Hackers obtained unauthorized HTTPS certificates for several Google domains and hijacked domains in the country-code top-level domains (ccTLDs) for Ghana, American Samoa, and Sierra Leone after compromising third-party operators and modifying authoritative DNS records.
Google underlines that the attacks affected domains of other organizations in the. GH,.SL, and. AS ccTLDs but “did not involve a compromise of Google’s systems.”
By gaining access to the domain name system (DNS) records, a threat actor can request an HTTPS certificate from a Certificate Authority (CA) for a domain they don’t own.
