Google Domains Impacted by Recent ccTLD Hijacks

Refract AI Intelligence Digest

BLUF

Compromised ccTLDs allowed attackers to forge valid SSL certificates for Google properties.

NEWS

Security researchers reported that hackers hijacked control of the .gh, .sl, and .as country-code top-level domains. Using this access, they successfully obtained trusted HTTPS certificates for multiple Google-owned domains through certificate authorities.

Why I Care

This undermines trust in SSL/TLS encryption and could allow attackers to intercept traffic or host convincing phishing sites that browsers will not flag as insecure. Any organization relying on Google services or monitoring certificate transparency logs needs to be aware of potential spoofing risks.

Next Steps

Domain administrators should monitor Certificate Transparency logs for unauthorized issuances immediately. Security teams must review their domain management policies and consider implementing stricter controls like DNSSEC and CAA records by the end of this quarter.

Hackers hijacked the .gh, .sl, and .as ccTLDs and obtained HTTPS certificates for several Google domains. The post Google Domains Impacted by Recent ccTLD Hijacks appeared first on SecurityWeek.
Back to Blog Listing

Source: Security Week ·

This digest was generated by Refract AI Collective to help the public sector security community stay informed.