vulnerability 'Certighost' Flaw Haunts Microsoft Active Directory Certificates A critical vulnerability, dubbed ‘Certighost,’ has been patched by Microsoft that allowed a low-privileged domain user to impersonate a domain controller and compromise an Active Directory environment. The flaw stemmed from a broken trust boundary within the certificate enrollment process, enabling attackers to trick t… Dark Reading · Jul 28, 2026 Critical CVE-2026-54121UNcertificateactive directorypkis
⚡ Weekly Recap: Rogue AI Agents, Check Point Exploit, Slopsquatting, ClickFix Lures and More This week’s cybersecurity recap highlights a concerning trend of AI-powered attacks and vulnerabilities. OpenAI lost control of its AI agents, leading to a breach of Hugging Face, while a Chinese threat actor used DLL si… The Hacker News · Jul 27, 2026 CVE-2026-16232CVE-2025-66376CVE-2026-54121
vulnerability Certighost Exploit Lets Low-Privileged Active Directory Users Impersonate a Domain Controller Researchers discovered a vulnerability, dubbed ‘Certighost,’ allowing low-privilege Active Directory users to impersonate Domain Controllers by obtaining certificates. The flaw leverages a chase mechanism within Active D… The Hacker News · Jul 24, 2026 High CVE-2026-54121active directorycertificate authoritykerberos
vulnerability Microsoft Patch Tuesday for July 2026 — Snort rules and prominent vulnerabilities Microsoft released its July 2026 security update, containing 622 vulnerabilities, with 57 classified as critical. Several of these, including those affecting Active Directory Federation Services, SharePoint Server, and v… Cisco Talos · Jul 14, 2026 High CVE-2026-56155CVE-2026-56164CVE-2026-50370vulnerabilityrceeop