.Gh (Ghana) ccTLD registry hit by cyberattack
Incident
Summary
Hide ▲
Show ▼
The .gh, .sl and .as ccTLD registries were compromised, letting attackers alter authoritative DNS records and obtain unauthorized HTTPS certificates for Google domains and other organizations. The incident put domains under those namespaces at risk and weakened certificate trust beyond the registries themselves.
Related Happenings
Google hit by network compromise
Incident
H score16
First: 07.10.2026 21:48
Last: 07.10.2026 21:48
Sources 1
About this happening:
The .gh, .sl, and .as ccTLD compromise led to unauthorized HTTPS certificates for Google and YouTube names, creating a risk of encrypted impersonation and...
Google hit by network compromise
IncidentAbout this happening: The .gh, .sl, and .as ccTLD compromise led to unauthorized HTTPS certificates for Google and YouTube names, creating a risk of encrypted impersonation and...
North African government technology authority data exposed after North African government technology authority breach
Data Leak
H score45
First: 11.09.2026 17:10
Last: 11.09.2026 17:10
Sources 1
About this happening:
A North African government technology authority suffered a data leak after attackers hijacked its central account server and exfiltrated a credential database containi...
North African government technology authority data exposed after North African government technology authority breach
Data LeakAbout this happening: A North African government technology authority suffered a data leak after attackers hijacked its central account server and exfiltrated a credential database containi...
UNC6508 China-linked REDCap espionage campaign
Campaign
H score39
First: 15.06.2026 17:00
Last: 15.06.2026 17:00
Sources 1
About this happening:
UNC6508 ran a China-linked espionage campaign against exposed REDCap servers used by North American medical, academic, and military research networks. The operatio...
UNC6508 China-linked REDCap espionage campaign
CampaignAbout this happening: UNC6508 ran a China-linked espionage campaign against exposed REDCap servers used by North American medical, academic, and military research networks. The operatio...
Tycoon 2FA-Storm-1747 ecosystem shift changes threat-actor operations
Threat Actor Meta
H score82
First: 05.03.2026 08:51
Last: 05.03.2026 08:51
Sources 1
About this happening:
Tycoon 2FA is a commercial phishing-as-a-service ecosystem that moved from adversary-in-the-middle credential harvesting into device-code phishing after a March...
Tycoon 2FA-Storm-1747 ecosystem shift changes threat-actor operations
Threat Actor MetaAbout this happening: Tycoon 2FA is a commercial phishing-as-a-service ecosystem that moved from adversary-in-the-middle credential harvesting into device-code phishing after a March...
Latest development: 17.05.2026 17:43
eSentire says Tycoon2FA now uses device-code phishing to target Microsoft 365 accounts, with invoice-themed lure emails carrying Trustifi click-tracking URLs that redirect through Trustifi, Cloudflare Workers, obfuscated JavaScript layers, and a fake Microsoft CAPTCHA page before sending victims to microsoft.com/devicelogin. The kit also adds anti-analysis defenses, including detection of Selenium, Puppeteer, Playwright, and Burp Suite, plus blocks for security vendors, VPNs, sandboxes, AI crawlers, and cloud providers.
Timeline
-
06.10.2026 03:00 2 articles · 2d ago
Attackers compromise .gh, .sl and .as registries and trigger certificate blocking
Initial DisclosureOn October 6, Google said attackers had compromised the .gh (Ghana), .sl (Sierra Leone) and .as (American Samoa) ccTLD registries, modified authoritative DNS records, and obtained unauthorized HTTPS certificates for Google domains and other organizations. Chrome blocked the unauthorized certificates for Google properties through CRLSets, Google worked with the issuing CAs to revoke the certificates, and the company urged domain owners to monitor Certificate Transparency (CT) logs and use restrictive Certification Authority Authorization (CAA) records.
Show sources
- Attackers Hijack Three ccTLDs to Obtain Google Certificates — www.infosecurity-magazine.com — 08.10.2026 17:30
- Attackers Hijack Three ccTLDs to Obtain Google Certificates — www.infosecurity-magazine.com — 08.10.2026 17:30