Security

Attackers compromise three country-code domain registries and obtain unauthorized certificates for Google domains

Attackers compromised country-code domain registries and obtained unauthorized HTTPS certificates for Google domains. Google said its own systems were not breached, while the affected domains and potential risk are described in the reporting.

Image: Ars Technica

Why it matters

Unauthorized certificates and control of affected domains could enable trusted impersonation without the usual browser certificate warnings.

What we know

Confirmed by several sources

Reported by one source

  • Google said its own systems were not breached. — The Hacker News
  • The unauthorized certificates could enable brand impersonation without the usual browser certificate warnings. — The Register

Coverage 5 publishers

  1. Ars Technica

    Hackers obtain counterfeit TLS certificates for Google and other large services

  2. BleepingComputer

    Hackers hijack Google domains after breaching ccTLD registries

  3. The Register

    Attackers hijacked top-level domains, minted fake security certs for Google and other orgs

  4. The Hacker News

    Attackers Hijack .gh, .sl, and .as Registries to Obtain Certificates for Google Domains

  5. Hacker News

    Hackers obtain counterfeit TLS certificates for Google and other large services

Articles stay on their publishers’ sites; each link opens the original.