Attackers Used Stolen Domain Control to Forge Google TLS Certificates
Attackers managed to take control of three national domain zones and used that access to obtain fake TLS certificates for Google domains and other major online services. According to a report from Ars Technica, citing a Google statement, the attackers targeted the .gh.sl, and .as country-code top-level domains. By altering authoritative DNS records, they bypassed the automated domain-control validation required by certificate authorities to issue certificates.
Google responded by updating Chrome to block all identified unauthorized certificates and worked with certificate authorities to revoke those issued for Google resources. The company did not disclose the names of other affected organizations or the total number of unauthorized certificates issued.
TLS certificates are essential for authenticating and encrypting connections to websites, mail servers, and other internet infrastructure. Unauthorized certificates can allow attackers to impersonate legitimate infrastructure cryptographically. Google emphasized that the infrastructure of affected domain owners was not compromised, and certificate authorities followed established protocols. However, the attackers' control over domain zones enabled them to redirect traffic and alter DNS records.
Google warned domain owners not to rely solely on browser-based certificate blocking. The company recommended monitoring certificate transparency logs for unexpected issuance and publishing restrictive Certification Authority Authorization DNS records to prevent misuse of cached validation data after DNS control is restored.