Sunday, April 6, 2025
HomeCyber Security NewsDozens of U.S .gov Websites Vulnerable to MITM Attack - TLS certificates...

Dozens of U.S .gov Websites Vulnerable to MITM Attack – TLS certificates Not Renewed due to Federal Shutdown

Published on

SIEM as a Service

Follow Us on Google News

U.S. federal shutdown affected many of the U.S government websites vulnerable to MITM attack by intercept the traffic because .gov websites haven’t renewed their TLS certificates.

In this case, dozens of U.S. government websites have been rendered either insecure or inaccessible and the sites include government payment portals and remote access services.

Due to the strict security measures Some of the .gov websites are no longer accessible and more then 80 TLS certificates are expired so far without being renewed.

- Advertisement - Google News

Currently there are 400,000 federal employees are not furloughed for last
21st day since the shutdown enters.

List of site includes NASA, the U.S. Department of Justice and the Court of Appeal, payment portal.

For an Example, U.S. Department of Justice website https://ows2.usdoj.gov, certificate expired on 17 December 2018 since then the site left with expired certificate which is signed by Godaddy.

Modern browsers Google Chrome and Mozilla Firefox hide an advance options to restrict user to bypass the warning as an unsecure and continue to browse the site safe.

Since the usdoj.gov and subdomains in Chromium’s HSTS preload list, users never allow to access the unencrypted sites during the U.S. DoJ websites.

When users avoid the warning then they will be victims to man-in-the-middle attacks.

Unfortunately, Most of the affected website are able to bypass the security warning and proceed to access the website therefore the site is vulnerable to MITM attacks.

for an example, https://rockettest.nasa.gov/ certificate expired on Jan 5 2018, but is not included in the HSTS preload list, so user still can bypass the security warning by clicking proceed to the concern website withoutsafe.

According to netcraft , With Donald Trump seemingly unwilling to compromise on his demands for a wall along the border with Mexico, and Democrats refusing to approve a budget containing $5.7bn for the wall, the hundreds of thousands of unpaid federal employees might not be the only ones hurting.

Also still it continues then there are most list of Gov websites in queue which is very nearly to expired within days, weeks — or maybe even months.

You can follow us on LinkedinTwitterFacebook for daily Cybersecurity updates also you can take the Best Cybersecurity courses online to keep your self-updated.

Balaji
Balaji
BALAJI is an Ex-Security Researcher (Threat Research Labs) at Comodo Cybersecurity. Editor-in-Chief & Co-Founder - Cyber Security News & GBHackers On Security.

Latest articles

Hack The box “Ghost” Challenge Cracked – A Detailed Technical Exploit

Cybersecurity researcher "0xdf" has cracked the "Ghost" challenge on Hack The Box (HTB), a...

Sec-Gemini v1 – Google’s New AI Model for Cybersecurity Threat Intelligence

Google has unveiled Sec-Gemini v1, an AI model designed to redefine cybersecurity operations by...

U.S. Secures Extradition of Rydox Cybercrime Marketplace Admins from Kosovo in Major International Operation

The United States has successfully extradited two Kosovo nationals, Ardit Kutleshi, 26, and Jetmir...

Ivanti Fully Patched Connect Secure RCE Vulnerability That Actively Exploited in the Wild

Ivanti has issued an urgent security advisory for CVE-2025-22457, a critical vulnerability impacting Ivanti...

Supply Chain Attack Prevention

Free Webinar - Supply Chain Attack Prevention

Recent attacks like Polyfill[.]io show how compromised third-party components become backdoors for hackers. PCI DSS 4.0’s Requirement 6.4.3 mandates stricter browser script controls, while Requirement 12.8 focuses on securing third-party providers.

Join Vivekanand Gopalan (VP of Products – Indusface) and Phani Deepak Akella (VP of Marketing – Indusface) as they break down these compliance requirements and share strategies to protect your applications from supply chain attacks.

Discussion points

Meeting PCI DSS 4.0 mandates.
Blocking malicious components and unauthorized JavaScript execution.
PIdentifying attack surfaces from third-party dependencies.
Preventing man-in-the-browser attacks with proactive monitoring.

More like this

Hack The box “Ghost” Challenge Cracked – A Detailed Technical Exploit

Cybersecurity researcher "0xdf" has cracked the "Ghost" challenge on Hack The Box (HTB), a...

Sec-Gemini v1 – Google’s New AI Model for Cybersecurity Threat Intelligence

Google has unveiled Sec-Gemini v1, an AI model designed to redefine cybersecurity operations by...

U.S. Secures Extradition of Rydox Cybercrime Marketplace Admins from Kosovo in Major International Operation

The United States has successfully extradited two Kosovo nationals, Ardit Kutleshi, 26, and Jetmir...