Last updated: October 8, 2026 at 8:36 AM UTC
All 909 Vulnerability 368 Breach 144 Threat 390 Defense 7
Tag: certificate-transparency (1 article)Clear

Attackers hijack .gh, .sl, and .as registries to obtain fraudulent TLS certificates for Google domains

Google disclosed that attackers hijacked the .gh, .sl, and .as country-code registries and changed authoritative DNS records to pass domain-validation checks, obtaining at least twelve TLS certificates for seven Google-owned names including google.com.gh, google.sl, and google.as. Let's Encrypt issued eleven and ZeroSSL one, all logged between September 22 and 27 and since revoked, and Chrome also blocked them through CRLSets. Such certificates let an attacker impersonate the real sites, though Google has not confirmed any misuse and says its own systems were not breached. Google advises domain owners to monitor certificate transparency logs and publish strict CAA records tied to their certificate authority.

Check
Monitor certificate transparency logs for all owned domains, including parked and country-code names, and publish strict CAA records that name only your certificate authority.
Affected
Organizations with domains under the hijacked .gh, .sl, and .as registries could have had domain-validated certificates issued to attackers able to impersonate their sites.
Fix
Watch certificate transparency logs, publish strict CAA records tied to your certificate authority account, and report any unrequested certificates to the issuing authority through a certificate problem report.