news.mlab.sh
2 results
vulnerability

Certighost Exploit Lets Low-Privileged Active Directory Users Impersonate a Domain Controller

Researchers discovered a vulnerability, dubbed ‘Certighost,’ allowing low-privilege Active Directory users to impersonate Domain Controllers by obtaining certificates. The flaw leverages a chase mechanism within Active Directory Certificate Services (AD CS), enabling attackers to steal Kerberos secrets and gain full do…

The Hacker News · Jul 24, 2026 High