Security

Google warns of stolen counterfeit TLS certificates

1 min readSource: TechRadar
Google warns of stolen counterfeit TLS certificates

Google has revealed that attackers stole counterfeit TLS certificates from major domains. The company revoked these certificates to protect Chrome users.

Recently, Google reported a cyberattack where criminals managed to hijack three country-code top-level domains (ccTLDs) to generate fraudulent HTTPS certificates. Such certificates can facilitate traffic interception and phishing, putting thousands of websites at risk, including some from Google.

The affected domains are .gh (Ghana), .sl (Sierra Leone), and .as (American Samoa). The attackers modified authoritative DNS records, allowing them to obtain HTTPS certificates covering not only Google domains but also those of other organizations. Fortunately, Google has revoked these fraudulent certificates, helping to mitigate risk for users.

## Why it matters This incident highlights the vulnerability of internet security certification systems. The attackers' ability to obtain counterfeit TLS certificates means they can conduct more convincing phishing attacks, tricking users into revealing sensitive information. Google's swift action to revoke the certificates is a crucial step in protecting users, but the threat remains.

## What we know Google has confirmed that the fraudulent HTTPS certificates have been revoked, meaning Chrome users are protected. However, the full extent of the websites affected by this attack has not yet been detailed, leaving many organizations uncertain about their security.

## What remains unclear It is still unclear how the attackers managed to hijack the ccTLDs or if there are other potentially at-risk domains. It is essential for organizations to review their security measures and remain vigilant against possible phishing attempts that may arise as a result of this attack.

Share:

Read at the original source:

TechRadar →
#google#hack#tls#certificates#security

Related news