Trusence Every claim has a source
Last updated 8 October 2026 Search Türkçe
← All stories
Security

Fake TLS certificates issued for Google and other major services

Google moved to block the certificates in Chrome after the hijack, limiting the risk for users of affected sites.

Google says attackers used hijacked DNS control over the .gh, .sl, and .as country-code domains to obtain fake TLS certificates for some Google domains and other widely used services. The company says its own systems were not breached, and that it moved quickly to block the certificates in Chrome while coordinating revocation with certificate authorities. Google also said Certificate Transparency logs later showed more affected organizations, including major global brands, so it expanded the browser blocks. For domain operators, the incident is a reminder to watch CT logs closely and publish restrictive CAA records, even though those records cannot stop issuance during an active DNS hijack.

Why it matters

The immediate impact falls on the operators of the affected domains and the people who rely on them, because a DNS hijack can lead to certificates being issued without the owner’s approval. Google’s response also shows that browser blocking and revocation can narrow exposure, but the incident makes CT log monitoring and restrictive CAA records more important for domain owners. CAA records still do not prevent issuance during an active DNS hijack, so the protection depends on spotting and reacting to misuse quickly.

Sources

  • Ars Technica
  • BleepingComputer