Technologies
Back
Cybersecurity & Privacy

Hackers obtain counterfeit TLS certificates for Google and other large services

Ars Technica
Advertisement468 × 90
Hackers obtain counterfeit TLS certificates for Google and other large services

Google recently disclosed that attackers successfully hijacked three top-level domains (.gh, .sl, and .as) to issue counterfeit TLS certificates for various high-profile services, including Google itself. By compromising the DNS records at the registry level, the attackers were able to intercept traffic and generate unauthorized cryptographic credentials. These certificates, which are essential for verifying the identity of websites, could have allowed the perpetrators to impersonate legitimate infrastructure and potentially conduct man-in-the-middle attacks. In response, Google has updated the Chrome browser to block the identified fraudulent certificates and is coordinating with other certificate authorities to ensure widespread revocation. This incident highlights a critical vulnerability in the domain registration and certificate issuance chain, emphasizing the risks associated with DNS-level compromises. Security experts recommend that organizations remain vigilant regarding their domain management and monitor for any unauthorized certificate issuance attempts.

This is a summary. Read the full article at the original source:

Ars Technica
Advertisement468 × 90
Share
Cybersecurity & Privacy

Related stories

Advertisement970 × 250