CriticalSecurity & Privacy
Attackers hijacked top-level domains, minted fake security certs for Google and other orgs
Attackers exploited hijacked country-code top-level domains to alter DNS records and obtain fraudulent HTTPS certificates for Google and other organizations, enabling convincing impersonation without the usual browser warnings. For CIOs, this underscores a broader supply-chain and trust-boundary risk: even if core systems are not breached, compromised domain governance can expose customers to phishing, malware delivery, and traffic interception while damaging brand trust. IT organizations should treat DNS and certificate management as part of critical security operations, not just infrastructure administration, because browser-side protections alone are insufficient and may not cover all users or all affected domains.