Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Attackers Exploit ccTLDs to Acquire Google Certificates

Attackers Exploit ccTLDs to Acquire Google Certificates

Posted on October 7, 2026 By CWS

On October 6, Google revealed that attackers had compromised three country-code top-level domains (ccTLDs), acquiring unauthorized HTTPS certificates for multiple Google domains. These affected domains include those ending in .gh (Ghana), .sl (Sierra Leone), and .as (American Samoa). Although Google’s internal systems were not breached, the incident posed a risk as attackers could impersonate Google’s sites to intercept private data.

Google’s Swift Response to the Threat

In response to the breach, Google quickly blocked the unauthorized certificates using Chrome’s CRLSets, a tool designed to rapidly invalidate certificates in emergencies. Furthermore, Google collaborated with the certificate authorities (CAs) responsible for issuing the certificates to ensure their revocation, safeguarding users across various browsers and applications.

The Certificate Transparency logs, which document all certificates issued by CAs, showed that at least 12 unauthorized certificates were issued between September 22 and September 27 for domains like google.com.gh, google.sl, and google.as. These certificates were issued by Let’s Encrypt and ZeroSSL, with the attackers manipulating DNS records to obtain them.

Insight into Certificate Transparency Logs

On October 7, The Hacker News identified the unauthorized certificates through CT search services. The 12 certificates covered seven different domains, with Let’s Encrypt responsible for issuing 11 of them and ZeroSSL for one. The issuance of these certificates was recorded on separate days for each ccTLD: .gh on September 22, .sl on September 25, and .as on September 27.

All certificates were domain-validated, meaning they were issued after verifying the applicant’s control over the domain. Normally, Google Trust Services, Google’s own CA, issues certificates for these Google domains. However, during these hijacks, attackers managed to modify authoritative DNS records to gain certificate issuance.

Recommendations for Domain Owners

In light of the attack, Google advised domain owners to monitor Certificate Transparency logs for their domains, including parked and regional ccTLD names. Google also recommended publishing a strict Certification Authority Authorization (CAA) record to restrict which CAs can issue certificates for a domain. Moreover, any unauthorized certificate should be reported to the issuing CA for prompt investigation.

Although CAA records cannot prevent certificate issuance during an active DNS hijack, they become crucial once domain control is restored. They help ensure that unauthorized certificates cannot be reissued by exploiting a previously completed domain check. Google’s proactive measures underscore the importance of robust domain security practices to protect against such sophisticated cyber threats.

As of October 7, all affected certificates were revoked, with the revocation process taking between a day and a week to complete. Google’s efforts to mitigate the impact included informing other potentially affected organizations and enhancing security protocols to prevent future incidents of this nature.

The Hacker News Tags:ccTLD, certificate authority, Certificate Transparency, Chrome, cyber attack, Cybersecurity, DNS hijack, domain security, Google, Google Trust Services, HTTPS certificates, Let's Encrypt, SSL, web security, ZeroSSL

Post navigation

Previous Post: CrowdStrike, AWS, NVIDIA Enhance Cybersecurity Accelerator
Next Post: Discord Users’ Data Exposed in Double Counter Breach

Related Posts

The ROI Problem in Attack Surface Management The ROI Problem in Attack Surface Management The Hacker News
Fortinet Exploits, RedLine Clipjack, NTLM Crack, Copilot Attack & More Fortinet Exploits, RedLine Clipjack, NTLM Crack, Copilot Attack & More The Hacker News
Amazon Kiro Vulnerability Risks Data Exposure Amazon Kiro Vulnerability Risks Data Exposure The Hacker News
TamperedChef Malware Disguised as Fake PDF Editors Steals Credentials and Cookies TamperedChef Malware Disguised as Fake PDF Editors Steals Credentials and Cookies The Hacker News
Navigating the Mythos Era with Network Detection and Response Navigating the Mythos Era with Network Detection and Response The Hacker News
Tor Browser Vulnerability: A Single Webpage Visit Risk Tor Browser Vulnerability: A Single Webpage Visit Risk The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Key Challenges Facing US SOCs: Solutions to Improve Efficiency
  • SonicWall Fixes Critical SSRF Vulnerability in SMA1000
  • Discord Users’ Data Exposed in Double Counter Breach
  • Attackers Exploit ccTLDs to Acquire Google Certificates
  • CrowdStrike, AWS, NVIDIA Enhance Cybersecurity Accelerator

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • October 2026
  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Key Challenges Facing US SOCs: Solutions to Improve Efficiency
  • SonicWall Fixes Critical SSRF Vulnerability in SMA1000
  • Discord Users’ Data Exposed in Double Counter Breach
  • Attackers Exploit ccTLDs to Acquire Google Certificates
  • CrowdStrike, AWS, NVIDIA Enhance Cybersecurity Accelerator

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark