A critical zero-day bug that affected Verisign and many IaaS services such as Google, Amazon, and DigitalOcean let hackers register homograph domains (.com and .net).
Successfully registering these homograph domains resembles the same well-known domains and subdomains used to perform social engineering and insider attacks and is a similar process to the IDN homograph attack.
Researchers identified several homograph domains operating since 2017 with an HTTPS certificate that mimicked various domains that include finance, online shopping ,technology, and other Fortune 100 sites.
Matt Hamilton, a researcher from Soluble, found that several Generic top-level domains (gTLDs) can be registered using the Unicode Latin IPA Extension character and also managed to register the following homograph domains.

The above registered homograph domains look identical to the corresponding original domains but are essentially created using Unicode Latin IPA.
Similarly, the researcher examined around 300 important domains and the vulnerability is believed to be used only in social engineering that intend to install malware and steal sensitive data.
According to the detailed report “It appears that Verisign and other providers were unaware of the so‑called “homoglyphs” within the Unicode Latin IPA Extension character set”.
Register the homograph domain with a mix of Unicode and Latin characters
Basically, Verisign prevents users from registering domains that use mixed scripts like “gооgle.com” using Cyrillic “о”.
However, due to the zero-day bug, registering a domain with a combination of Unicode and Latin characters was possible, provided the Unicode characters were the same as in Latin.
“Companies like Verisign explicitly enforce anti-homograph measures (which prohibit mixed scripts) because they don’t want similar domains in the gTLD. Public services that exist under a shared root, such as “s3.amazonaws.com,” “storage.googleapis.com,” or other services that allow users to create arbitrary subdomains, should enforce the same restrictions,” the researcher said.
This bug did not affect only the gTLDs of VeriSign but is likely to affect any TLD that allows Latin IPA characters.
This vulnerability is considered a zero day, as multiple instances of HTTPS certificate logs were detected via Certificate Transparency, as well as an “unofficial” JavaScript library hosted on a “prominent domain.”

