Hackers obtain counterfeit TLS certificates for Google and other large services
Attackers hijacked three country code top-level domains — .gh, .sl and .as — and used DNS record changes to mint counterfeit TLS certificates for Google domains and other major brands. Google updated Chrome to block all identified counterfeit certificates and warned it cannot guarantee it found every affected domain.
- ccTLDs .gh, .sl and .as were hijacked and DNS records modified
- Counterfeit certificates issued for several Google domains and major services
- Chrome blocked known counterfeit certificates; other browsers notified
- Google cannot guarantee all counterfeit certificates were found
Read next
Security