Certighost (CVE-2026-54121): How Low-Privilege Users Impersonate Domain Controllers

Certighost (CVE-2026-54121) How Low-Privilege Users Impersonate Domain Controllers

Introduction Active Directory Certificate Services (AD CS) serves as a foundational component in modern enterprise identity environments, facilitating public key infrastructure (PKI), machine authentication, VPN access, and smart card logins. However, misconfigurations and deep-seated flaws in how Enterprise Certificate Authorities (CAs) process incoming certificate requests or resolve directory objects can create severe privilege escalation vectors. The Certighost vulnerability (CVE-2026-54121) exposes a critical breakdown in this identity trust boundary, allowing an

How ClickFix and ConsentFix Subvert Microsoft 365 Sessions in Seconds

How ClIckFIx and ConsentFIx Subvert MIcrosoft 365 SessIons In Seconds

Introduction As organizations fortify their digital infrastructure with robust Multi-Factor Authentication (MFA) and strict conditional access guidelines, threat actors are increasingly shifting away from hacking the systems directly. Instead, modern adversaries exploit the inherent trust mechanisms within legitimate cloud architectures. Among the most dangerous of these emerging threat vectors are the ClickFix technique and its cloud-native evolution, ConsentFix. Operating at the intersection of