{"id":41766,"date":"2025-09-05T02:24:43","date_gmt":"2025-09-04T23:24:43","guid":{"rendered":"https:\/\/digitrendz.blog\/?p=41766"},"modified":"2025-09-05T02:24:47","modified_gmt":"2025-09-04T23:24:47","slug":"rising-threat-more-1-1-1-1-certificates-mis-issued","status":"publish","type":"post","link":"https:\/\/digitrendz.blog\/z\/newswire\/technology\/41766\/rising-threat-more-1-1-1-1-certificates-mis-issued\/","title":{"rendered":"Rising Threat: More 1.1.1.1 Certificates Mis-Issued"},"content":{"rendered":"<details class=\"wp-block-details ticss-586932b6 is-layout-flow wp-block-details-is-layout-flow\"><summary>\u25bc Summary<\/summary>\n<p class=\"ticss-0c48f427 has-small-font-size wp-block-paragraph\">&#8211; Three mis-issued TLS certificates for Cloudflare&#8217;s 1.1.1.1 service were discovered, raising concerns about potential decryption of encrypted DNS queries.<br>&#8211; An audit revealed that Fina CA mis-issued a total of 12 certificates, nine more than initially known, all of which have been revoked.<br>&#8211; Cloudflare stated there is no evidence that any of the certificates were used maliciously to impersonate its services.<br>&#8211; Fina CA claimed the certificates were issued for internal testing due to an error in IP address entry and were published as part of standard procedure.<br>&#8211; Cloudflare acknowledged it should have detected the mis-issuances earlier through Certificate Transparency, which it helps administer.<br><\/p>\n<\/details>\n\n<p class=\"wp-block-paragraph\"><\/p>\n\n<p class=\"has-drop-cap wp-block-paragraph\"><mark style=\"background-color:rgba(0, 0, 0, 0);color:#f34c3e\" class=\"has-inline-color\">T<\/mark>he recent discovery of <strong>mis-issued <a href=\"https:\/\/digitrendz.blog\/z\/newswire\/technology\/41122\/1-1-1-1-dns-mis-issued-certificates-threaten-internet-security\/\" class=\"acp-article-link\" data-article-id=\"41122\" title=\"1.1.1.1 DNS Mis-issued Certificates Threaten Internet Security\" target=\"_blank\" rel=\"noopener noreferrer\">TLS certificates<\/a><\/strong> for <a href=\"https:\/\/digitrendz.blog\/z\/entity\/cloudflare\/\" class=\"acp-entity-link\" data-entity-id=\"5730\" data-entity-category=\"Organization\" title=\"Learn more about Cloudflare\" target=\"_blank\" rel=\"noopener noreferrer\">Cloudflare<\/a>\u2019s widely used 1.1.1.1 encrypted <a href=\"https:\/\/digitrendz.blog\/z\/entity\/dns\/\" class=\"acp-entity-link\" data-entity-id=\"23252\" data-entity-category=\"Technology\" title=\"Learn more about DNS\" target=\"_blank\" rel=\"noopener noreferrer\">DNS<\/a> service has sent ripples through the cybersecurity community. Security experts are alarmed by the possibility that unauthorized parties could have gained the ability to intercept and manipulate encrypted DNS traffic, potentially redirecting users to harmful websites or eavesdropping on their queries. This incident underscores the critical importance of robust certificate management and oversight in maintaining trust across the internet.<\/p>\n\n<p class=\"wp-block-paragraph\">Since the initial report, further investigation has revealed that the scope of the problem is larger than first thought. <strong>Cloudflare has confirmed<\/strong> that a total of twelve certificates were improperly issued by <a href=\"https:\/\/digitrendz.blog\/z\/entity\/fina-ca\/\" class=\"acp-entity-link\" data-entity-id=\"100802\" data-entity-category=\"Organization\" title=\"Learn more about Fina CA\" target=\"_blank\" rel=\"noopener noreferrer\">Fina CA<\/a>, a <a href=\"https:\/\/digitrendz.blog\/z\/entity\/microsoft\/\" class=\"acp-entity-link\" data-entity-id=\"251\" data-entity-category=\"Organization\" title=\"Learn more about Microsoft\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft<\/a>-trusted <a href=\"https:\/\/digitrendz.blog\/z\/topic\/certificate-authority\/\" class=\"acp-topic-link\" data-topic-id=\"80028\" title=\"Explore: certificate authority\" target=\"_blank\" rel=\"noopener noreferrer\">certificate authority<\/a>, with nine of those certificates having been issued since February of this year. All of these certificates have now been revoked, though the company states there is no evidence they were used maliciously in any attack or impersonation attempt.<\/p>\n\n<p class=\"wp-block-paragraph\">Cloudflare acknowledged that its own monitoring systems, including participation in the <a href=\"https:\/\/digitrendz.blog\/z\/topic\/certificate-transparency\/\" class=\"acp-topic-link\" data-topic-id=\"80034\" title=\"Explore: certificate transparency\" target=\"_blank\" rel=\"noopener noreferrer\">Certificate Transparency<\/a> framework, should have detected these irregularities sooner. The company helps administer this very system, which is designed to provide public oversight of certificate issuance and prevent exactly this kind of error or misuse.<\/p>\n\n<p class=\"wp-block-paragraph\">For its part, Fina CA provided a brief explanation, stating that the certificates were generated during <a href=\"https:\/\/digitrendz.blog\/z\/topic\/internal-testing\/\" class=\"acp-topic-link\" data-topic-id=\"80033\" title=\"Explore: internal testing\" target=\"_blank\" rel=\"noopener noreferrer\">internal testing<\/a> of its production certificate issuance process. According to the CA, the mis-issuance resulted from an error in entering IP addresses. The certificates were published to public Certificate Transparency logs as part of standard procedure, which is how they eventually came to light.<\/p>\n\n<p class=\"wp-block-paragraph\"><em>(Source: <a href=\"https:\/\/arstechnica.com\/information-technology\/2025\/09\/the-number-of-mis-issued-1-1-1-1-certificates-grows-heres-the-latest\/\" target=\"_blank\">Ars Technica<\/a>)<\/em><\/p>","protected":false},"excerpt":{"rendered":"<p>Mis-issued TLS certificates for Cloudflare&#8217;s 1.1.1.1 service raised security concerns, potentially allowing interception and manipulation of encrypted DNS traffic. Cloudflare confirmed twelve certificates were improperly issued by Fina CA, all now revoked with no evidence of malicious use. The er&#8230;<\/p>\n","protected":false},"author":1,"featured_media":41765,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_themeisle_gutenberg_block_has_review":false,"cybocfi_hide_featured_image":"","footnotes":""},"categories":[6579,3297,3327,3254],"tags":[65520,65518,64171,65519,64172],"entities":[3844,16065,60689,65522,24209,904,4020,26195,3565,60340],"class_list":["post-41766","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-bigtech-companies","category-cybersecurity","category-newswire","category-technology","tag-certificate-transparency","tag-cloudflare-1-1-1-1","tag-dns-security","tag-mis-issued-certificates","tag-tls-certificates","entity-cloudflare","entity-dns","entity-february-2024","entity-fina-ca","entity-https-2","entity-microsoft","entity-thursday","entity-tls","entity-wednesday","entity-wednesday-morning"],"_links":{"self":[{"href":"https:\/\/digitrendz.blog\/z\/wp-json\/wp\/v2\/posts\/41766","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/digitrendz.blog\/z\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/digitrendz.blog\/z\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/digitrendz.blog\/z\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/digitrendz.blog\/z\/wp-json\/wp\/v2\/comments?post=41766"}],"version-history":[{"count":0,"href":"https:\/\/digitrendz.blog\/z\/wp-json\/wp\/v2\/posts\/41766\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/digitrendz.blog\/z\/wp-json\/wp\/v2\/media\/41765"}],"wp:attachment":[{"href":"https:\/\/digitrendz.blog\/z\/wp-json\/wp\/v2\/media?parent=41766"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/digitrendz.blog\/z\/wp-json\/wp\/v2\/categories?post=41766"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/digitrendz.blog\/z\/wp-json\/wp\/v2\/tags?post=41766"},{"taxonomy":"entity","embeddable":true,"href":"https:\/\/digitrendz.blog\/z\/wp-json\/wp\/v2\/entities?post=41766"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}