Attackers Hijack .gh, .sl, and .as Registries to Obtain Certificates for Google Domains
Summary
Attackers compromised the .gh, .sl, and .as top-level domains to obtain unauthorized HTTPS certificates for several Google domains. While Google's internal systems were not breached, this incident allowed attackers to impersonate legitimate sites using these ccTLDs.
IFF Assessment
The compromise of domain registries and the issuance of fraudulent certificates represent a significant threat to the integrity of encrypted communications, enabling attackers to conduct man-in-the-middle attacks.
Defender Context
This incident highlights the critical importance of domain registry security and the potential impact of compromised DNS infrastructure. Defenders should be vigilant about certificate anomalies and the risks associated with trust relationships between domain registrars and certificate authorities.