Researchers H0j3n and Aniq Fakhrul disclosed a proof-of-concept exploit named Certighost for CVE-2026-54121, an Active Directory Certificate Services (AD CS) vulnerability patched by Microsoft on July 14, 2026. The flaw allows a low-privileged Active Directory user to obtain a Domain Controller certificate and authenticate as that machine using PKINIT, ultimately enabling DCSync attacks to extract sensitive credentials such as the krbtgt hash. Exploitation requires only a standard domain account, network access, and a vulnerable Enterprise Certification Authority (CA), without administrator privileges or user interaction. The vulnerability exists in the AD CS enrollment "chase" process, where the Certification Authority trusts attacker-controlled SMB and LDAP endpoints without properly validating that they belong to a legitimate Domain Controller. Attackers can relay authentication through Netlogon, impersonate a Domain Controller, and obtain a valid certificate for the targeted machine. The public exploit automates the attack by creating or reusing a machine account, relaying authentication, and generating Kerberos credentials capable of compromising the entire Active Directory domain. Microsoft's July security update introduces strict validation of chase targets, including DNS name, SID, and SERVER_TRUST_ACCOUNT verification, preventing unauthorized certificate issuance. Organizations should immediately deploy the July 2026 AD CS updates, monitor certificate enrollment activity, and restrict unnecessary machine account creation. Researchers also provided a temporary mitigation by disabling the chase fallback, although it may impact legitimate certificate enrollment workflows. While no confirmed in-the-wild exploitation has been reported, the availability of a public exploit significantly increases the risk to unpatched environments.
At the core of an advanced malvertising attack scheme known as FakeAgent, SectopRAT was utilized by the cybercriminals in exploiting Anthropic’s Claude platform for the distribut...
Researchers at Group-IB have uncovered a previously undocumented cyber espionage campaign, tracked as JadeProx, targeting government, healthcare, and education organizations across...
A new Lampion malware campaign is actively targeting users in Portugal through highly localized phishing emails impersonating financial and administrative communications. Originall...