Unauthorized Certificate Issuance via Hijacked .gh, .sl, and .as Domains Targeting Google Services
Attackers hijacked .gh, .sl, and .as domain registries to obtain unauthorized HTTPS certificates for Google domains, enabling potential man-in-the-middle attacks. Google blocked the certificates via CRLSets, collaborated with CAs to revoke them, and advised domain owners to monitor Certificate Transparency logs and enforce strict CAA records.
Attackers compromised three country-code top-level domains (ccTLDs) and obtained unauthorized HTTPS certificates for several Google domains, Google said on October 6.
Google's own systems were not breached, but any domain ending in .gh (Ghana), .sl (Sierra Leone) or .as (American Samoa) was put at risk. With such a certificate, an attacker could pose as the real site over an encrypted
*** END OF TRANSMISSION ***