{"id":487,"date":"2026-10-06T20:05:41","date_gmt":"2026-10-06T20:05:41","guid":{"rendered":"https:\/\/bugleblast.com\/?p=487"},"modified":"2026-10-06T20:06:16","modified_gmt":"2026-10-06T20:06:16","slug":"cctld-hijack-counterfeit-tls-certificates-google-chrome","status":"publish","type":"post","link":"https:\/\/bugleblast.com\/?p=487","title":{"rendered":"HACKERS HIJACK THREE COUNTRY DOMAINS TO FAKE GOOGLE\u2019S SECURITY LOCKS! | Attackers seized the .gh, .sl and .as registries, rewired DNS and walked off with real-looking HTTPS certs for Google and other big names \u2014 and Google admits it may not have found them all"},"content":{"rendered":"<p>That little padlock in your browser? Somebody just counterfeited it. Google said Tuesday that attackers hijacked three country-code top-level domains \u2014 <strong>.gh<\/strong> (Ghana), <strong>.sl<\/strong> (Sierra Leone) and <strong>.as<\/strong> (American Samoa) \u2014 and used that control to obtain unauthorized HTTPS certificates covering <strong>\u201cseveral Google domains\u201d<\/strong> plus domains belonging to other organizations, according to <a href=\"https:\/\/blog.google\/security\/chromes-response-to-recent-cctld-registry-hijacks\/\">Google\u2019s own post<\/a>.<\/p>\n<p>How it worked: the attackers compromised the third-party ccTLD infrastructure and modified authoritative DNS records, <a href=\"https:\/\/arstechnica.com\/security\/2026\/10\/hackers-obtain-counterfeit-tls-certificates-for-google-and-other-large-services\/\">Ars Technica<\/a> explains. With traffic for selected sites pointed at them, they could pass the tests certificate authorities use to confirm someone controls a domain \u2014 and walk away with valid-looking certs. Google said its own systems were not compromised and it has \u201cno reason to believe\u201d the issuing CAs did anything wrong.<\/p>\n<p>The fix so far: Chrome blocked the unauthorized certificates it identified using its emergency CRLSets mechanism, and Google worked with the issuing CAs to revoke them for other browsers. Google says Chrome users don\u2019t need to do anything.<\/p>\n<p>But here\u2019s the gut punch, straight from Google: \u201cDue to the complexity of DNS hijacks, we cannot guarantee that our analysis identified every affected domain, nor do Chrome interventions reliably protect non-Chrome users.\u201d Google didn\u2019t name the other affected brands, and Ars says it isn\u2019t clear how many certificates were issued.<\/p>\n<p>Got a website? Google\u2019s advice is to watch Certificate Transparency logs for certs on your domains and publish restrictive CAA records naming which authorities may issue for you. History buffs will remember the 2011 DigiNotar hack, when forged Google certs were used against at least 300,000 people with ties to Iran, per Ars.<\/p>\n<p><strong>Sources:<\/strong> <a href=\"https:\/\/blog.google\/security\/chromes-response-to-recent-cctld-registry-hijacks\/\">Google<\/a> \u00b7 <a href=\"https:\/\/arstechnica.com\/security\/2026\/10\/hackers-obtain-counterfeit-tls-certificates-for-google-and-other-large-services\/\">Ars Technica<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Attackers seized the .gh, .sl and .as registries, rewired DNS and walked off with real-looking HTTPS certs for Google and other big names \u2014 and Google admits it may not have found them all<\/p>\n","protected":false},"author":1,"featured_media":488,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_jetpack_newsletter_access":"","_jetpack_dont_email_post_to_subs":false,"_jetpack_newsletter_tier_id":0,"_jetpack_memberships_contains_paywalled_content":false,"_jetpack_feature_clip_id":0,"_jetpack_memberships_contains_paid_content":false,"footnotes":"","jetpack_post_was_ever_published":false},"categories":[1],"tags":[],"class_list":["post-487","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized"],"jetpack_sharing_enabled":true,"jetpack_featured_media_url":"https:\/\/bugleblast.com\/wp-content\/uploads\/2026\/10\/bb-cctld-cert-hijack-1006.jpg","_links":{"self":[{"href":"https:\/\/bugleblast.com\/index.php?rest_route=\/wp\/v2\/posts\/487","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/bugleblast.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/bugleblast.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/bugleblast.com\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/bugleblast.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=487"}],"version-history":[{"count":1,"href":"https:\/\/bugleblast.com\/index.php?rest_route=\/wp\/v2\/posts\/487\/revisions"}],"predecessor-version":[{"id":489,"href":"https:\/\/bugleblast.com\/index.php?rest_route=\/wp\/v2\/posts\/487\/revisions\/489"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/bugleblast.com\/index.php?rest_route=\/wp\/v2\/media\/488"}],"wp:attachment":[{"href":"https:\/\/bugleblast.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=487"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/bugleblast.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=487"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/bugleblast.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=487"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}