Google Domains Impacted by Recent ccTLD Hijacks
Google has disclosed that several of its domains were affected by a recent hijack of third-party country-code top-level domains (ccTLDs).
The incident occurred last week and targeted the .gh (Ghana), .sl (Sierra Leone), and .as (American Samoa) ccTLDs, putting all domains with those suffixes at risk.
“During these hijacks, attackers modified authoritative DNS records and obtained unauthorized HTTPS certificates covering several Google domains, as well as domains belonging to other organizations,” the internet giant says.
According to Google, the Certification Authorities (CAs) that issued the certificates are not to be blamed, given the nature of the attacks.
Immediately after learning of the incident, Google blocked the unauthorized certificates for its domains in Chrome and worked with the issuing CAs to revoke them.
Analysis of Certificate Transparency (CT) log data revealed that multiple other organizations, including global brands and popular online services, have been affected.
Advertisement. Scroll to continue reading.
...
Copyright of this story solely belongs to www.securityweek.com. To see the full text click HERE