
Why it matters
Unauthorized certificates and control of affected domains could enable trusted impersonation without the usual browser certificate warnings.
What we know
Confirmed by several sources
- Attackers compromised three country-code top-level domain registries and obtained unauthorized HTTPS certificates for Google domains. — BleepingComputer, The Hacker News, Ars Technica
- The affected country-code domains were Ghana, American Samoa, and Sierra Leone. — BleepingComputer, The Hacker News
Reported by one source
- Google said its own systems were not breached. — The Hacker News
- The unauthorized certificates could enable brand impersonation without the usual browser certificate warnings. — The Register
Coverage 5 publishers
-
Hackers obtain counterfeit TLS certificates for Google and other large services
-
Hackers hijack Google domains after breaching ccTLD registries
-
Attackers hijacked top-level domains, minted fake security certs for Google and other orgs
-
Attackers Hijack .gh, .sl, and .as Registries to Obtain Certificates for Google Domains
-
Hackers obtain counterfeit TLS certificates for Google and other large services
Articles stay on their publishers’ sites; each link opens the original.