
Google blocks fake certificates for hijacked .gh, .sl, .as
Attackers took over the DNS of three country domains and obtained HTTPS certificates for Google and other brands' sites, the company says. Chrome already blocks them.
Google said on Oct. 6 that attackers hijacked country-code domains in Ghana (.gh), Sierra Leone (.sl) and American Samoa (.as) and used them to obtain fake HTTPS certificates for Google sites and for other organizations. The Chrome security team said so in Google's security blog, where it says it learned of the incidents "last week." Chrome already blocks those certificates, and its users do not need to do anything.
An HTTPS certificate is what lets a browser trust a site's identity. Before issuing one, a certificate authority checks that the applicant controls the domain, and one of the tests runs through DNS, the system that tells browsers which server each name points to. According to Google, the attackers compromised outside operators that manage the three domains and changed the authoritative DNS records, which let them pass that validation.
With those certificates, BleepingComputer notes, a fake site could have posed as the brand without the browser warning anyone. Google says its own systems were untouched and that it sees no reason to think the certificate authorities acted improperly.
What Chrome did
Chrome blocked the certificates for Google properties using CRLSets, an emergency blocking mechanism built into the browser, and asked the issuing authorities to revoke them. Public Certificate Transparency logs, which record every certificate issued, helped identify other affected organizations. Google refers to global brands and widely used online services but does not name them. Chrome blocked those certificates too.
The protection has a limit that Google acknowledges: CRLSets work only in Chrome, and the company admits it may not have identified every affected domain.
What Google asks domain owners to do
For those who manage domains, including parked and regional ones, the company recommends watching Certificate Transparency logs and publishing restrictive CAA records, which limit who can issue certificates. It notes that a CAA record does not stop issuance while a hijack is still active, but it does prevent saved validations from being reused once DNS control is recovered. Chrome says it is working on longer-term protections, such as shorter-lived certificates.
There is no CVE: this is not a software vulnerability with a version and a patch, but a compromise of infrastructure. Everything above rests on Google's announcement and on BleepingComputer's report, which is based on it; this newsroom found no analysis by specialists outside Google and no statement from the registry operators. It is also unknown who is behind the attacks, how many certificates were issued, or exactly when the hijackings took place.



