Hackers Obtain Counterfeit TLS Certificates for Google
Attackers hijacked three top-level domains and used their control to issue counterfeit TLS certificates for Google and other large organizations, Google announced Tuesday.

Attackers hijacked three top-level domains and used their control to issue counterfeit TLS certificates for Google and other large organizations, Google announced Tuesday.
The attackers targeted the .gh, .sl, and .as country code top-level domains (ccTLDs) and modified authoritative DNS records for selected domains. By controlling these DNS records, the attackers bypassed automated domain control validation checks, allowing them to obtain unauthorized certificates for "several Google domains" and "several leading global brands and widely used online services."
Google stated it has updated Chrome to block all identified unauthorized certificates and worked with issuing certification authorities to revoke certificates for Google properties. The compromised certificates could allow attackers to impersonate affected infrastructure cryptographically.
TLS certificates are cryptographic credentials essential for website authentication and encryption. The incident highlights a potential vulnerability in the domain control validation process used by certificate authorities.