Urgent.News

What's breaking now, across thousands of outlets.

Tech

Attackers hijacked top-level domains, minted fake security certs for Google and other orgs

Trusted brand impersonation without the usual browser certificate warnings spells trouble

Attackers hijacked top-level domains, minted fake security certs for Google and other orgs

Hackers have taken control of key website addresses, creating fake versions of Google and other well-known sites. Attackers manipulated the internet's domain name system (DNS) records and created fake security certificates for several Google domains and those of other organizations. The attacks occurred in the .gh (Ghana), .sl (Sierra Leone), and .as (American Samoa) country-code top-level domains. Google was alerted to the incidents last week.

During the hijacks, the cybercriminals altered the authoritative DNS records and obtained unauthorized HTTPS certificates covering Google domains and domains of other organizations. However, Google's systems remained unaffected, and Chrome swiftly blocked suspected counterfeit certificates for the affected ccTLDs, ensuring protection for Chrome users.

The attackers can now impersonate legitimate organizations and websites without triggering browser security alerts, enabling them to intercept or modify data sent by users to the impersonated sites. This could allow them to distribute malware or launch phishing attacks, abusing the trusted organization's brand.

Google advises domain owners to monitor Certificate Transparency (CT) logs for their domains, including parked or regional ccTLD properties, to identify unauthorized certificates in near real-time. If an organization operates a domain in .gh, .sl, or .as, they should review recent CT log entries for any unexpected certificates. Additionally, organizations can publish restrictive Certification Authority Authorization (CAA) DNS records, limiting certificate issuance to specific authorized accounts and validation methods, preventing attackers from minting new certificates after a hijacking ends.

Written by urgent.news from The Register Science's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Also reported by 1 other outlet

Read the original at theregister.com →

More in Tech

My git changelog showed every pull request twice — a commit range isn't a change list

Last release cycle I generated notes for our own service the naive way: git log v0.9.0..v0.10.0 , format the subjects, done. The output listed 12 commits. We had merged 6 pull requests.

  • Git log command generated 12 commit subjects during release cycle
  • Merge PRs appeared twice due to merge-commit repository behavior
  • First-parent-with-boundaries logic implemented in Git Changelog Generator

More from Wednesday 7 October →