[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fxMVSKnWC84fhhI-Za8FXWi_mbujkzjbvGQvhhTdfEOA":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":23,"created_at":24,"published_at":25,"article":26,"tags":30,"podcasts":49},"a3e93bc5-6f6d-475f-abce-c88ee56d9664","certighost-exploit-enables-domain-controller-impersonation-via-ad-certificate-services","f3bb9fd4-4f1e-426d-a713-4b32ec3674c6","Certighost Exploit Enables Domain Controller Impersonation via AD Certificate Services","The Certighost exploit (CVE-2026-54121) exposes a critical flaw in Active Directory Certificate Services (AD CS) that allows any low-privileged domain user to obtain a Domain Controller certificate and perform DCSync attacks, ultimately retrieving the krbtgt secret. This is particularly dangerous because it requires no administrator privileges, no user interaction, and only basic network access — dramatically lowering the bar for full domain compromise. Once an attacker possesses the krbtgt hash, they can forge Golden Tickets and maintain persistent, undetected access across the entire domain. This attack class highlights how misconfigured or unpatched PKI infrastructure can silently undermine the entire security boundary of an Active Directory environment.","**Immediate actions:**\n- Apply Microsoft's patch for CVE-2026-54121 to all domain controllers and AD CS servers immediately.\n- Audit AD CS certificate templates to ensure no template grants low-privileged users the ability to enroll for Domain Controller or machine authentication certificates.\n- Restrict network access to AD CS enrollment endpoints to only authorized systems and administrators.\n\n**Long-term improvements:**\n- Implement the principle of least privilege for all AD CS enrollment permissions, removing unnecessary enrollment rights from default domain users.\n- Regularly review and harden AD CS configurations using tools such as Locksmith or PSPKIAudit to detect dangerous template misconfigurations.\n- Segment AD CS infrastructure from general-purpose network zones to limit lateral movement opportunities.\n\n**Detection measures:**\n- Monitor for unusual certificate enrollment events (Event IDs 4886, 4887) involving non-administrative accounts requesting Domain Controller authentication certificates.\n- Alert on unexpected DCSync activity (replication requests from non-DC accounts) using SIEM rules targeting Event ID 4662 with replication permissions.\n- Deploy honeypot Domain Controller accounts to detect Golden Ticket and DCSync abuse patterns in near real-time.",[12,13,14,15,16,17,18,19,20,21,22],"CIS Control 7: Continuous Vulnerability Management","CIS Control 5: Account Management","CIS Control 12: Network Infrastructure Management","NIST SP 800-53 SI-2: Flaw Remediation","NIST SP 800-53 AC-6: Least Privilege","NIST SP 800-53 AU-12: Audit Record Generation","NIST SP 800-53 SC-7: Boundary Protection","MITRE ATT&CK T1649: Steal or Forge Authentication Certificates","MITRE ATT&CK T1003.006: DCSync","NIST CSF ID.RA-1: Asset Vulnerabilities Identified","ITIL Change Management: Emergency Change Procedures","published","2026-07-24T16:21:47.14474+00:00","2026-07-24T16:21:46.86+00:00",{"id":7,"url":27,"slug":28,"title":29},"https:\u002F\u002Fthehackernews.com\u002F2026\u002F07\u002Fcertighost-exploit-lets-low-privileged.html","certighost-exploit-lets-low-privileged-active-directory-users-impersonate-a-doma-283f9b","Certighost Exploit Lets Low-Privileged Active Directory Users Impersonate a Domain Controller",[31,37,43],{"id":32,"name":33,"slug":34,"description":35,"color":36},"05757c8d-6b93-4194-b35d-7359e7d33b0e","Vulnerability Management","vulnerability-management","Missing scans, no risk prioritization","#fb923c",{"id":38,"name":39,"slug":40,"description":41,"color":42},"1ec88fde-2d0f-4ed8-932a-33f5ccc0fdc7","Access Control","access-control","Excessive privileges, missing MFA, weak auth","#f97316",{"id":44,"name":45,"slug":46,"description":47,"color":48},"af7fce9e-1ce8-4156-93bc-09dcfbfdf29d","Patch Management","patch-management","Unpatched vulnerabilities, delayed updates","#ef4444",[50,56],{"id":51,"date":52,"edition":53,"title":54,"audio_url":55},"167c93da-62a7-447b-a185-ef897a93e06d","2026-07-26","afternoon","ThreatNoir Weekend Brief — July 26","https:\u002F\u002Fcdn.threatnoir.com\u002Fpodcasts\u002F2026-07-26\u002Fthreatnoir-afternoon-brief-2026-07-26.mp3",{"id":57,"date":58,"edition":59,"title":60,"audio_url":61},"930bbc16-25e4-42e2-9b08-bcca9eb8f473","2026-07-25","morning","ThreatNoir Weekend Brief — July 25","https:\u002F\u002Fcdn.threatnoir.com\u002Fpodcasts\u002F2026-07-25\u002Fthreatnoir-morning-brief-2026-07-25.mp3"]