Tag: domain compromise
2 articles

Certighost Exposes Hidden Privilege Risks in Certificate Authorities
A single misstep in a Certificate Authority can have devastating consequences, as seen in CVE-2026-54121, aka Certighost, which allows a low-privileged domain user to escalate to full domain compromise. This shocking vulnerability exploits a little-known "chase" functionality in Active Directory Certificate Services.

Certighost Exploit Hijacks Windows Domains With Authenticated Attacks
Beware of the Certighost exploit, a sneaky attack that lets hackers hijack Windows domains by manipulating machine account attributes and snagging authentication certificates. This vulnerability, tracked as CVE-2026-54121, was patched in July 2026, but not before security researchers publicly disclosed its technical details.