Chrome Blocks Rogue Certificates After Registry Hijacks
Attackers hijacked the .gh, .sl, and .as registries, altered DNS records, and passed automated validation to obtain unauthorized TLS certificates for Google and other major services. Chrome blocked identified certificates, while Google urged domain owners to monitor Certificate Transparency logs and tighten CAA policies.
This incident exposes a fragile trust chain: attackers did not breach Google or a certificate authority—they compromised the infrastructure used to prove domain ownership.
- –Registry and DNS control can still enable cryptographic impersonation even when certificate authorities follow their procedures
- –Chrome’s rapid blocklist response limits damage, but undiscovered certificates and non-Chrome clients remain exposed
- –Certificate Transparency monitoring should cover every domain, including parked and regional properties
- –Restrictive CAA records with ACME account bindings can prevent attackers from reusing cached validation after DNS control is restored
- –The episode strengthens the case for shorter certificate lifetimes and reduced domain-control-validation reuse
DISCOVERED
1h ago
2026-10-07
PUBLISHED
5h ago
2026-10-07
RELEVANCE
AUTHOR
colinprince