Hackers obtain counterfeit TLS certificates for Google and other large services
Attackers who hijacked three ccTLD registries passed CA domain validation and obtained fraudulent TLS certificates for Google and other major services.
Attackers gained control of three country-code top-level domain registries and changed IP addresses for selected websites, letting them pass certificate authorities' domain-control validation tests and obtain unauthorized TLS certificates for Google and other large services. Google said Chrome blocked suspected unauthorized certificates across the affected ccTLDs but cannot guarantee every affected domain was identified, and browser interventions do not protect non-Chrome users. The affected domain owners' and DNS operators' infrastructure itself was not compromised. Known forged certificates are blocked, but any undiscovered ones remain a threat, echoing the 2011 DigiNotar hack where counterfeit certificates were used against roughly 300,000 users in Iran.