Hackers have managed to obtain counterfeit TLS certificates for Google and other major online services, according to a security report. Fraudulent certificates could allow attackers to impersonate trusted websites and intercept traffic. The incident raises fresh questions about how certificate authorities verify requests and whether users need to take protective steps.
- 2Hackers obtain counterfeit TLS certificates for Google and other major services●Hackers obtain counterfeit TLS certificates for Google and other large services
Hackers have obtained counterfeit TLS certificates impersonating Google and other large internet services, potentially allowing them to intercept traffic or mount convincing phishing attacks. Security researchers are examining how the fraudulent certificates were issued, and the incident is raising fresh questions about weaknesses in the certificate authority system that underpins trust on the web.
- 3Hackers Get Unauthorized TLS Certificates for Google Domains▼Hackers Obtain Unauthorized TLS Certificates for Google via Hijacked Domains
Attackers obtained TLS certificates for Google web properties without authorization, using hijacked domains to pass certificate authority validation. The certificates could have enabled interception of traffic to the affected Google sites. The incident raises fresh questions about domain-based validation in the web's certificate system and how quickly the rogue certificates were detected and revoked.
- 4Cloudflare details plans for an Internet-scale certificate authority▼Building a certificate authority for the whole Internet
Cloudflare has published a post explaining how it is building a certificate authority capable of issuing TLS certificates for websites across the entire Internet. The company, which already provides security and performance services to millions of sites, outlines the technical and operational challenges of running certificate issuance at massive scale, including automation, security controls and trust requirements. Readers in the developer community are weighing in on the engineering involved.
- 5Attackers compromise .gh, .sl and .as domain registries●Attackers compromised .gh, .sl, and .as ccTLD registries. Modified authoritative DNS. Passed automated domain control va
Attackers gained access to the country-code top-level domain registries for Ghana (.gh), Sierra Leone (.sl) and American Samoa (.as) and altered their authoritative DNS records. The changes let them pass automated domain control validation and obtain valid TLS certificates for Google domains and other major brands. Google itself was not hacked, and certificate authorities followed their normal procedures, raising concern about weaknesses in the domain validation trust chain.
- 6Hackers obtain counterfeit TLS certificates for Google and major services●Hackers obtain counterfeit TLS certificates for Google and other large services https:// lemmy.world/post/52855851
Hackers have obtained counterfeit TLS certificates for Google and other major online services, raising concerns that attackers could impersonate trusted websites, intercept encrypted traffic, or bypass browser security warnings. The incident highlights weaknesses in the certificate authority system that underpins web encryption, and users are discussing which services were affected and how authorities and browsers will respond.
- 7Hackers Forge Real Google TLS Certificates via Hijacked Country Domains▼Hackers Used Hijacked Country Domains to Forge Real Google TLS Certificates
Hackers hijacked top-level domains belonging to small countries and used that control to obtain legitimate TLS certificates bearing Google's name, according to a Fortune report. By compromising country-code domain infrastructure, the attackers were able to pass certificate authority validation checks, potentially enabling convincing phishing or man-in-the-middle attacks that browsers would treat as trusted.
- 8Hackers obtain counterfeit TLS certificates for Google domains●Hackers obtain counterfeit TLS certificates for Google and other large services Compromise of 3 domain registries allows
Attackers compromised three domain registries and used the access to obtain fraudulent TLS certificates for Google and other major services. The unauthorized certificates could let the attackers impersonate trusted websites and intercept traffic. Security researchers are highlighting how registry-level compromise undermines the certificate authority system, and questions are being raised about revocation procedures and how widely the fake certificates were actually used.
- 9Hackers Forge TLS Certificates Impersonating Google and Major Services●Hackers Impersonate Google and Other Large Services With Counterfeit TLS Certificates https://www. privacyguides.org/new
Attackers have issued counterfeit TLS certificates impersonating Google and other major online services, raising concerns about web security and certificate authority oversight. The report has drawn attention in privacy and security communities, where users are being urged to verify certificates and stay alert to potential phishing risks posed by fraudulent HTTPS credentials.
- 10Cloudflare to issue quantum-safe TLS certificates●Cloudflare plans to issue quantum-safe # TLS # certificates # Cloudflare said Tuesday it plans to issue quantum-proof TL
Cloudflare said Tuesday it plans to issue quantum-proof TLS certificates, positioning itself among the first certificate authorities to adopt cryptography designed to withstand attacks from future quantum computers. The move is seen as an early step toward protecting encrypted web traffic from 'harvest now, decrypt later' threats, and security watchers are weighing how quickly the wider industry will follow suit.