TL;DR Researchers have published full technical details and working proof-of-concept code for Certighost, tracked as CVE-2026-54121. The...
active directory
At a glance Actor or group Unnamed Russian-speaking crew tracked as Operation STANDOFF; self-branded “GG Influence” and...
TL;DR ManageEngine patched a critical ADAudit Plus vulnerability tracked as CVE-2026-6516. Two weaknesses in the product’s Agent...
TL;DR Synacktiv publicly disclosed a Kerberos reflection bypass tracked as CVE-2026-26128. The flaw lets a domain user...
A sophisticated new threat actor, UNC6692, is redefining the art of the initial breach. According to a...
The Warlock ransomware group (also tracked as Water Manaul) has significantly sharpened its claws. A recent deep-dive...
The SentinelOne Digital Forensics & Incident Response (DFIR) team issued a warning: the very appliances designed to...
The SafeBreach Labs research team has pulled back the curtain on a significant security weakness in the...
A severe vulnerability has been discovered in ASUSTOR ADM (ASUSTOR Data Master), the operating system that powers...
ManageEngine has issued a critical security alert for ADSelfService Plus, its widely used self-service password management and...
Fortinet has issued a warning regarding the active exploitation of a three-year-old vulnerability that allows attackers to...
A newly disclosed Windows vulnerability, CVE-2025-58726, allows attackers with low privileges to gain SYSTEM-level access remotely by...
The Samba Team has released an urgent security advisory addressing two vulnerabilities, including a critical command injection...
At DEF CON 2025, Akamai security researcher Yuval Gordon revealed the story of BadSuccessor (CVE-2025-53779), an Active...
Recently, eSentire’s Threat Response Unit (TRU) investigated a ransomware attack that it has attributed to an affiliate...
SafeBreach Labs researchers have uncovered a new class of denial-of-service (DoS) vulnerabilities in Microsoft Windows that could...
Security researcher Ron Ben Yizhak from SafeBreach Labs has uncovered a novel attack technique dubbed Endpoint Mapper...
A recent investigation by SpecterOps has uncovered a chain of critical vulnerabilities in OneLogin’s Active Directory (AD)...
Researchers at NetSPI detailed a spoofing vulnerability (CVE-2025-26685) in Microsoft Defender for Identity (MDI). This flaw, while...
A newly disclosed vulnerability, CVE-2025-33073, revealed by RedTeam Pentesting GmbH, exposes a critical flaw in Microsoft Windows’...
Weaponizing Group Policy: Custom Client-Side Extensions as a Stealthy Backdoor into Active Directory
Weaponizing Group Policy: Custom Client-Side Extensions as a Stealthy Backdoor into Active Directory
A newly published report by Antoine Cauchois, Staff Research Engineer at Tenable, reveals a stealthy persistence technique...
Akamai security researcher Yuval Gordon has uncovered an Active Directory privilege escalation vulnerability in Windows Server 2025,...