Google said several of its domains were affected by a hijack of third-party ccTLDs, including .gh, .sl, and .as, which allowed attackers to alter DNS records and obtain unauthorized HTTPS certificates. The company blocked the certificates in Chrome, worked with CAs to revoke them, and urged domain owners to monitor Certificate Transparency logs and publish restrictive CAA records. #Google #.gh #.sl #.as
Keypoints
- Attackers hijacked third-party ccTLDs last week.
- The affected suffixes were .gh, .sl, and .as.
- DNS records were modified to obtain unauthorized HTTPS certificates.
- Google blocked the certificates in Chrome and helped revoke them.
- Domain owners are advised to monitor CT logs and use restrictive CAA records.
Read More: https://www.securityweek.com/google-domains-impacted-by-recent-cctld-domain-hijacks/