Attackers Hijack .gh, .sl, and .as Registries to Obtain Certificates for Google Domains
thehackernews.com Oct 8, 2026

Attackers Hijack .gh, .sl, and .as Registries to Obtain Certificates for Google Domains

AI-summarised brief · reviewed before publication

Attackers compromised the .gh, .sl, and .as country‑code top‑level domains, issuing unauthorized HTTPS certificates for several Google and YouTube names. Google’s systems were untouched, but the hijacked domains could allow attackers to impersonate Google sites and intercept encrypted traffic. Chrome immediately blocked the rogue certificates via CRLSets, and Google worked with Let's Encrypt, ZeroSSL, and other CAs to revoke the 12 certificates logged between September 22 and 27. The incident also exposed other global brands, though specifics remain undisclosed.

💡 Why It Matters

  • · The breach shows how DNS hijacks can undermine even the most secure sites, revealing that certificate authorities can be tricked into issuing valid keys for compromised domains.
  • · It underscores the need for stricter DNS and CAA controls to prevent future exploitation.