My primary question is how is this possible?
(It does look like the malicious ad is no longer being served, through.)
The correct solution is for a public information campaign to inform everyone never to click on any "Ad" link in any Google search ever. It's the only way to prevent our parents and grandparents from being phished, hijacked, or worse.