Multiple news sites are pointing to this article that explains clearly how to break SHA1:
https://sites.google.com/site/itstheshappening/
“Our recommendations: We recommend that SHA-1 based signatures should be marked as unsafe much sooner than prescribed by current international policy”
SHA1 is still used in many firmware technologies.
