The certificates were issued correctly — the attackers controlled the DNS, which is all the check asks for
2026-10-10Security
Three country-code registries were compromised and unauthorized HTTPS certificates were obtained for Google domains and others. No certificate authority broke a rule. Domain control validation proves control of a name, and for a while the attackers had it.