Home / Oct 07, 2026 / Story
0
#1 Ars Technica Security general October 06, 2026 at 19:21 UTC

Hackers obtain counterfeit TLS certificates for Google and other large services

By Dan Goodin

AI Summary

Attackers compromised three domain registries to obtain counterfeit TLS certificates for Google and other major services, enabling potential man-in-the-middle attacks against encrypted traffic. This represents a fundamental PKI trust failure, as fraudulent certificates issued through legitimate CA infrastructure can bypass standard certificate validation and browser warnings.

Relevance score: 92.0/100

# More from October 07