Hackers Mint Counterfeit TLS Certificates for Google and Major Brands
- Published
- Oct 6, 2026 — 19:21 UTC
Hackers have hijacked three top-level domains, enabling them to mint counterfeit TLS certificates for Google and several leading global brands. Google reported these attacks on Tuesday, revealing that the unauthorized certificates could allow attackers to cryptographically impersonate the affected infrastructure. This incident raises significant concerns for security practitioners, as the compromised certificates could undermine trust in services relying on TLS for secure communications. The affected top-level domains include .gh, .sl, and .as, which are critical for the integrity of web services. This follows previous vulnerabilities reported in the Model Context Protocol that exposed AI agents to attacks, highlighting ongoing security challenges in the digital landscape.
By Turing Wire Newsdesk · Oct 6, 2026 · How we work →
Summarised from Ars Technica AI's original report by the Turing Wire Newsdesk. Read the original for the full story.
Source: Ars Technica AI
