Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Hackers Breach Domain Registries for Unauthorized Certificates

Hackers Breach Domain Registries for Unauthorized Certificates

Posted on October 7, 2026 By CWS

In a recent security breach, hackers have exploited the domain registries of Ghana, Sierra Leone, and American Samoa, issuing unauthorized HTTPS certificates for major organizations including Google. Google’s proactive response involved Chrome automatically blocking these certificates, while Google collaborated with certification authorities to revoke them.

Details of the Breach

On October 6, Google disclosed that it had discovered the breach in the previous week. The compromised domains—.gh, .sl, and .as—put numerous websites at risk, although Google clarified that not all domains were affected. Significantly, Google’s internal systems remained secure throughout the incident, and the certificate authorities involved were not at fault. The hackers targeted the third-party domain infrastructure, which is critical for certificate validation processes.

Mechanics of DNS Hijacking

The attackers manipulated authoritative DNS records, which are essential for domain lookups. By controlling these records, attackers can falsify domain control validation, misleading certificate authorities into issuing certificates. This process typically checks whether the requester can publish a specific DNS record, a step that can be bypassed if an attacker controls the DNS infrastructure.

Although possessing an unauthorized certificate could allow attackers to mimic trusted websites, this requires redirecting users to their servers. Google’s report did not confirm whether the certificates were used in active traffic interception.

Chrome’s Protective Measures

Google promptly used CRLSets, Chrome’s emergency certificate blocking system, to invalidate the compromised certificates for its domains. Additionally, Google engaged with issuing authorities to ensure these certificates were revoked across all platforms, not just Chrome.

Further analysis of Certificate Transparency logs revealed certificates linked to other major organizations. Google continues to block these certificates in Chrome and alerts affected parties. However, Google cautions that some domains may still be undetected, emphasizing the importance of domain owners conducting their own checks.

To enhance security, organizations are advised to monitor Certificate Transparency logs vigilantly and explore tools for detecting unauthorized certificate issuance. Google also suggests implementing restrictive Certification Authority Authorization records and considering shorter certificate lifetimes and reduced validation reuse to bolster security practices.

In conclusion, while the breach underscores vulnerabilities in domain and certificate management, Google’s swift actions and recommendations aim to mitigate risks and enhance future security protocols.

Cyber Security News Tags:Certification Authority, Chrome protection, Cybersecurity, data protection, DNS hijacking, domain control validation, domain registry breach, Google security, HTTPS certificates, web security

Post navigation

Previous Post: PoeLLM Malware Targets AI Systems for Crypto Mining
Next Post: Malicious npm Packages Uncovered in Extensive Malware Campaign

Related Posts

TeamViewer DEX Vulnerabilities Let Attackers Trigger DoS Attack and Expose Sensitive Data TeamViewer DEX Vulnerabilities Let Attackers Trigger DoS Attack and Expose Sensitive Data Cyber Security News
Critical Apache Syncope Vulnerability Exposes User Sessions Critical Apache Syncope Vulnerability Exposes User Sessions Cyber Security News
Beware of Weaponized AI Tool Installers That Infect Your Devices With Ransomware Beware of Weaponized AI Tool Installers That Infect Your Devices With Ransomware Cyber Security News
Deep Dive into Endpoint Security Deep Dive into Endpoint Security Cyber Security News
Fancy Bear Targets Microsoft Vulnerability in Cyberattack Fancy Bear Targets Microsoft Vulnerability in Cyberattack Cyber Security News
Google Chrome 0-Day Vulnerability Actively Exploited in the Wild Google Chrome 0-Day Vulnerability Actively Exploited in the Wild Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • CrowdStrike, AWS, NVIDIA Enhance Cybersecurity Accelerator
  • Malicious npm Packages Uncovered in Extensive Malware Campaign
  • Hackers Breach Domain Registries for Unauthorized Certificates
  • PoeLLM Malware Targets AI Systems for Crypto Mining
  • SonicWall Addresses Critical SMA1000 Vulnerabilities

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • October 2026
  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • CrowdStrike, AWS, NVIDIA Enhance Cybersecurity Accelerator
  • Malicious npm Packages Uncovered in Extensive Malware Campaign
  • Hackers Breach Domain Registries for Unauthorized Certificates
  • PoeLLM Malware Targets AI Systems for Crypto Mining
  • SonicWall Addresses Critical SMA1000 Vulnerabilities

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark