Attackers hijacked the operators of three country-code top-level domains (.gh, .sl, and .as) and used the access to obtain unauthorized HTTPS certificates for Google domains and other major organizations. Google responded by blocking and revoking these certificates in Chrome and collaborating with certificate authorities and affected entities, but warned that browser-side protections may not cover all impacted domains or users of other browsers. The company emphasized ongoing efforts to strengthen HTTPS ecosystem security and mitigate risks from DNS and routing compromises.
https://www.helpnetsecurity.com/2026/10/07/google-unauthorized-https-certificates-cctld-hijacks/

