< ciso
brief />
Tag Banner

All news with #active directory tag

41 articles

Certighost: Privilege Risks in Your Certificate Authority

🔒 Certighost (CVE-2026-54121) demonstrates how a standard domain user can coerce an Enterprise CA to issue a Domain Controller certificate via AD CS "chase" behavior. The flaw allows an attacker to obtain PKINIT authentication as a DC, perform DCSync, and escalate to domain compromise. Microsoft patched the issue on July 14, 2026; mitigate by patching, restricting CA outbound access, and reducing MachineAccountQuota.
read more →

A decade of AWS Managed Microsoft AD evolution

🔒 Over ten years, AWS Managed Microsoft AD evolved from a basic managed Microsoft Active Directory offering into a foundational enterprise identity service integrated across more than 20 AWS services. The service reduced operational overhead by handling domain controllers, HA, backups, patching, and replication while adding features like schema extensions, gMSA, multi-Region replication, and CRUD APIs. Recent additions include Hybrid Edition, self-service edition upgrades, and integrations for database, file, and remote-access authentication.
read more →

Proof‑of‑Concept for Certighost AD CS Exploit

🔒 A proof-of-concept exploit for the “Certighost” Active Directory Certificate Services vulnerability (CVE-2026-54121) was released after Microsoft patched the issue in the July 2026 Patch Tuesday updates. Researchers showed how a low-privileged user can abuse the AD CS “chase” fallback to have a CA contact an attacker-controlled host and issue certificates for targeted machine accounts. The exploit automates PKINIT authentication as a domain controller to obtain Kerberos credentials and perform domain-level actions; Microsoft added validation to the chase process as a fix.
read more →

Certighost flaw in AD CS lets attackers spoof DCs

🛡️ Researchers disclosed "Certighost," a vulnerability in Microsoft Active Directory Certificate Services (AD CS) that lets a low‑privilege domain user trick the CA into issuing certificates impersonating a Domain Controller. The issue abuses a directory-object resolution fallback called a "chase," where attacker-controlled identity data supplied via attributes like cdc can be used by the CA during issuance. Microsoft patched the flaw in its July 2026 updates and researchers provided a temporary policy-based mitigation for environments that cannot immediately install the patch.
read more →

Certighost AD CS exploit lets low-privileged users

🔒 Researchers published a working exploit on July 24 that lets a low-privileged Active Directory user obtain a certificate for a Domain Controller and authenticate as that machine. Codenamed Certighost, the flaw enables a Kerberos credential capable of DCSync to retrieve the krbtgt secret. Microsoft patched AD CS as CVE-2026-54121 on July 14 and rated it a CVSS 8.8; the full proof-of-concept was released publicly.
read more →

Agentic ChatGPT-5.5 Executes Full Network Attacks

🛡️ Cato Networks found a single prompt can cause OpenAI’s GPT-5.5 to plan and execute a full offensive cyber-attack in a controlled Active Directory lab. The model carried out reconnaissance, exploitation, lateral movement, privilege escalation and exfiltration, reaching domain admin in about 40 minutes. Researchers tested six scenarios, noting adaptive behavior when conditions changed and emphasizing the risk of accelerating existing attack workflows.
read more →

AI-assisted PowerShell used for noisy AD reconnaissance

🛡️ Huntress investigators reported an early-June 2026 intrusion where an unknown actor used a vibe-coded PowerShell script to enumerate Active Directory. The attacker gained RDP access with pre-compromised credentials, staged tools under C:\ProgramData\, and executed an AI-suspected payload that mapped DCs, users, groups, OUs, trusts, and produced an AD_Report.html. After harvesting data into CSVs and archiving them, files were exfiltrated to a remote server, with additional enumeration using s5cmd and SharpShares.
read more →

Recovering active ADFS signing keys via Machine DPAPI

🛡️ This post examines how ADFS token-signing private keys persisted in the machine-scoped key store and protected by Machine DPAPI can be recovered by a sufficiently privileged local context. It describes a red team finding where manual certificate rotations with AutoCertificateRollover disabled created configuration drift, leaving active signing keys exposed in Machine DPAPI and enabling forged SAML assertions. The article outlines extraction details, detection guidance, and mitigation measures including HSM use and configuration validation.
read more →

Amazon RDS for Db2 adds self-managed Active Directory support

🔒 Amazon RDS for Db2 now lets customers join DB instances directly to self-managed Microsoft Active Directory domains, whether on-premises, in AWS, or in another cloud. Using Kerberos for authentication, this enables single sign-on and allows customers to authenticate and authorize database users without deploying AWS Managed Microsoft AD or creating a domain trust. Domain join is available when creating or modifying instances using a delegated AD service account stored in AWS Secrets Manager and encrypted with AWS KMS, and the feature is generally available in all Regions where RDS for Db2 is offered, including GovCloud.
read more →

Legacy Infrastructure Enables AI Agent Hijacking

🔒 This article explains how attackers bypass AI security by exploiting legacy infrastructure that AI agents inherit, such as Active Directory, cloud storage, and unpatched servers. It outlines a staged attack where a CVE-exploited perimeter server leads to credential theft, lateral movement, and compromise of an AI Co-Pilot's knowledge base. The piece urges exposure management that maps dependencies and fixes choke points to protect AI environments.
read more →

Unpatched Windows search: URI leaks NTLMv2 hashes

🔒 Researchers disclosed an unpatched Windows issue that can expose a user's NTLMv2 hash via the search: URI handler. Similar to CVE-2026-33829 in the Snipping Tool, the flaw leverages a crumb=location: parameter to force an SMB connection and trigger NTLM authentication. The weakness produces the same Net-NTLMv2 leak and attack prerequisites, and Microsoft declined to patch it after responsible disclosure.
read more →

AI-built ransomware toolkit automates EDR evasion

🛡️ A threat actor used an AI-assisted ransomware toolkit to automate Active Directory discovery and iterate EDR evasion techniques. Researchers found Cursor and Claude Opus agents used for coding, analysis, testing, and checking public research for bypass methods, with some malware tested against Sophos, CrowdStrike, and Microsoft EDR products. Sophos determined the workflow was human-directed, while AI accelerated development, producing numerous payload modules and mapping techniques to MITRE ATT&CK.
read more →

Active Directory Certificate Services: Exploitation Risks

🔐 This Unit 42 report examines how misconfigured Active Directory Certificate Services (AD CS) components create high-impact attack surfaces that enable privilege escalation, identity impersonation, and persistent access. It details exploitation techniques—especially certificate template misconfigurations and shadow credential abuse—tools observed in the wild, and a five-phase adversary lifecycle. The report emphasizes behavioral detection, telemetry correlation, and mitigation guidance to help defenders close monitoring gaps.
read more →

AWS Adds STIG-Aligned Security Settings to Managed AD

🔒 AWS Directory Service for Microsoft Active Directory (AWS Managed Microsoft AD) now offers expanded STIG-aligned security settings focused on high-impact directory controls. These settings are available today through a self-service interface, both programmatically and via the AWS Management Console, enabling administrators to declare desired configurations and have AWS implement and persist them. When new domain controllers are added or directories are scaled or deployed in additional regions, AWS automatically applies the declared settings to new instances to maintain consistency.
read more →

Autonomous Exposure Validation: Webinar on AI-Driven Threats

🔒 In February 2026 researchers flagged a major shift: threat actors now deploy custom AI agents that automate attacks through the kill chain, from Active Directory mapping to rapid Domain Admin takeover. Join a technical webinar with Picus Security leaders Kevin Cole and Gursel Arici for a deep dive into Autonomous Exposure Validation. Learn how to safely ingest threat intelligence, simulate attacks, and close the gap between CTI, Red, and Blue teams to speed detection and remediation.
read more →

AWS Managed Microsoft AD upgraded to 2016 functional level

🔒 AWS has automatically upgraded all AWS Managed Microsoft AD directories to the Windows functional level 2016, effective Apr 20, 2026. The update delivers enhanced authentication and improved privileged access management and enables built-in LAPS to generate unique, complex local administrator passwords stored securely in Active Directory. The upgrade is applied in all Regions where the service is available, except Middle East (UAE) and Middle East (Bahrain). See the AWS Directory Service Administration Guide for details.
read more →

Microsoft: April update causes domain controller loops

⚠️After installing the April 2026 Windows security update (KB5082063), some non‑Global Catalog domain controllers configured with Privileged Access Management (PAM) may experience Local Security Authority Subsystem Service (LSASS) crashes during startup. Affected servers can enter repeated reboot loops, disrupting authentication and directory services and potentially rendering domains unavailable. Microsoft is investigating and advises administrators to contact Microsoft Support for Business for mitigation options until a permanent fix is released.
read more →

Core infrastructure engineer pleads guilty in insider attack

🔒 A core infrastructure engineer, Daniel Rhyne, pleaded guilty on April 1 after launching an insider extortion attack that used routine admin tools and techniques to disable systems and accounts. He initiated unauthorized RDP sessions, deleted administrator accounts, changed passwords, and scheduled tasks on the domain controller, then claimed to have erased backups while demanding roughly $750,000 in bitcoin. Security experts say the methods were alarmingly predictable and could have been prevented by immutable backups, strict least privilege controls, and behavioral alerts for high‑risk tools.
read more →

AWS Managed Microsoft AD Adds Multi-Region in Opt-In Regions

🔁 AWS Directory Service for Microsoft Active Directory (AWS Managed Microsoft AD) now supports Multi-Region replication in AWS Opt-In regions. The automated feature deploys domain controllers across Availability Zones per region, handles inter-region networking, and replicates users, groups, Group Policy Objects, and schema to maintain a single authoritative directory. It configures an Active Directory site per region to optimize authentication performance and reduce cross-region transfer costs; availability excludes the Middle East (UAE) and Middle East (Bahrain) regions and pricing is hourly per domain controller plus data transfer.
read more →

Detecting Kerberos Relay via DNS CNAME Abuse and Mitigation

🔒 CrowdStrike outlines detection for CVE-2026-20929, a Kerberos relay vulnerability exploited via DNS CNAME abuse that can enroll certificates from Active Directory Certificate Services (AD CS). Their correlation-based detection flags anomalous certificate-based authentications coincident with unusual AD CS Kerberos service access within a short time window. Customers can enable the provided CRT rule in Falcon Next‑Gen SIEM to activate alerts and support hunting.
read more →