๐จ ACTIVE EXPLOITATION
- New Certighost PoC exploit enables attackers to hijack Windows domains
A PoC exploit for Certighost lets attackers hijack Windows domains via AD CS.
- Applies to Windows Active Directory Certificate Services (AD CS) before July 2026 patch
- Vulnerability allows low-privileged domain users to impersonate Domain Controllers
- Attack abuses AD CS chase fallback mechanism by spoofing domain controller identity
- Exploit automates certificate request to gain domain controller Kerberos credentials
- Attackers can perform privileged Active Directory operations including DCSync
๐ Coverage: bleepingcomputer.com ยท ๐ Original: bleepingcomputer.com ยท ๐ via BleepingComputer
๐ต๏ธ RESEARCH & DEEP DIVES
-
Confused Deputy Flaws Persist in Google Cloud and Microsoft Azure Confused deputy vulnerabilities allow attackers to gain admin permissions in Google Cloud and Microsoft Azure.
- Affects users of Google Cloud and Microsoft Azure platforms
- Vulnerabilities enable attackers to bypass access controls
- Attackers can escalate privileges to administrative levels
- Exploits involve confused deputy flaws in cloud service authorization
๐ Coverage: darkreading.com ยท ๐ via Dark Reading
-
New AI attack reconstructs typed text from keyboard sounds with up to 99% accuracy Researchers developed an AI attack that reconstructs typed text from keyboard sounds.
- Applies to laptop users across multiple brands including Apple, Dell, HP, and Lenovo
- Reconstructs typed text by analyzing acoustic keystroke sounds without prior victim-specific training
- Attack scenarios include smartphone recording nearby, contact microphones on desks or walls, and audio from online meetings
- Uses unsupervised audio analysis combined with Transformer-based language models and iterative feedback for decoding
- Achieves 90-99% accuracy after capturing 100-250 keystrokes depending on recording method and environment
๐ Coverage: cyberinsider.com ยท ๐ via r/cybersecurity