New Exploit Allows Low-Privileged Users to Impersonate Active Directory Domain Controllers

AI-generated NewsSnap summary based on source reporting.
Published: 2026-07-24
Category: technology
Source: The Hacker News
Original source

Cybersecurity researchers have unveiled "Certighost," an exploit that enables low-privileged Active Directory users to obtain a Domain Controller certificate and impersonate the machine. This critical flaw, identified as CVE-2026-54121, was patched by Microsoft ten days prior to the exploit's public disclosure. The incident underscores the urgent need for organizations to apply security updates to Active Directory Certificate Services hosts promptly.

Want more?

Open NewsSnap.ai for the full app experience, including audio, personalization, and more news tools.

Open NewsSnap.ai