E-Ink News Daily

← Back to list

Hackers obtain counterfeit TLS certificates for Google and other large services

Hackers hijacked three country-code top-level domains (.gh, .sl, .as) to forge TLS certificates for Google and other major services by manipulating DNS records to pass domain validation checks. Google responded by updating Chrome to block unauthorized certificates and coordinating with certificate authorities for revocation.

Background

TLS certificates are essential for securing web communications worldwide. This incident highlights ongoing vulnerabilities in the certificate authority validation ecosystem, particularly around less-monitored ccTLDs.

Source
Ars Technica
Published
Oct 7, 2026 at 03:21 AM
Score
8.0 / 10