Hackers obtain counterfeit TLS certificates for Google and other large services
Summary
Attackers hijacked three top-level domains to mint counterfeit TLS certificates for Google and other major services, exploiting DNS and domain control validation. Google blocked the unauthorized certificates and urged domain owners to monitor certificate transparency logs and publish strict CA Authorization records; the incident highlights weaknesses in TLS issuance and DNS-based trust.