MikeTrendsTrends right now

search

TLS certificates

Trends

  1. 1
    Hackers obtain counterfeit TLS certificates for Google and other servicesโ—Hackers obtain counterfeit TLS certificates for Google and other large services https://arstechnica.com/security/2026/10MmastodonTechnologyCybersecurity37 h ago

    Hackers have managed to obtain counterfeit TLS certificates for Google and other major online services, according to a security report. Fraudulent certificates could allow attackers to impersonate trusted websites and intercept traffic. The incident raises fresh questions about how certificate authorities verify requests and whether users need to take protective steps.

  2. 2
    Xray-core hid certificate verification bypass vulnerabilityโ—Xray-core concealed a certificate verification bypass vulnerabilityYhnTechnologyCybersecurity8834 min ago

    Xray-core, the widely used proxy tool, is under criticism for concealing a certificate verification bypass vulnerability rather than disclosing it publicly. The issue is being discussed on the net4people mailing list, where security researchers argue that a TLS verification flaw in censorship-circumvention software puts users at direct risk of detection and should have been disclosed promptly.

  3. 3

    Caddy, the open-source web server written in Go, is trending among developers. The project bills itself as a fast, extensible HTTP/1, HTTP/2 and HTTP/3 server with automatic HTTPS, meaning it provisions and renews TLS certificates by default. It runs across platforms and is widely used as a reverse proxy and lightweight alternative to Nginx. Developers are discussing it for its simplicity and secure-by-default configuration.

  4. 4
    Hackers obtain counterfeit TLS certificates for Google and major servicesโ–ผHackers obtain counterfeit TLS certificates for Google and other large servicesMmastodon1178 min ago

    Hackers have obtained unauthorized TLS certificates for Google and other major services after compromising three domain registries, security outlet Ars Technica reports. The forged certificates could let attackers impersonate trusted websites and intercept traffic. The incident has drawn attention across technical communities, with discussion focusing on how the registry compromise was possible and what it means for the certificate authority system.

  5. 5
    Hackers obtain counterfeit TLS certificates for Google and other major servicesโ—Hackers obtain counterfeit TLS certificates for Google and other large servicesYhn1122 h ago

    Hackers have obtained counterfeit TLS certificates impersonating Google and other large internet services, potentially allowing them to intercept traffic or mount convincing phishing attacks. Security researchers are examining how the fraudulent certificates were issued, and the incident is raising fresh questions about weaknesses in the certificate authority system that underpins trust on the web.

  6. 6
    Cloudflare details plans for an Internet-scale certificate authorityโ–ผBuilding a certificate authority for the whole InternetYhnCultureBooks741 d ago

    Cloudflare has published a post explaining how it is building a certificate authority capable of issuing TLS certificates for websites across the entire Internet. The company, which already provides security and performance services to millions of sites, outlines the technical and operational challenges of running certificate issuance at massive scale, including automation, security controls and trust requirements. Readers in the developer community are weighing in on the engineering involved.

  7. 7
    Hackers Forge Real Google TLS Certificates via Hijacked Country Domainsโ–ผHackers Used Hijacked Country Domains to Forge Real Google TLS Certificatesโœ‰newsBusinessStartups4 h ago

    Hackers hijacked top-level domains belonging to small countries and used that control to obtain legitimate TLS certificates bearing Google's name, according to a Fortune report. By compromising country-code domain infrastructure, the attackers were able to pass certificate authority validation checks, potentially enabling convincing phishing or man-in-the-middle attacks that browsers would treat as trusted.

  8. 8
    Hackers obtain counterfeit TLS certificates for Google domainsโ—Hackers obtain counterfeit TLS certificates for Google and other large services Compromise of 3 domain registries allowsMmastodonBusinessStartups342 min ago

    Attackers compromised three domain registries and used the access to obtain fraudulent TLS certificates for Google and other major services. The unauthorized certificates could let the attackers impersonate trusted websites and intercept traffic. Security researchers are highlighting how registry-level compromise undermines the certificate authority system, and questions are being raised about revocation procedures and how widely the fake certificates were actually used.

  9. 9
    Cloudflare to issue quantum-safe TLS certificatesโ–ผCloudflare plans to issue quantum-safe # TLS # certificates # Cloudflare said Tuesday it plans to issue quantum-proof TLMmastodonSciencePhysics23 d ago

    Cloudflare said Tuesday it plans to issue quantum-proof TLS certificates, positioning itself among the first certificate authorities to adopt cryptography designed to withstand attacks from future quantum computers. The move is seen as an early step toward protecting encrypted web traffic from 'harvest now, decrypt later' threats, and security watchers are weighing how quickly the wider industry will follow suit.

  10. 10
    wolfSSL introduces wolfCert for embedded device certificate enrollmentโ—Introduction to wolfCert: Certificate Enrollment for Embedded Devices https://www. wolfssl.com/introduction-to-wo lfcertMmastodonBusinessCrypto01 d ago

    wolfSSL has introduced wolfCert, a new tool for certificate enrollment on embedded devices. The announcement outlines how the component supports enrolling and managing certificates in constrained, resource-limited environments, complementing the company's existing TLS and cryptography offerings. The release is being circulated among security and embedded systems developers tracking certificate management options for IoT and embedded deployments.

  11. 11
    Critical 10/10 vulnerability flagged in vm2 sandbox libraryโ—๐Ÿšจ EUVD-2026-81591 ๐Ÿ“Š Score: 10.0/10 (CVSS v3.1) ๐Ÿ“ฆ Product: vm2 ๐Ÿข Vendor: patriksimek ๐Ÿ“… Updated: 2026-10-01 ๐Ÿ“ vm2 NodeVM cMmastodonTechnologyCybersecurity05 d ago

    A maximum-severity security flaw, tracked as EUVD-2026-81591, has been disclosed in vm2, the Node.js sandbox library maintained by Patrik Simek. The vulnerability, rated 10.0 out of 10 under CVSS v3.1, allows the NodeVM component to replace the host process TLS trust store, potentially undermining certificate validation. The advisory was updated on 1 October 2026 and appears in the EU vulnerability database.

  12. 12
    Cloudflare to issue quantum-safe TLS certificatesโ—Cloudflare plans to issue quantum-safe TLS certificates The move will be part of a major overhaul of the ecosystem for wMmastodonTechnologyCybersecurity16 d ago

    Cloudflare has announced plans to issue quantum-safe TLS certificates as part of a major overhaul of the website authentication ecosystem. The move is aimed at protecting encrypted web traffic against future attacks by quantum computers, which could eventually break today's widely used cryptographic algorithms. Security watchers are highlighting it as a significant step toward post-quantum encryption across the web.

Repos