Decrypted: The UK Cyber Briefing
Oct 8, 2026 · 5 min · 5 segments
Attackers took over the .gh, .sl and .as registries and obtained genuine HTTPS certificates for Google and others. The lesson for UK organisations sits below the website: who controls your DNS, and…
Last week, attackers took over the registries behind three country code domains.
The weakness sat a level below the website in the address book that the whole certificate system quietly trusts.
Next, a notary who phones the number in the directory.
Before a certificate authority issues a certificate, it checks that the applicant controls the domain.
Usually, that check reads the domain's DNS records.
That's the public directory that says where a name lives.
Imagine a notary asked to certify that a stranger owns a house.
The notary rings the number listed in the town hall directory.
If someone has rewritten the directory, the notary calls the burglar, hears the right answers, and stamps the paperwork.
The attackers changed authoritative DNS records at the registries, which let them pass the automated validation checks.
The certificates were real, and the browser padlock would have appeared.
The certificate authorities followed their rules.
The input they trusted had been poisoned, and also what a defender could see.
Every certificate that Chrome trusts by default must be disclosed in public certificate transparency logs.
Analysis of those logs is how the unauthorized certificates were found.
It said it cannot guarantee that its analysis found every affected domain, and it said Chrome's interventions do not reliably protect people using other browsers.
Last week, attackers took over the registries behind three country code domains.
The weakness sat a level below the website in the address book that the whole certificate system quietly trusts.
Next, a notary who phones the number in the directory.
Before a certificate authority issues a certificate, it checks that the applicant controls the domain.
Usually, that check reads the domain's DNS records.
That's the public directory that says where a name lives.
Imagine a notary asked to certify that a stranger owns a house.
The notary rings the number listed in the town hall directory.
If someone has rewritten the directory, the notary calls the burglar, hears the right answers, and stamps the paperwork.
The attackers changed authoritative DNS records at the registries, which let them pass the automated validation checks.
The certificates were real, and the browser padlock would have appeared.
The certificate authorities followed their rules.
The input they trusted had been poisoned, and also what a defender could see.
Every certificate that Chrome trusts by default must be disclosed in public certificate transparency logs.
Analysis of those logs is how the unauthorized certificates were found.
It said it cannot guarantee that its analysis found every affected domain, and it said Chrome's interventions do not reliably protect people using other browsers.
The rest of this transcript — segmented and speaker-labeled, so you land on the exact moment something was said
Search every transcript — by keyword, by phrase, or by meaning, across every show Radar indexes
Trends — what is surging across podcasts, measured against its own baseline
Alerts — when a name you follow appears in a newly indexed episode
No account is needed to search Radar.