Attackers hijacked three top-level domains and used their control to mint counterfeit TLS certificates for Google and other large organizations, as first reported by Ars Technica.
The attackers gained control of the .gh, .sl, and .as country code top-level domains (ccTLDs) and altered DNS records. This allowed them to intercept traffic and issue unauthorized TLS certificates for several Google domains and other major global brands. Google stated that it has updated Chrome to block these counterfeit certificates and collaborated with other certificate authorities to ensure broader browser protection. TLS certificates are crucial for website authentication and encryption, binding an identity to a public key. Unauthorized certificates enable attackers to impersonate legitimate infrastructure. While Google has blocked known counterfeit certificates, it cautioned that undiscovered ones could still pose a threat. This incident did not involve compromising the domain owners' or DNS operators' infrastructure but rather exploiting the certificate issuance process. This is not the first time counterfeit certificates have been issued; a similar incident occurred in 2011 with DigiNotar, highlighting ongoing vulnerabilities in certificate authorities and domain management.
Source: Ars Technica
