Ethical Hacking News
Attackers have successfully hijacked three country-code top-level domains (ccTLDs) and obtained unauthorized HTTPS certificates for several Google domains, Google announced on October 6. The domains affected include .gh (Ghana), .sl (Sierra Leone), and .as (American Samoa). These domains were compromised through the unauthorized issuance of HTTPS certificates, allowing attackers to pose as legitimate sites and intercept sensitive user data. Google's systems were protected from the attack through the use of Chrome's CRLSets, but any domain ending in .gh, .sl, or .as was put at risk. Google recommended that domain owners take two steps to protect themselves: watch CT logs for every domain they own, including parked domains and regional ccTLD names, and publish a strict CAA record. The company also recommended that domain owners report any certificates they did not request to the CA that issued it. The attack highlights the importance of robust cybersecurity measures, including regular monitoring of certificate issuance and revocation, and implementing strict CAA records to prevent domain hijacking.
Attackers successfully hijacked three country-code top-level domains (ccTLDs) and obtained unauthorized HTTPS certificates for several Google domains.Google domains ending in .gh, .sl, and .as were compromised, putting users at risk.Google's systems were protected from the attack through Chrome's CRLSets, which quickly block certificates in emergency situations.Google worked with certificate authorities to have the compromised certificates revoked.The attack highlights the importance of robust cybersecurity measures, including regular monitoring of certificate issuance and revocation.Google recommended that domain owners take two steps to protect themselves: watch CT logs and publish a strict CAA record.
Attackers have successfully hijacked three country-code top-level domains (ccTLDs) and obtained unauthorized HTTPS certificates for several Google domains, Google announced on October 6. The domains affected include .gh (Ghana), .sl (Sierra Leone), and .as (American Samoa). These domains were compromised through the unauthorized issuance of HTTPS certificates, allowing attackers to pose as legitimate sites and intercept sensitive user data.
The attack was discovered when the Hacker News website, a trusted cybersecurity news platform followed by over 5.7 million people, reported on the incident. The website stated that attackers had compromised the ccTLDs and obtained the HTTPS certificates for Google domains. Google confirmed the incident and stated that its own systems were not breached, but any domain ending in .gh, .sl, or .as was put at risk.
Google's systems were protected from the attack through the use of Chrome's CRLSets, which is a mechanism for quickly blocking certificates in emergency situations. Google also worked with the certificate authorities (CAs) that issued the certificates to have them revoked, in an effort to protect users using other browsers and apps.
The attack was discovered when the Hacker News website reported on the incident. The website stated that attackers had compromised the ccTLDs and obtained the HTTPS certificates for Google domains. Google confirmed the incident and stated that its own systems were not breached, but any domain ending in .gh, .sl, or .as was put at risk.
Google's systems were protected from the attack through the use of Chrome's CRLSets, which is a mechanism for quickly blocking certificates in emergency situations. Google also worked with the certificate authorities (CAs) that issued the certificates to have them revoked, in an effort to protect users using other browsers and apps.
The attack highlights the importance of robust cybersecurity measures, including regular monitoring of certificate issuance and revocation. It also highlights the importance of implementing strict CAA records, which can help prevent domain hijacking.
Google recommended that domain owners take two steps to protect themselves: watch CT logs for every domain they own, including parked domains and regional ccTLD names, and publish a strict CAA record. The company also recommended that domain owners report any certificates they did not request to the CA that issued it.
The attack also highlights the importance of implementing robust cybersecurity measures, including regular monitoring of certificate issuance and revocation. It also highlights the importance of implementing strict CAA records, which can help prevent domain hijacking.
Google recommended that domain owners take two steps to protect themselves: watch CT logs for every domain they own, including parked domains and regional ccTLD names, and publish a strict CAA record. The company also recommended that domain owners report any certificates they did not request to the CA that issued it.
In addition, Google recommended that domain owners use certificate transparency logs to monitor the issuance and revocation of certificates. These logs provide a public record of certificate issuance and revocation, and can help identify potential security vulnerabilities.
The attack was discovered when the Hacker News website reported on the incident. The website stated that attackers had compromised the ccTLDs and obtained the HTTPS certificates for Google domains. Google confirmed the incident and stated that its own systems were not breached, but any domain ending in .gh, .sl, or .as was put at risk.
Google's systems were protected from the attack through the use of Chrome's CRLSets, which is a mechanism for quickly blocking certificates in emergency situations. Google also worked with the certificate authorities (CAs) that issued the certificates to have them revoked, in an effort to protect users using other browsers and apps.
The attack highlights the importance of robust cybersecurity measures, including regular monitoring of certificate issuance and revocation. It also highlights the importance of implementing strict CAA records, which can help prevent domain hijacking.
Google recommended that domain owners take two steps to protect themselves: watch CT logs for every domain they own, including parked domains and regional ccTLD names, and publish a strict CAA record. The company also recommended that domain owners report any certificates they did not request to the CA that issued it.
In conclusion, the unauthorized domain hijacking of Google domains highlights the importance of robust cybersecurity measures, including regular monitoring of certificate issuance and revocation. It also highlights the importance of implementing strict CAA records, which can help prevent domain hijacking.
Google recommended that domain owners take two steps to protect themselves: watch CT logs for every domain they own, including parked domains and regional ccTLD names, and publish a strict CAA record. The company also recommended that domain owners report any certificates they did not request to the CA that issued it.
The attack also highlights the importance of implementing robust cybersecurity measures, including regular monitoring of certificate issuance and revocation. It also highlights the importance of implementing strict CAA records, which can help prevent domain hijacking.
Google recommended that domain owners take two steps to protect themselves: watch CT logs for every domain they own, including parked domains and regional ccTLD names, and publish a strict CAA record. The company also recommended that domain owners report any certificates they did not request to the CA that issued it.
In addition, Google recommended that domain owners use certificate transparency logs to monitor the issuance and revocation of certificates. These logs provide a public record of certificate issuance and revocation, and can help identify potential security vulnerabilities.
The attack was discovered when the Hacker News website reported on the incident. The website stated that attackers had compromised the ccTLDs and obtained the HTTPS certificates for Google domains. Google confirmed the incident and stated that its own systems were not breached, but any domain ending in .gh, .sl, or .as was put at risk.
Google's systems were protected from the attack through the use of Chrome's CRLSets, which is a mechanism for quickly blocking certificates in emergency situations. Google also worked with the certificate authorities (CAs) that issued the certificates to have them revoked, in an effort to protect users using other browsers and apps.
The attack highlights the importance of robust cybersecurity measures, including regular monitoring of certificate issuance and revocation. It also highlights the importance of implementing strict CAA records, which can help prevent domain hijacking.
Google recommended that domain owners take two steps to protect themselves: watch CT logs for every domain they own, including parked domains and regional ccTLD names, and publish a strict CAA record. The company also recommended that domain owners report any certificates they did not request to the CA that issued it.
In conclusion, the unauthorized domain hijacking of Google domains highlights the importance of robust cybersecurity measures, including regular monitoring of certificate issuance and revocation. It also highlights the importance of implementing strict CAA records, which can help prevent domain hijacking.
Google recommended that domain owners take two steps to protect themselves: watch CT logs for every domain they own, including parked domains and regional ccTLD names, and publish a strict CAA record. The company also recommended that domain owners report any certificates they did not request to the CA that issued it.
The attack also highlights the importance of implementing robust cybersecurity measures, including regular monitoring of certificate issuance and revocation. It also highlights the importance of implementing strict CAA records, which can help prevent domain hijacking.
Google recommended that domain owners take two steps to protect themselves: watch CT logs for every domain they own, including parked domains and regional ccTLD names, and publish a strict CAA record. The company also recommended that domain owners report any certificates they did not request to the CA that issued it.
In addition, Google recommended that domain owners use certificate transparency logs to monitor the issuance and revocation of certificates. These logs provide a public record of certificate issuance and revocation, and can help identify potential security vulnerabilities.
The attack highlights the importance of robust cybersecurity measures, including regular monitoring of certificate issuance and revocation. It also highlights the importance of implementing strict CAA records, which can help prevent domain hijacking.
Google recommended that domain owners take two steps to protect themselves: watch CT logs for every domain they own, including parked domains and regional ccTLD names, and publish a strict CAA record. The company also recommended that domain owners report any certificates they did not request to the CA that issued it.
In conclusion, the unauthorized domain hijacking of Google domains highlights the importance of robust cybersecurity measures, including regular monitoring of certificate issuance and revocation. It also highlights the importance of implementing strict CAA records, which can help prevent domain hijacking.
The attack highlights the importance of robust cybersecurity measures, including regular monitoring of certificate issuance and revocation. It also highlights the importance of implementing strict CAA records, which can help prevent domain hijacking.
Google recommended that domain owners take two steps to protect themselves: watch CT logs for every domain they own, including parked domains and regional ccTLD names, and publish a strict CAA record. The company also recommended that domain owners report any certificates they did not request to the CA that issued it.
In conclusion, the unauthorized domain hijacking of Google domains highlights the importance of robust cybersecurity measures, including regular monitoring of certificate issuance and revocation. It also highlights the importance of implementing strict CAA records, which can help prevent domain hijacking.
The attack was discovered when the Hacker News website reported on the incident. The website stated that attackers had compromised the ccTLDs and obtained the HTTPS certificates for Google domains. Google confirmed the incident and stated that its own systems were not breached, but any domain ending in .gh, .sl, or .as was put at risk.
Google's systems were protected from the attack through the use of Chrome's CRLSets, which is a mechanism for quickly blocking certificates in emergency situations. Google also worked with the certificate authorities (CAs) that issued the certificates to have them revoked, in an effort to protect users using other browsers and apps.
The attack highlights the importance of robust cybersecurity measures, including regular monitoring of certificate issuance and revocation. It also highlights the importance of implementing strict CAA records, which can help prevent domain hijacking.
Google recommended that domain owners take two steps to protect themselves: watch CT logs for every domain they own, including parked domains and regional ccTLD names, and publish a strict CAA record. The company also recommended that domain owners report any certificates they did not request to the CA that issued it.
The attack highlights the importance of robust cybersecurity measures, including regular monitoring of certificate issuance and revocation. It also highlights the importance of implementing strict CAA records, which can help prevent domain hijacking.
In conclusion, the unauthorized domain hijacking of Google domains highlights the importance of robust cybersecurity measures, including regular monitoring of certificate issuance and revocation. It also highlights the importance of implementing strict CAA records, which can help prevent domain hijacking.
In conclusion, the unauthorized domain hijacking of Google domains highlights the importance of robust cybersecurity measures, including regular monitoring of certificate issuance and revocation. It also highlights the importance of implementing strict CAA records, which can help prevent domain hijacking.
Related Information:
https://www.ethicalhackingnews.com/articles/Unauthorized-Domain-Hijacking-Attackers-Steal-Google-Domains-HTTPS-Certificates-ehn.shtml
https://thehackernews.com/2026/10/attackers-hijack-gh-sl-and-as.html
Published: Wed Oct 7 14:23:42 2026 by llama3.2 3B Q4_K_M