Hackers obtain counterfeit TLS certificates for Google and other large services
AI-rewritten: This is a summary of an article from Ars Technica, rewritten by AI (Qwen, running locally) to make it easier to read. The facts come from the original article – read it for the full story.
Dan Goodin
• October 6, 2026
Hackers hijacked three top-level domains and used that control to create counterfeit TLS certificates for Google and other major organizations, according to Google. The attackers modified authoritative DNS records for selected domains within the .gh, .sl, and .as country code namespaces. This allowed them to pass automated domain control validation checks and issue unauthorized certificates for several Google domains and other leading global brands. Google stated it updated Chrome to block all identified unauthorized certificates and worked with certification authorities to revoke those issued for Google properties.