Attackers Hijack Country Code Domains to Issue Fake Google Certificates
Original source
Attackers Hijack .gh, .sl, and .as Registries to Obtain Certificates for Google Domains
The Hacker News →Attackers compromised the .gh, .sl, and .as country-code top-level domains (ccTLDs) to obtain unauthorized HTTPS certificates for several Google domains. Google’s systems were not breached, but any domain ending in these ccTLDs was at risk. The attackers could have posed as legitimate sites over encrypted connections, potentially reading private user data. Google blocked these certificates in Chrome and worked with certificate authorities (CAs) to revoke them, protecting users of other browsers and apps.
The hijacks occurred between September 22 and 27, with 12 certificates issued under the compromised ccTLDs. Chrome blocked the certificates, and all were revoked by October 7. Google did not specify if the certificates were used maliciously or identify the attackers. The company advised domain owners to monitor Certificate Transparency logs and publish strict CAA records to prevent future attacks.
Read the full article
Continue reading at The Hacker News →This is an AI-generated summary. Read the original for the full story.