Google Domains Impacted by Recent ccTLD Hijacks
BLUF
Compromised ccTLDs allowed attackers to forge valid SSL certificates for Google properties.
NEWS
Security researchers reported that hackers hijacked control of the .gh, .sl, and .as country-code top-level domains. Using this access, they successfully obtained trusted HTTPS certificates for multiple Google-owned domains through certificate authorities.
Why I Care
This undermines trust in SSL/TLS encryption and could allow attackers to intercept traffic or host convincing phishing sites that browsers will not flag as insecure. Any organization relying on Google services or monitoring certificate transparency logs needs to be aware of potential spoofing risks.
Next Steps
Domain administrators should monitor Certificate Transparency logs for unauthorized issuances immediately. Security teams must review their domain management policies and consider implementing stricter controls like DNSSEC and CAA records by the end of this quarter.
Source: Security Week ·