BreachFeed
← All incidents
suspectedhighSupply chainFirst reported Oct 7, 2026 · Disclosed Oct 6, 2026

ccTLD registries (.gh, .sl, .as): compromise used to issue unauthorized HTTPS certificates

Attackers compromised the .gh, .sl and .as country-code domain registries and used that access to obtain unauthorized HTTPS certificates for Google and other organizations. In an October 6 disclosure, Google said Chrome automatically blocked the identified certificates and it worked with certificate authorities to revoke those covering its properties.

Members only

The full record: the timeline and 3 linked reports

  • Every update as it happened, with the status at each step
  • Every report behind the record, newest first
  • Alerts the moment .gh, .sl and .as ccTLD registries — or anything else you track — is hit again

A free account is all it takes — no card, one minute.

ccTLD registries (.gh, .sl, .as): compromise used to issue unauthorized HTTPS certificates · BreachFeed