TGViewer
SITREP - Independent OSINT Channel SITREP - Independent OSINT Channel @sitreports · 23K subscribers
Post #39530 309
🔍 ccTLD hijacks enabled counterfeit certs for Google domains

Google says attackers hijacked the .gh, .sl, and .as registries, altered authoritative DNS records, and obtained unauthorized HTTPS certificates for several Google domains and other organizations. Chrome has already blocked suspected rogue certs across the affected namespaces, but Google says its own systems were not breached. The company advises monitoring Certificate Transparency logs and reviewing recent issuance in those ccTLDs.

This is a registry-level trust failure: control of DNS plus valid-looking certificates can remove normal browser warning signals and support convincing impersonation, interception, phishing, or malware delivery. Chrome-side blocking reduces exposure for some users, but Google notes it may not identify every affected domain and does not reliably protect non-Chrome traffic.

🛰️ Open sources - closed narratives
@sitreports
More from @sitreports
  1. Oct 9, 2026🔍 FBI details China-linked email access portal The FBI says China-linked hackers operated…
  2. Oct 9, 2026📡 Ransomware disrupts Japan’s IDCF Cloud IDC Frontier says a ransomware attack hit its ID…
  3. Oct 9, 2026🔍 FakeGit reactivates at scale on GitHub FakeGit has resumed activity with 17,610 malicio…
  4. Oct 9, 2026🔍 Cisco flags five critical NX-OS flaws on Nexus switches Cisco has issued advisories for…
  5. Oct 9, 2026🔍 Low-cost Android phones found shipping with firmware-level malware Bitdefender’s Midnig…
  6. Oct 9, 2026🔍 UAC-0099 deploys ASHVEIN RAT against Ukrainian government staff UAC-0099 is targeting U…
Threads Profile ViewerView any public Threads profile without an account.Open ThreadLook →Writing with AI? Make it sound human.Metric37 rewrites AI drafts so they read naturally. Free AI detector, 1,500 words free.Try Metric37 →