[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fuG27EI8TfTUljzX1H4bkj_rrovsYsEPDdnYo_Qir7hU":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":23,"created_at":24,"published_at":25,"article":26,"tags":30,"podcasts":49},"48998357-0d9e-4eeb-bbe9-e415e75a0dc1","hijacked-country-code-registries-used-to-issue-fraudulent-tls-certificates","382e36d6-7eb7-46ee-af72-54406771ca8f","Hijacked Country-Code Registries Used to Issue Fraudulent TLS Certificates","Attackers compromised the administrative infrastructure of three country-code top-level domain (ccTLD) registries, exploiting weaknesses in registry access controls and DNS management to fraudulently obtain HTTPS certificates for high-profile domains owned by Google. This attack demonstrates that the certificate trust model is only as strong as the weakest DNS authority in the chain — a compromised registry can undermine the integrity of encrypted communications globally. Because HTTPS certificates are widely trusted by browsers by default, end users would have had no visual warning that they were connecting to an impersonator. Google's rapid response using CRLSets and coordinated certificate revocation limited real-world harm, but the window of exposure highlights how critical timely detection and revocation mechanisms are. Organizations cannot rely solely on certificate issuance controls; they must actively monitor for unauthorized certificates referencing their domains.","**Immediate actions:**\n- Enroll all owned domains in Certificate Transparency (CT) log monitoring services to receive real-time alerts for unauthorized certificate issuance.\n- Enable DNSSEC on all authoritative DNS zones to cryptographically protect DNS records from unauthorized modification.\n- Audit and restrict privileged access to DNS management consoles and domain registrar accounts using multi-factor authentication and least-privilege principles.\n\n**Long-term improvements:**\n- Implement CAA (Certification Authority Authorization) DNS records to explicitly restrict which certificate authorities are permitted to issue certificates for your domains.\n- Establish formal relationships with trusted certificate authorities to ensure rapid revocation of any fraudulently issued certificates.\n- Advocate for and adopt DMARC, DANE, and other standards that bind cryptographic identity more tightly to DNS infrastructure.\n\n**Detection measures:**\n- Continuously monitor Certificate Transparency logs (e.g., via crt.sh or Google's Cert Monitor) for any certificates issued for your domain without authorization.\n- Integrate CT log alerts into your Security Operations Center (SOC) workflow with defined escalation and revocation playbooks.\n- Conduct periodic third-party audits of DNS registrar account security and registry-level access controls.",[12,13,14,15,16,17,18,19,20,21,22],"CIS Control 4 – Secure Configuration of Enterprise Assets and Software","CIS Control 6 – Access Control Management","CIS Control 13 – Network Monitoring and Defense","NIST SP 800-53 AC-2 (Account Management)","NIST SP 800-53 IA-5 (Authenticator Management)","NIST SP 800-53 SC-20 (Secure Name\u002FAddress Resolution Service)","NIST SP 800-53 IR-4 (Incident Handling)","NIST Cybersecurity Framework DE.CM-7 (Monitoring for Unauthorized Activity)","RFC 6844 – DNS Certification Authority Authorization (CAA)","RFC 6962 – Certificate Transparency","ITIL Service Continuity Management – Recovery and Response Procedures","published","2026-10-07T20:20:54.039349+00:00","2026-10-07T20:20:53.85+00:00",{"id":7,"url":27,"slug":28,"title":29},"https:\u002F\u002Fthehackernews.com\u002F2026\u002F10\u002Fattackers-hijack-gh-sl-and-as.html","attackers-hijack-gh-sl-and-as-registries-to-obtain-certificates-for-google-domai-d19160","Attackers Hijack .gh, .sl, and .as Registries to Obtain Certificates for Google Domains",[31,37,43],{"id":32,"name":33,"slug":34,"description":35,"color":36},"182e11d5-57c4-444e-8ec8-4682ad60261b","Incident Response","incident-response","Slow detection, poor containment, missing playbooks","#14b8a6",{"id":38,"name":39,"slug":40,"description":41,"color":42},"1ec88fde-2d0f-4ed8-932a-33f5ccc0fdc7","Access Control","access-control","Excessive privileges, missing MFA, weak auth","#f97316",{"id":44,"name":45,"slug":46,"description":47,"color":48},"859cf0ad-a7e9-42bb-a75d-bac6511fa5d5","Configuration Management","configuration-management","Misconfigs, default credentials, exposed services","#eab308",[]]