The Matthew Chapman Podcast

Hijacked Country Domains Minted Fake Google TLS Certificates

Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.

0:00 | 4:53
Here is your briefing for Wednesday, October seventh, twenty twenty-six. Google says attackers hijacked three country code top-level domains, dot G.H., dot S.L., and dot A.S., then rewrote the authoritative D.N.S. records for selected domains underneath them. Controlling D.N.S. meant they could pass automated domain validation and get real certificate authorities to issue unauthorized T.L.S. certificates for several Google domains and, in Google's words, several leading global brands. Chrome now blocks every bad certificate Google found, and the Google ones were revoked. But Google is blunt that it can't promise it found them all, and Chrome's block does nothing for anyone on another browser. So, if you own domains, watch certificate transparency logs for issuance you didn't ask for, and publish restrictive C.A.A. records. Nobody broke the crypto. They just owned the phone book. The F.B.I. and the Secret Service warned that the FortiBleed campaign is still active against internet-facing FortiGate firewalls and S.S.L. V.P.N. gateways. As of June, the Russian-speaking operation had collected more than eighty-six thousand six hundred working device credentials across one hundred ninety-four countries, getting in with reused and leaked passwords, then sniffing authentication traffic and cracking hashes on a G.P.U. cluster. The agencies say the crew looks like an initial access broker, with overlaps to the INC and Lynx ransomware operations. It creates new admin accounts on the firewall, and sometimes deletes yours so you're locked out of your own box. The fix list is the usual one, done for real this time. Phishing-resistant M.F.A., kill active sessions, reset V.P.N. and admin passwords, and switch admin password storage to P.B.K.D.F. two. Quick update on yesterday's Atlassian story, because it got worse fast. After watchTowr published technical details for C.V.E. twenty twenty-six dash twenty-one thousand five hundred eighty-nine, Previdian saw exploitation attempts hit its honeypots within two hours. So far that's fifteen attempts from three I.P. addresses, and a Nuclei template is out, so mass scanning is next. The "you need to know the exact file name" caveat turns out to be less comforting than it sounded. On Crowd and Jira, an attacker can pull the crowd dot properties file, use the credentials inside to get admin, and then mint a brand new Jira administrator. If you were waiting for a reason to patch today, this is it. A researcher named Syed Anas Mohiuddin got one AI agent inside a network to hand malicious instructions to another agent, at Google, Rapid7, JPMorgan Chase, Weaviate, and two government teams. He calls it protocol pivoting. Plant text an agent reads, it delegates the task over M.C.P. or Google's agent-to-agent protocol, and the next agent runs it because it trusts whoever handed over the work. The Google bug, rated eight, was in its M.C.P. toolbox for databases, which followed redirects and didn't check target I.P. addresses. That's a classic server-side request forgery, and it's been fixed. Rapid7 put it best. Every piece did exactly what it was designed to do, and nobody watched the hallway in between. Treat anything an L.L.M. hands your tools like input from a stranger on the internet. Island researchers found a human-operated phishing platform that poses as advertising products for ChatGPT, Gemini, Claude, Perplexity, Manus, and Meta's new Muse agent. One site, muse ads dot A.I., showed up barely a week after Muse launched. Click Connect, and you get a fake login window drawn inside the real browser, with an address bar that says accounts dot google dot com or your Okta tenant. Behind it, a live operator watches you type and picks which M.F.A. challenge you see next, a text code, an authenticator prompt, or number matching. The targets are agency staff and media buyers, and the prize is ad accounts with clean spend history. The crew also left older source code sitting in public GitHub repos, which is a nice touch. Forged certificates from hijacked domains, firewall logins sold to ransomware crews, an Atlassian bug exploited before lunch, agents trusting other agents, and fake login windows run by a live human. Every one of them wins by borrowing trust somebody else already earned. That's the briefing. Stay sharp, keep your systems patched, and we'll see you tomorrow.

Kindle: https://www.amazon.com/dp/B0HHMH88H9 
Apple Books: https://books.apple.com/us/book/local-ai-on-the-mac/id6807243472

Barnes & Noble: https://www.barnesandnoble.com/w/books/1151622292?ean=2940185390764

https://mattch

Support the show