← All stories
● Covered by 1 source · 1 reportMedium impact1 negative

Attackers hijacked TLDs to mint counterfeit TLS certificates for Google and other services

🔄 Updated 1h ago
New to BrevFeed? We gather this story from every outlet covering it into one summary — ranked by real-world impact, not just the latest headline — so you never miss what matters. What is BrevFeed? →

Key points

  • Attackers hijacked .gh, .sl, and .as ccTLDs.
  • Unauthorized TLS certificates were minted for Google and other services.
  • Google updated Chrome to block identified unauthorized certificates.
  • Domain owners are advised to monitor certificate transparency logs.

TLD Hijack and Certificate Forgery

Attackers gained control over the .gh, .sl, and .as country code top-level domains (ccTLDs). This control allowed them to alter authoritative DNS records for specific domains within these namespaces. By manipulating these DNS records, the attackers bypassed automated domain control validation checks, leading to the issuance of counterfeit TLS certificates.

Impact on Google and Other Services

The unauthorized certificates were obtained for "several Google domains" and "several leading global brands and widely used online services." Possession of these counterfeit certificates enables attackers to cryptographically impersonate the legitimate infrastructure, potentially compromising user trust and security. Google did not specify which of its domains or other organizations were affected.

Google's Response and User Protection

Google responded by updating its Chrome browser to block all certificates identified as unauthorized. The company also collaborated with the issuing certification authorities to ensure the revocation of these fraudulent certificates for Google properties. Chrome users do not need to take any action to be protected by these updates.

Recommendations for Domain Owners

Google advises domain owners not to rely solely on browser-side interventions for protection. Instead, domain owners should actively monitor certificate transparency logs for any unexpected certificate issuances across their domains. Additionally, publishing restrictive Certification Authority Authorization (CAA) DNS records can prevent attackers from reusing cached validation data after DNS control is re-established.

✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →

The daily brief

One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.

One email a day. Unsubscribe in one click, any time.

Today's brief

Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.

~4 min · 3 stories · Oct 06

▶ Play today's brief Listen on Spotify

New every morning, and the back catalogue is archived by date.

Reporting from

Attackers compromised three country code top-level domains (.gh, .sl, .as) to modify DNS records and obtain unauthorized TLS certificates for Google and other major online services. This allowed them to impersonate affected infrastructure, prompting Google to update Chrome to block these certificates and advise domain owners on preventative measures.