blog.google Hackers Acquire Counterfeit TLS Certificates via ccTLD Hijacks
Article Content
- •Hackers hijacked ccTLDs to obtain unauthorized TLS certificates.
- •Google confirmed no compromise of its systems or those of affected domain owners.
- •Chrome has blocked the unauthorized certificates, but the scope of impact is still being assessed.
On October 6, 2026, Google reported that hackers obtained unauthorized TLS certificates through the hijacking of ccTLDs (.gh, .sl, .as). The attackers modified DNS records to gain control over these domains, allowing them to issue certificates for various Google and other organizations' domains. Google stated that this incident did not compromise their infrastructure or that of the affected domain owners. Although Chrome has blocked the unauthorized certificates, the full extent of the impact remains unclear, with additional organizations potentially affected. The certificates were issued without the Certification Authorities (CAs) being at fault. The incident echoes previous events, such as the 2011 DigiNotar breach, highlighting ongoing vulnerabilities in certificate issuance processes.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track DigiNotar in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Common questions
What domains are affected?
Are the unauthorized certificates still valid?
What should organizations do now?
Continue Reading
Critical Authentication Bypass in Cisco Catalyst SD-WAN Manager Exploited On September 30, 2026, Cisco disclosed a critical vulnerability (CVE-2026-76504) in the Catalyst SD-WAN Manager that allows unauthenticated remote attackers to bypass authentication and gain admin-level access to the system. This flaw stems from improper handling of URI encoding in HTTP requests, enabling attackers to…
Critical Citrix NetScaler Zero-Day Vulnerabilities Exploited In late September 2026, two critical zero-day vulnerabilities (CVE-2026-88771 and CVE-2026-88772) in Citrix NetScaler ADC and Gateway were actively exploited, allowing remote code execution. The Cybersecurity and Infrastructure Security Agency (CISA) added these CVEs to its Known Exploited Vulnerabilities catalog on…