Hackers obtain counterfeit TLS certificates for Google and other large services

Google recently disclosed that attackers successfully hijacked three top-level domains (.gh, .sl, and .as) to issue counterfeit TLS certificates for various high-profile services, including Google itself. By compromising the DNS records at the registry level, the attackers were able to intercept traffic and generate unauthorized cryptographic credentials. These certificates, which are essential for verifying the identity of websites, could have allowed the perpetrators to impersonate legitimate infrastructure and potentially conduct man-in-the-middle attacks. In response, Google has updated the Chrome browser to block the identified fraudulent certificates and is coordinating with other certificate authorities to ensure widespread revocation. This incident highlights a critical vulnerability in the domain registration and certificate issuance chain, emphasizing the risks associated with DNS-level compromises. Security experts recommend that organizations remain vigilant regarding their domain management and monitor for any unauthorized certificate issuance attempts.
This is a summary. Read the full article at the original source:
Ars TechnicaRelated stories
Online fashion retailer Asos has confirmed it is investigating a security incident involving an extortion hack. The attackers reportedly gained unauth…
Google has introduced PageBreak, an autonomous AI agent designed to enhance web application security by identifying vulnerabilities. In recent interna…
In a recent interview with Dark Reading, Nick Kakolowski, senior director for CISO research at IANS, explores the profound impact of artificial intell…



