Chrome blocked unauthorized HTTPS certificates for domains in hijacked .gh, .sl, and .as ccTLD namespaces using CRLSets to protect users automatically. The attacks involved DNS record modifications to obtain fraudulent certificates for Google and other global brands' domains, though the CAs themselves were not at fault.
Background
ccTLD registry hijacking involves attackers compromising country-code top-level domain registries to intercept traffic and obtain fraudulent SSL/TLS certificates. This incident highlights ongoing vulnerabilities in the domain and certificate infrastructure that global brands face.
- Source
- Lobsters
- Published
- Oct 7, 2026 at 02:00 AM
- Score
- 7.0 / 10