التقنية والذكاء الاصطناعي
Hackers obtain counterfeit TLS certificates for Google and other large services
المصدر: Ars Technica - All content · نُشر

Attackers hijacked three top-level domains and used their control to mint counterfeit TLS certificates for Google and other large organizations, Google said Tuesday. The attackers launched a series of attacks on the .gh, .sl, and .as country code top-level domains (ccTLDs) and th
Attackers hijacked three top-level domains and used their control to mint counterfeit TLS certificates for Google and other large organizations, Google said Tuesday. The attackers launched a series of attacks on the .gh, .sl, and .as country code top-level domains (ccTLDs) and then modified authoritative DNS records for selected domains within those namespaces. By controlling those DNS records, the attackers were able to pass automated domain control validation checks and obtain unauthorized certificates for “several Google domains” and “several leading global brands and widely used online services.” Google said it updated Chrome to block all certificates it identified as unauthorized, and worked with the issuing certification authorities to ensure the unauthorized certificates for Google properties were revoked.
Certificate issuance: The weak link in the chain TLS certificates are the cryptographic credentials that underpin authentication and encryption protections for websites, mail servers, and other Internet infrastructure. These x.509 certificates use a digital signature to bind a domain name such as google.com to a public key. The public key is publicly available, while the private key is held only by the website operator.
When a connection shows that the keys match, the visiting party knows it’s connected to the authentic site rather than an impostor. Possession of unauthorized certificates allows attackers to cryptographically impersonate the affected infrastructure. Read full article Comments
أخبار ذات صلة

Google’s power-hungry data centers crave nuclear energy
Google announced a new agreement to update six nuclear power plant sites across the US as the tech giant seeks to generate more electricity for its power-hungry data centers. Google signed the 20-year deal with Constellation, the leading nuclear power plant operator in the US. Th
The Verge ·

Google Photos vs. Gallery app: What's the difference and which should you use?
We compare Google's Photos and Gallery apps, so you can decide which one to use.
Engadget - Technology News & Expert Reviews ·

8 Best Prime Day Wearable Deals: Apple, Google, Samsung (2026)
I’ve tested the wearables, tracked the prices, and found the Prime Day deals worth grabbing.
WIRED ·

MCP for agent-to-agent comms may be the riskiest protocol you've never heard of
The adoption of AI agents in millions of organizations is creating new opportunities for attackers to make them take malicious actions, such as exfiltrating database contents and sensitive business and personal information. In the past five months, Google and four other organizat
Ars Technica - All content ·

Google told to halt work on datacentres in Finland over environmental concerns
Order on two construction sites comes after Google failed to carry out environmental impact assessments Google has been ordered to temporarily stop work on two datacentres in Finland after failing to do the necessary environmental impact assessments on its construction sites. The
World news | The Guardian ·