Attackers hijacked three ccTLDs and used the access to obtain unauthorized HTTPS certificates for Google and YouTube domains under .gh, .sl, and .as, creating a risk of impersonation over encrypted connections. Google said its own systems were not breached, Chrome blocked the certificates, and the company urged domain owners to monitor Certificate Transparency logs and enforce strict CAA records. #Google #YouTube #LetβsEncrypt #ZeroSSL #.gh #.sl #.as
Keypoints
- Attackers compromised three ccTLDs: .gh, .sl, and .as.
- Unauthorized HTTPS certificates were issued for Google and YouTube domains.
- Googleβs own systems were not breached.
- Chrome blocked the certificates using CRLSets.
- Google advised CT log monitoring and strict CAA records.
Read More: https://thehackernews.com/2026/10/attackers-hijack-gh-sl-and-as.html