Wasn't one of the certificates used using SHA-1 (the other two were MD5) - could it be that this new cryptographic attack works not only against MD5 but also SHA-1 ?
"We have developed a forensic tool for collision attacks [7] that can efficiently detect a wide range of known and unknown collision attacks against MD5 as well as MD5's successor SHA-1."