- Country: United States
Hackers obtain counterfeit TLS certificates for Google and other large services
Compromise of 3 domain registries allows hackers to walk off with unauthorized certs.
Compromise of 3 domain registries allows hackers to walk off with unauthorized certs.
CVE-2026-103921: TLS Certificate Validation Bypass in @graphql-tools/executor-legacy-ws Vulnerability ID: CVE-2026-103921 CVSS Score: 7.4 Published: 2026-10-05 A vulnerability in @graphql-tools/executor-legacy-ws prior to version 1.1.35 hardcodes the TLS rejectUnauthorized setting to false for…
If you still renew TLS certificates by hand from a calendar reminder, the next three years will be rough. The CA/Browser Forum approved Ballot SC-081v3 in April 2025, and the maximum lifetime of publicly trusted certificates is being cut in stages. The schedule From Maximum validity 15 March 2026…