Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Google Domains Expose Vulnerability in Recent ccTLD Hijacks

Google Domains Expose Vulnerability in Recent ccTLD Hijacks

Posted on October 9, 2026 By CWS

Google recently revealed that several of its domains were compromised due to the hijacking of third-party country-code top-level domains (ccTLDs). This incident has raised significant concerns over digital security.

Details of the ccTLD Hijacking Incident

The hijacking took place last week, targeting the .gh (Ghana), .sl (Sierra Leone), and .as (American Samoa) ccTLDs. This breach put numerous domains using these suffixes at risk, including those owned by Google.

During the attack, unauthorized modifications were made to authoritative DNS records. Attackers also obtained HTTPS certificates for several Google domains and those of other organizations, according to Google’s statement.

Google’s Response and Mitigation Efforts

Google clarified that the Certification Authorities (CAs) involved in issuing these certificates were not at fault, considering the attack’s nature. Upon discovering the breach, Google promptly blocked the unauthorized certificates in Chrome and collaborated with the CAs to revoke them.

Through the analysis of Certificate Transparency (CT) log data, it was found that other organizations, including international brands and popular online services, were also impacted. To protect users, Google took immediate steps to block these certificates in Chrome and informed affected organizations when feasible.

Preventive Measures and Future Outlook

Despite Google’s efforts to mitigate the issue, some domains might still be vulnerable. Google advises domain owners to monitor CT logs vigilantly, particularly for domains in the affected regions, and to implement restrictive CAA DNS records to enhance protection after DNS control is reinstated.

Google emphasizes the importance of restoring restrictive CAA policies, which confine certificate issuance to specific authorized accounts and validation methods. This practice prevents attackers from exploiting cached validation states to issue new certificates post-hijack.

In conclusion, this incident highlights the ongoing challenges in digital security and the need for vigilant monitoring and proactive security measures. As organizations continue to address these threats, the focus remains on ensuring robust defenses against future vulnerabilities.

Security Week News Tags:American Samoa, ccTLD hijack, Chrome, Cybersecurity, DNS, domain security, Ghana, Google, HTTPS certificates, internet security, Sierra Leone

Post navigation

Previous Post: Federal Agencies Urged to Patch Flaws Exploited by Flax Typhoon
Next Post: Top Container Image Scanning Tools of 2026

Related Posts

Apple Blocks 2 Million App Store Apps for Security in 2025 Apple Blocks 2 Million App Store Apps for Security in 2025 Security Week News
Orange Belgium Data Breach Impacts 850,000 Customers Orange Belgium Data Breach Impacts 850,000 Customers Security Week News
Wiz Warns of Ongoing Exploitation of Recent Ivanti Vulnerabilities Wiz Warns of Ongoing Exploitation of Recent Ivanti Vulnerabilities Security Week News
Data Breach at Dutch Carrier Odido Affects Millions Data Breach at Dutch Carrier Odido Affects Millions Security Week News
Critical BeyondTrust Flaw Targeted in Ransomware Surge Critical BeyondTrust Flaw Targeted in Ransomware Surge Security Week News
Copperhelm Secures M for Innovative Cloud Security Copperhelm Secures $7M for Innovative Cloud Security Security Week News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Hackers Exploit Terraform Workflows to Spread Malware
  • Anthropic Accelerates AI Bug Reports for Open Source Security
  • Citrix Addresses Critical NetScaler Vulnerability
  • Top Container Image Scanning Tools of 2026
  • Google Domains Expose Vulnerability in Recent ccTLD Hijacks

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • October 2026
  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Hackers Exploit Terraform Workflows to Spread Malware
  • Anthropic Accelerates AI Bug Reports for Open Source Security
  • Citrix Addresses Critical NetScaler Vulnerability
  • Top Container Image Scanning Tools of 2026
  • Google Domains Expose Vulnerability in Recent ccTLD Hijacks

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark