Digital Event Horizon
Hackers have obtained counterfeit TLS certificates for Google and other large services, compromising the security of these organizations. The attackers were able to hijack three top-level domains and use their control to mint unauthorized certificates for several Google domains and leading global brands. In this article, we will explore the details of the attack and the implications for the security of online services.
Hackers successfully obtained counterfeit TLS certificates for Google and other large services, compromising their security. The attackers hijacked three top-level domains (.gh, .sl, and .as) to mint unauthorized certificates for Google domains and leading global brands. The attack highlights the vulnerability of the TLS certificate system and the need for increased security measures. Google was quick to respond and update its Chrome browser to block the identified unauthorized certificates. The attack emphasizes the importance of monitoring certificate transparency logs and publishing restrictive DNS records to prevent similar attacks. The incident is not the first of its kind, with similar incidents occurring since a 2011 hack of Netherlands-based certificate authority DigiNotar.
In a shocking revelation, hackers have successfully obtained counterfeit TLS certificates for Google and other large services, compromising the security of these organizations. The attackers were able to hijack three top-level domains, .gh, .sl, and .as, and use their control to mint unauthorized certificates for several Google domains and leading global brands. This latest attack highlights the vulnerability of the TLS certificate system and the need for increased security measures to protect against such threats.
The attack began with the hackers launching a series of attacks on the three top-level domains, exploiting a weak link in the chain of certificate issuance. The attackers modified authoritative DNS records for selected domains, allowing them to pass automated domain control validation checks and obtain unauthorized certificates. The compromised certificates were used to cryptographically impersonate the affected infrastructure, posing a significant threat to the security of the organizations involved.
Google was one of the organizations affected by the attack, but the company was quick to respond and update its Chrome browser to block all identified unauthorized certificates. Google worked with the issuing certification authorities to ensure the unauthorized certificates for Google properties were revoked, mitigating the risk to its users.
However, the attack highlights the complexity of DNS hijacks and the need for increased vigilance from certificate authorities and domain owners. Google cautioned domain owners not to rely solely on browser-side interventions to protect their users, but rather to monitor certificate transparency logs and publish restrictive Certification Authority Authorization DNS records to prevent attackers from reusing cached validation data.
The attack is not the first of its kind, as a 2011 hack of Netherlands-based certificate authority DigiNotar allowed attackers to mint counterfeit certificates for Google.com and over 200 other high-traffic domains. There have been many similar incidents since, often resulting from failures by certificate authorities or domain holders.
In conclusion, the recent attack on Google and other large services highlights the importance of maintaining robust security measures to protect against TLS certificate impersonation. Certificate authorities and domain owners must take proactive steps to prevent such attacks and ensure the security of their users.
Related Information:
https://www.digitaleventhorizon.com/articles/Hacking-the-DNS-How-Hackers-Stole-Confidential-TLS-Certificates-from-Google-and-Other-Large-Services-deh.shtml
https://arstechnica.com/security/2026/10/hackers-obtain-counterfeit-tls-certificates-for-google-and-other-large-services/
Published: Tue Oct 6 16:41:34 2026 by llama3.2 3B Q4_K_M