WORLDTECH NEWS Global technology intelligence.Contact
← Back to WORLDTECH
Cybersecurity SINGLE SOURCE

Hackers obtain counterfeit TLS certificates for Google and other large services

Small padlock on a network cable at a patch panelAI illustration
WORLDTECH illustration · AI-generated (Canva)Google logo shown for identification only; no affiliation with or endorsement of WORLDTECH is implied.

What happened

The attackers launched a series of attacks on the .gh, .sl, and .as country code top-level domains (ccTLDs) and then modified authoritative DNS (the system that turns a domain name into an address) records for selected domains within those namespaces. Google said it updated Chrome to block all certificates it identified as unauthorized, and worked with the issuing certification authorities to ensure the unauthorized certificates for Google properties were revoked. Google is an Internet and software company based in Mountain View.

Compromise of 3 domain registries allows hackers to walk off with unauthorized certs. Attackers hijacked three top-level domains and used their control to mint counterfeit TLS (the encryption that secures a connection to a website) certificates for Google and other large organizations, Google said Tuesday. These x.509 certificates use a digital signature to bind a domain name such as google.com to a public key.

Sources & evidence