Select a theme from the list.
Insights

From our experts

Latest
MatchBoil Evolves Into a Stealthier Espionage Tool Against Ukraine's Essential IndustriesFBI Domain Seizures Cut Into Flax Typhoon's Global Hacking PlatformActive Directory Defenses Face an 11-Hour Race to Protect Tier 0Southern Company Portal Breach Exposes 400,000 Utility AccountsRegistry Hijacks Expose a Dangerous Weak Link Beneath HTTPS TrustRansomware Recovery CEO Accused of Hiding Millions in Secret PaymentsAlleged Ploutus Developer Arrested as ATM Jackpotting Crackdown Reaches Malware LeadershipRogue AI Agents Tested Wikimedia's Boundaries and Tried to Turn Web Tools Into ProxiesPwn2Own Researchers Break 32 Zero-Days Across Phones, AI Systems and Smart DevicesEmergency Exchange Update Closes a Door Into Other Users' MailboxesApple Moves to Rein In AI Agents With Sweeping Mac Data AccessPredictable Session Keys Put Rejetto File Servers on the Attack RadarMatchBoil Evolves Into a Stealthier Espionage Tool Against Ukraine's Essential IndustriesFBI Domain Seizures Cut Into Flax Typhoon's Global Hacking PlatformActive Directory Defenses Face an 11-Hour Race to Protect Tier 0Southern Company Portal Breach Exposes 400,000 Utility AccountsRegistry Hijacks Expose a Dangerous Weak Link Beneath HTTPS TrustRansomware Recovery CEO Accused of Hiding Millions in Secret PaymentsAlleged Ploutus Developer Arrested as ATM Jackpotting Crackdown Reaches Malware LeadershipRogue AI Agents Tested Wikimedia's Boundaries and Tried to Turn Web Tools Into ProxiesPwn2Own Researchers Break 32 Zero-Days Across Phones, AI Systems and Smart DevicesEmergency Exchange Update Closes a Door Into Other Users' MailboxesApple Moves to Rein In AI Agents With Sweeping Mac Data AccessPredictable Session Keys Put Rejetto File Servers on the Attack Radar
Security Insight

Registry Hijacks Expose a Dangerous Weak Link Beneath HTTPS Trust

Registry Hijacks Expose a Dangerous Weak Link Beneath HTTPS Trust
Photo by Ann H on Pexels

Attackers compromised operators connected to three country-code domain registries and obtained unauthorized HTTPS certificates for Google and YouTube domains. Google's infrastructure was not breached, but the incident shows how control of authoritative DNS can let criminals impersonate trusted services while presenting apparently valid encrypted connections.

A series of attacks against the domain registries for Ghana, Sierra Leone and American Samoa has demonstrated that the security of HTTPS depends on far more than the organization named in a web address.

DNS control enabled valid certificate requests

The attackers compromised infrastructure associated with the .gh, .sl and .as country-code top-level domains. By changing authoritative DNS records, they could demonstrate apparent control of targeted domains and request legitimate TLS certificates from public certificate authorities.

Certificate Transparency records reviewed by The Hacker News showed at least 12 unauthorized certificates covering seven Google and YouTube domains. Eleven were issued by Let's Encrypt and one by ZeroSSL between September 22 and September 27. The certificates were later revoked.

Google said its own systems were not compromised. The company blocked the certificates in Chrome using CRLSets, an emergency mechanism for rejecting selected certificates, and worked with certificate authorities to extend protection beyond its browser. Google also found indications that other global brands and widely used online services may have been affected.

Why the padlock is not enough

Users are commonly taught that an HTTPS padlock means a website is trustworthy. In reality, it confirms that the browser has established an encrypted connection with a system presenting a recognized certificate. If attackers control DNS long enough to obtain that certificate, the encrypted connection may terminate at malicious infrastructure.

The incident therefore represents a supply chain problem in internet identity. A company can secure its applications, accounts and internal networks yet still face impersonation if a registry, registrar, DNS provider or certificate validation process is manipulated.

Defensive priorities for domain owners

  • Monitor Certificate Transparency logs for every registered and parked domain.
  • Use registry locks and strong administrative authentication where available.
  • Limit certificate issuance through restrictive CAA records.
  • Alert on unauthorized nameserver and DNS record changes.
  • Maintain an emergency process for certificate revocation and DNS restoration.

CAA records can reduce exposure, particularly after legitimate DNS control has been restored, but they cannot fully stop an attacker who can actively modify authoritative records. I believe organizations should treat domain and certificate monitoring as part of their security operations program rather than a task left solely to web administrators. Brand protection, DNS security and certificate management now belong in the same risk conversation as identity and endpoint defense.

Talk to our team →

Latest

MatchBoil Evolves Into a Stealthier Espionage Tool Against Ukraine's Essential IndustriesOct 9, 2026FBI Domain Seizures Cut Into Flax Typhoon's Global Hacking PlatformOct 9, 2026Active Directory Defenses Face an 11-Hour Race to Protect Tier 0Oct 9, 2026Southern Company Portal Breach Exposes 400,000 Utility AccountsOct 8, 2026Registry Hijacks Expose a Dangerous Weak Link Beneath HTTPS TrustOct 8, 2026Ransomware Recovery CEO Accused of Hiding Millions in Secret PaymentsOct 8, 2026

Most read

1Sophos Turns Its Own Network Into a Proving Ground for Safer Enterprise AI2Sophos Fusion Recasts the Security Platform as an AI-Driven Defense System3Microsoft Makes Passkeys the Entra ID Default and Sets a Deadline for Native SMS Authentication4Global CMS Exploitation Wave Plants Webshells on Business Websites5Critical NGINX Overflow Puts Internet-Facing Servers on an Urgent Upgrade Path6Laser Attack Exposes an Unpatchable Weakness in Tangem Crypto Wallet Cards