Tag: domain hijacking
5 articles

Hackers Exploit ccTLD Vulnerabilities to Hijack Google Domains
Google revealed that several top brands and online services were hit by the same attacks, following their initial mitigation efforts. Attackers exploited vulnerabilities in country-code top-level domain (ccTLD) registries and DNS to hijack Google domains, not by breaching Google's infrastructure, but by compromising third-party operators.

Hackers Hijack Country-Code Domains to Obtain Google HTTPS Certificates
Hackers hijacked country-code domains to obtain unauthorized Google HTTPS certificates, putting several domains at risk between September 22 and 27. Google quickly sprang into action, revoking the certificates and blocking them in Chrome to prevent any further damage.

Browser Alerts Expose Rogue Scripts in Thousands of Sites
Thousands of websites, repositories, and documentation pages are unwittingly exposing users to rogue scripts, thanks to a long-abandoned content delivery network domain that was re-registered by a malicious actor. This simple domain hack has opened the door to a massive security vulnerability.

Hackers Exploit Dropcatch Domains to Redirect Traffic to Scams and Malware
Hackers are exploiting "dropcatch domains" - previously owned domains that are re-registered by new owners - to redirect traffic to scams and malware, taking advantage of the reputation and connections they inherit from their past life. With nearly one in five new domain registrations being a re-registration of an expired name, the threat is more widespread than you might think.

Scottish Healthcare Domains Hijacked, Redirect to Illicit Content
Imagine visiting a trusted healthcare website, only to be redirected to explicit content or illegal streams - that's the alarming reality for some Scottish healthcare domains that have been hijacked. Patients and staff are left with unanswered questions and growing concern after researchers uncovered the breach affecting NHS Scotland-linked sites.