Hackers hijack ccTLDs to forge Google certificates
Attackers gained control of the main domain registries for Ghana (.gh), Sierra Leone (.sl), and American Samoa (.as), allowing them to manipulate DNS records and fraudulently obtain HTTPS certificates for Google and several other organizations. Google says its systems were not breached. Chrome responded by blocking the unauthorized certificates, and Google worked with certificate authorities to revoke them, but undiscovered certificates may still pose a risk.
- Attackers compromised three ccTLD registries' DNS records
- Fake TLS certificates issued for Google and other domains
- Google's systems and certificate authorities were not hacked
- Chrome blocked known unauthorized certificates
- Undetected certificates could still threaten affected sites
Sources covering this
How it unfolded
- Ars Technica Hackers obtain counterfeit TLS certificates for Google and other large services
- The Hacker News Attackers Hijack .gh, .sl, and .as Registries to Obtain Certificates for Google Domains
- The Register Attackers hijacked top-level domains, minted fake security certs for Google and other orgs
- BleepingComputer Hackers hijack Google domains after breaching ccTLD registries
- TechRadar Google says counterfeit TLS certificates of major services stolen by hackers
- Infosecurity Magazine Attackers Hijack Three ccTLDs to Obtain Google Certificates
- SecurityWeek Google Domains Impacted by Recent ccTLD Hijacks
In this story
More in Cybersecurity
Citrix patches NetScaler flaw enabling remote code execution
Citrix has released security updates to fix a critical vulnerability in NetScaler ADC and NetScaler Gateway that could allow remote code…
US and allies disrupt Chinese hacking tools targeting infrastructure
US authorities and international partners have seized domains and tools used by China's Integrity Technology Group to support…
AI-powered attacks target South Korean banks
A cyberattack campaign targeting South Korean financial institutions used AI-based tools to steal personal data, CrowdStrike reported.
Metasploit adds modules for recent and legacy vulnerabilities
The latest Metasploit update includes 12 new modules targeting a range of vulnerabilities, from newly identified flaws in AI and server…