bleeping-computer · Crawled Oct 7, 2026
Hackers hijack Google domains after breaching ccTLD registries
Read original article ↗AI Summary
Hackers breached third-party operators managing country-code top-level domains (ccTLDs) for Ghana (.GH), Sierra Leone (.SL), and American Samoa (.AS), gaining control of authoritative DNS records. This allowed them to hijack domains and obtain unauthorized HTTPS certificates by passing domain ownership validation at Certificate Authorities. The attackers could then impersonate legitimate services and serve malicious content. Google detected the abuse through Certificate Transparency logs, blocked the rogue certificates in Chrome via CRLSets, and notified affected organizations, though it emphasized its own systems were not compromised.
AI-extracted · verify before operational use
No entities or IoCs were extracted from this article.