Mmastodon first seen 19 h ago, last 57 min ago, peak #9
Hackers obtain counterfeit TLS certificates for Google and major services
Original: Hackers obtain counterfeit TLS certificates for Google and other large services
Hackers have obtained counterfeit TLS certificates for Google and other large services after compromising three domain registries, security reporting by Ars Technica says. The registry compromise allowed the attackers to walk away with unauthorized certificates, which could be used to impersonate trusted websites and intercept traffic. The incident raises fresh concerns about the security of the certificate issuance system that underpins web encryption.
Why now: A compromise of domain registries undermining HTTPS trust for major services is a serious and unusual security breach.
Evidence
- Hackers obtain counterfeit TLS certificates for Google and other large services · Ars Technica
Compromise of 3 domain registries allows hackers to walk off with unauthorized certs.
Elsewhere
API: https://socialmediatrends-api.osmike.com/v1/trends/1286836