Three Country Code Top-Level Domains, Including Ghana’s, Compromised; Google Chrome Promptly Blocks Unauthorized HTTPS Certificates
15 hour ago / Read about 0 minute
Author:小编   

On October 6, Google reported that three country code top-level domains (ccTLDs)—.gh (Ghana), .sl (Sierra Leone), and .as (American Samoa)—had been compromised. In response, Google Chrome has taken swift action by blocking the associated unauthorized HTTPS certificates. The attackers gained unauthorized access to a third-party domain name registration management system, where they tampered with authoritative DNS records. By exploiting control over DNS settings, they were able to bypass automated verification processes employed by certificate authorities. Coupled with traffic redirection techniques, this enabled connections to fraudulent websites to pass certificate validation checks undetected.

Google clarified that the attackers had specifically targeted and altered the authoritative DNS records for certain domains under these ccTLDs, posing a potential security risk to all domain names sharing these suffixes. At present, there is no indication of any wrongdoing on the part of the involved certificate authorities. To mitigate the threat, Chrome has proactively blocked the compromised certificates via its Certificate Revocation List (CRL) and is working closely with the issuing authorities to ensure the revocation of these certificates.