stocks
Read original source (Arstechnica)

DNS Hijacks Let Attackers Mint Fake TLS Certificates for Google and Other Major Services

DNS Hijacks Let Attackers Mint Fake TLS Certificates for Google and Other Major Services

Attackers hijacked three country-code top-level domains and used DNS control to obtain unauthorized TLS certificates for Google and other services. The incident exposes a trust-chain weakness that can bypass normal certificate validation without breaching the targeted companies.

A series of DNS hijacks allowed attackers to obtain unauthorized TLS certificates for Google and other major online services, exposing a weakness in one of the Internet’s core trust systems.

The supplied source says attackers took control of the .gh, .sl and .as country-code top-level domains, then modified authoritative DNS records for selected domains.

That control allowed them to pass automated domain-validation checks used by certificate authorities and obtain certificates that could cryptographically impersonate legitimate infrastructure.

Google said it updated Chrome to block the unauthorized certificates it identified and worked with certificate authorities to revoke certificates tied to Google properties.

Importantly, the affected companies’ infrastructure was not directly compromised. The failure occurred because attackers controlled the DNS layer strongly enough to satisfy existing certificate-validation requirements.

That makes the incident strategically important for cloud and cybersecurity companies. Modern Internet security relies on multiple layers of trust, and attackers increasingly target the weakest link rather than attempting to breach the largest companies directly.

Google is advising domain owners to monitor certificate-transparency logs and publish restrictive Certification Authority Authorization records.

The remaining uncertainty is whether every unauthorized certificate has been found.

BTI’s bottom line: the incident shows why cybersecurity spending continues to move beyond endpoint defense. DNS integrity, certificate transparency and identity infrastructure are becoming more important as attackers exploit trust relationships between systems rather than attacking one company head-on.

Research and commentary are provided for information, not personalized investment advice. Verify material claims with the linked source and original company disclosures. Report a correction · About BTI