Researchers from CWI Amsterdam and Google reveal the first practical collision for SHA-1. The algorithm affirms the insecurity of the algorithm and reinforces our judgment that it must be retired from security use on the Web. The deprecation policy will reach all Firefox users tomorrow. It is enabled by default in Firefox 52. It will affect people accessing websites that have not yet migrated to SHA-2 certificates, well under 0.1% of Web traffic. Users should always make sure to update to the latest version of Firefox for the most-recent security updates and features.”]
Source: https://blog.mozilla.org/security/2017/02/23/the-end-of-sha-1-on-the-public-web/

