{"ok":true,"trend":{"id":1324529,"platform":"hn","region":"global","key":"hackers obtain counterfeit tls certificates for google and other large services","title":"Hackers obtain counterfeit TLS certificates for Google and other large services","url":"https://arstechnica.com/security/2026/10/hackers-obtain-counterfeit-tls-certificates-for-google-and-other-large-services/","first_seen":"2026-10-07T05:50:39.911288Z","last_seen":"2026-10-07T11:50:39.694802Z","last_rank":16,"peak_rank":16,"last_volume":96,"peak_volume":96,"seen_count":25,"score":64.75,"category_hint":null,"section":null,"category":null,"summary":"Security researchers report that hackers have obtained fraudulent TLS certificates impersonating Google and other major online services. Such certificates could allow attackers to intercept traffic or serve fake versions of trusted sites without browser warnings. The incident raises fresh questions about weaknesses in the certificate authority system that underpins HTTPS trust across the web.","why":"Trust in HTTPS depends on certificate authorities, so counterfeit certificates for Google undermine core web security and worry users and security professionals.","tone":"negative","entities":["Google","certificate authorities","TLS"],"summarized_at":"2026-10-07T05:52:47.040363Z","meta":{"lang":"en","link":"https://arstechnica.com/security/2026/10/hackers-obtain-counterfeit-tls-certificates-for-google-and-other-large-services/","hn_id":"49988230","comments":28},"nw":null,"promo":null,"kind":null,"importance":null,"hidden":false,"hide_reason":null,"judged_at":null,"title_en":"Hackers obtain counterfeit TLS certificates for major web services","timeline":[{"captured_at":"2026-10-07T05:50:39.911288Z","rank":29,"volume":9},{"captured_at":"2026-10-07T06:05:39.727001Z","rank":27,"volume":13},{"captured_at":"2026-10-07T06:20:39.750398Z","rank":26,"volume":20},{"captured_at":"2026-10-07T06:35:39.999082Z","rank":25,"volume":24},{"captured_at":"2026-10-07T06:50:39.899812Z","rank":22,"volume":28},{"captured_at":"2026-10-07T07:05:39.713089Z","rank":22,"volume":34},{"captured_at":"2026-10-07T07:20:39.781830Z","rank":22,"volume":36},{"captured_at":"2026-10-07T07:35:39.756352Z","rank":22,"volume":38},{"captured_at":"2026-10-07T07:50:39.749328Z","rank":21,"volume":42},{"captured_at":"2026-10-07T08:05:39.714610Z","rank":21,"volume":45},{"captured_at":"2026-10-07T08:20:39.724170Z","rank":20,"volume":49},{"captured_at":"2026-10-07T08:35:39.705767Z","rank":19,"volume":54},{"captured_at":"2026-10-07T08:50:39.732733Z","rank":19,"volume":56},{"captured_at":"2026-10-07T09:05:39.893869Z","rank":19,"volume":59},{"captured_at":"2026-10-07T09:20:39.769282Z","rank":19,"volume":62},{"captured_at":"2026-10-07T09:35:39.714349Z","rank":19,"volume":65},{"captured_at":"2026-10-07T09:50:39.894568Z","rank":18,"volume":67},{"captured_at":"2026-10-07T10:05:39.864141Z","rank":18,"volume":70},{"captured_at":"2026-10-07T10:20:39.769484Z","rank":18,"volume":72},{"captured_at":"2026-10-07T10:35:39.787015Z","rank":18,"volume":76},{"captured_at":"2026-10-07T10:50:39.725676Z","rank":18,"volume":79},{"captured_at":"2026-10-07T11:05:39.834231Z","rank":18,"volume":85},{"captured_at":"2026-10-07T11:20:39.705041Z","rank":16,"volume":88},{"captured_at":"2026-10-07T11:35:39.916767Z","rank":18,"volume":93},{"captured_at":"2026-10-07T11:50:39.694802Z","rank":16,"volume":96}],"posts":[{"platform":"hn","url":"https://news.ycombinator.com/item?id=49988230","author":"colinprince","title":"Hackers obtain counterfeit TLS certificates for Google and other large services","snippet":null,"posted_at":"2026-10-07T04:37:05Z","likes":96}],"elsewhere":[{"id":1286836,"platform":"mastodon","region":"global","title":"Hackers obtain counterfeit TLS certificates for Google and other large services","last_rank":12,"last_seen":"2026-10-07T11:50:42.490679Z","summary":"Hackers have obtained unauthorized TLS certificates for Google and other major services after compromising three domain registries, security outlet Ars Technica reports. The forged certificates could let attackers impersonate trusted websites and intercept traffic. The incident has drawn attention across technical communities, with discussion focusing on how the registry compromise was possible and what it means for the certificate authority system."}],"window":"7d"}}