suspectedhighSupply chainFirst reported Oct 7, 2026 · Disclosed Oct 6, 2026
ccTLD registries (.gh, .sl, .as): compromise used to issue unauthorized HTTPS certificates
Attackers compromised the .gh, .sl and .as country-code domain registries and used that access to obtain unauthorized HTTPS certificates for Google and other organizations. In an October 6 disclosure, Google said Chrome automatically blocked the identified certificates and it worked with certificate authorities to revoke those covering its properties.
Members only
The full record: the timeline and 3 linked reports
- Every update as it happened, with the status at each step
- Every report behind the record, newest first
- Alerts the moment .gh, .sl and .as ccTLD registries — or anything else you track — is hit again
A free account is all it takes — no card, one minute.