
Oct 9, 2026 · 8 min
Attackers allegedly hijack registries to obtain Google certificates
Top level domain theft, Yandex attacked, Cisco Nexus flaws
The incident exposes how weaknesses in domain-registry controls can undermine the trust model behind HTTPS certificates.
- 1Attackers allegedly compromised the .gh, .sl, and .as registries to obtain unauthorized certificates for Google and other organizations.
- 2The case links domain-registry security to certificate issuance, showing how failures in one layer can weaken trust across the web.
- 3The briefing places the registry compromise alongside attacks involving Yandex and Cisco Nexus flaws.
Don't miss
The briefing connects alleged access to three country-code registries with unauthorized HTTPS certificates for Google domains.
The brief
The briefing focuses on an alleged compromise of the .gh, .sl, and .as country-code domain registries, turning obscure registry access into a web-trust problem.
Attackers allegedly used that access to obtain unauthorized HTTPS certificates for Google domains and other organizations, raising questions about who can authorize encrypted connections.
The episode’s central tension is that HTTPS depends on more than browser security: weaknesses in domain registries and certificate issuance can combine into a larger failure.
Google appears in the story because the alleged certificates targeted its domains, making the registry compromise consequential beyond the countries whose top-level domains were involved.
The briefing closes by placing the incident within the broader Cybersecurity Headlines series, which covers the full stories behind its weekday headlines.