Attackers gained control over the .gh, .sl, and .as country code top-level domains (ccTLDs). This control allowed them to alter authoritative DNS records for specific domains within these namespaces. By manipulating these DNS records, the attackers bypassed automated domain control validation checks, leading to the issuance of counterfeit TLS certificates.
The unauthorized certificates were obtained for "several Google domains" and "several leading global brands and widely used online services." Possession of these counterfeit certificates enables attackers to cryptographically impersonate the legitimate infrastructure, potentially compromising user trust and security. Google did not specify which of its domains or other organizations were affected.
Google responded by updating its Chrome browser to block all certificates identified as unauthorized. The company also collaborated with the issuing certification authorities to ensure the revocation of these fraudulent certificates for Google properties. Chrome users do not need to take any action to be protected by these updates.
Google advises domain owners not to rely solely on browser-side interventions for protection. Instead, domain owners should actively monitor certificate transparency logs for any unexpected certificate issuances across their domains. Additionally, publishing restrictive Certification Authority Authorization (CAA) DNS records can prevent attackers from reusing cached validation data after DNS control is re-established.
✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →
One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.
One email a day. Unsubscribe in one click, any time.
Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.
▶ Play today's briefNew every morning, and the back catalogue is archived by date.
Attackers compromised three country code top-level domains (.gh, .sl, .as) to modify DNS records and obtain unauthorized TLS certificates for Google and other major online services. This allowed them to impersonate affected infrastructure, prompting Google to update Chrome to block these certificates and advise domain owners on preventative measures.