On October 06, 2026, Alphabet Inc (NASDAQ: GOOG) disclosed a series of domain hijacking incidents impacting country-code top-level domains such as .gh, .sl, and .as. These attacks targeted third-party registrars rather than Google's internal systems, raising security concerns for websites using these suffixes.
The recent domain hijacking incidents reported by Alphabet involved unauthorized alterations of DNS records and illicit acquisition of HTTPS certificates for several Google domains and other organizations. Importantly, Google’s own systems were not compromised; instead, attackers exploited vulnerabilities at third-party registrars managing country-code top-level domains (.gh for Ghana, .sl for Sierra Leone, and .as for American Samoa). This breach escalates the risk of phishing, data interception, and impersonation attacks for websites using these domain suffixes.
Google responded swiftly by blocking the unauthorized certificates in its Chrome browser via CRLSets and collaborating with Certification Authorities (CAs) to revoke these certificates across platforms. Investigations through Certificate Transparency logs revealed that other prominent brands and digital services were likely affected, prompting Google to proactively restrict access and notify impacted parties. Chrome users remain protected without needing additional action.
No comments:
Post a Comment
Note: Only a member of this blog may post a comment.