< ciso
brief />
Tag Banner

All news with #active directory tag

49 articles

Soldier Sentenced for Major Telecom Data Extortion

🔒 A U.S. Army soldier pleaded guilty to hacking multiple telecom firms and stealing mobile call and text metadata for over 100 million AT&T customers, and was sentenced to 70 months in federal prison with nearly $300,000 restitution. Operating as “Kiberphant0m” from a base in South Korea, he and alleged co-conspirators accessed Snowflake-stored data lacking MFA, extorted providers including Verizon, and later re-extorted victims with purported national security materials. Authorities linked co-conspirators to prior large-scale cybercrime, and investigators highlighted the unique insider threat posed by an active-duty soldier with secret clearance. While Wagenius cooperated, prosecutors noted prison attempts to probe system vulnerabilities and to prompt AI for exploit code; despite the scale of stolen data, his extortion proceeds were minimal.
read more →

Windows 11 update breaks domain trust for some

🔒 Microsoft is investigating reports that the Windows 11 KB5124008 security update is breaking domain trust on some enterprise systems, preventing valid domain logins. Administrators report that affected devices lose their secure channel with Active Directory after reboot and observed Kerberos and NTLM failures. The issue may be linked to the Machine Identity Isolation setting, especially when set to enforcement mode, and some have restored access by adjusting registry values and repairing the secure channel.
read more →

Three threat groups target Russian enterprises

🔒 Kaspersky reports three distinct threat clusters—NightEagle, Hacking Cat, and Toy Ghouls—are actively targeting Russian enterprises using novel persistence, lateral movement, and destructive techniques. NightEagle leverages GhostContainer against Microsoft Exchange and abuses tunnels and Active Directory exploits for persistence. Hacking Cat has shifted to Gorilla RAT and multiple Monkey ransomware variants, while Toy Ghouls deploys a custom Bird Agent backdoor using HiveMQ and Matrix for C2.
read more →

Teams and New Outlook Fail to Launch on ARM PCs

🔧 Microsoft is addressing a known bug causing Microsoft Teams and the new Outlook to crash or fail to launch on ARM-based Windows devices after August 2026 updates. The issue mainly affects Surface Pro 11 and Surface Laptop 7 running Windows 11 24H2 or later, particularly on new or freshly imaged PCs without Microsoft Store updates. As a temporary workaround, Microsoft advises installing the Auto Super Resolution Package (v1.0.19.0+) via Microsoft Store. A permanent fix will be delivered in a future Windows update.
read more →

Impersonating IT Support to Gain Enterprise Access

🛡️ Microsoft Threat Intelligence observed a human-operated campaign abusing Microsoft Teams external collaboration to impersonate IT support and socially engineer users into granting interactive remote sessions. Attackers install a malicious MSI that stages a portable Node.js runtime and an obfuscated JavaScript implant to provide persistent C2-driven command execution. The operators perform extensive host and Active Directory reconnaissance and pivot enterprise-wide via WinRM, using legitimate tooling to blend into normal operations.
read more →

Managing Identity Source Transitions for IAM Identity Center

🔐 This AWS blog explains how to plan and execute an identity source transition in AWS IAM Identity Center, focusing on migrations such as Active Directory to Okta. It outlines destructive and non‑destructive transition scenarios, a five‑step migration runbook, and prerequisites including backup, validation, SCIM configuration, and restore processes. The post also references sample scripts and a migration tool on GitHub to automate prechecks, cutover, validation, and cleanup.
read more →

Elastic Beanstalk adds Active Directory domain join

🔒 AWS Elastic Beanstalk now automatically joins Windows Server instances to an Active Directory domain managed with AWS Directory Service. Previously requiring custom join scripts, the new feature uses configuration options so every instance, including those launched by auto scaling, joins the domain at boot before application deployment. Domain-joined instances can use Windows-integrated authentication, group policy, and access domain resources, and the join process is resilient so failures don't block deployments.
read more →

TerminalFix campaign uses reverse-tunnel to pivot

🛡️ Microsoft Threat Intelligence details a TerminalFix campaign, a ClickFix variant that lures users with a fake Cloudflare Turnstile overlay and tricks them into pasting a malicious PowerShell command into Windows Terminal or PowerShell. The command drops a ZIP with a legitimate executable and a malicious DLL that is sideloaded, then uses steganography to extract further payloads from PNG images, establishes dual persistence, performs extensive Active Directory reconnaissance, and deploys a Python-based reverse-tunnel implant for SOCKS-style network access. The chain enables persistent, network-level proxy access and increases risk of lateral movement and data or credential theft.
read more →

Certighost: Privilege Risks in Your Certificate Authority

🔒 Certighost (CVE-2026-54121) demonstrates how a standard domain user can coerce an Enterprise CA to issue a Domain Controller certificate via AD CS "chase" behavior. The flaw allows an attacker to obtain PKINIT authentication as a DC, perform DCSync, and escalate to domain compromise. Microsoft patched the issue on July 14, 2026; mitigate by patching, restricting CA outbound access, and reducing MachineAccountQuota.
read more →

A decade of AWS Managed Microsoft AD evolution

🔒 Over ten years, AWS Managed Microsoft AD evolved from a basic managed Microsoft Active Directory offering into a foundational enterprise identity service integrated across more than 20 AWS services. The service reduced operational overhead by handling domain controllers, HA, backups, patching, and replication while adding features like schema extensions, gMSA, multi-Region replication, and CRUD APIs. Recent additions include Hybrid Edition, self-service edition upgrades, and integrations for database, file, and remote-access authentication.
read more →

Proof‑of‑Concept for Certighost AD CS Exploit

🔒 A proof-of-concept exploit for the “Certighost” Active Directory Certificate Services vulnerability (CVE-2026-54121) was released after Microsoft patched the issue in the July 2026 Patch Tuesday updates. Researchers showed how a low-privileged user can abuse the AD CS “chase” fallback to have a CA contact an attacker-controlled host and issue certificates for targeted machine accounts. The exploit automates PKINIT authentication as a domain controller to obtain Kerberos credentials and perform domain-level actions; Microsoft added validation to the chase process as a fix.
read more →

Certighost flaw in AD CS lets attackers spoof DCs

🛡️ Researchers disclosed "Certighost," a vulnerability in Microsoft Active Directory Certificate Services (AD CS) that lets a low‑privilege domain user trick the CA into issuing certificates impersonating a Domain Controller. The issue abuses a directory-object resolution fallback called a "chase," where attacker-controlled identity data supplied via attributes like cdc can be used by the CA during issuance. Microsoft patched the flaw in its July 2026 updates and researchers provided a temporary policy-based mitigation for environments that cannot immediately install the patch.
read more →

Certighost AD CS exploit lets low-privileged users

🔒 Researchers published a working exploit on July 24 that lets a low-privileged Active Directory user obtain a certificate for a Domain Controller and authenticate as that machine. Codenamed Certighost, the flaw enables a Kerberos credential capable of DCSync to retrieve the krbtgt secret. Microsoft patched AD CS as CVE-2026-54121 on July 14 and rated it a CVSS 8.8; the full proof-of-concept was released publicly.
read more →

Agentic ChatGPT-5.5 Executes Full Network Attacks

🛡️ Cato Networks found a single prompt can cause OpenAI’s GPT-5.5 to plan and execute a full offensive cyber-attack in a controlled Active Directory lab. The model carried out reconnaissance, exploitation, lateral movement, privilege escalation and exfiltration, reaching domain admin in about 40 minutes. Researchers tested six scenarios, noting adaptive behavior when conditions changed and emphasizing the risk of accelerating existing attack workflows.
read more →

AI-assisted PowerShell used for noisy AD reconnaissance

🛡️ Huntress investigators reported an early-June 2026 intrusion where an unknown actor used a vibe-coded PowerShell script to enumerate Active Directory. The attacker gained RDP access with pre-compromised credentials, staged tools under C:\ProgramData\, and executed an AI-suspected payload that mapped DCs, users, groups, OUs, trusts, and produced an AD_Report.html. After harvesting data into CSVs and archiving them, files were exfiltrated to a remote server, with additional enumeration using s5cmd and SharpShares.
read more →

Recovering active ADFS signing keys via Machine DPAPI

🛡️ This post examines how ADFS token-signing private keys persisted in the machine-scoped key store and protected by Machine DPAPI can be recovered by a sufficiently privileged local context. It describes a red team finding where manual certificate rotations with AutoCertificateRollover disabled created configuration drift, leaving active signing keys exposed in Machine DPAPI and enabling forged SAML assertions. The article outlines extraction details, detection guidance, and mitigation measures including HSM use and configuration validation.
read more →

Amazon RDS for Db2 adds self-managed Active Directory support

🔒 Amazon RDS for Db2 now lets customers join DB instances directly to self-managed Microsoft Active Directory domains, whether on-premises, in AWS, or in another cloud. Using Kerberos for authentication, this enables single sign-on and allows customers to authenticate and authorize database users without deploying AWS Managed Microsoft AD or creating a domain trust. Domain join is available when creating or modifying instances using a delegated AD service account stored in AWS Secrets Manager and encrypted with AWS KMS, and the feature is generally available in all Regions where RDS for Db2 is offered, including GovCloud.
read more →

Legacy Infrastructure Enables AI Agent Hijacking

🔒 This article explains how attackers bypass AI security by exploiting legacy infrastructure that AI agents inherit, such as Active Directory, cloud storage, and unpatched servers. It outlines a staged attack where a CVE-exploited perimeter server leads to credential theft, lateral movement, and compromise of an AI Co-Pilot's knowledge base. The piece urges exposure management that maps dependencies and fixes choke points to protect AI environments.
read more →

Unpatched Windows search: URI leaks NTLMv2 hashes

🔒 Researchers disclosed an unpatched Windows issue that can expose a user's NTLMv2 hash via the search: URI handler. Similar to CVE-2026-33829 in the Snipping Tool, the flaw leverages a crumb=location: parameter to force an SMB connection and trigger NTLM authentication. The weakness produces the same Net-NTLMv2 leak and attack prerequisites, and Microsoft declined to patch it after responsible disclosure.
read more →

AI-built ransomware toolkit automates EDR evasion

🛡️ A threat actor used an AI-assisted ransomware toolkit to automate Active Directory discovery and iterate EDR evasion techniques. Researchers found Cursor and Claude Opus agents used for coding, analysis, testing, and checking public research for bypass methods, with some malware tested against Sophos, CrowdStrike, and Microsoft EDR products. Sophos determined the workflow was human-directed, while AI accelerated development, producing numerous payload modules and mapping techniques to MITRE ATT&CK.
read more →