{
  "id": 12737292,
  "title": "Attackers hijacked top-level domains, minted fake security certs for Google and other orgs",
  "url": "https://urgent.news/2026/10/07/attackers-hijacked-top-level-domains-minted-fake-security-certs-for-12737292",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-10-07T19:38:06.000Z",
  "source": {
    "name": "The Register",
    "slug": "the-register",
    "url": "https://www.theregister.com/security/2026/10/07/attackers-hijacked-top-level-domains-minted-fake-security-certs-for-google-and-other-orgs/5301718"
  },
  "original_language": "en",
  "account": "Hackers have seized control of key internet addresses, creating fake security certificates for major companies like Google and others. By manipulating DNS records, they minted fraudulent HTTPS certificates for domains belonging to Google and other organizations in the .gh (Ghana), .sl (Sierra Leone), and .as (American Samoa) country-code top-level namespaces (ccTLDs). Google detected the attacks last week and warned of the hijacks, stating that the certificates were obtained without authorization. The fraudulent certs did not compromise Google's systems directly. However, they allow attackers to impersonate legitimate sites, potentially intercepting or modifying data sent by users and distributing malware or phishing schemes. Google acknowledged that browser interventions, such as Chrome blocking suspected counterfeit certificates, are necessary but not foolproof for protecting users across all devices. To safeguard their domains, Google advises organizations to monitor Certificate Transparency logs for any suspicious certificates issued for their domains. They also suggest using restrictive Certification Authority Authorization records to control which Certificate Authorities can issue certificates for their domains, helping protect domains once DNS control is restored.",
  "summary": "Trusted brand impersonation without the usual browser certificate warnings spells trouble",
  "key_points": [],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 2,
    "also_reported_by": [
      {
        "outlet": "The Register Science",
        "title": "Attackers hijacked top-level domains, minted fake security certs for Google and other orgs",
        "url": "https://urgent.news/2026/10/07/attackers-hijacked-top-level-domains-minted-fake-security-certs-for",
        "published": "2026-10-07T19:38:06.000Z"
      }
    ]
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}