#kerberos

3 posts · Last used 19d

Back to Timeline
thecybersecguru @thecybersecguru@infosec.exchange · Jul 26, 2026
🚨 Low-privileged Active Directory user → Full Domain Admin? A new AD CS vulnerability called Certighost (CVE-2026-54121) makes it possible. The attack abuses the certificate enrollment "chase" mechanism to obtain a Domain Controller certificate, authenticate via PKINIT, perform DCSync, and ultimately extract the krbtgt secret for complete Active Directory compromise. ✅ No admin privileges required ✅ Public PoC available ✅ Patched by Microsoft, but unpatched Enterprise CAs remain at risk I break down: • How the exploit works internally • Why AD CS trusts the wrong host • PKINIT → DCSync attack chain • Microsoft's patch and new validation logic • Detection and mitigation guidance 🔗 https://thecybersecguru.com/news/certighost-cve-2026-54121-ad-cs-domain-controller-impersonation/ #CyberSecurity #ActiveDirectory #ADCS #WindowsServer #Microsoft #PKINIT #Kerberos #DCSync #CVE202654121 #CVE #BlueTeam #RedTeam #ThreatDetection #InfoSec #SOC #Windows #Pentest #DFIR #CyberDefense
0
0
0
sekurak News @sekurakbot@mastodon.com.pl · Mar 06, 2026
Problemy NTLM: drugie starcie. Wymuszenie uwierzytelnienia NTLM Wstęp W poprzednim artykule poświęconym NTLM, rozebraliśmy na czynniki pierwsze podstawowe pojęcia: czym jest NetNTLM a czym hash NT, jak można przeprowadzić ataki polegające na przechwyceniu challenge NetNTLM  oraz na czym polegają podatności typu relay.   Jeżeli powyższe pojęcia nie są dla Ciebie zrozumiałe, to przed przystąpieniem do dalszej lektury, koniecznie... #Aktualności #Teksty #ActiveDirectory #Coercion #Kerberos #Ntlm #Windows https://sekurak.pl/problemy-ntlm-drugie-starcie-wymuszenie-uwierzytelnienia-ntlm/
0
0
0

You've seen all posts