Skip to main content

Tag: active directory certificate services

2 articles

Blurred Windows domain authentication screen on a computer terminal in a corporate office setting.

Certighost Exploit Hijacks Windows Domains With Authenticated Attacks

Beware of the Certighost exploit, a sneaky attack that lets hackers hijack Windows domains by manipulating machine account attributes and snagging authentication certificates. This vulnerability, tracked as CVE-2026-54121, was patched in July 2026, but not before security researchers publicly disclosed its technical details.

Analyst 207
Windows office workstations with computers and monitors in daylight-lit setting, highlighting potential vulnerabilities in…

Attackers Exploit AD CS for Stealthy Privilege Escalation

Malicious actors are exploiting weaknesses in Active Directory Certificate Services (AD CS) to secretly escalate privileges, often disguising their attacks as routine administrative actions. This stealthy tactic allows them to blend in with normal operations, making it a high-impact threat that's often under-monitored.

Analyst 207