Hackers seize control of three ccTLDs to forge fake TLS certificates for Google and others
Attackers compromised the.gh,.sl and.as country code domains, using the hijacked DNS records to obtain counterfeit TLS certificates for Google and several major online services.
A coordinated attack on the.gh,.sl and.as country code top-level domains allowed hackers to modify DNS entries for selected domains, enabling them to pass domain-control validation and acquire fake TLS certificates for several Google domains and other leading online services. Google announced that Chrome has been patched to reject all identified fraudulent certificates and that it has collaborated with the relevant certification authorities to revoke the illicit issuances.
The incident highlights the vulnerability of the TLS certificate chain, where possession of a valid-looking certificate can let attackers impersonate targeted sites. Google emphasized that users need not take any action, but domain owners should not rely solely on browser defenses. It recommended continuous monitoring of certificate-transparency logs and the deployment of restrictive Certification Authority Authorization (CAA) DNS records to prevent future misuse.
Why it matters
Fake TLS certificates can let attackers impersonate major websites, risking data theft and user trust.
In this story
