Cyber Security News

Attackers Hijack .gh, .sl, and .as Domains to Obtain Unauthorized SSL Certificates

Attackers compromised the infrastructure of third-party country-code top-level domains (ccTLDs) for Ghana (.gh), Sierra Leone (.sl), and American Samoa (.as).

They modified authoritative DNS records to obtain unauthorized HTTPS certificates for Google domains and other organizations.

Attackers Hijack Domains

In a disclosure on October 6, 2026, Chrome’s Secure Web and Networking Team stated that these incidents did not involve a breach of Google’s systems. Instead, the attackers targeted the affected ccTLD namespaces, which put any domain using those suffixes at risk.

Google promptly blocked the unauthorized certificates for its properties in Chrome and coordinated with issuing certification authorities to revoke them. Further analysis revealed certificates linked to additional organizations, prompting broader protective measures on the browser.

The attacks exploited the relationship between DNS control and certificate issuance. Certification authorities typically verify that applicants control a requested domain before issuing certificates.

Depending on the validation method, proving control may involve publishing a specific DNS record. Consequently, an attacker controlling authoritative DNS can falsely appear to fulfill domain validation requirements without authorization from the legitimate owner.

Google emphasized that it had no reason to believe that the certification authorities issuing the affected certificates acted improperly. Instead, the disclosure identified compromised DNS infrastructure as the root cause of the trust failure.

The incident report does not specify the attackers, disclose the initial compromise method, list affected domains, or provide a total certificate count. It also does not clarify whether the certificates were used to intercept traffic or impersonate services.

Chrome implemented CRLSets to reject unauthorized certificates. Chromium describes CRLSets as its primary method for quickly blocking certificates in emergencies, rather than a complete replacement for all certificate revocation methods.

Initially, Google blocked certificates covering its own properties, and Certificate Transparency analysis later revealed additional affected organizations, including major global brands and commonly used online services.

Chrome proactively blocked those certificates and, where possible, reached out to impacted organizations. Google also coordinated with issuing authorities to ensure revocation and extend protection beyond Chrome.

Chrome users do not need to take any action to benefit from these protections. However, Google cautioned that its investigation might not have identified every affected domain, and Chrome-specific measures may not reliably protect users of other clients.

Google recommends continuous monitoring of Certificate Transparency across all domain portfolios, including parked domains and regional properties.

CT logs provide publicly auditable records, and monitoring services can alert owners when certificates or precertificates are issued for their domains. Organizations operating .gh, .sl, or .as domains should review recent entries for any unexpected certificate issuances.

Google also suggests implementing restrictive Certification Authority Authorization (CAA) policies with ACME account bindings. RFC 8657 defines the accountUri and validationMethods parameters, allowing supported CAA policies to limit certificate issuance to specific accounts and validation methods. Organizations must verify that their chosen authority supports these restrictions.

While CAA cannot prevent issuance during an active DNS hijack, restoring restrictive policies after recovery can stop attackers from exploiting cached domain-validation results to obtain additional certificates.

Google stated it would continue to advocate for shorter certificate lifetimes and reduced validation reuse across the HTTPS ecosystem.

Stops Cyber threats before impact with 21 min faster MTTR. Integrate ANYRUN’s Sandbox in your SOC.

Divya

Divya is a Senior Journalist at GBhackers covering Cyber Attacks, Threats, Breaches, Vulnerabilities and other happenings in the cyber world.

Recent Posts

Insignary Launches Clarity AIR to Detect Undeclared Open-Source and AI-Written Code

Toronto, Canada, October 8th, 2026, CyberNewswire Insignary Launches Clarity AIR: Closing the Blind Spot Between…

38 minutes ago

Hackers Hijack Tensorlake Package to Spread Shai-Hulud Supply Chain Malware

A threat actor published a malicious version of the tensorlake npm package on October 8,…

2 hours ago

PoC Exploit Released for Zammad Vulnerability Enabling Session Hijacking and Remote Code Execution

A proof-of-concept (PoC) exploit has been released for CVE-2026-102489, a critical vulnerability in Zammad that…

2 hours ago

Critical LMCache RCE Vulnerability Remains Unpatched, Public PoC Exploit Available

A critical vulnerability in LMCache allows unauthenticated attackers to execute arbitrary code against reachable multi-process…

2 hours ago

16 Malicious Firefox Extensions Impersonate Crypto Wallets to Steal Seed Phrases and Private Keys

16 malicious Firefox extensions that impersonate cryptocurrency wallets to intercept recovery phrases and private keys…

3 hours ago

Exposed DarkSword iOS Servers Reveal Crypto Wallet Theft From Compromised iPhones

Exposed directories on five servers have revealed an operational DarkSword/Coruna exploitation platform built to compromise…

4 hours ago