❌

Normal view

There are new articles available, click to refresh the page.
Yesterday β€” 6 October 2026Tech & News

Hackers obtain counterfeit TLS certificates for Google and other large services

6 October 2026 at 19:21

Attackers hijacked three top-level domains and used their control to mint counterfeit TLS certificates for Google and other large organizations, Google said Tuesday.

The attackers launched a series of attacks on the .gh, .sl, and .as country code top-level domains (ccTLDs) and then modified authoritative DNS records for selected domains within those namespaces. By controlling those DNS records, the attackers were able to pass automated domain control validation checks and obtain unauthorized certificates for β€œseveral Google domains” and β€œseveral leading global brands and widely used online services.” Google said it updated Chrome to block all certificates it identified as unauthorized, and worked with the issuing certification authorities to ensure the unauthorized certificates for Google properties were revoked.

Certificate issuance: The weak link in the chain

TLS certificates are the cryptographic credentials that underpin authentication and encryption protections for websites, mail servers, and other Internet infrastructure. These x.509 certificates use a digital signature to bind a domain name such as google.com to a public key. The public key is publicly available, while the private key is held only by the website operator. When a connection shows that the keys match, the visiting party knows it’s connected to the authentic site rather than an impostor. Possession of unauthorized certificates allows attackers to cryptographically impersonate the affected infrastructure.

Read full article

Comments

Β© Getty Images

Before yesterdayTech & News

Interview: Firefox's chief on why he hopes a redesign will help win users from Chrome

29 September 2026 at 13:00

Today, the Firefox 157 update will roll out a redesign of the web browser across desktop and mobile platforms. The team that made it hopes it will help expand the browser's audience beyond privacy-conscious techies and open-web or open source advocates to a broader audience who might simply pick the browser because they prefer its user experience over competitors like Chrome, Edge, and Safari.

In advance of the redesign's launch, I spent half an hour chatting with Mozilla's head of Firefox, Ajit Varma, about Firefox's current market position and product strategy, and what barriers or opportunities there are for gaining ground in a Chromium-dominated landscape.

Read full article

Comments

Β© Mozilla

❌
❌