FRIDAY, JULY 24, 2026 48° E  /  GLOBAL TECH · SUMMARISED SUBSCRIBE
AI, business, devices, policy — global tech, summarised every 30 minutes.
Security · 2h ago

Certighost Exploit Lets Low-Privileged Users Impersonate Domain Controllers

By Meridian48 News Desk · Summarised from The Hacker News ·

Researchers published a working exploit on July 24 that allows low-privileged Active Directory users to obtain a Domain Controller certificate. The flaw, named Certighost, enables attackers to authenticate as a Domain Controller and use DCSync to retrieve the krbtgt secret. This grants directory replication rights, posing a severe security risk to enterprise networks.

Meridian48 take
While the exploit requires specific conditions, it highlights a dangerous privilege escalation vector that organizations should patch immediately.
Read the full reporting
Certighost Exploit Lets Low-Privileged Active Directory Users Impersonate a Domain Controller →
The Hacker News
active-directorycertificate-exploit
More security briefs
Go deeper on security
AllAIStartupsBusinessDevicesPolicySecurityDev ToolsPakistan