Newsletter Subscribe
Enter your email address below and subscribe to our newsletter
[forminator_form id="25163"]

arstechnica.ua.arstechnica.Attackers took control of three country-code top-level domains and used that access to obtain unauthorized TLS certificates for several Google domains and for other large brands and widely used online services, Google said Tuesday, Oct. 6. The attacks targeted .gh (Ghana), .sl (Sierra Leone) and .as (American Samoa).arstechnica+1
Google, owned by Alphabet , said it updated Chrome to block every certificate it had identified as unauthorized. It also worked with the certificate authorities that issued them to get the certificates for Google properties revoked. The company did not say which of its domains were affected, did not name the other organizations involved, and did not say how many certificates were issued.ua+1
According to Ars Technica, the attackers changed authoritative DNS records for selected domains under the three registries. With control of those records, they passed the automated domain-control validation checks that certificate authorities run before issuing a certificate. Google said the affected domain owners' own infrastructure was not compromised and that the certificate authorities followed the rules. Control of the zones let the attackers change IP addresses and name-server delegations, so they could redirect traffic and answer the validation challenges.arstechnica+1
A TLS certificate uses a digital signature to tie a domain name to a public key. Someone holding an unauthorized certificate can cryptographically pass themselves off as the real site. Startup Fortune noted that domain validation "only proves you control the domain at the moment of the check," not whether you are supposed to control it.startupfortune+1
Google said Chrome users do not need to do anything to be protected. It warned domain owners not to rely only on browser-side blocking. It advised them to watch certificate transparency logs for certificates they didn't expect and to publish restrictive Certification Authority Authorization (CAA) DNS records. Those records stop attackers from reusing cached validation data after the domain owner gets DNS control back.arstechnica
The incident follows similar episodes. According to Startup Fortune, a Let's Encrypt certificate was issued for google.tg earlier in 2026 after Togo's .tg registry was compromised. In 2011, attackers who breached the Dutch certificate authority DigiNotar forged a wildcard certificate for google.com and used it against internet users in Iran. Google's threat researchers have also tracked a campaign called Sea Turtle, which used stolen credentials to hijack domains on several ccTLD registries and obtain certificates for them.startupfortune
"This incident didn't need a zero-day in OpenSSL or a cryptographic break," Startup Fortune wrote. "It needed an underfunded, undersecured government domain registry."startupfortune