{"id":20600,"date":"2026-10-07T12:05:42","date_gmt":"2026-10-07T12:05:42","guid":{"rendered":"https:\/\/news.theck1.no\/?p=20600"},"modified":"2026-10-07T12:05:42","modified_gmt":"2026-10-07T12:05:42","slug":"hackers-obtain-counterfeit-tls-certificates-for-google-and-other-large-services","status":"publish","type":"post","link":"https:\/\/news.theck1.no\/?p=20600","title":{"rendered":"Hackers obtain counterfeit TLS certificates for Google and other large services"},"content":{"rendered":"<p style=\"margin:0 0 1em; padding:0.6em 0.9em; border:1px solid #d0d7de; border-radius:6px; background:#f6f8fa; color:#444; font-size:0.9em;\"><strong>AI-rewritten:<\/strong> This is a summary of an article from Ars Technica, rewritten by AI (Qwen, running locally) to make it easier to read. The facts come from the original article &ndash; read it for the full story.<\/p>\n<div style=\"margin-bottom:1em; color:#666; font-size:0.9em;\"><strong>Ars Technica &bull;<br \/>\n                    Dan Goodin<br \/>\n                 &bull; October 6, 2026<\/strong><\/div>\n<hr\/>\n<p>Hackers hijacked three top-level domains and used that control to create counterfeit TLS certificates for Google and other major organizations, according to Google. The attackers modified authoritative DNS records for selected domains within the .gh, .sl, and .as country code namespaces. This allowed them to pass automated domain control validation checks and issue unauthorized certificates for several Google domains and other leading global brands. Google stated it updated Chrome to block all identified unauthorized certificates and worked with certification authorities to revoke those issued for Google properties.<\/p>\n<p><!--more--><\/p>\n<p>TLS certificates are cryptographic credentials that bind a domain name to a public key, ensuring visitors connect to the authentic site rather than an impostor. Possession of these unauthorized certificates allows attackers to cryptographically impersonate affected infrastructure. While Chrome users do not need to take action to be protected, Google cautioned domain owners not to rely solely on browser-side interventions. The company advised monitoring certificate transparency logs and publishing restrictive Certification Authority Authorization DNS records to prevent attackers from reusing cached validation data after DNS control is restored.<\/p>\n<p>Google noted the incident did not involve the compromise of any affected domain owner&#8217;s infrastructure or certificate authority requirements. With control of the three ccTLDs, attackers changed IP addresses and modified nameserver delegations for selected websites, enabling them to send and receive traffic while passing industry validation checks. This follows a 2011 hack of DigiNotar that minted counterfeit certificates for Google.com and over 200 other domains, affecting at least 300,000 people. Although all known unauthorized certificates are now blocked, any undiscovered certificates remain a threat.<\/p>\n<div style=\"margin-top:2em; padding:1em; border-left:4px solid #0073aa; background:#f5f7fa;\">\n<p style=\"margin:0;\"><strong>Source:<\/strong> Ars Technica &bull;<br \/>\n                    Dan Goodin<br \/>\n                 &bull; October 6, 2026<\/p>\n<p style=\"margin:0.5em 0 0;\"><a href=\"https:\/\/arstechnica.com\/security\/2026\/10\/hackers-obtain-counterfeit-tls-certificates-for-google-and-other-large-services\/\" target=\"_blank\" rel=\"noopener\">Read the original article at Ars Technica &rarr;<\/a><\/p>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>AI-rewritten: This is a summary of an article from Ars Technica, rewritten by AI (Qwen, running locally) to make it easier to read. The facts come from the original article &ndash; read it for the full story. Ars Technica &bull; Dan Goodin &bull; October 6, 2026 Hackers hijacked three top-level domains and used that control<\/p>\n<p class=\"more-link\"><a href=\"https:\/\/news.theck1.no\/?p=20600\" class=\"themebutton2\">READ MORE<\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[6],"tags":[],"class_list":["post-20600","post","type-post","status-publish","format-standard","hentry","category-artificial-intelligence"],"_links":{"self":[{"href":"https:\/\/news.theck1.no\/index.php?rest_route=\/wp\/v2\/posts\/20600","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/news.theck1.no\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/news.theck1.no\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/news.theck1.no\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/news.theck1.no\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=20600"}],"version-history":[{"count":0,"href":"https:\/\/news.theck1.no\/index.php?rest_route=\/wp\/v2\/posts\/20600\/revisions"}],"wp:attachment":[{"href":"https:\/\/news.theck1.no\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=20600"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/news.theck1.no\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=20600"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/news.theck1.no\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=20600"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}