The Hacker News · il y a 4h

Des attaquants détournent les registres .gh, .sl et .as pour obtenir des certificats pour Google Domains

Titre original : Attackers Hijack .gh, .sl, and .as Registries to Obtain Certificates for Google Domains

Alerte   Publié 2026-10-07

Résumé

Des attaquants ont compromis les registres de trois extensions nationales (.gh, .sl et .as), leur permettant d'émettre des certificats HTTPS frauduleux pour des domaines appartenant à Google. Bien que les systèmes de Google n'aient pas été touchés, ces certificats permettent d'usurper l'identité de sites officiels via des connexions chiffrées. Aucune action technique n'est requise pour les administrateurs de serveurs tiers, car l'incident concerne spécifiquement la gestion de ces trois domaines de premier niveau (ccTLDs).

Extrait original (en anglais)

Attackers compromised three country-code top-level domains (ccTLDs) and obtained unauthorized HTTPS certificates for several Google domains, Google said on October 6. Google's own systems were not breached, but any domain ending in .gh (Ghana), .sl (Sierra Leone) or .as (American Samoa) was put at risk. With such a certificate, an attacker could pose as the real site over an encrypted