🔒Attackers Hijack TLDs to Mint Fake TLS Certs for Google and Others
TLS Certificates Under Threat: What You Need to Know
TL;DR
Attackers hijacked TLDs to mint counterfeit TLS certificates for Google and other major brands. Chrome blocked these unauthorized certs, but domain owners must stay vigilant.
Attackers hijacked three top-level domains (.gh, .sl, and .as) to mint counterfeit TLS certificates for Google and other leading brands. This compromised the security of these domains by allowing attackers to impersonate them. Domain owners must now monitor certificate transparency logs and publish restrictive Certification Authority Authorization DNS records to prevent future attacks. The incident highlights the importance of proactive security measures in protecting TLS certificates.

Key Points
Attackers hijacked three TLDs: .gh, .sl, and .as, to mint counterfeit TLS certificates.
Google and several leading global brands were affected by unauthorized certificate issuance.
Chrome blocked all identified unauthorized certificates to mitigate immediate risks.
Domain owners must monitor certificate transparency logs and publish restrictive DNS records.
The incident underscores the need for proactive security measures in TLS certificate management.
Why It Matters
If you're managing a domain, this incident shows the importance of monitoring certificate transparency logs and publishing restrictive DNS records. For example, if you're running a critical service on a .com domain, you should ensure your CA authorization is up-to-date to prevent similar attacks. The risk of unauthorized certificates remains, so vigilance is key.
Comments
Be the first to comment
Enjoyed this article?
Get it daily. 7am. Free. Reads in 5 minutes.
Join 3,556 builders reading daily.