{"id":2095,"date":"2026-10-08T07:17:37","date_gmt":"2026-10-08T00:17:37","guid":{"rendered":"https:\/\/vncybers.vn\/tin-tac-chiem-quyen-cctld-chung-chi-https-google-youtube\/"},"modified":"2026-10-08T07:17:37","modified_gmt":"2026-10-08T00:17:37","slug":"attackers-hijack-cctld-registries-google-youtube-https-certificates-2","status":"publish","type":"post","link":"https:\/\/vncybers.vn\/en\/tin-tac-chiem-quyen-cctld-chung-chi-https-google-youtube\/","title":{"rendered":"Attackers Hijack Three ccTLD Registries and Obtain HTTPS Certificates for Google and YouTube"},"content":{"rendered":"<p><strong>Google says the registries for the .gh, .sl, and .as country-code domains were hijacked, allowing attackers to alter authoritative DNS and obtain unauthorized HTTPS certificates for several Google and YouTube domains as well as domains belonging to other organizations. Google's systems were not breached, but the incident shows that the HTTPS padlock alone cannot prove a website is genuine when DNS or a registry is compromised.<\/strong><\/p>\n<p>According to an October 6, 2026 notice from the Chrome Secure Web and Networking Team, the hijacks affected the country-code namespaces of Ghana (.gh), Sierra Leone (.sl), and American Samoa (.as). Google learned of the incidents the previous week and immediately added the unauthorized certificates to CRLSets so Chrome would block them automatically.<\/p>\n<h2>A Valid Certificate Can Still Serve a Hijacked Domain<\/h2>\n<p>During domain-validated certificate issuance, a certificate authority (CA) checks whether the applicant controls the domain. Once attackers can alter authoritative DNS records, they can pass that check and obtain a browser-trusted certificate without compromising the CA itself.<\/p>\n<p>Google emphasized that it had no reason to believe the CAs involved had acted improperly. The failure occurred in third-party ccTLD infrastructure: temporary control of DNS created evidence of domain control that was fraudulent yet appeared valid to certificate-issuance systems.<\/p>\n<figure class=\"wp-block-image size-large\"><img decoding=\"async\" src=\"https:\/\/vncybers.vn\/wp-content\/uploads\/2026\/10\/cctld-hijack-inline.jpg\" alt=\"Data center infrastructure supporting DNS and web services\"\/><figcaption>Website protection depends on registries, DNS, CAs, and certificate-revocation mechanisms working together. Real-world illustrative photo.<\/figcaption><\/figure>\n<h2>At Least 12 Certificates Appeared in Transparency Logs<\/h2>\n<p>The Hacker News reviewed Certificate Transparency (CT) data and identified at least 12 certificates for seven Google and YouTube domains logged between September 22 and 27. Let's Encrypt issued 11 and ZeroSSL issued one. The names included google.com.gh, google.sl, google.as, and several Google and YouTube variants under the three ccTLDs.<\/p>\n<p>By October 7, all 12 identified certificates had been revoked. The interval between their first appearance in CT and revocation ranged from roughly a day and a half to nearly a week. Google has not disclosed evidence that the certificates were used to steal data, nor has it identified the attackers or explained how the three registries were compromised.<\/p>\n<h2>Chrome Blocked the Certificates, but the Risk Extended Beyond Google<\/h2>\n<p>After the initial mitigation, CT data indicated that other organizations, including major global brands and widely used online services, may also have been affected. Google proactively blocked additional suspicious certificates in Chrome and contacted organizations it could identify.<\/p>\n<p>Chrome users do not need to take any action to receive this protection. Google warned, however, that browser-side measures may not identify every affected domain and cannot reliably protect users of other browsers or applications.<\/p>\n<h2>What Should Domain Owners Do?<\/h2>\n<ul>\n<li><strong>Monitor Certificate Transparency:<\/strong> cover the entire domain portfolio, including parked and regional domains, to receive near-real-time alerts when new certificates are issued.<\/li>\n<li><strong>Review .gh, .sl, and .as domains immediately:<\/strong> compare recently issued certificates against the organization's approved inventory.<\/li>\n<li><strong>Publish restrictive CAA records:<\/strong> specify which CAs may issue certificates and, where supported, bind issuance to a particular ACME account and validation method.<\/li>\n<li><strong>Report unknown certificates:<\/strong> submit a Certificate Problem Report to the issuing CA to trigger investigation and revocation procedures.<\/li>\n<\/ul>\n<p>CAA cannot prevent certificate issuance while attackers control DNS because they can also modify the CAA record. Restoring a restrictive CAA policy after an incident remains essential: CAs may reuse domain-control validation for a period of time, while strict CAA settings can prevent attackers from continuing to exploit cached validation state.<\/p>\n<h2>Lessons About the HTTPS Chain of Trust<\/h2>\n<p>The incident shows that HTTPS security depends on an entire chain: domain registries, DNS providers, CAs, CT logs, browsers, and the domain owner's operations team. Compromising a single link can produce a certificate that appears fully valid and makes impersonation difficult for users to detect.<\/p>\n<p>Organizations should monitor CT as a continuous security signal rather than checking it only during incidents. Domain and DNS administration should also be protected with phishing-resistant MFA, least privilege, locks on critical changes, and out-of-band verification procedures.<\/p>\n<p style=\"text-align: right; margin-top: 40px;\"><em><strong>VNCyberS<\/strong> compiled from Google Chrome Security and The Hacker News<\/em><\/p>","protected":false},"excerpt":{"rendered":"<p>Google cho bi\u1ebft c\u00e1c c\u01a1 quan qu\u1ea3n l\u00fd t\u00ean mi\u1ec1n qu\u1ed1c gia .gh, .sl v\u00e0 .as \u0111\u00e3 b\u1ecb chi\u1ebfm quy\u1ec1n, cho ph\u00e9p k\u1ebb t\u1ea5n c\u00f4ng thay \u0111\u1ed5i DNS c\u00f3 th\u1ea9m quy\u1ec1n v\u00e0 xin c\u1ea5p ch\u1ee9ng ch\u1ec9 HTTPS tr\u00e1i ph\u00e9p cho nhi\u1ec1u t\u00ean mi\u1ec1n Google, YouTube c\u00f9ng c\u00e1c t\u1ed5 ch\u1ee9c kh\u00e1c. S\u1ef1 c\u1ed1 kh\u00f4ng x\u00e2m nh\u1eadp [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":2093,"comment_status":"","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"inline_featured_image":false,"footnotes":""},"categories":[1],"tags":[925,922,924,832,385,923],"class_list":["post-2095","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-tin-tuc","tag-caa","tag-cctld-hijack","tag-certificate-transparency","tag-dns-security","tag-google-chrome","tag-https-certificate"],"_links":{"self":[{"href":"https:\/\/vncybers.vn\/en\/wp-json\/wp\/v2\/posts\/2095","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/vncybers.vn\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/vncybers.vn\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/vncybers.vn\/en\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/vncybers.vn\/en\/wp-json\/wp\/v2\/comments?post=2095"}],"version-history":[{"count":0,"href":"https:\/\/vncybers.vn\/en\/wp-json\/wp\/v2\/posts\/2095\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/vncybers.vn\/en\/wp-json\/wp\/v2\/media\/2093"}],"wp:attachment":[{"href":"https:\/\/vncybers.vn\/en\/wp-json\/wp\/v2\/media?parent=2095"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/vncybers.vn\/en\/wp-json\/wp\/v2\/categories?post=2095"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/vncybers.vn\/en\/wp-json\/wp\/v2\/tags?post=2095"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}