Updated: Google warns of unauthorized TLS certificates trusted by almost all OSes | Ars Technica
ID: 8c1e575f-2458-5699-a84c-ec57aba3e3da
STIX ID: report--8c1e575f-2458-5699-a84c-ec57aba3e3da
Feed Name: Security Ledger
Threat Score
Google disclosed that unauthorized digital certificates for multiple Google domains were issued by an intermediate CA held by MCS Holdings and rooted at CNNIC. Because CNNIC is included in major root stores, those certificates would be trusted by most browsers and OSes and could be used to impersonate sites or perform man-in-the-middle interception; Google blocked the intermediate in Chrome and reported no confirmed abuse at the time.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
