Mmastodon TechnologyCybersecurity first seen 10 h ago, last 10 h ago, peak #7
Attackers compromise .gh, .sl and .as domain registries
Original: Attackers compromised .gh, .sl, and .as ccTLD registries. Modified authoritative DNS. Passed automated domain control va
Attackers gained access to the country-code top-level domain registries for Ghana (.gh), Sierra Leone (.sl) and American Samoa (.as) and altered their authoritative DNS records. The changes let them pass automated domain control validation and obtain valid TLS certificates for Google domains and other major brands. Google itself was not hacked, and certificate authorities followed their normal procedures, raising concern about weaknesses in the domain validation trust chain.
Why now: A supply-chain-style compromise of DNS registries that yielded legitimate certificates for major brands exposes a gap in how domain control and TLS trust are validated.
.gh registry.sl registry.as registryGooglecertificate authorities
Evidence
- Attackers compromised .gh, .sl, and .as ccTLD registries. Modified authoritative DNS. Passed automated domain control validation. Got valid TLS certificates for Google domains and other major brands. Google wasn't hacked. The CAs didn't make a mistake. The trust chain worked… · threataft@infosec.exchange · 4
API: https://socialmediatrends-api.osmike.com/v1/trends/1435838