Find notable cyber news and cases, enriched with sources, timelines, and signals.

.Gh (Ghana) ccTLD registry hit by cyberattack

Incident
First reported
Last updated
Happening score
H score 26
1 unique sources, 1 articles

Summary

Hide ▲

The .gh, .sl and .as ccTLD registries were compromised, letting attackers alter authoritative DNS records and obtain unauthorized HTTPS certificates for Google domains and other organizations. The incident put domains under those namespaces at risk and weakened certificate trust beyond the registries themselves.

Related Happenings

Google hit by network compromise

Incident
H score16 First: 07.10.2026 21:48 Last: 07.10.2026 21:48 Sources 1

About this happening: The .gh, .sl, and .as ccTLD compromise led to unauthorized HTTPS certificates for Google and YouTube names, creating a risk of encrypted impersonation and...

North African government technology authority data exposed after North African government technology authority breach

Data Leak
H score45 First: 11.09.2026 17:10 Last: 11.09.2026 17:10 Sources 1

About this happening: A North African government technology authority suffered a data leak after attackers hijacked its central account server and exfiltrated a credential database containi...

UNC6508 China-linked REDCap espionage campaign

Campaign
H score39 First: 15.06.2026 17:00 Last: 15.06.2026 17:00 Sources 1

About this happening: UNC6508 ran a China-linked espionage campaign against exposed REDCap servers used by North American medical, academic, and military research networks. The operatio...

Tycoon 2FA-Storm-1747 ecosystem shift changes threat-actor operations

Threat Actor Meta
H score82 First: 05.03.2026 08:51 Last: 05.03.2026 08:51 Sources 1

About this happening: Tycoon 2FA is a commercial phishing-as-a-service ecosystem that moved from adversary-in-the-middle credential harvesting into device-code phishing after a March...

Latest development: 17.05.2026 17:43

eSentire says Tycoon2FA now uses device-code phishing to target Microsoft 365 accounts, with invoice-themed lure emails carrying Trustifi click-tracking URLs that redirect through Trustifi, Cloudflare Workers, obfuscated JavaScript layers, and a fake Microsoft CAPTCHA page before sending victims to microsoft.com/devicelogin. The kit also adds anti-analysis defenses, including detection of Selenium, Puppeteer, Playwright, and Burp Suite, plus blocks for security vendors, VPNs, sandboxes, AI crawlers, and cloud providers.

Timeline

  1. 06.10.2026 03:00 2 articles · 2d ago

    Attackers compromise .gh, .sl and .as registries and trigger certificate blocking

    Initial Disclosure

    On October 6, Google said attackers had compromised the .gh (Ghana), .sl (Sierra Leone) and .as (American Samoa) ccTLD registries, modified authoritative DNS records, and obtained unauthorized HTTPS certificates for Google domains and other organizations. Chrome blocked the unauthorized certificates for Google properties through CRLSets, Google worked with the issuing CAs to revoke the certificates, and the company urged domain owners to monitor Certificate Transparency (CT) logs and use restrictive Certification Authority Authorization (CAA) records.

    Show sources