Google says attackers hijacked the .gh, .sl and .as country-code domains and used that access to obtain unauthorized HTTPS/TLS certificates for several Google properties and other major online services.
Google says attackers hijacked the .gh, .sl and .as country-code domains and used that access to obtain unauthorized HTTPS/TLS certificates for several Google properties and other major online services.
By altering authoritative DNS records, the attackers were able to request certificates that appeared legitimate, prompting Google to block them in Chrome and work with certificate authorities to revoke them. Google says its own systems were not compromised and Chrome users do not need to take any action.