MikeTrendsTrends right now

search

TLS certificates

Trends

  1. 1
    Hackers obtain counterfeit TLS certificates for Google and other servicesโ—Hackers obtain counterfeit TLS certificates for Google and other large services https://arstechnica.com/security/2026/10MmastodonTechnologyCybersecurity313 h ago

    Hackers have managed to obtain counterfeit TLS certificates for Google and other major online services, according to a security report. Fraudulent certificates could allow attackers to impersonate trusted websites and intercept traffic. The incident raises fresh questions about how certificate authorities verify requests and whether users need to take protective steps.

  2. 2
    Hackers obtain counterfeit TLS certificates for Google and major servicesโ–ผHackers obtain counterfeit TLS certificates for Google and other large servicesMmastodon1194 h ago

    Hackers have obtained counterfeit TLS certificates for Google and other large services after compromising three domain registries, security reporting by Ars Technica says. The registry compromise allowed the attackers to walk away with unauthorized certificates, which could be used to impersonate trusted websites and intercept traffic. The incident raises fresh concerns about the security of the certificate issuance system that underpins web encryption.

  3. 3

    Caddy, the open-source web server written in Go, is trending among developers. The project bills itself as a fast, extensible HTTP/1, HTTP/2 and HTTP/3 server with automatic HTTPS, meaning it provisions and renews TLS certificates by default. It runs across platforms and is widely used as a reverse proxy and lightweight alternative to Nginx. Developers are discussing it for its simplicity and secure-by-default configuration.

  4. 4
    Hackers obtain counterfeit TLS certificates for Google and other major servicesโ—Hackers obtain counterfeit TLS certificates for Google and other large servicesYhn1128 h ago

    Hackers have obtained counterfeit TLS certificates impersonating Google and other large internet services, potentially allowing them to intercept traffic or mount convincing phishing attacks. Security researchers are examining how the fraudulent certificates were issued, and the incident is raising fresh questions about weaknesses in the certificate authority system that underpins trust on the web.

  5. 5
    Cloudflare details plans for an Internet-scale certificate authorityโ–ผBuilding a certificate authority for the whole InternetYhnCultureBooks741 d ago

    Cloudflare has published a post explaining how it is building a certificate authority capable of issuing TLS certificates for websites across the entire Internet. The company, which already provides security and performance services to millions of sites, outlines the technical and operational challenges of running certificate issuance at massive scale, including automation, security controls and trust requirements. Readers in the developer community are weighing in on the engineering involved.

  6. 6
    Hackers Issue Unauthorized TLS Certificates for Google Domainsโ–ผHackers Obtain Unauthorized TLS Certificates for Google via Hijacked Domainsโœ‰newsTechnologyGadgets59 min ago

    Hackers obtained unauthorized TLS certificates for Google web properties by hijacking control of internet domains, allowing them to potentially impersonate Google sites. The incident highlights weaknesses in certificate authorities' domain validation processes and raises concerns about internet security infrastructure. Security commentators are scrutinizing how the hijacked domains passed verification checks and what safeguards certificate issuers need to strengthen.

  7. 7
    Hackers Forge Real Google TLS Certificates via Hijacked Country Domainsโ–ผHackers Used Hijacked Country Domains to Forge Real Google TLS Certificatesโœ‰newsBusinessStartups10 h ago

    Hackers hijacked top-level domains belonging to small countries and used that control to obtain legitimate TLS certificates bearing Google's name, according to a Fortune report. By compromising country-code domain infrastructure, the attackers were able to pass certificate authority validation checks, potentially enabling convincing phishing or man-in-the-middle attacks that browsers would treat as trusted.

  8. 8
    Hackers obtain counterfeit TLS certificates for Google domainsโ—Hackers obtain counterfeit TLS certificates for Google and other large services Compromise of 3 domain registries allowsMmastodonBusinessStartups36 h ago

    Attackers compromised three domain registries and used the access to obtain fraudulent TLS certificates for Google and other major services. The unauthorized certificates could let the attackers impersonate trusted websites and intercept traffic. Security researchers are highlighting how registry-level compromise undermines the certificate authority system, and questions are being raised about revocation procedures and how widely the fake certificates were actually used.

  9. 9
    Cloudflare to issue quantum-safe TLS certificatesโ–ผCloudflare plans to issue quantum-safe # TLS # certificates # Cloudflare said Tuesday it plans to issue quantum-proof TLMmastodonSciencePhysics23 d ago

    Cloudflare said Tuesday it plans to issue quantum-proof TLS certificates, positioning itself among the first certificate authorities to adopt cryptography designed to withstand attacks from future quantum computers. The move is seen as an early step toward protecting encrypted web traffic from 'harvest now, decrypt later' threats, and security watchers are weighing how quickly the wider industry will follow suit.

  10. 10
    wolfSSL introduces wolfCert for embedded device certificate enrollmentโ—Introduction to wolfCert: Certificate Enrollment for Embedded Devices https://www. wolfssl.com/introduction-to-wo lfcertMmastodonBusinessCrypto02 d ago

    wolfSSL has introduced wolfCert, a new tool for certificate enrollment on embedded devices. The announcement outlines how the component supports enrolling and managing certificates in constrained, resource-limited environments, complementing the company's existing TLS and cryptography offerings. The release is being circulated among security and embedded systems developers tracking certificate management options for IoT and embedded deployments.

  11. 11
    Critical 10/10 vulnerability flagged in vm2 sandbox libraryโ—๐Ÿšจ EUVD-2026-81591 ๐Ÿ“Š Score: 10.0/10 (CVSS v3.1) ๐Ÿ“ฆ Product: vm2 ๐Ÿข Vendor: patriksimek ๐Ÿ“… Updated: 2026-10-01 ๐Ÿ“ vm2 NodeVM cMmastodonTechnologyCybersecurity06 d ago

    A maximum-severity security flaw, tracked as EUVD-2026-81591, has been disclosed in vm2, the Node.js sandbox library maintained by Patrik Simek. The vulnerability, rated 10.0 out of 10 under CVSS v3.1, allows the NodeVM component to replace the host process TLS trust store, potentially undermining certificate validation. The advisory was updated on 1 October 2026 and appears in the EU vulnerability database.

Repos