The flaws could have let attackers hijack identities and take over domains in environments where Active Directory still runs most enterprise access.
This story is only covered by news sources that have yet to be evaluated by the independent media monitoring agencies we use to assess the quality and reliability of news outlets on our platform. Learn more here.
"ResetNightmare" and "KerberLoss" exploit weaknesses of identity systems in the interpretation of user and service names, potentially disrupting services by attackers, undermining authentication or spending themselves as privileged users. The identity-based cyber resilience and crisis management expert, Semperis, announced that Shai Laron, security researcher at Semperis, has discovered two critical security vulnerabilities in Active-Directory (…