Ethical Hacking News
Hackers Have Obtained Counterfeit TLS Certificates for Google and Other Large Services, Exposing Thousands of Users to Cryptographic Impersonation
Hackers obtained counterfeit TLS certificates for Google and other large services, leaving thousands of users vulnerable. Attackers exploited a weak link in the TLS certificate chain to hijack three top-level domains (.gh, .sl, and .as) and mint counterfeit certificates. The TLS certificate chain is vulnerable to exploitation by sophisticated hackers, as demonstrated by the recent attack. Google has updated Chrome to block unauthorized certificates, and certificate authorities are working to revoke unauthorized certificates for Google properties. Similar incidents have occurred in the past, highlighting the need for robust measures to prevent such attacks, including better monitoring and validation of certificate issuance and revocation.
In a shocking revelation, hackers have successfully obtained counterfeit TLS certificates for Google and other large services, leaving thousands of users vulnerable to cryptographic impersonation. The attack, which was carried out by exploiting a weak link in the TLS certificate chain, has highlighted the ongoing vulnerability of the internet infrastructure to sophisticated cyber threats.
According to Google, the hackers were able to hijack three top-level domains (.gh, .sl, and .as) and use their control to mint counterfeit TLS certificates for several Google domains and other leading global brands and widely used online services. The attackers were able to pass automated domain control validation checks and obtain unauthorized certificates by modifying authoritative DNS records for selected domains within those namespaces.
The TLS certificate chain is the backbone of the internet's security, providing cryptographic credentials that underpin authentication and encryption protections for websites, mail servers, and other Internet infrastructure. These x.509 certificates use a digital signature to bind a domain name to a public key, with the private key held only by the website operator. When a connection shows that the keys match, the visiting party knows it's connected to the authentic site rather than an impostor.
However, the attack has exposed the vulnerability of the TLS certificate chain to exploitation by sophisticated hackers. The attackers were able to obtain control of the three affected top-level domains and use this control to modify DNS records, allowing them to pass industry validation checks and obtain unauthorized certificates.
Google has updated Chrome to block all certificates it identified as unauthorized, and is working with the issuing certification authorities to ensure the unauthorized certificates for Google properties were revoked. However, the incident highlights the importance of domain owners monitoring certificate transparency logs and publishing restrictive Certification Authority Authorization DNS records to prevent attackers from reusing cached validation data after DNS control is restored.
The incident is not the first of its kind, as there have been several similar incidents in the past, often through failures by certificate authorities or domain holders. In 2011, a hack of Netherlands-based certificate authority DigiNotar allowed attackers to mint counterfeit certificates for Google.com and over 200 other high-traffic domains. The certificates were used against at least 300,000 people with ties to Iran as they browsed the sites impersonated by the forged certificates.
The attack has raised concerns about the security of the internet infrastructure and the importance of maintaining the integrity of the TLS certificate chain. It has also highlighted the need for more robust measures to prevent such attacks in the future, including better monitoring and validation of certificate issuance and revocation.
In conclusion, the attack highlights the ongoing vulnerability of the internet infrastructure to sophisticated cyber threats, and the need for more robust measures to prevent such attacks in the future. It is essential for domain owners to take proactive steps to monitor certificate transparency logs and publish restrictive Certification Authority Authorization DNS records to prevent attackers from reusing cached validation data after DNS control is restored.
Related Information:
https://www.ethicalhackingnews.com/articles/Hackers-Exploit-Weak-Link-in-TLS-Certificate-Chain-Obtain-Counterfeit-Certificates-for-Google-and-Other-Large-Services-ehn.shtml
https://arstechnica.com/security/2026/10/hackers-obtain-counterfeit-tls-certificates-for-google-and-other-large-services/
Published: Tue Oct 6 17:17:49 2026 by llama3.2 3B Q4_K_M