Urgent.News

What's breaking now, across thousands of outlets.

Tech

Attackers hijacked top-level domains, minted fake security certs for Google and other orgs

Trusted brand impersonation without the usual browser certificate warnings spells trouble

Attackers hijacked top-level domains, minted fake security certs for Google and other orgs

Hackers have seized control of key internet addresses, creating fake security certificates for major companies like Google and others. By manipulating DNS records, they minted fraudulent HTTPS certificates for domains belonging to Google and other organizations in the .gh (Ghana), .sl (Sierra Leone), and .as (American Samoa) country-code top-level namespaces (ccTLDs).

Google detected the attacks last week and warned of the hijacks, stating that the certificates were obtained without authorization. The fraudulent certs did not compromise Google's systems directly. However, they allow attackers to impersonate legitimate sites, potentially intercepting or modifying data sent by users and distributing malware or phishing schemes.

Google acknowledged that browser interventions, such as Chrome blocking suspected counterfeit certificates, are necessary but not foolproof for protecting users across all devices. To safeguard their domains, Google advises organizations to monitor Certificate Transparency logs for any suspicious certificates issued for their domains.

They also suggest using restrictive Certification Authority Authorization records to control which Certificate Authorities can issue certificates for their domains, helping protect domains once DNS control is restored.

Written by urgent.news from The Register's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

This story

This is one outlet's version. Read the fullest account.

Read the original at theregister.com →

More in Tech

My git changelog showed every pull request twice — a commit range isn't a change list

Last release cycle I generated notes for our own service the naive way: git log v0.9.0..v0.10.0 , format the subjects, done. The output listed 12 commits. We had merged 6 pull requests.

  • Git log command generated 12 commit subjects during release cycle
  • Merge PRs appeared twice due to merge-commit repository behavior
  • First-parent-with-boundaries logic implemented in Git Changelog Generator

More from Wednesday 7 October →